Every form submission lands on a server, and that server stands in a country with laws. For European businesses — and anyone with European customers — which country has become a genuine compliance question, with a decade of legal history behind it. Here's that story in plain language, what EU hosting actually buys you, and (honestly) what it doesn't.
When someone submits your contact form, their name, email and message are stored wherever your form service keeps its servers — and from that moment the data sits under that country's jurisdiction, reachable by its authorities under its rules. Most of the big form tools are US companies storing data in US clouds. That isn't a scandal; it's just a fact with consequences worth knowing.
GDPR lets personal data leave the EU only with safeguards. For the US specifically, the safeguard keeps getting rebuilt: the Safe Harbor agreement was struck down by the EU's top court in 2015; its successor Privacy Shield was struck down in 2020 (the "Schrems II" ruling); today's Data Privacy Framework has been in place since 2023 — valid as we write this, and challenged through the same legal route that killed the first two.
A business using a US-hosted form tool is not doing anything illegal — it's relying on that framework (or on standard contractual clauses and its own transfer assessment). It works, but it's paperwork plus a dependency on an agreement with a mortality record.
Honesty where the marketing usually isn't: EU hosting is not GDPR compliance. Compliance lives in your practices — what you tell people, what you collect, how long you keep it, how you answer rights requests. A US-hosted form with tight practices beats an EU-hosted one used carelessly. Hosting location removes one moving part; it doesn't move the others for you.
hform stores every submission on our own server in Stockholm, Sweden — not a US cloud region labeled "EU", our own hardware in our own country. One honest nuance, the kind you should demand from any provider: the notification emails that alert you to new messages are delivered via Postmark (USA) under EU standard contractual clauses, exactly as our privacy policy and DPA disclose. The stored data itself never leaves Sweden. If a form provider can't tell you where storage ends and delivery begins, that's your signal to ask more questions.
No. EU–US transfers are lawful under the Data Privacy Framework or standard contractual clauses. EU hosting simply removes that dependency: there’s no framework to rely on and nothing to re-paper if the framework is struck down, as its two predecessors were.
It’s valid as of August 2026, and many businesses do. Its two predecessors — Safe Harbor and Privacy Shield — were both struck down by the EU’s top court, and the current framework faces the same style of challenge. Relying on it is legal; treating it as permanent is optimistic.
No — compliance is about your practices: what you tell people, what you collect, how long you keep it, how you honor rights requests. EU hosting removes the transfer question, which is one real piece of the puzzle, not the puzzle.
Submissions are stored on our own server in Stockholm, Sweden. Notification emails are delivered via Postmark (USA) under EU standard contractual clauses — disclosed in our privacy policy and DPA. The stored messages themselves never leave Sweden.
Build a form in two minutes: EU-hosted (Sweden), automatic retention limits, CSV export, published DPA. The honest part stays yours; the plumbing is done. Free plan included, plain pricing beyond it.
More on forms and privacy: GDPR for forms · Consent checkboxes · Data retention · The privacy note — or see all guides.
This guide is plain-language orientation, not legal advice. For edge cases — special-category data, children's data, large-scale processing — talk to someone who does this for a living.