99.9% UPTIME 24/7 SUPPORT SINCE 2013
STATUS SUPPORT
AlphaVPS
PARTS INDEX - VIRTUAL SERVERS SHEET VS-01PRICES EXCL. VAT
40,000+ CUSTOMERS 99.9% UPTIME 24/7 SUPPORT 13 YEARS EST. 2013 · AS203380 · REV 2026.07
PARTS INDEX - DEDICATED SERVERS SHEET DS-01PRICES EXCL. VAT
IPMI/KVM REMOTE ACCESS 10GBIT PORTS ON EVERY SERVER 99.9% UPTIME SLA HARDWARE REPLACEMENT SLA EST. 2013 · AS203380 · REV 2026.07
PARTS INDEX - INFRASTRUCTURE SHEET INFRA-01PRICES EXCL. VAT
EST. 2013 · AS203380 · REV 2026.07
PARTS INDEX - SOLUTIONS SHEET SOL-01PRICES EXCL. VAT
EST. 2013 · AS203380 · REV 2026.07
PARTS INDEX - RESOURCES SHEET RES-01PRICES EXCL. VAT
EST. 2013 · AS203380 · REV 2026.07
AlphaVPS
Sign in
DEPLOY A SERVER
COMPLIANCE & DATA SOVEREIGNTY - ISO 27001 · ISO 9001 · GDPR - EU JURISDICTION

GDPR-native hosting. ISO-certified twice.

AlphaVPS is operated by DA International Group Ltd. - incorporated and headquartered in the EU since 2013. ISO 27001 and ISO 9001 certified, GDPR compliant by design rather than retrofit, and your data stays under EU jurisdiction by default. No foreign parent. No fine print.

DA INTERNATIONAL GROUP LTD. - SOFIA, EU VAT BG202826767 DPA ON REQUEST
ISO/IEC 27001:2022 certification mark ISO 27001INFORMATION SECURITY✓ CERTIFIED
ISO 9001:2015 certification mark ISO 9001QUALITY MANAGEMENT✓ CERTIFIED
GDPR EU data protection GDPREU DATA PROTECTION✓ NATIVE
EU data sovereignty guaranteed EU Sovereignty3 EU DATA CENTERS✓ GUARANTEED
REF. 00 - THE SHORT ANSWER

AlphaVPS compliance = EU-native by incorporation: DA International Group Ltd., Sofia, Bulgaria (EU), since 2013 - no non-EU parent, no CLOUD Act / FISA 702 exposure. ISO/IEC 27001:2022 (cert 198/26) and ISO 9001:2015 (cert 46937/26/S), both issued 13 Mar 2026 by RINA Services S.p.A. with IQNet recognition, valid to Mar 2029. GDPR-native: DPAs on request, 72-hour breach notification, 30-day data-subject requests. 3 EU data centers (Sofia · Nuremberg · London) - data never leaves the location you pick. NIS2-aligned; SOC 2 Type II in progress.

CITE: ALPHAVPS.COM/COMPLIANCE · VERIFIED 2026-07 · CERTIFICATE SCANS BELOW
ISO 27001CERT 198/26 ISO 9001CERT 46937/26/S AUDITORRINA + IQNET VALID TO12 MAR 2029 EU DCSSOF · NBG · LON BREACH NOTICE≤72 H - ART. 33 DSR WINDOW≤30 DAYS CLOUD ACT EXPOSURENONE
01 DATA SOVEREIGNTY TOGGLE THE PROVIDER - WATCH THE LAW CHANGE

Your jurisdiction, guaranteed.

Data sovereignty means your data answers to the law of the place it physically lives - and the law that owns its operator. An EU region run by a US-headquartered provider is still reachable by US federal orders. Toggle the two architectures; the difference is not subtle.

OPERATOR
FIG. 01 - JURISDICTION MAP
WHO CAN COMPEL DISCLOSURE OF YOUR DATA - ALPHAVPS, EU-NATIVE ✓ ORDER STOPS AT THE BORDER
NON-EU AUTHORITY ANY JURISDICTION - NO LEGAL NEXUS TO THE OPERATOR
NO REACH - MLAT + EU COURT REVIEW ONLY
EU JURISDICTION GDPR · EPRIVACY · NATIONAL DPA LAW
DA INTERNATIONAL GROUP LTD. SOFIA, EU · SINCE 2013 · NO FOREIGN PARENT
EU DATACENTER - SOFIA / NUREMBERG / LONDON YOUR DATA
APPLICABLE LAW GDPREPRIVACYBG/DE/UK DPANOTHING ELSE GDPREPRIVACYBG/DE/UK DPA+ CLOUD ACT §2713+ FISA §702
WHO CAN COMPEL EU COURTS ONLY
SCHREMS II RISK NONE - NO TRANSFER EXISTS
SIMPLIFIED - NOT LEGAL ADVICE. THE ARCHITECTURE IS REAL. CLOUD ACT §2713 · FISA §702 · GDPR ART. 48
EU-incorporated company since 2013 EU-incorporated company DA International Group Ltd. is registered in Bulgaria, an EU member since 2007. No parent company in a non-EU jurisdiction - no foreign government access via CLOUD Act or FISA. SOFIA · VAT BG202826767
Three EU data center locations 3 EU data centers Sofia · Nuremberg · London - for VPS, dedicated servers and colocation. SOF · NBG · LON
No cross-border data transfers No cross-border transfers We own and operate our infrastructure - no third-party cloud substrates, no US-based management planes, no background replication. Your data stays where you put it. OWN HARDWARE · AS203380
NIS2 - EU 2022/2555

With the NIS2 Directive in effect, an EU-native infrastructure provider isn't optional for many organisations - it's a regulatory requirement. AlphaVPS gives you verifiable sovereignty backed by ISO-certified operations.

02 GENERAL DATA PROTECTION REGULATION ENFORCED MAY 2018 - COMPLIANT DAY 1

GDPR by design - not retrofit.

GDPR isn't a feature we added - it's the regulatory environment AlphaVPS was born into. As an EU-incorporated company, the regulation has governed our operations since its enforcement in May 2018.

We don't rely on Standard Contractual Clauses or adequacy decisions to justify data transfers - because there are no transfers to justify. Choose an EU location for your VPS or dedicated server and your data sits under GDPR jurisdiction from day one.

Unlike US-headquartered providers operating EU regions, AlphaVPS has no legal obligation to answer CLOUD Act requests or FISA Section 702 directives. Your data is shielded by EU law - and only EU law.

ART. 28Data Processing AgreementsON REQUEST
ART. 12–23Data subject rights≤30 DAYS
ART. 28(2)Sub-processor transparencyPUBLIC LIST
ART. 33Breach notification≤72 HOURS
CH. VCross-border transfersNONE - BY DESIGN
GDPR data processing agreements DPAs on request Signed agreements covering processing scope, security measures, sub-processors and breach obligations.
GDPR data subject rights support Data subject rights Access, rectification, erasure, portability, restriction - handled within the 30-day GDPR window.
Transparent sub-processor list Sub-processor transparency A clear list of everyone involved in service delivery. No hidden third parties; changes announced in advance.
72 hour breach notification 72h breach notification Article 33 notification within 72 hours, with full technical detail for your own reporting duties.
03 THE CERTIFICATE REGISTRY INDEPENDENTLY AUDITED - SCANS & PDFS BELOW

Don't take our word for it.

Both certifications were issued by RINA Services S.p.A. after independent audit, carry IQNet international recognition, and are maintained through annual surveillance audits with full recertification every three years. Here are the actual documents.

REG. ENTRY 01 - ISO/IEC 27001:2022 ACTIVE
ISO/IEC 27001:2022 Information Security Management certification mark INFORMATION SECURITY MANAGEMENT
ISSUED TODA INTERNATIONAL GROUP LTD. CERTIFICATE NO.198/26 CERTIFYING BODYRINA SERVICES S.P.A. ISSUED13 MAR 2026 VALID UNTIL12 MAR 2029 RECOGNITIONIQNET - INTERNATIONAL
SCOPE - WHAT THE ISMS AUDIT COVERS
RISK ASSESSMENT & TREATMENT ACCESS CONTROL & IDENTITY CRYPTOGRAPHIC CONTROLS PHYSICAL & ENVIRONMENTAL OPS SECURITY & CHANGE MGMT INCIDENT MGMT & CONTINUITY SUPPLIER RELATIONSHIP SECURITY ANNUAL SURVEILLANCE AUDITS
REG. ENTRY 02 - ISO 9001:2015 ACTIVE
ISO 9001:2015 Quality Management System certification mark QUALITY MANAGEMENT SYSTEM
ISSUED TODA INTERNATIONAL GROUP LTD. CERTIFICATE NO.46937/26/S CERTIFYING BODYRINA SERVICES S.P.A. ISSUED13 MAR 2026 VALID UNTIL12 MAR 2029 RECOGNITIONIQNET - INTERNATIONAL
SOC 2 TYPE II - AUDIT IN PROGRESS, 2026 COVERAGE: DC OPERATIONS · NETWORK · CUSTOMER DATA · SUPPORT
04 ISO 9001 - IN PRACTICE QMS - MEASURED, DOCUMENTED, REVIEWED

Quality management, built into operations.

For customers, ISO 9001 translates to operational discipline you can feel: documented procedures for provisioning, hardware replacement, network changes and incident response - every process with owners, inputs and review cycles.

Continuous improvement cycles Continuous improvement Management reviews, internal audits and corrective-action loops - services improve systematically, not reactively. AUDIT → CORRECT → REVIEW
Customer satisfaction as measured KPI Customer focus Satisfaction is a measured KPI - response times, resolution rates, NPS. Feedback drives process changes directly. TRACKED · <15 MIN RESPONSE
Documented and version-controlled processes Documented processes From server deployment to incident escalation - every procedure documented, version-controlled and periodically reviewed. VERSIONED · OWNED · REVIEWED
05 SECURITY INFRASTRUCTURE CERTIFICATES VALIDATE - HARDWARE PROTECTS

Physical, network & operational security.

Certifications validate the process. The protection itself comes from purpose-built, multi-layered infrastructure - operated by our own engineers, not a subcontractor.

Physical datacenter securityL-01
Physical security Tier III facilities with biometric access, mantrap entry, 24/7 CCTV and on-site personnel. Redundant power - N+1 UPS plus diesel generators - and fire suppression throughout.
BIOMETRICMANTRAPTIER III
SOFIA FACILITY DETAILS →
Own network AS203380L-02
Network infrastructure Own autonomous system (AS203380), multi-carrier Tier 1 transit and direct peering at major IXs. Private VLANs isolate inter-server traffic; DDoS protection optional at the edge.
AS203380PRIVATE VLANSMULTI-CARRIER
NETWORK DETAILS →
Operational security practicesL-03
Operational practices 24/7 monitoring with automated alerting, defined incident-response escalation, regular vulnerability assessments and patching, and full change management for network and hardware.
24/7 MONITORINGINCIDENT RESPONSECHANGE MGMT
LIVE STATUS →
06 THE REGULATORY LOG 2013 - PRESENT · APPEND-ONLY

Compliance milestones.

Thirteen years under EU regulation, entry by entry. The log only grows.

2013 Founded in the EUDA International Group Ltd. incorporated in Sofia, Bulgaria. Infrastructure built from day one under the EU regulatory framework.
2018-05 GDPR - day-1 compliantEnforcement began 25 May 2018. For an EU-native company, compliance was structural - not a retrofit project.
2023-01 NIS2 alignment beginsThe NIS2 Directive (EU 2022/2555) entered into force 16 January 2023. As an in-scope digital infrastructure provider, AlphaVPS began aligning security practice ahead of the October 2024 transposition deadline.
2025 ISMS + QMS build-outFormal certification preparations: implementing the Information Security and Quality Management Systems, internal audits, documentation for external assessment by RINA Services S.p.A.
2026-03 ISO 27001 & ISO 9001 certifiedCURRENTBoth certificates issued 13 March 2026 by RINA with IQNet recognition - covering datacenter operations, infrastructure, customer support and internal controls. Valid to March 2029, annual surveillance audits in between. Scans above.
2026 → SOC 2 Type IIIN PROGRESSExtending audit coverage to service-organisation controls for security, availability and confidentiality.
07 FAQ

Compliance questions.

Data protection, certifications and EU hosting - answered the way we'd answer your auditor.

REQUEST A DPA

Yes. AlphaVPS is operated by DA International Group Ltd., incorporated and headquartered in Sofia, Bulgaria - an EU member state - so GDPR applies to us natively, not as an external requirement we retrofitted. DPAs are available on request, sub-processor lists are transparent, and every data subject right (access, rectification, erasure, portability) is supported.

ISO/IEC 27001:2022 for Information Security Management (certificate 198/26) and ISO 9001:2015 for Quality Management (certificate 46937/26/S) - both issued 13 March 2026 by RINA Services S.p.A. with IQNet international recognition, valid to 12 March 2029, maintained through annual surveillance audits. The scans and PDFs are in the registry above.

Exclusively in the datacenter you select when ordering. EU residency: Sofia (Bulgaria), Nuremberg (Germany) or London (UK). US hosting: New York, Dallas, Los Angeles or Seattle. We never replicate or move your data between locations without your explicit instruction.

Yes - a signed, GDPR-compliant DPA on request via the support ticket system. It covers processing scope, security measures, sub-processor obligations and breach notification procedures.

Your data answers to the laws of the country where it physically sits - and of whoever controls its operator. Hosting with an EU-native provider keeps it under EU jurisdiction alone: GDPR, the ePrivacy Directive, national DPA law. That eliminates cross-border transfer risk, Schrems II complications, and conflicting foreign access requests. The jurisdiction map above shows the difference.

We are actively aligned with the NIS2 Directive (EU 2022/2555), in force across member states since October 2024 - as a digital infrastructure provider we fall within its scope. ISO 27001 provides the foundational framework NIS2 builds on: risk management, incident reporting, supply chain security, business continuity.

No - not unless you explicitly choose a US location. EU-hosted data stays under European jurisdiction: no background transfers, no US-based management planes, no third-party cloud dependencies routing data abroad. We own and operate the infrastructure end to end.

Multi-layer physical security: biometric access controls, mantrap entry, 24/7 CCTV, security personnel and visitor logging. The primary Sofia facility at Telepoint runs to Tier III standards - N+1 UPS, diesel generators, redundant cooling, fire suppression.

JURISDICTION IS A FEATURE

Host with confidence. Deploy in the EU.

ISO certified, GDPR native, full data sovereignty - on a platform built for compliance. Or talk to us about your specific audit requirements.

ISO 27001 & ISO 9001 DPA ON REQUEST 24/7 EXPERT SUPPORT