---
title: "Sovereignty is recursive, and my suppliers are my customers"
url: "https://palumb.com/blog/sovereignty-is-recursive"
description: "Jurisdiction follows the company, so it follows the whole chain. What I verify, what no page can, and why my sub-processor list read backwards is a list of the customers I want."
---

[← Blog](/blog/)

# Sovereignty is recursive, and my suppliers are my customers

![](/adriano-foschi.webp)

[Adriano Foschi](/about/)

28 August 2026

![A crowned pigeon seen from behind in a dark panelled room, facing its own reflection in a tall mirror with a green frame, a violet curtain drawn back at the right.](/blog/sovereignty-is-recursive.webp)

**Residency is where the bytes sit. Sovereignty is which law reaches the company holding them.** That distinction is the reason Palumb exists, and the long version, written for the people who have to sign, is on [the jurisdiction page](/eu-jurisdiction/).

This post is about the part that page does not cover: the distinction does not stop at my suppliers. It keeps going down.

## Jurisdiction follows the company, and companies have suppliers

If a vendor is incorporated in the United States, a US warrant reaches the data in its possession wherever that data physically sits. Everyone in this market now knows that argument. The version nobody puts on a landing page is the next step: a European vendor whose database runs on an American parent’s infrastructure hands the same exposure back to you, one level down.

Nobody did anything wrong there. Jurisdiction is a property of a company, and my supplier has suppliers of its own, each with a country and an owner. So sovereignty is not a property of a vendor. It is a property of a **chain**, and a chain is only as sovereign as its weakest link.

That is why the second question on [the sub-processor page](/sub-processors/) weighs as much as the first. Where are you incorporated, and whose infrastructure do you run on. Incorporation and hosting have to point the same way, or the answer is residency wearing the other word.

## What I verify, and what no page can

Level one I verify at primary sources, which means legal documents, company registers, licence files, the vendor’s own DPA. Never an aggregator, and never a list of European alternatives. Ten companies, each with its country of establishment and the company that ultimately owns it, in public. That is what the ownership column on that page is for.

Level two I follow **where the supplier publishes it**, and today four of them do:

| Supplier | What it publishes about its own chain |
| --- | --- |
| Simple Analytics (NL) | Worldstream, Leaseweb, Intention (NL), Hetzner (DE), Bunny (SI), Hyperping (FR) |
| Phare (EE) | Hetzner (DE) for the application and database, Bunny (SI) for CDN and monitoring agents, Scaleway (FR) for backups and email, Brevo (FR) and Lettermint (NL) for email, Mistral AI (FR) for incident summaries, Vemetric (AT) for analytics, Paddle (IE) as merchant of record |
| Bugsink (NL) | Hetzner (DE) for hosting, Scaleway (FR) for transactional email, Stripe for payments only |
| Formward (SE) | Hostup (SE) for servers and database, Sinch and Mailjet (FR) for notification email, Stripe for billing |

Then it stops, and I would rather say so than imply otherwise. My list names the companies **I have a contract with**, with the scope, the place of processing and the ultimate owner. It does not document the chain below them, and it never will: a recursive list is impossible to keep true, and a list that is wrong is worse than a list that is short. What governs the level below me is my contract with the level above it, not a page on my website.

So the honest claim is a small one. Level one verified and published, level two followed where the supplier publishes it, and the promise without exceptions kept where it belongs, which is the path your notification data travels.

## Where my own chain is not clean, and it is the leg you are on

If you joined the waitlist, your email address sits with Sendinblue SAS, a French company trading as Brevo. Annex 2 of its terms, checked again on 7 September 2026, lists OVH in France and Google Cloud with servers in Belgium for hosting, and then Cloudflare, Zendesk and Omni, which are American companies. That is the one leg of my own chain where the second level is mixed, and you should hear it from me.

The perimeter, stated: that supplier holds an email address you typed into a form, and nothing else, ever. No notification data can reach it, because the delivery path does not touch it.

I chose it anyway, and here is the reasoning. I went through that category at the source, and no mainstream provider in it avoids the American hyperscalers. One candidate markets itself as Germany only, and its own DPA says the data is stored and processed on AWS. Another has a very short chain and it is Google from end to end. Brevo is the one with European iron in the mix, it is French, and it covers the whole cycle in a single supplier.

Payments are the structural exception, and they are nobody’s to fix. The card networks are American for every vendor on earth, European or not. Creem, an Estonian company, is the merchant of record, so it handles the card and Palumb never does. Two other suppliers name Stripe at level two, and in both cases the scope is billing: no form content, no error events, no application data.

I publish these four paragraphs because I apply the same test to the vendors I write about on the comparison pages. A criterion you use on other people has to survive being turned around, and the version you declare yourself costs less than the version a reader finds.

## My suppliers are my customers

Read my sub-processor list backwards and it is a list of the customers I want. Phare, Simple Analytics, Bugsink, Creem: small European SaaS companies, technical, run by people who as buyers have already made the argument I am making to you. They are also my suppliers, and I would rather look at that in the face than discover it later.

One of them is the whole thesis in miniature. Bugsink ships self-hostable, and I pay for the hosted version. That is exactly the choice I ask a Palumb customer to make, which is why [the self-hosting page](/self-hosting/) says it plainly: it is easy, here is how, and I would not do it myself. Maintaining something has a running cost, and it rarely pays for a team that does not do notifications for a living.

This is what I mean when I say sovereignty is recursive. I cannot audit the chain below me, and neither can you. What makes a chain sovereign all the way down is not a page: it is **each link buying the way it sells**. If every European SaaS applies at level one the test its own customers apply to it, the property propagates without anybody publishing an audit that reaches the bottom. An ecosystem that buys from itself holds the line that no single vendor can hold alone.

It is a market, not a manifesto, and it costs. Choosing the analytics for this site alone ruled out four candidates: three on price, in a phase where I pay for nothing that is not necessary, and one because it does not publish which company it is. A fifth counted as European on a list of European alternatives, because it is self-hostable, while the licence file in its own repository said San Francisco. That rule is also the reason I can be checked: the criteria are written down, the list is public, and you get to run the same test on me.

If you know something about one of these companies that I do not, or one of these entries is wrong, tell me at [privacy@palumb.com](mailto:privacy@palumb.com). A list is worth exactly as much as its accuracy.

Everyone who joins gets in, and it costs nothing. Your invite goes out when the beta opens.

[Join the beta](/waitlist/)