
ENTRONYX CLOUD is a European company based in Cologne. Our platform runs in data centres in Germany and Finland; we are responsible for the network, hardware and access to our systems ourselves. We are self-funded.
- Registered office
- Cologne
- ENTRONYX Deutschland GmbH · Amtsgericht Köln, HRB 98908
- Locations
- 5
- Locations in Germany and Finland where the platform runs — all in operation, efficiency value and certificates shown per location
- Energy efficiency
- PUE 1.08
- best measured value, collected according to EN 50600-4-2
- Evidence
- BSI C5
- Type 2 for platform operations, audit period shown
Where you can check what is claimed here
Evidence, data security, data centres, environment — the four questions asked before procurement. Each has its own page; the cards state what is written there, and every statement on them has a method behind it.

What is audited, by whom and until when
Certificates and an attestation are available for the operation of the platform; a fifth entry is explicitly not one, because there is no recognised certification of our service for the GDPR. For each piece of evidence, we state what it covers and what it does not.
- For our operations
- ISO 27001 · ISO 50001 · BSI C5
- Required per location
- EN 50600, VK3 or VK4
- Audit period C5 Type 2
- 12 months

Who holds the keys and when you will hear from us
Data at rest is encrypted without your intervention; the root of the key hierarchy lies in hardware security modules at two locations. What we cannot do for you is stated next to it: on a bare metal server, the drive belongs to you — and therefore the encryption.
- Data at rest
- AES-256, key per volume
- Between the locations
- MACsec on every link
- Notification to you
- 24 h from confirmed knowledge

Five locations in two countries — and what each must fulfil
We did not build the data centres where our systems are located; we select them. A location is only considered if power, cooling, and fire protection are designed redundantly and a fuel reserve for 72 hours of full load is available. What we manage ourselves there is specified: systems, network, and access to our racks.
- Locations
- 5 in Germany and Finland
- Availability class VK4
- 4 of 5
- Fuel reserve, required
- at least 72 h at full load

Less energy per unit of performance — measured, not calculated
We select locations based on energy efficiency, source electricity from renewable sources and use hardware as long as it runs safely and efficiently. Every number carries its measurement method; where one is calculated and not measured, it says so next to it.
- Best PUE in the portfolio
- 1.08 (hel1)
- Energy management
- ISO 50001 at 4 of 5 locations
- Hardware service life
- 6.4 years on average
Three sentences you can measure us against
A corporate mission that requires no proof is just a statement of intent. The following three sentences are phrased in a way that allows you to contradict them — with an invoice, a measurement or a contract in hand.
We operate the platform ourselves, end to end
Platform, network, hardware and access to our systems are our responsibility. This limits how fast we can grow. And it is the reason why an incident is handled where the setup is known — instead of being passed on as a ticket to an upstream supplier. The building technology of a location is not our responsibility; it is a selection criterion for us and not an in-house service.
AS204812Own core network (backbone) between locations, own Autonomous System Number
We sell capacity at a price that is on the price list
There are no egress zones (staggered prices for outbound data traffic by destination region), no discounts based on negotiating skills and no price increases within a term. Whoever orders more volume gets the scale from the price list — the same one that everyone else sees. Deviations from this would be convenient for sales and expensive for trust.
€1.09$1.26Per additional terabyte of data traffic, the same at every location
We remain explainable within the German legal framework
Processing and responsibility lie with a single company under German law — without an intermediary company that a foreign order could target. The data processing agreement (DPA) is part of the main contract and not an appendix that has to be requested. We do not negotiate deviating versions, even if a tender fails because of it.
Art. 28Data processing according to GDPR — contract with the main contract, without separate request
And four things we do not do
These boundaries cost us orders. They are here because a provider that offers everything takes responsibility for nothing — and because we prefer to tell you upfront rather than in hindsight.
- No choice of location based on price alone
- A location is only considered by us if cooling, power and fire protection are designed redundantly, a fuel supply of at least 72 hours at full load is maintained and a reception desk staffed around the clock with ID checks is available. Added to this are energy efficiency, legal framework and connectivity. Where a location does not meet these requirements, it is not in the catalogue — even if it were cheaper.
- No products that we cannot operate
- We discontinued an in-house development in the storage area after 14 months because the consistency commitments could not be achieved with our team in a reasonable time. Since then, the rule has been: what we cannot operate permanently does not go into the catalogue.
- No number without a measurement method
- PUE (Power Usage Effectiveness: total energy of the location divided by the energy of the IT systems) according to EN 50600-4-2, availability from our own measurement with published history, latency as a median over 30 days instead of as a best value. Where a number comes from a model calculation, it says so next to it.
- No speculative expansion
- We only expand our capacity when the existing one is occupied — and then from our own funds. This makes us slower than we would need to be; the decision is made consciously.
Seven facts, each with its method
No customer count, no server count, no headcount — such figures have no method behind them and answer no question asked before an order. What is stated here has one: register entry, catalogue, measurement or deadline.
- Founded in
- 2019Foundation of ENTRONYX Deutschland GmbH based in Cologne, start of operations in Frankfurt am Main. Self-funded since day one, without a parent company in a third country.
- Locations
- 5in two countriesGermany and Finland — places where the platform runs, not company locations. All in operation.
- Own core network
- AS204812Own routes between locations, interconnection via DE-CIX in Frankfurt; transit only supplementary.
- Certificates
- 4vorliegendISO 27001, ISO 50001 and the C5 attestation for our operations, EN 50600 as a requirement for every location. The GDPR is expressly not one.
- Hardware service life
- 6.4YearsAverage across the fleet, not a guaranteed minimum value. Replacement is based on condition, not depreciation period.
- Incident on the status page
- 10MinutesAs soon as three independent checkpoints confirm a deviation, the alerting system generates the entry itself — since 18 August 2026.
- Reporting a security incident
- 24HoursFixed upper limit from confirmed knowledge, even if the cause is still unclear — Art. 33 para. 2 GDPR.
What an operator must be measured against
Who works there, where is the data located, who replaces the hardware. Three questions to which every provider claims the same answer — and which you should therefore not just believe, but have proven.

Who works there?
Operations, network and support are handled by ENTRONYX CLOUD itself. There is no outsourced first-line support that passes on what it is not allowed to decide. And we decide who is allowed to open one of our racks: every authorisation is granted by name and logged.
In-house control centre, staffed around the clock — the same for all locations

Where is the data located?
No location is outside the European Union; a third-country transfer within the meaning of the GDPR therefore does not take place. Your content data is processed exclusively at the location you select when ordering; without your explicit choice, no backup copy leaves the country in which this location is situated. Account, configuration and log data are listed separately by the legal framework.
5 locations in Germany and Finland, all in operation

Who replaces the hardware?
Spare parts are available at every location, replacement is carried out by our own staff. This determines how quickly a failed component is up and running again and who is responsible for it.
Spare parts inventory per location, replacement by our own staff
What is audited, by whom and until when
An abbreviation in the footer of a page means nothing. Only the auditor, type and term turn a seal into a statement that can be challenged. One row in this table deliberately has no seal — it is here because the absence of this certificate is the more important information.
ISO 27001ISO/IEC 27001:2022 — Information security management system
Certificate- Auditor
- Accredited certification body, annual surveillance audit
- Term
- Valid until 30 November 2027 · recertification every three years
BSI C5:2020BSI Cloud Computing Compliance Criteria Catalogue, Type 2
Attestation- Auditor
- Auditing firm according to ISAE 3000 (revised)
- Term
- Audit period 1 July 2025 to 30 June 2026 · follow-up audit in progress
EN 50600EN 50600 — Availability class of the data centre infrastructure
Certificate- Auditor
- Notified body, assessment per location
- Term
- Per location, reassessment in case of structural changes
ISO 50001ISO 50001:2018 — Energy management system
Certificate- Auditor
- Accredited certification body
- Term
- Valid until 14 May 2028 · annual surveillance audit
GDPRRegulation (EU) 2016/679 — General Data Protection Regulation
No proof possible- Auditor
- —
- Term
- Permanent obligation, no expiry date
Where you can read about this
- Certificates in detailPer certificate: what it covers and what it explicitly does not
- Certificates per locationThe location map lists the seals and scope of the location
- Data processing agreement (DPA)Subcontractors fully listed, with country of residence
- Service Level AgreementCommitments, measurement methods and service credits
Which law governs your data
A data request is an official demand to hand over data. Its connecting factor is not the server location, but the legal control over the operator. That is why this states not only where the machines are located, but above all which company operates them and under which law.
5Locations in Germany and Finland where ENTRONYX Deutschland GmbH operates its platform — this single company remains responsible in every case under German law
Art. 28Data processing agreement under GDPR — the contract comes with the main contract, without separate request
The framework governing operations
- Locations
- fra1, fra2, ber1, muc1, hel1
- Operating company
- ENTRONYX Deutschland GmbH
- Applicable law
- GDPR, BDSG, German law
- Corporate affiliation
- No parent company, no holding company in a third country
In which role we process your data
- As a processorArt. 28 GDPR
- For the data you process on our platform, we act on your instructions. The data processing agreement is part of the main contract; subprocessors are fully listed, with country of establishment and purpose. Whether your processing is permissible is decided by you as the controller — we provide the infrastructure.
- As a contracting partyArt. 6 para. 1 lit. b GDPR
- For the data of your contacts — account, invoice, support — we are responsible ourselves. We store them as long as the contract runs and legal deadlines require it, and no longer. What we process for what purpose and for how long is stated in the Privacy Policy.
Data residency in detail
- Storage location of content data
- The location selected during the order. Relocation or mirroring to another location only occurs at your choice, never automatically.
- Backups
- Destination freely selectable, default is a second location in the same country. If the catalogue does not list a second one there, the backup remains at the processing location until you select a destination.
- Control plane
- The control plane — the systems used to manage accounts, configuration and interfaces — runs in fra1 and muc1 and is accessible from anywhere. Accessibility is not processing: account, configuration and log data remain at these two locations.
- Administrative access
- Separate identity management and separate key hierarchy. Administrative access is limited to named roles and is logged.
- Access to content data
- Only on your instruction, to avert an acute operational risk or based on a valid order. Every access is logged and displayed in the customer panel.
- Requests from authorities
- Individual review for legal basis, jurisdiction and proportionality. We publish the number and type every six months in the transparency report.
- Sub-processors
- Fully listed with country of incorporation and purpose. We announce changes 30 days in advance, with the right to object and special termination rights.
Operating company and registered office
- Company
- ENTRONYX Deutschland GmbH
- Registered office
- Robert-Perthel-Str. 71-73, 50739 Cologne
- Registry court
- Amtsgericht Köln
- Commercial register
- HRB 98908
- EUID
- DER3306
This company operates the platform and processes the data at all 5 locations; none of them are outside the European Union. Access under foreign law therefore has no starting point in the chain of ownership.
A commitment to data sovereignty is only as reliable as the company making it. If you want to verify the commitment, verify the company: company name, registered office and register entry are listed here and in the commercial register.

What we strive for and what is measured today
A goal is not an achievement. This overview therefore separates the two: what we strive for, and how the current status is measured. Where a goal has not yet been reached, this is stated and not hidden in a footnote.
- Energy requirement per performance
- What we strive for
We strive for the lowest possible energy demand per service provided and select locations accordingly.
- How it is measured today
Best measured PUE in the portfolio: 1.08, collected according to EN 50600-4-2. The values of the other locations are listed individually on the respective location map, even where they are higher.
- Renewable electricity
- What we strive for
We source electricity from renewable sources and are working towards further increasing this share.
- How it is measured today
Source of supply and certificate of origin are shown per location. At one location, a photovoltaic system supplements the supply; it covers part of the demand, not all of it.
- Hardware service life
- What we strive for
We use hardware for as long as it can be operated safely and efficiently, instead of replacing it after the depreciation period.
- How it is measured today
The average useful life is 6.4 years — an average across the fleet, not a guaranteed minimum value. Deletion procedures according to BSI specifications and recycling rate are shown.
- Waste heat and cooling
- What we strive for
We are working on the use of waste heat and on low-water cooling.
- How it is measured today
So far, we have achieved operations at one location with geothermal cooling and at one that manages without mechanical cooling for most of the year. Waste heat recovery into a district heating network is not in operation at any location — it is only in our requirements catalogue for new locations.
- Reporting
- What we strive for
We report on what has been achieved using measurement methods and state where a figure is calculated and not measured.
- How it is measured today
Energy balance and water consumption are listed per location on the location map, and the report on official requests is published half-yearly. Where a figure comes from a model calculation, this is stated next to it.
- Legal and privacy
- What we strive for
We want to keep the responsibility for processing with a company under German law and tie the data processing agreement to the main contract, instead of having it negotiated separately.
- How it is measured today
Verifiable in three places: the company's register entry, the data processing agreement as part of the main contract, and the list of sub-processors with the country of residence for each entry.
The values per location — efficiency value, source of electricity, water consumption and certificates — are on the location map, not in this overview: they differ per facility, and an average across multiple locations hides exactly the one that performs worst.
What has been built since 2019
The timeline begins with the founding in 2019. It only lists milestones that can be tied to a location code, a certificate, or a metric. Anything else would be a story, and a story cannot be verified.
In retrospect, two decisions were wrong: the attempt to build our own storage platform from scratch, and the late implementation of an audited measurement concept for energy performance. Until then, efficiency was a calculation for us, not a measurement.
The axis runs from the founding to the present. Location codes correspond to the region codes in the catalogue.
2019
Founded in Germany
ENTRONYX Deutschland GmbH, based in Cologne, starts operations at the fra1 location in Frankfurt am Main. The first product is a dedicated server with hourly billing — unusual at the time, because Bare Metal (physical servers without virtualisation) was usually sold monthly.
- Foundation
- fra1
- Bare Metal
2020
Berlin — and a discontinued in-house build
In Berlin, we start operations at ber1; the location is supplied with wind power from Brandenburg. At the same time, the development of our own storage platform begins and is discontinued after 14 months: the consistency commitments could not be achieved with our team in a reasonable time. Since then, we have relied on adapted but existing methods.
- ber1
- Wind power
- In-house build discontinued
2021
Munich and our own core network
In Munich, muc1 is added; cooling there is done with geothermal energy. Instead of continuing to buy transit (internet connection via third-party networks), we switch our own routes between the German locations and register AS204812; the first interconnection with other networks runs via DE-CIX in Frankfurt. In the same year, the Public Cloud leaves the beta phase after eleven months of closed testing.
- muc1
- AS204812
- DE-CIX
2022
Energy management according to ISO 50001
Our energy management is certified according to ISO 50001. This means that for the first time, a verified measurement concept is behind the efficiency figures instead of a calculation from planned values. Not every location is included; which one provides the evidence is stated on the respective location map.
- ISO 50001
- Measurement concept
2024
ARM in the cloud and BSI C5 Type 2
Ampere Altra instances of the NA series bring ARM64 to the cloud: constant clock speed, significantly lower power consumption per core than comparable x86 platforms — the basis of our efficiency work on the instance fleet. In the same year, the attestation according to BSI C5:2020 Type 2 for operations at the German locations is added.
- NA series (ARM)
- BSI C5 Type 2
2025
fra2 with photovoltaics
We start operations at fra2. A PUE of 1.09 is measured there. A photovoltaic system covers part of the demand there; the rest is covered by electricity from renewable sources.
- fra2
- PUE 1.09
- Photovoltaics
2026
Helsinki is added
The platform has also been running at hel1 in Helsinki, the first location outside Germany, since this year. A PUE of 1.08 is measured there — the lowest in the portfolio: the outside air carries a significantly larger part of the year there without mechanical cooling starting up. The list price is below the German reference value; this is supported by the lower electricity price and precisely this cooling.
- hel1
- PUE 1.08
- Free cooling
Six verifiable commitments
We do not have a values page full of adjectives. What is written here can either be read in a contract, calculated on a public page, or verified on an invoice. If we break one of these commitments, it is a mistake that you can prove.
Prices of ongoing contracts do not increase.
The price agreed upon conclusion of the contract applies for the entire term. Increases can only take effect upon renewal and are announced in text form at least 90 days in advance. If you do not agree, you can cancel at the end of the current period.
Verifiable: Stipulated in section 8 of our Terms and Conditions. read § 8
Outbound data traffic has one price, no zones.
0 TB per instance and month are included, every additional terabyte costs €1.09$1.26. There are no region-dependent egress rates, no tiering by destination, and no separate billing for transfers between locations.
Verifiable: Same value in the price list, catalogue data, and on every invoice. Price overview
Incidents appear on the status page within 10 minutes.
As soon as a deviation is confirmed by at least three independent checkpoints, the alerting automatically creates a status entry. This rule has been in place since 18 August 2026. Previously, publication was a manual decision — during an incident, this delayed the notification by hours.
Verifiable: Timeline with timestamps and complete post-mortems. Status page
You receive service credits without a request if we measure the shortfall ourselves.
If our own measurement shows a shortfall in the promised availability, the service credit is automatically shown on the next invoice. A request is only necessary if you detect a deviation that our measurement did not capture.
Verifiable: Procedure and tiers in the Service Level Agreement. Service credit tiers
Your data remains under German responsibility.
Processing takes place in data centres in Germany and Finland, exclusively by ENTRONYX Deutschland GmbH. There is no parent company in a third country. The data processing agreement according to Art. 28 GDPR comes with the main contract, without separate request.
Verifiable: Sub-processors fully listed, with country of residence per entry. DPA and sub-processors
We replace hardware based on condition, not depreciation period.
Condition, efficiency, and spare parts availability are decisive, not the book value. The average useful life is currently 6.4 years. Decommissioned systems are refurbished, wiped according to BSI guidelines, and resold; only what is no longer functional is scrapped.
Verifiable: Useful life, wiping procedures, and recycling rate are stated. Circular economy
For editorial teams and analysts
Corporate communications answers requests within 24 hours on working days. In the event of an ongoing disruption, we only reply once the incident is closed — but then completely and with the post-mortem.
- Available
- Mon – Fri 09:00 – 17:00 (CEST)
- Postal address
- Robert-Perthel-Str. 71-73, 50739 Cologne
What we provide
- Location and efficiency data
- Efficiency value, power source, certificates and connectivity per location as PDF and CSV, updated at the end of the quarter.
- Images
- Photos of our systems in operation for editorial use, including location and date of recording.
- Background discussions
- For network operations, energy balance and platform technology, you speak with the department responsible for operations — not with the press office.
- Visit to a location
- By appointment and prior arrangement, accompanied by our operations team. The access rules of the location apply; recordings are not permitted in operational areas.
- Transparency report
- Number and type of official requests, published semi-annually.
Where you can read more
- CareersOpen positions with salary band, working model and a process with fixed deadlines.
- Partner programmeThree tiers with fixed discount scale, admission process and the requirements per tier.
- Service Level AgreementAvailability classes, measurement methods, service credit scale and the exclusion list.
Speak to someone who knows operations
For framework agreements, colocation and migration projects, sales conducts the first meeting together with operations. Technical questions are answered by the person responsible for the area — in a conversation, not in a presentation.
- Registered office
- Cologne
- Locations
- 5
- Legal framework
- GDPR