Data Jurisdiction & International Access
This page is published by Inovacijų dialogas, MB (operating the Vantemo platform) under Article 28 of the EU Data Act (Regulation (EU) 2023/2854). Article 28(1) requires a provider of data processing services to make publicly available, for each of its services, the jurisdiction to which the ICT infrastructure deployed for the service is subject, together with a general description of the measures it takes to prevent unlawful international governmental access to, or transfer of, non-personal data held in the Union. Article 28(2) requires this information to be referenced in customer contracts; that cross-reference is contained in Article 14 of our Data Processing Agreement.
The Data Act obligation concerns non-personal data (for example product catalogues, store content, configuration, logs, and aggregate analytics). The processing and international transfer of personal data is governed separately by our Data Processing Agreement, Privacy Policy, and the Sub-processor List, under Chapter V of the GDPR. The jurisdiction disclosure below covers both, because the same ICT infrastructure processes both categories.
How to read the jurisdiction column
For each component we show both where the data is physically processed and the jurisdiction the provider — and therefore its infrastructure — is legally subject to. These are not always the same. A provider incorporated in the United States remains subject to United States law (including the U.S. CLOUD Act) even when the data it holds is stored in the European Union. Where that is the case we state United States in the jurisdiction column and describe, further below, the safeguards that apply.
ICT infrastructure — jurisdiction per component
| Service component | Provider | Processing region | Jurisdiction the infrastructure is subject to |
|---|---|---|---|
| Application compute / servers | Hostinger | Lithuania (EU) | Lithuania / EU |
| Primary database (PostgreSQL) | Self-managed by Vantemo on Hostinger infrastructure | Lithuania (EU) | Lithuania / EU |
| Session & cache store (Redis) | Self-managed by Vantemo on Hostinger infrastructure | Lithuania (EU) | Lithuania / EU |
| Object storage (Cloudflare R2) | Cloudflare Inc. | Western Europe (placed by a best-effort location hint — not a contractual EEA-residency guarantee) | United States (Cloudflare is US-incorporated and subject to US jurisdiction, including the CLOUD Act) |
| CDN, DNS, DDoS mitigation, TLS termination | Cloudflare Inc. | Global edge network; EU points of presence serve EU traffic | United States |
| Transactional & marketing email | Amazon Web Services — Simple Email Service (SES) | eu-north-1 (Stockholm, Sweden; EU) | United States (AWS is US-incorporated and subject to US jurisdiction; data resides in the EEA) |
| Email-event message queue | Amazon Web Services — SNS / SQS | eu-north-1 (Stockholm, Sweden; EU) | United States (data resides in the EEA) |
| Platform & product analytics | PostHog Inc. | Merchant-dashboard analytics on PostHog Cloud US; marketing-site analytics on PostHog Cloud EU (Frankfurt) | United States |
| Platform & merchant payment processing | Stripe Inc. | United States / EU | United States |
| Storefront payment processing (where enabled by the merchant) | MakeCommerce (Maksekeskus AS) | Estonia (EU) | Estonia / EU |
| SMS delivery | Twilio Inc. | United States | United States |
| Error monitoring & performance tracing | Sentry (Functional Software, Inc.) | United States | United States |
| AI assistant, retrieval embeddings & ad-creative generation | Anthropic PBC · OpenAI, L.L.C. · Google LLC (Gemini API) | United States | United States |
| Machine translation | DeepL SE | Germany (EU) | Germany / EU |
The authoritative stores of record for customer store data — the primary database, session store, and application servers — are located within the European Union (Lithuania). The US-jurisdiction components above are engaged for specific functions (email delivery, object storage, edge delivery, payments, SMS, monitoring, AI, and analytics) and receive only the data necessary for those functions. The always-current provider list, with the corresponding personal-data transfer mechanisms, is maintained on the Sub-processor List and in Annex B of the DPA.
Measures against unlawful international governmental access
The following is a general description of the technical, organisational, and contractual measures we adopt to prevent international and third-country governmental access to, or transfer of, non-personal data held in the Union where such access or transfer would create a conflict with Union law or the national law of the relevant Member State (Data Act Article 28(1)(b)):
- EU residency of the stores of record. The primary database, the session/cache store, and the application compute that hold and process customer store data — including non-personal data such as product catalogues, store content, and configuration — are hosted and processed within the European Union (Lithuania). Data at rest for these systems does not leave the EEA through our own infrastructure.
- Encryption. All data in transit is encrypted using TLS 1.2 or higher; sensitive fields, secrets, and backups are encrypted at rest. See Annex C of the DPA for the full technical and organisational measures.
- Contractual safeguards with US-jurisdiction providers. Where a component is provided by a US-incorporated provider, we rely on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, where the provider is certified, the EU-US Data Privacy Framework, together with data-processing agreements that impose confidentiality and lawful-access obligations that flow down to any onward sub-processors.
- Data minimisation. US-jurisdiction providers receive only the data necessary for their specific function. The authoritative copies remain in the EU; US-hosted components hold working, derived, or transmission copies rather than the primary stores of record.
- Response to governmental access requests. Where we or one of our providers receive a request from a third-country authority for non-personal data held in the Union, our posture is to: (a) require the request to be based on a valid, legally binding instrument; (b) assess whether complying would conflict with Union law or the national law of the relevant Member State; (c) where such a conflict exists, challenge the request through the legal channels available and disclose only the minimum required by a final, enforceable order; and (d) where legally permitted, notify the affected customer. Our sub-processor contracts require equivalent commitments.
- No routine outbound transfer. We do not routinely transfer non-personal data outside the EU through our own infrastructure. Third-country processing occurs only through the listed providers, for the specific functions set out in the table above.
Requests & contact
To request the applicable transfer documentation, the identity and location of downstream sub-processors, or further detail on any measure described above, contact [email protected].
Change history
| Date | Change |
|---|---|
| 8 July 2026 | v1.1 — Initial publication of the Data Act Article 28 jurisdiction and international-access disclosure. Pending counsel review. |