GUIDE · DATA PROTECTION
EU-hosted team wiki: what to check for GDPR
A team wiki ends up holding names, customer details, internal procedures and sometimes passwords that should not be there. If you are in the EU, where that data sits and who can touch it matters. These are the questions to ask any provider, with BookHost’s own answers as a worked example.
Last reviewed .
“EU-hosted” is only the start
Many services say they host in the EU. That usually describes where the main servers are. It says nothing about the payment provider, the email service, the support tool, the AI feature or where backups are copied. Under the GDPR, a wiki provider that stores your content on your behalf is a processor, and you need to know the whole chain.
This page is practical guidance, not legal advice. For a formal assessment, involve your data protection officer or a lawyer.
Six things to check
1. Where the wiki and its database run
Ask for the hosting company and the countries, not just “Europe”. A provider that names its infrastructure partner and locations is easier to assess than one that does not.
2. A data processing agreement you can read
Art. 28 GDPR requires a contract between you and any processor. Look for a document you can download before you sign up, not one you have to request after paying. Check that it covers instructions, confidentiality, security measures, help with data subject requests, breach notification, and return or deletion at the end.
3. The list of sub-processors
Every service the provider uses to handle your data should be named, with its role and processing location. Check how you are told about changes and whether you can object. Pay attention to anything outside the EU and the legal basis used for that transfer (Art. 44 onwards GDPR).
4. Where backups live
Backups are copies of everything. Ask where they are stored, whether they are encrypted, how long they are kept, and whether they sit on the same machine as the live data. A backup in another country can change your assessment even when the main server is in the EU.
5. How you get your data out
Portability is part of good data handling and your bargaining position as a customer. Ask what export formats exist, whether exports include attachments, users and permissions, and whether you can get a full copy that restores elsewhere.
6. How and when data is deleted
Ask for concrete periods: when live data is deleted after the contract ends, when backup copies expire, and whether you can ask for earlier deletion and a written confirmation.
How BookHost answers these questions
BookHost hosts BookStack, the open-source wiki. Here is what our published documents say. The legal documents themselves are in German.
| Question | BookHost |
|---|---|
| Hosting location | Hetzner infrastructure in Germany or Finland. Processing of instance and backup data at Hetzner is limited to those two countries. |
| Processing agreement | A data processing agreement under Art. 28 GDPR is published at /legal/avv and accepted at sign-up. |
| Sub-processors | Listed in Annex 3 of the agreement, with role and location. We announce new or replaced sub-processors at least 30 days in advance, and you can object. |
| Backups | Daily, encrypted, on Hetzner in Germany or Finland. Backups older than seven days are removed at the next daily retention run. Currently on the same server as the workspaces. |
| Exports | BookStack content exports during the subscription, plus on request a database dump and file archive with a manifest. |
| Deletion | Active instance data within 30 days after the contract ends; protected backup copies within a further seven days. Earlier deletion on request. |
The providers outside the core hosting
Hosting in the EU does not mean every service processes data only in the EU. The agreement names these providers:
- Hetzner Online GmbH (Germany): infrastructure and storage for workspaces and backups.
- Stripe Payments Europe (Ireland): payments, subscriptions and the customer portal. Stripe acts as its own controller for its payment and regulatory tasks, receives billing data rather than wiki content, and can process data internationally.
- Google Ireland: only if you choose Google sign-in for the BookHost dashboard. Password sign-in remains available. Google can process data internationally.
- Resend Inc. (USA): transactional email such as password resets and notifications, with EU data processing under standard contractual clauses.
- TensorX Limited (Ireland): AI processing for the document intake and “Ask your wiki” betas. TensorX’s documented GPU infrastructure is in Dublin and Helsinki. It also serves the optional semantic wiki indexing (beta), which stays off until an owner or admin switches it on. Nothing is sent to TensorX unless someone uses or activates these features. Until the updated processing conditions are independently verified, use the betas only with non-personal content.
What we do not claim
- We do not advertise any security certification.
- We do not claim encryption of every active disk or end-to-end encryption; backups are encrypted before storage and public access uses TLS.
- We do not offer a contractual availability commitment or a fixed restore time.
- Backups are not yet copied to a second location.
The details are on our backups and recovery page and in the privacy policy.
Your side of the work
Even with a careful provider, some of the job stays with you:
- Record the wiki in your record of processing activities.
- Decide what does not belong in the wiki, such as passwords, health data or HR files, and tell the team.
- Use BookStack roles and book permissions so client and HR material is only visible to the people who need it.
- Remove leavers’ accounts promptly.
- Keep your own exports if you need copies beyond the provider’s retention.
- Review the sub-processor list when you are notified of a change.
Moving an existing wiki
If you already run BookStack on a server outside the EU, or on a machine you would rather not maintain, the migration page explains the two files we need and what we do not migrate. Moving from Confluence? Our BookStack vs Confluence comparison covers that route. Pricing and the free trial are on the pricing page.
Frequently asked questions
Does using BookHost take care of GDPR for us?
No provider can make your use of a wiki compliant on your behalf; you remain the controller for what your team stores. BookHost offers a data processing agreement under Art. 28 GDPR, core hosting and backups at Hetzner in Germany or Finland, and a published list of service providers. Our descriptions of processing are not a legal assessment.
Does any data leave the EU with BookHost?
Wiki content and backups at Hetzner are processed in Germany and Finland. Stripe payments and optional Google sign-in can involve international processing, and transactional email is sent through Resend Inc. (USA) with EU data processing under standard contractual clauses. The AI betas use TensorX in Ireland and should only be used with non-personal content for now.
Where are BookHost backups stored?
Daily encrypted backups are stored on Hetzner infrastructure in Germany or Finland. Today they live on the same server as the workspaces; a copy at a second location is in preparation and not yet in operation.
What happens to our wiki when we cancel?
You keep normal access until the end of the billing period, so export what you need first. Active instance data is deleted within 30 days after the contract ends, and protected backup copies expire within a further seven days. Earlier deletion can be requested.
Sources
Third-party details were checked against these pages on 25 September 2026. Vendors change plans and features, so check the current version before you decide.
Try BookHost free for 14 days
Get your own hosted BookStack workspace with daily backups and security updates handled for you; no card is needed for the trial.