Does the US CLOUD Act reach your "EU-hosted" email provider?
"EU-hosted" gets used to mean two different things, and the difference matters more than it looks like on a pricing page. One meaning: the servers are physically in the EU. The other, stronger meaning: the company operating those servers isn't subject to US legal process that could compel data disclosure regardless of where the servers sit. The US CLOUD Act is specifically why that second meaning matters.
What the CLOUD Act actually does
The US CLOUD Act (2018) clarified that US law enforcement can compel a US company, or a company otherwise subject to US jurisdiction, such as a US subsidiary, to produce data it controls, regardless of where that data is physically stored. A US-headquartered provider running EU data centers doesn't escape US legal process just because the servers are in Frankfurt; the compellable party is the company, not the hardware.
Why this surprises people evaluating "EU-hosted" vendors
The instinct is to treat data center location as the whole answer to "is my data subject to US jurisdiction," because that's the variable most pricing pages and marketing copy actually highlight. Corporate structure, who legally controls the company operating those servers, is a separate and arguably more decisive variable, and it's much less visible on a typical vendor comparison page. A US cloud giant's EU region is still, legally, a US company's infrastructure.
The practical distinction worth asking about
This is genuinely a legal question with real nuance, not something a vendor's blog post should present as settled law, and this isn't legal advice. Two things matter: whether a US parent controls the company, and whether the US has a bilateral data-access agreement with the country where the company is incorporated. Envello is operated by AKTAI LTD, a private limited company registered in England and Wales, with no US parent controlling it. That answers the first question cleanly. The second is worth being specific about rather than glossing over: the US and UK have had a bilateral CLOUD Act Executive Agreement in force since July 2020, giving US and UK law enforcement a faster route to compel data from each other's providers than exists between the US and most other countries, including EU member states, where no equivalent agreement is in place today. So a UK-incorporated provider and a fully EU-incorporated one aren't in an identical legal position on this specific question, even though neither has a US parent. What doesn't change: Envello's data itself is stored on EU infrastructure (AWS SES eu-central-1), a separate question from where the operating company is incorporated, covered above, and any request under the UK-US Agreement still goes through that agreement's own process rather than a unilateral one.
How this interacts with SCCs and subprocessors
Corporate jurisdiction and data transfer mechanisms are related but distinct questions. Standard Contractual Clauses (covered in their own post) govern lawful transfer of data to a subprocessor outside the EEA; they don't change which government can compel the primary vendor itself. Even a fully EU-incorporated company could still use a US-based subprocessor for some narrow function, in which case the SCC question and the corporate-jurisdiction question both apply, to different links in the chain.
What to actually ask a vendor
- Is the entity you're contracting with EU-incorporated, UK-incorporated, or a subsidiary of a US parent? Each sits in a different legal position
- "EU-hosted" alone doesn't answer the jurisdiction question, ask specifically about corporate structure and country of incorporation, not just data center location
- If the entity is UK-incorporated, ask whether the US-UK CLOUD Act Agreement (in force since 2020) matters for your case, it's a faster channel than exists between the US and most other non-US countries
- If any subprocessor in the chain is US-based or US-owned, what transfer mechanism (SCCs, typically) governs that specific relationship
- If this matters materially for your compliance posture, get a specific, written answer rather than inferring it from marketing language