There is a quiet assumption behind a lot of wellness technology: that the safest place for client records is a big, reputable cloud, and that once the data is “in the EU” the jurisdiction question is settled. It is a reasonable-sounding belief. It is also incomplete — and for a business holding health records, the gap is worth understanding before you rely on it.
Physical location is not legal reach
Where your data physically lives and who can legally compel access to it are two separate facts. The US CLOUD Act makes the point sharply: US authorities can require a US-owned cloud provider to disclose data even when the servers holding it sit inside the EU. The determining factor is who owns the provider, not which country the hard drives are in. So a European wellness business can host client records in Frankfurt or Dublin and still have those records reachable, through the vendor, by a legal system on another continent.
Scale turns this from a technicality into a structural feature of the market. Per the European DIGITAL SME Alliance and n-ix, three US firms hold roughly 65% of the European cloud market. That means a large majority of “EU-hosted” workloads run on infrastructure operated by companies subject to that extraterritorial reach. None of this implies wrongdoing by anyone. It simply means that “our data is in Europe” and “only we can reach our data” are different sentences, and it is easy to say the first while believing the second.
Why this bites harder for health records
For most businesses the sovereignty question is a preference. For a wellness practice it edges toward a duty. GDPR treats health data as a “special category” under Article 9, with a higher bar for lawful processing and protection — precisely because the information is intimate and the trust behind it is fragile. If a client asks you point-blank whether any foreign authority could reach their file, the honest answer, on a US-owned cloud, is a qualified “it’s complicated.” On infrastructure you host and govern yourself, the answer can be a clean “no third party holds it to compel.”
NIS2 sharpens the incentive from the other direction. Fully in force across the EU in 2026, it brings audits, 24-hour incident reporting, fines up to EUR 10 million or 2% of turnover, and possible personal liability for management; Germany’s BSI issued an early EUR 850,000 fine for weak incident detection, per Reed Smith and Freshfields. Regulators increasingly expect you to demonstrate control over your data’s whereabouts and access — which is far easier when the answer isn’t routed through someone else’s terms of service.
An honest caveat
Self-hosting is not automatically safer, and pretending otherwise would be a disservice. When you run your own stack, the operational responsibility — patching, backups, monitoring, incident response — is genuinely yours. A well-run US cloud may protect a poorly-staffed practice better than a neglected self-hosted server ever could. Sovereignty is a real advantage only when you pair it with the discipline to operate the thing. For some businesses that discipline is available; for some it isn’t, and the honest recommendation there is different. The goal is a deliberate choice, not a reflexive one in either direction.
Keeping the data reachable only by you
The cleanest way to shorten the “who can reach it” answer is to remove the party who could be compelled. That is the design intent behind a self-hosted platform: the client data, the customer relationship and the billing stay inside infrastructure you govern, in your own jurisdiction, rather than as a tenant on a system you don’t control. VBWD is a full-stack, self-hosted SDK — one Python backend core serving web, native iOS and native Android from a single build — with a plugin architecture (booking, payments, memberships, catalogue, CMS, chat) that toggles on and off without a restart, so a small team can run capabilities usually reserved for large operators. VBWD’s sovereign-by-default post lays out the reasoning in full.
It is source-available under BSL 1.1 — free for commercial use while annual VBWD-attributable sales stay below the value of 6.7 BTC a year. It is younger than the twenty-year incumbents and trades some accumulated edge-case maturity for auditability, speed and data sovereignty. For many wellness businesses that is the better trade; for some it isn’t, and it is worth weighing honestly against the operational load that comes with running your own stack.
If your practice is wrestling with any of this — the booking system that fights you, the client data you’re not sure you truly control, the fees that grow every year — the useful next step is concrete: see it running for your own business. Request an enterprise installation and bring the numbers you want to improve.
Sources: European DIGITAL SME Alliance and n-ix (CLOUD Act reach, 65% cloud concentration); EU GDPR Article 9; Reed Smith and Freshfields (NIS2, BSI fine).



