The questions your legal team will ask.
Residency is where the bytes sit. Sovereignty is which law reaches the company holding them. Every serious vendor in this category can keep your data in Europe; what none of them can move is the jurisdiction of the company itself, because that follows incorporation and not geography.
This page is the long version, written for the people who have to sign: what compels whom, why an adequacy decision answers a different question, and what passes through our hands.
A map of Europe with seven marked countries: Italy for founder, France for cloud, data, Germany for domain, mail, Netherlands for monitoring, Slovenia for CDN, Sweden for contact form, Estonia for payments. Every one of them is inside the European Union.
Last updated:
Who can be compelled to hand over data?
The company, not the data centre. A provider incorporated in the United States answers to a US warrant for data in its possession or control wherever that data physically sits: that is the CLOUD Act, and an EU region does not change it. The same logic applies to any non-EU parent: a European subsidiary with a foreign owner has two governments in the room.
Two limits worth knowing, because they keep this a fact rather than a scare. The CLOUD Act's executive agreements (the ones that let a foreign authority request directly) exist with two countries only, the United Kingdom and Australia (checked 17 August 2026). And mutual legal assistance treaties exist almost everywhere, Italy included: they are slower, court-supervised, and they are not the same instrument.
Palumb has no parent in another jurisdiction. There is one company law in the room, and it is European. That is a structural property, not a policy we could quietly change, which is the only kind of promise worth reading.
Doesn't an adequacy decision settle this?
It settles a different question. An adequacy decision says a transfer to that country is lawful: it does not say who can compel the company once the data is there. Those are two different sentences, and procurement usually needs the second one answered.
It is also revocable. The Privacy Shield framework was invalidated in 2020, and every arrangement built on it had to be redone. Inside the Union there is nothing to authorise and nothing to withdraw.
And the current one is under review. On 29 June 2026 the US Supreme Court held in Trump v. Slaughter that the President may remove Federal Trade Commission commissioners at will, and the adequacy decision behind the EU–US Data Privacy Framework rests in part on the independence of those commissioners, which it cites at §58–60. On 31 July 2026 the Chair of the European Data Protection Board wrote to the Commission asking it “to closely assess whether this development affects the functioning of Commission Implementing Decision EU 2023/1795”, the decision that makes EU-to-US transfers lawful.
It still stands, and those transfers are still lawful. We are not telling you otherwise, and a vendor page that implied it would be wrong. What we are telling you is that this is the third framework in the series (Safe Harbour and Privacy Shield were both struck down), and the body that coordinates every data protection authority in the Union has asked for the third to be looked at again. That letter is public. A supplier inside your own jurisdiction does not depend on it, because there is no transfer to authorise.
Vendor by vendor, the specifics (where each company is incorporated, its registration number, whose infrastructure runs its EU region) are on the comparison pages, each with the date it was checked and the source it came from.
What passes through our hands
Half of this answer is architecture rather than policy: we do not hold your templates because we never receive them.
We hold
- Subscribers and topics. Who is subscribed to what, with the contact details you send us.
- The run journal. Each step of a workflow and its result, which is what lets a run survive a restart.
- Delivery attempts. What was sent, when, and what the provider answered.
- Provider credentials. Your SMTP or API keys, encrypted at rest and scoped to your tenant.
We never do
- Your workflow logic. It runs in your deployment. We call it; we never store it.
- Your templates. Your engine renders them and hands us the output. There is no template store here.
- Your sending reputation. Delivery goes out on your credentials, never from a shared Palumb pool.
Every company that touches any of this is named, with who owns it, on the sub-processors page.
This page is an account of the law, not legal advice. It sets out who can compel whom, and where each company sits, with the source and the date beside every claim. It does not tell you what to do about it, and it is no substitute for a lawyer who knows your situation. Everything here is stated as fact, and we will correct any of it that turns out to be wrong: write to us.
Everyone who joins gets in, and it costs nothing. Your invite goes out when the beta opens.
Join the beta