Your email marketing data is subject to US law if your provider is a US company, even when the data is stored in Europe. Under the US CLOUD Act, US authorities can compel US-based providers to hand over data they control, regardless of where the servers sit. Choosing a provider outside US jurisdiction, such as Swiss-hosted Mailpro, keeps your subscriber data out of that reach.
Why hosting location alone is not enough
A US-headquartered provider can store your data in a Frankfurt or Dublin data center and still fall under the CLOUD Act, because the law applies to US companies, not to a geographic region. An "EU region" toggle changes the street address, not which government can request the data. To assess any provider, check two things: where the data is hosted and which country's laws govern the company.
The practical test is simple: check who owns your provider, not just where its servers sit. See our guide to email marketing not hosted in the USA.
How to keep your data outside US law
Use a provider that is both hosted and headquartered outside the United States. Mailpro is Swiss-hosted and Swiss-run, with customer data stored in Geneva. Switzerland sits outside US jurisdiction and holds an EU adequacy decision, so data flows freely between the EU and Switzerland with no US exposure. If you must use a US provider, you will likely rely on Standard Contractual Clauses, which add paperwork and Schrems II risk. See also our FAQ on GDPR and companies outside Europe.
Mailpro and data privacy
Email data that stays out of US reach
Mailpro runs on Swiss infrastructure with GDPR compliance built in, so your subscriber data stays outside US jurisdiction and the CLOUD Act.