Skip to content

EU and Privacy

A platform you can defend
to a client's legal team.

Belgian company under EU jurisdiction. Customer data hosted in the EU. GDPR consent built into the platform. Your client's compliance posture becomes part of the platform you choose, by architecture rather than by a setting someone has to remember to switch on.

EU law is the law that applies to your client's data

Nimbu is built and run by Zenjoy, a Belgian company under EU jurisdiction, regulated by the APD (Autorité de protection des données / Gegevensbeschermingsautoriteit). Customer data is hosted in the EU.

01

Which legal system has authority

Most platforms answer the privacy question with where the servers happen to sit this quarter. The question underneath it is which legal system has authority over the company holding the data. For Nimbu, that system is European, and it does not change when a data-transfer framework is renegotiated or struck down in court.

02

Jurisdiction is not a configuration screen

A US-incorporated vendor can host EU data in Frankfurt and still answer to a different legal system. A Belgian company under the APD answers to one. That distinction is structural. It is not something a region setting in a control panel can replicate.

03

One answer to give the DPO

When a client's DPO or legal team asks where the data lives and who can reach it, you want a clean answer in the proposal rather than a research project. Belgian company, APD jurisdiction, EU-hosted data. That is the answer.

That ordering matters.

Server location and legal jurisdiction are two different questions

This is the structural fact, stated once and plainly. Any CMS or commerce platform incorporated in the United States is reachable by US authorities under the CLOUD Act, regardless of where its servers are located.

What the CLOUD Act does

The US CLOUD Act (2018) lets US authorities compel a US-incorporated company to produce data it controls, even when that data is stored on infrastructure in the EU. This is a fact about how those companies are organised as legal entities, not a claim about any specific vendor.

Why it surfaced publicly

In 2025, Microsoft France testified before the French Senate that it could not guarantee EU customer data would never be transferred to US authorities, because the parent company is subject to US law. The server region was European. The jurisdiction was not.

What this means for your client

Server location and a Data Privacy Framework certification address transfer mechanics. They do not change which legal system has ultimate authority over the company. A Belgian company under EU jurisdiction is a different answer to a different question, and it is the answer you can put in writing.

Server region was European. The jurisdiction was not.

Native consent

One tag replaces a third-party consent tool

Consent ships with the platform. You model purposes, applications, and cookies once, with required, opt-out, and default flags, and translatable copy for every locale. Then you drop one Liquid tag into any theme. The consent banner renders privacy-first, served from Nimbu's CDN.

What this removes is a whole class of audit risk. A bolted-on consent tool is a separate vendor with a separate contract that drifts out of compliance when nobody is watching it. When consent is part of the platform, it is part of every site you ship, by default.

  • Model purposes per site Required, opt-out, and default flags with translatable copy for every locale.
  • CDN-served banner Script served from Nimbu. No third-party CMP to license, configure, or keep current.
  • Ships on day one Every site you build handles consent from the moment it goes live, in every language.
theme/layout.liquid
{% comment %} drop once in your layout {% endcomment %}
$ {% consent_manager %}
banner rendered, all locales, CDN-served
# no third-party CMP, no tag manager wiring
consent purposes: analytics, marketing, functional

Sensitive fields encrypted at rest, keys held in the EU

Sensitive customer fields are encrypted at rest, with the keys held in the EU. To be precise about scope, because precision is the point: this is field-level encryption for designated sensitive fields, not full-database encryption.

The encryption is part of the data model. When you model a channel, an encrypted field type is available alongside text, select, relation, and date. Sensitive data is handled at the storage layer rather than patched in afterward.

  • Part of the data model Encrypted field type available at channel creation, not retrofitted.
  • Keys held in the EU EU key management. Not a US-incorporated parent under the CLOUD Act.
  • Honest about scope Field-level encryption for designated sensitive fields. That is what we claim and what we deliver.
A request path from visitor to site to data store, staying entirely inside the European boundary

The answer you can hand to a client's legal team

When a client signs with your agency, they inherit the compliance posture of the platforms you build on. A platform with EU jurisdiction, EU-hosted data, and field-level encryption of sensitive data is a posture you can hand a client without a caveat.

  • Belgian company under APD jurisdiction

    EU law is the law that applies to your client's data, by structure not by setting.

  • Customer data hosted in the EU

    Not a region setting. EU-hosted by default for every site on the platform.

  • GDPR consent built in

    One consent_manager tag. CDN-served banner. No third-party CMP to license or audit.

  • Sensitive fields encrypted with EU-held keys

    Field-level, honest scope. Part of the data model from day one.

  • Not a US-incorporated entity under the CLOUD Act

    A structural fact about how Nimbu is organised. It is the answer you put in writing.

  • DPA and subprocessor list available on request

    The procurement document set a client's legal team will ask for, at /security.

Proposal ready

A block you can paste into a client proposal

This uses only claims Nimbu stands behind. Copy it into an RFP response or a proposal as-is. Do not extend it to claims Nimbu does not make.

Data protection and EU jurisdiction

This site is built on Nimbu, a European site and commerce platform operated by Zenjoy, a Belgian company. As an EU-incorporated company, Nimbu is under EU jurisdiction and is registered with the Belgian data protection authority (APD, Autorité de protection des données / Gegevensbeschermingsautoriteit).

  • Hosting: Customer data is hosted in the EU.
  • Consent: GDPR consent and cookie management are built into the platform, including a CDN-served consent banner configured per site and per language.
  • Encryption: Sensitive customer fields are encrypted at rest, with encryption keys held in the EU.
  • Jurisdiction: As a Belgian company under EU jurisdiction, Nimbu is not a US-incorporated entity subject to the US CLOUD Act.

A Data Processing Agreement (DPA) and a current subprocessor list are available on request.

Keep it factual and keep it inside these lines.

When the client's legal team asked where the data lived and who could reach the authenticated parts, we had the EU jurisdiction and APD answer in the proposal, and the platform that actually delivered the portal.

Technical lead, Zenjoy

Book a demo and bring a real client scenario

We will walk through jurisdiction, EU hosting, built-in consent, and field-level encryption against the kind of question your client's legal team is going to ask you. 30 minutes. A personal reply.

Request received.

We read every request personally and will get back to you to schedule the call.

Book a demo

We reply personally to plan a 30-minute call.