How Dossira Describes Data Location
The current hosting statement
Dossira is provided by a Norwegian company. Customer data and user identities are hosted on Hetzner infrastructure in Germany and Finland. Dossira does not use AWS, Microsoft Azure or Google Cloud for this hosting.
That is a hosting statement. It should not be expanded into a claim that hosting location alone guarantees sovereignty, GDPR compliance, immunity from lawful access, or a particular operational-access model.
Separate the questions in a review
A procurement or security review should distinguish:
- where file payloads and application data are stored;
- where identity data is stored;
- which subprocessors support the service;
- which personnel can obtain operational access and under what controls;
- which contractual and legal terms apply.
The Security & Privacy Hub and legal documents should be used for the current details. If a required fact is not stated there, request clarification rather than inferring it from the word “European.”
Verification has limits
Dossira does not currently expose a customer-facing audit ledger that proves the location or identity of every operational access event. Public copy must not imply otherwise. Hosting documentation, contractual terms, subprocessor information, and direct due-diligence answers are the appropriate evidence paths for the private preview.
Read the current data-hosting details before relying on the hosting statement in a procurement or security review.