Skip to main content

European Sovereignty

Which companies can touch your data, where it lives, and what your money builds.

Last updated 3 Aug 2026

An EU Region Is Not Sovereignty

An EU region of an American cloud is not the same as EU privacy rights. The US CLOUD Act obliges American companies to hand over data they hold regardless of where the server stands. A Frankfurt datacenter with an American owner is still within its reach, and GDPR compliance alone does not change that.

Tilery is built the other way around: we run on infrastructure that is both European-owned and hosted in Europe. There is no US company between you and your maps, except the usual payment infrastructure.

The Companies Behind the Service

ProviderWhat they doOwnership
ScalewayAll hosting: servers, databases, storage, outbound emailScaleway SAS, France (part of the Iliad Group)
CreemPayments, as merchant of recordArmitage Labs OÜ, Estonia
ProtonSupport inbox (support@tilery.eu)Proton AG, Switzerland (EU adequacy decision)

That is the whole list. Everything else the service needs (captcha, logging, metrics) runs self-hosted on that same Scaleway infrastructure, operated by us.

Where Your Data Lives

In the European Union. Our infrastructure runs in Scaleway’s EU regions, spread across multiple availability zones, and map tiles are served from dedicated servers we operate there. Database backups use Scaleway’s managed backups, kept in the same region as the database. Nothing leaves the EU.

Loading the map…

The map above is served by Tilery itself, from the infrastructure it describes. Click a pin for who sits there.

What We Deliberately Don’t Use

  • No US CDN or edge proxy in the request path: your tile traffic is never routed through an American network.
  • No third-party captcha. No reCAPTCHA, no Cloudflare Turnstile. Our captcha is self-hosted, so sign-in traffic never leaves our origin.
  • No tracking scripts or third-party analytics on this site.
  • No external font or asset CDNs. Every byte of this site is served from our own origin: fonts, scripts, styles.

No Transfer Mechanisms, Because No Transfers

We do not rely on the EU–US Data Privacy Framework or Standard Contractual Clauses to move customer data to the United States: there are no such transfers to legitimize. The Framework’s two predecessors, Safe Harbor and Privacy Shield, were both struck down by the EU Court of Justice; if the current one falls too, nothing about Tilery changes.

The Other Half: Building It

Privacy is the defensive half of sovereignty. The other half is what your money builds. “There is no European AWS” is partly a demand problem: every European company that defaults to a US cloud starves the alternatives of exactly the revenue that would make them competitive. We spend the other way. Every infrastructure euro Tilery spends goes to a European company, a claim you can audit against the table above.

This is not sentiment; it is resilience. Service cutoffs happen, export rules shift, and an internet that runs on three clouds has three points of failure. Keeping other providers viable is what keeps any of them substitutable. Our own map stack is the honest example: we build on OpenStreetMap because no small company could produce planet-wide map data from scratch. The open commons is what makes a shop like ours possible at all, and the principle comes free with it: an open map stack cannot be held hostage, by us or by anyone else.

When you buy tiles from us, that is where the money goes: into the European tech economy, not out of it.

Honest Boundaries

A sovereignty claim is only worth what it excludes, so here is where the boundary actually sits:

  • Creem’s own stack runs partly on US-owned infrastructure. Our merchant of record is Estonian-owned, but they publish no subprocessor list, and their site and API sit behind American hosting and CDN providers. Checkout data (name, email, billing country, payment details) is processed under Creem’s privacy policy and may transit or be stored on US-owned systems. Your card number never reaches Tilery’s infrastructure at all.
  • Card payments run on global networks. Visa and Mastercard are US companies, as they are for every European service that accepts cards.
  • TLS certificates are issued by Let’s Encrypt, a US non-profit. Certificate issuance involves no customer data.
  • Map data comes from OpenStreetMap, packaged by the Protomaps project. That is inbound public data; nothing of yours travels the other way.

Who We Are

Tilery AS is a Norwegian company (org. nr. 837 547 652). Norway is part of the EEA, so the GDPR applies to us directly, under the supervision of Datatilsynet, the Norwegian Data Protection Authority. What data we collect and why is spelled out in our Privacy Policy.