The European course platform for creators.
You can build a course anywhere. Selling one to European students, or licensing it to a European company, is a different question — and most course platforms haven't taken it seriously yet.
We have. lernaura is the EU-hosted creator platform built for both D2C sales and B2B per-seat licensing, with AI search that doesn't ship your students' content to a US model in the process.
This page is for two readers. If you're a creator with European students, the For creators section is where to start. If you're a procurement reviewer or DPO evaluating lernaura for a corporate license, skip to For procurement teams — it has the subprocessors list and the GDPR specifics.
Why EU hosting matters in 2026
In 2020 the Court of Justice of the European Union struck down the EU-US Privacy Shield in the ruling now known as Schrems II. Six years later, the replacement — the EU-US Data Privacy Framework — is still under active legal challenge, and the legal community's working assumption is that any data flow from the EU to the US carries non-trivial regulatory risk.
For a course creator, that risk shows up in three places. Your student list is personal data the moment a single student is an EU resident. Your video content carries embedded personal data (voiceovers, on-screen names, faces in case-study footage). And your community posts are routinely personal data by default. A US-hosted course platform processes all of it on US infrastructure under US law — a data-transfer question that gets more uncomfortable to answer every year.
The practical consequence is rarely a regulator at your door. It's slower problems. Procurement reviews that stall. Subject Access Requests that take weeks because the platform's DSAR tooling lives in another time zone. The awkward email from a German student asking where their data is, which you didn't have a good answer to.
EU hosting fixes the underlying question, not just the answer to it.
For creators
What "EU-hosted" actually means at lernaura
Flag-waving is not hosting. When we say EU-hosted, we mean the substrate the platform runs on is EU-resident — not just the company that operates it.
Database: Scaleway — French-owned hardware in France
Application hosting: Scalingo, hosted in France
Underlying infrastructure: Scaleway, hosted in France
AI inference for semantic search: Mistral, hosted in France
Speech-to-text / transcription: Gladia, hosted in France
Transactional email: Brevo, hosted in France
Payments: Mollie (EU, Netherlands-headquartered, EU-regulated)
Video processing and storage: api.video, EU region
Live sessions: Whereby, EU region
Edge / CDN: Cloudflare, with EU-only routing where supported
No customer data leaves the EU under normal operation. The subprocessor list is published on this page and updated when it changes — not buried in a DPA appendix.
GDPR by default — what you don't have to think about
GDPR is mostly a question of who's doing the thinking. For most creators on US platforms, the answer is "you, in your spare time". On lernaura the answer is "the platform, by default":
DPA is embedded in our Terms of Use. Accepted at signup, applies to every plan including the free tier. We don't run a separate DPA signing flow — the agreement is the same for everyone, no negotiation needed. This is the pattern modern SaaS uses (Vercel, Cloudflare, Stripe). See more in the For procurement teams section below.
DSAR tooling is one click. A student asks for their data, you export a complete JSON archive in seconds.
Right to erasure runs on automated retention rules per course. You set the policy once.
Cookie consent uses an EU-compliant default banner. No paid third-party tool.
Lawful basis is tracked per audience. When you onboard a B2B buyer, the consent path is separate from your D2C audience.
Most of this is invisible to you while you're teaching. That's the point.
AI that respects EU data law
lernaura is AI-first throughout. Upload a video and the platform automatically transcribes it, translates it into your target languages, generates multi-language subtitles, sets local-currency pricing across every market you sell into, and indexes everything into a reusable content catalog so you never do the same work twice. The same AI surface powers semantic search across all your content for your students.
All of this runs on EU-resident models. We built it on the assumption that GDPR Article 22 — the article that governs automated decision-making about EU residents — is going to be enforced more, not less, as AI proliferates.
Three commitments shape how it works:
Your content is not used to train any third-party model. Not OpenAI, not Anthropic, not anyone. We use Mistral and Gladia, both France-hosted, with contractual no-training clauses.
The AI is augmentation, not automated decision-making. It surfaces lessons, finds answers, suggests next modules. It does not grade, admit, certify, or deny access to a student. Anywhere a decision would have legal or similarly significant effect, a human is in the loop.
Transparent model lineage. You can see which model is running, where it's hosted, and how long embeddings and transcripts are retained. No black box.
If you want the full version of this argument, the supporting blog post AI in course platforms and GDPR Article 22 is the deeper read.
EU AI Act compliance, built into the architecture
The EU AI Act requires AI providers and deployers to document their systems comprehensively — model lineage, data inputs and outputs, audit trails, risk classification. For platforms that bolted AI onto existing systems, that documentation has to be reconstructed after the fact. On lernaura it already exists, because the platform produces it as it runs — which is what you inherit as a customer.
Every AI invocation on lernaura runs as a versioned skill — a documented, auditable unit. For each call the platform records:
- Which model was used (Mistral, Gladia, or a specific embedding model), and its version
- The data and inputs the model received
- The output the model produced
- Timestamp, context, and the skill version in effect at the time of the call
We can produce AI Act documentation per design. When a regulator, auditor, or procurement reviewer asks "show us how this AI works," we don't reconstruct it from logs. The documentation is the architecture, and an audit-trail export is available on request.
For creators, this means your obligations as an AI Act deployer — where they apply to you — are dramatically reduced. We're doing the upstream documentation work by design.
For B2B buyers, this means your DPO and your AI governance lead have clean answers to the questions they're starting to ask in 2026 procurement reviews. The audit trail is there; nobody has to invent it after the deal.
The mechanism behind this — the versioned-skill audit trail that produces AI Act documentation as a side effect of running the platform — is laid out in full on our AI-first, compliance-first page.
Selling to European companies — without losing the deal at security review
Most independent creators eventually get a "can we license your course for our team?" email. Almost no creator platform handles what happens next well.
On lernaura, the workflow is built around a clear mental model: the company isn't buying lernaura, they're licensing your content. lernaura is the merchant for the transaction and the delivery platform for their team. Here's how it lands:
- You set a per-seat licensing price for any course, community membership or newsletter.
- The licensee company pays lernaura for the N seats they want — for example, 10 seats at €200 = €2,000.
- lernaura is the merchant on record: we invoice the company, handle EU VAT, take 5% + €0.50, and pay you the balance monthly (or on close, depending on terms).
- The licensee gets their own delegated admin — they manage users themselves (add, remove, off-board), rebrand the experience their team sees with their own logo and colours, configure content-use policy (downloads, expiry, watermarking), and pull usage analytics for L&D reporting. You don't do any of this work; they do.
- Their nominated seat holders access your licensed content through their own lernaura accounts, inside the licensee's branded experience.
This is the B2B per-seat licensing flow, and it's the thing no other creator platform offers as a built-in workflow. Teachable, Kajabi, Thinkific, Podia and Skool are all pure D2C. Enterprise LMS vendors like Cornerstone and Docebo cost €30k+ and don't host independent creators. We sit in the unoccupied middle — and the fact that the data stays in the EU the whole time is what makes the deal possible to close with European licensees.
For procurement teams
If you're evaluating lernaura on behalf of a corporate buyer, this section has the answers your DPO and security review will ask for. None of it is buried in a sales call.
Subprocessors
| Provider | Region | Function |
|---|---|---|
| Scaleway | France | Application database |
| Scalingo | France | Application hosting |
| Scaleway | France | Underlying infrastructure |
| Mistral | France | AI inference / embeddingsContractual no-training clause |
| Gladia | France | Speech-to-text / transcriptionContractual no-training clause |
| Brevo | France | Transactional email |
| Mollie | EU (Netherlands) | PaymentsEU-regulated payment institution |
| api.video | EU | Video upload / playbackEU-only |
| Whereby | EU | Live sessionsEU-only |
| Cloudflare | EU-only routing | Edge / CDN |
This table is the source of truth. When it changes, it changes here first.
Data residency commitments
Customer data — meaning your employees' learning activity, their identifiers, the course content they consume — is stored and processed in the EU under normal operation. The single exception is when content is consumed outside the EU, then that piece of content is streamed to the user; we document those flows clearly.
Certifications and assurance
GDPR DPA: Embedded in our Terms of Use, accepted by every customer at signup. We don't sign separate DPAs, and we don't counter-sign customer-prepared DPAs. This is the standard pattern for modern SaaS (Vercel, Cloudflare, Stripe operate the same way). Our DPA covers GDPR Article 28 requirements comprehensively — your DPO will recognise the structure.
SOC 2 Type II: In preparation.
ISO 27001: In preparation alongside SOC 2.
A note on our compliance posture. Because lernaura was built AI-first on EU infrastructure from day one, our compliance work is largely formalising an architecture that's already aligned with GDPR, EU AI Act, and the typical SOC 2 / ISO control set. Compliance is the documentation of what we already do — not a retrofit.
What happens to data on cancellation
A creator or B2B buyer cancelling triggers a 30-day grace period where data can be exported, followed by a hard delete from primary systems within 30 days and from backups within 90. No data is retained for marketing or model-training purposes.
Subject Access Requests
Subject Access Requests reach a one-click flow inside the platform for end users. For requests routed through the controller (the creator, or the B2B buyer), we provide a structured JSON export within the GDPR-mandated 30-day window — typically within 5 business days.
Migration
If you're moving from a US-hosted platform, the catalog migration is managed by us and takes 48 hours. The scope: we re-host your current content (videos, course lessons, posts, community archives) and your contact lists (students, members, subscribers) on EU infrastructure on day one — everything you need to keep delivering and selling without losing your audience.
What we don't move, deliberately: payment methods stay with your existing payment provider; your students re-attach their card the first time they log in to lernaura. Cross-platform PCI migration is a category of risk we won't take with your business. Historical analytics and completion data also don't move — that kind of cross-platform transfer never works cleanly. The new platform starts with a clean slate of activity from day one.
We have done this from Teachable, Kajabi, Thinkific, Podia and Skool. If you're on something else, send us the platform name — the runbook is similar.
FAQ
- Where is my course data stored?
- France. Database and underlying infrastructure (Scaleway, French-owned hardware), application hosting (Scalingo), AI inference (Mistral) and video (api.video EU) are all EU-resident. The full subprocessor list is above.
- Where is my students' personal data stored?
- Same answer. Student identifiers, learning activity, and any content they generate (community posts, quiz answers, assignment uploads) are stored in the EU.
- Is the DPA included from the start?
- Yes. The DPA is embedded in our Terms of Use, accepted at signup — same for every customer including the free tier, no negotiation, no separate signing flow.
- Will you sign our DPA?
- No, and that's deliberate. Our DPA is embedded in our Terms of Use and covers GDPR Article 28 comprehensively. We don't sign customer-prepared DPAs because doing so would create a fragmented mosaic of bilateral agreements at scale. This is the same pattern used by Vercel, Cloudflare, Stripe and most sophisticated modern SaaS. If your DPO wants to review our DPA before procurement, it's published — they'll find it covers what they need.
- Do you sub-process to any US vendors?
- The platform substrate — database, application hosting, infrastructure, AI inference, video — is EU-resident. We do not sub-process customer data to US vendors for any core platform flow. Where any non-EU flow exists (specific support or analytics tooling, if applicable) it is documented in the subprocessors table.
- Is your AI training on my course content?
- No. We use Mistral, a France-hosted model provider, with a contractual no-training clause. Your content is not used to train any third-party model.
- What happens to my data if I cancel?
- 30-day export window, hard delete from primary systems within 30 days of cancellation, deletion from backups within 90.
- Are you SOC 2 / ISO 27001 certified?
- SOC 2 Type II and ISO 27001 are both in preparation. Because lernaura was built AI-first on EU infrastructure from day one, this is formalising controls our architecture already implements rather than retrofitting.
- Do you support German, French, and Dutch DPO requirements?
- Yes. Our DPA accommodates German Bundesdatenschutzgesetz, French Article 39 CNIL obligations, and Dutch AVG specifics by default. Your DPO will recognise the structure when they review the published version.
Try lernaura
Building in the EU shouldn't be the thing that holds your course business back. It should be the thing that makes the next conversation easier.
Related reading
- Where is your course platform's data stored?
A factual side-by-side of where Teachable, Kajabi, Thinkific, Podia, Skool and lernaura host your data.
- lernaura vs Teachable
The EU-sovereign, AI-native alternative at 5% + €0.50 per sale, with no monthly fee.
- Sovereignty for SaaS — why the EU-owned rail matters
The CLOUD Act, Schrems, and why an EU region of a US cloud isn't the same thing.