Jurisdiction and protection against government access
This page exists because the EU Data Act requires it. It says which law the infrastructure falls under, and what stands in the way of your data being handed to a government outside the EU where doing so would conflict with EU or Swedish law. It covers all data, personal and otherwise.
Where the service runs, and under which law
The server and the database sit with Netcup GmbH, a German company, in Germany or Austria. The infrastructure therefore falls under German or Austrian law and under EU law. There is no American cloud provider in the chain holding your database. If you connect one of the integrations listed below, that provider receives the text you send it, but the database stays where it is.
Every customer runs in its own instance with its own database file and its own system user. These are not rows in a shared table.
Backups are held at Netcup and pulled down to hardware in Sweden that bargguo controls. The copies sit in Germany, Austria and Sweden, nowhere else.
The parties who can see anything, and what they see
| Party | What they can see | When |
|---|---|---|
| Netcup GmbH | The server the database sits on. A German company under German law. | All customers |
| Cloudflare, Inc. | DNS lookups for bargguo.com. The records are not proxied, so they are not in the traffic path and see neither the request nor the content. US company. | All customers |
| Cloudflare Email Routing | Incoming messages and attachments, if the customer chose forwarding instead of connecting their own mailbox. | Only by customer choice |
| Slack, GitHub, Linear | The ticket text sent to each service. US companies. | Only if the customer connected the account |
A customer who declines forwarding and the integrations, which is the standard route, has no party outside the EU processing their content.
What stands in the way of a handover to a government outside the EU
Technical
The central database and your active instance sit with a provider inside the EU. bargguo uses no American cloud service to store or run the instances, so there is no party outside the EU holding the database who could be ordered to produce it. If you connect an integration yourself, that provider processes the data sent to it. Each customer has their own database and their own key for stored secrets, so an order aimed at one customer would not reach the data of another. Traffic runs over TLS.
Organisational
Access to an instance is limited to whoever runs the service, and happens only after asking the customer, except where it is needed to fix a fault. Such direct access is recorded in an operations log that is kept and produced on request. Everything done inside the service is written to an audit log the customer reads themselves.
Contractual
A request from a government outside the EU is not complied with until it has been tested against EU and Swedish law. Where the request is not recognised or enforceable under a standing international agreement, and has no basis in EU or Swedish law, nothing is handed over. The customer is told before anything is released, unless the law expressly forbids it, and then as soon as that prohibition lifts.
Sub-processors are named in the data processing agreement. A new one is announced in advance and the customer may object. If we cannot resolve the objection the customer may terminate at no cost and take their data with them.
What we do not claim
No provider can guarantee that a foreign authority will never try. What we can state is where the data sits, who can reach it, what we do before anything is released, and that you will be told. That is also all the regulation asks us to describe.
Backups have been encrypted at rest since 22 September 2026, with a key that has never been on the server. The server holds only the public half, so it can write copies and cannot read them. The private half sits with bargguo, on hardware not reachable from the internet. That a copy really can be read back with that key was proven the same day.
Where this sits in the agreement
The switching clause in the general terms points here. What can be exported and in which formats is on the data export page. Sub-processors, security measures and your right to audit are in the data processing agreement, which travels with the contract.