Blog · GDPR & EU compliance

    Where your course platform stores your data — and why it matters.

    The question "where is my data?" sounds simple. The answer is rarely the one-line answer most course platforms put on their trust page. This is a 2026 side-by-side of the six platforms most creators end up choosing between.

    If you're new to why hosting region matters for course platforms, our piece on Schrems II for course creators is the prerequisite read.


    The platforms, side by side

    The table below is sourced from each platform's public DPA, subprocessor list, or trust page as of May 2026. We link the source in the footnotes. Where a platform doesn't publish the information, we say so.

    PlatformPrimary regionDatabaseVideo processingCDNDPA on free tier
    lernauraEU (France)Scaleway (FR)api.video EUCloudflare, EU routingYes
    TeachableUS (us-east)USUS (in-house)Cloudfront USNo
    KajabiUS (us-east)USUS (Wistia)Cloudfront USNo
    ThinkificCanadaCanadaUSCloudfront USNo
    PodiaUS (us-east)USUSCloudfront USNo
    SkoolUSUSNot hosted (Vimeo/Wistia)Cloudfront USNo

    Footnotes:

    • Teachable, Kajabi, Podia and Skool DPAs require the user to request from support or are paywalled to paid plans.
    • Thinkific is Canadian; Canada has GDPR adequacy status with the EU as of the time of writing, which is a real legal advantage over the US-hosted platforms even though it is not EU-local.
    • Skool doesn't host video natively; your video lives wherever you store it (typically Vimeo or Wistia, both US-headquartered).

    What this actually means

    Hosting region affects four practical things in your course business.

    1. Data Subject Access Request turnaround

    GDPR Article 12 requires you to fulfil a data subject's request within 30 days. The practical median turnaround on US-hosted platforms is days-to-weeks, because the workflow runs through a US support team with EU-aware tooling layered on top. On EU-hosted platforms with EU-local tooling, the median is typically under 24 hours, because the data and the workflow are co-located.

    If you've never had a DSAR yet, this sounds abstract. The first time a regulator-curious student asks, you'll discover how it actually works.

    2. DPA workflow

    The Data Processing Agreement is the legal instrument that makes a platform a "data processor" on your behalf. On every US-hosted course platform in the table above, DPA is gated to paid plans, or has to be requested via support. On lernaura, the DPA is embedded in our Terms of Use, accepted at signup, applying to every plan including the free tier. We don't run a separate DPA signing flow — same comprehensive coverage for every customer, no negotiation, the same pattern modern SaaS like Vercel, Cloudflare and Stripe use.

    This matters less for solo creators and more for B2B-facing sales. The first question any corporate procurement reviewer asks is "send me the DPA." If you can point them at a published, comprehensive DPA they can read before procurement, the conversation continues. If you have to request one from support or negotiate it, it stalls.

    3. Schrems II / DPF posture

    Every US-hosted platform now relies on DPF self-certification for EU-US data transfers. As covered in our Schrems II post, DPF is under active legal challenge (Schrems III) and most data protection lawyers expect another invalidation within 18-36 months.

    If your platform's compliance posture depends on a framework expected to fall, you have a planning horizon problem. The Canadian option (Thinkific) is one step better than the US options because Canada has adequacy without DPF dependency. EU-local (lernaura) removes the question entirely.

    4. Procurement-review failure modes

    If you ever plan to sell B2B — and most independent creators eventually get inbound interest — procurement reviews from European companies increasingly require EU data residency. "DPF-certified US-hosted" is not always sufficient. "EU-hosted" is.

    Even if you never go B2B, the same question shows up in lower-stakes form when a thoughtful student asks where their data lives, or when a German consumer-rights site mentions your course in a roundup.


    The DPF disclaimer

    It's worth restating the DPF point explicitly. Even DPF-certified US-hosted platforms still operate under US law:

    The CLOUD Act (2018) allows US authorities to compel disclosure of data held by US providers regardless of where the data is stored, including in EU data centres operated by US companies.

    FISA 702 authorises bulk surveillance of non-US persons' communications, including data held by US companies.

    Executive Order 12333 authorises additional surveillance with even fewer constraints.

    A DPF self-certification is a contract. The underlying laws don't change because of it. Schrems II said this was incompatible with GDPR. DPF did not change those laws; it changed the legal framework around the transfers. The same incompatibility argument that worked in 2020 is the basis of the current Schrems III challenge.


    What to do if you're on a US-hosted platform today

    You may not be ready to switch. That's fine. Five practical things you can do without changing platforms:

    1. Read your current DPA. Skim section 4 (transfers) and section 7 (subprocessors). Note what you don't understand. The DPA is the contract that defines what your platform is allowed to do with your data; you should know what it says.
    2. Document your data flows. Where do student names, emails, video, payment details, and community posts go? Even a hand-drawn diagram puts you ahead of 90% of creators.
    3. Run a 30-day DSAR drill. Pretend a student has asked for everything you have on them. How long does it take you to assemble it? What can't you get?
    4. Audit your subprocessor list. If your platform's DPA references a subprocessor list URL, open it. Note the regions. Note which are US-resident.
    5. Document your Transfer Impact Assessment posture. If you're transferring EU data to the US, the GDPR technically requires you to have run a TIA. Almost no independent creator has. A simple written assessment — even three paragraphs — is meaningful evidence of good-faith effort.

    None of this requires changing platforms. All of it puts you in a stronger position whether you switch or not.


    The lernaura position

    lernaura is EU-hosted on French infrastructure: Scaleway (database + infrastructure, French-owned hardware), Scalingo (application hosting), Mistral (AI inference for semantic search), Gladia (transcription), Brevo France (transactional email), Mollie (EU-regulated payments), api.video EU (video), Whereby EU (live sessions). The DPA is embedded in our Terms of Use, accepted at signup, applying to every plan including the free tier.

    We made this architectural decision in 2024. The argument was that the next decade of EU data law will move further from US transfers, not closer. Building on EU infrastructure from day one was the only design that didn't bet on Schrems II being the last word.

    If you want the long version, our European course platform page covers it.

    If you're considering moving to an EU-hosted course platform, sign up free — the platform stays free until you monetize. Our managed migration moves your current content (courses, videos, community archives) and your contact lists (students, members) in 48 hours. Payment methods stay with your existing provider; students re-attach on first login.


    Make it. Keep it.

    The whole back office of cross-border selling — tax, payments, collection, FX, disputes — handled by lernaura. One integration, one clean payout, EU-owned end to end. Creators: the free platform is waiting.
    For sellers based in the EU/EEA, selling to buyers across Europe and North America — more countries on both sides soon.