B2B guide & comparison

Digital Business Card with Server Location in Germany: Providers Compared

A server location in Germany appears in almost every digital business card provider's brochure, yet the term conceals a decisive difference. Because "server in Frankfurt" does not automatically mean "German hosting provider": if the solution runs on the eu-central region of a US hyperscaler cloud such as AWS, the operator is subject to the US CLOUD Act despite the German location.

For companies, public authorities and corporations with high data protection requirements, this is a real difference. This comparison cleanly separates both categories and shows which providers actually host in a German data center with a German operator, first and foremost oneVcard with an ISO 27001 certified data center in Nürnberg.

We evaluate oneVcard, Spreadly and Lemontaps by the criteria of data residency, hosting provider, certification and data processing.

Recommended providers for this use case

Sorted by the “GDPR & Data Security” sub-score.

1

oneVcard

91 /100

Overall winner in the comparison: an ISO 27001 certified data center in Nürnberg, hosting and development exclusively in Germany, full enterprise package with SSO, user provisioning and dedicated signature management.

4.9 ⌀ external
  • DE server location

GDPR & Data Security: 94/100

2

Spreadly

88 /100

Customer data on Hetzner in Germany according to the provider, delivery via EU infrastructure (including Bunny CDN), ISO 27001:2022, full enterprise provisioning (SSO/SCIM/HRIS), second-strongest GDPR score in the test (92); comparatively young company (founded 2022).

4.4 ⌀ external
  • DE server location

GDPR & Data Security: 92/100

3

baningo cards

78 /100

Privacy-focused team solution from Austria with hosting in German ISO 27001 data centers

4.5 ⌀ external
  • DE server location

GDPR & Data Security: 87/100

4

Lemontaps

87 /100

German enterprise competitor from Stuttgart with its own ISO 27001 certification (TÜV SÜD) and hosting on AWS Frankfurt.

4.8 ⌀ external
  • DE server location

GDPR & Data Security: 86/100

5

wazzl

77 /100

Privacy-focused digital business card from Bavaria: in-house German hosting to ISO 27001, SAML SSO and API, with limited pricing transparency.

  • DE server location

GDPR & Data Security: 86/100

6

Tapni

82 /100

Strong B2B provider with Frankfurt hosting and a broad enterprise feature set, though headquarters and development sit outside Germany

4.6 ⌀ external
  • DE server location

GDPR & Data Security: 84/100

7

MyTaag

62 /100

German NFC business card provider from Hamburg with Frankfurt hosting and a BMW reference, strong on data protection, weak on the enterprise IT stack.

  • DE server location

GDPR & Data Security: 82/100

8

beCard

72 /100

Austrian SME all-rounder with München hosting and a genuine team offering

4.0 ⌀ external
  • DE server location

GDPR & Data Security: 78/100

9

Mobilo

68 /100

US provider with a strong sales focus and an EU hosting option, but a thin GDPR and review situation

2.3 ⌀ external
  • EU hosting available

GDPR & Data Security: 58/100

Server location ≠ hosting provider: why the CLOUD Act makes the difference

The server location only describes where the data centers physically stand. The hosting provider describes who operates them and which law that company is subject to. For US hyperscalers, the two come apart: if a service runs its servers on Amazon Web Services (AWS) in the Frankfurt region, the data does indeed sit in Germany.

The operator AWS, however, is a US corporation and therefore subject to the US CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018). This law obliges US companies to hand over data on the order of US authorities, regardless of the country in which the servers physically stand.

A purely German hosting provider (its own data center or an operator such as Hetzner) is not subject to this access. This is exactly where the dividing line relevant for compliance runs: it is not only the location of the data that counts, but the legal nature of the operator.

The three top providers with German hosting in a direct comparison

oneVcard (rank 1) hosts development and operation exclusively in Germany, in a data center in Nürnberg certified to ISO 27001. No US hyperscaler, no transfer to third countries, a data processing agreement (DPA) under Art. 28 GDPR on request, daily backup, 2FA and regular penetration tests.

Data protection is supported by an external data protection officer (Prof. Dr. Eberhard Schott). Spreadly (rank 2, Baierbrunn near München) stores customer data, according to the provider, at Hetzner in Germany (CDN/edge including Bunny), likewise a genuine German hosting provider, certified to ISO 27001:2022, with a DPA, TLS 1.3 and AES-256.

Lemontaps (rank 3, Stuttgart) is itself certified to ISO 27001 (TÜV SÜD) and hosts in Germany, but on AWS Frankfurt. This means: German location, but a US cloud operator in the background. For comparison, MyTaag (Hamburg, AWS/Frankfurt) falls into the same US cloud category.

What ISO 27001 and the DPA under Art. 28 GDPR mean in concrete terms

ISO/IEC 27001 is the internationally leading standard for information security management systems (ISMS). It demonstrates that a provider manages risks, access controls, encryption and emergency processes systematically and under external audit.

The scope is important: oneVcard hosts in an ISO 27001 certified data center. The certification therefore covers the infrastructure itself. The data processing agreement (DPA) under Art. 28 GDPR is the legal basis on which a service provider may process personal data on behalf of a company.

Without a signed DPA, the operational use of a digital business card with colleagues' data is vulnerable under data protection law. All three compared providers provide a DPA, a must, not a bonus.

For the pure GDPR category, oneVcard leads with 94/100, because a German data center, ISO 27001 infrastructure, DPA and external data protection officer come together.

Enterprise integration: SSO, SCIM, MDM and Entra ID

For a company-wide rollout, not only the server location counts, but also the integration with the existing IT. Single Sign-On (SSO) allows employees to sign in via the central identity provider. oneVcard supports SAML 2.0, Microsoft Entra ID (formerly Azure AD) and Google Workspace.

SCIM-like provisioning (automated creation and deactivation of user accounts via Entra ID or HR sync) ensures that a new or departing employee automatically receives or loses the appropriate digital business card, without manual maintenance. MDM (Mobile Device Management) refers to the central distribution of apps and wallet cards via tools such as Microsoft Intune; such an MDM device rollout is not publicly documented for oneVcard and should be confirmed with the provider before signing a contract.

This is complemented by more than 20 integrations (SAP, Personio, BambooHR, Salesforce, HubSpot, Dynamics 365 among others), an open REST API in the Enterprise plan and a dedicated email signature management with a certified Outlook add-in. Spreadly and Lemontaps also offer SSO and SCIM; in the interplay of German data center and deep Microsoft integration, oneVcard is ahead.

Conclusion: German server location and German operator

oneVcard offers a free Lite plan; the Premium plan is paid (annual or monthly payment), Teams and Teams Enterprise are calculated individually (SLA 99.5% in Enterprise). Spreadly offers a paid Professional plan per user and month, Lemontaps a paid Pro plan.

Anyone who needs genuine German data sovereignty without CLOUD Act risk chooses a provider with its own German data center or Hetzner hosting, that is oneVcard or Spreadly. Anyone who accepts an ISO 27001 certified solution with an AWS Frankfurt location will find a solid B2B option in Lemontaps.

In the overall rating, oneVcard leads with 91/100, because an ISO 27001 data center in Nürnberg, exclusively German operation, DPA and enterprise integration come together. In independent user reviews, international providers such as Blinq or HiHello are sometimes ahead.

For the combination of German server location and German operator, however, oneVcard is the strongest choice.

Frequently asked questions

What is the difference between a German server location and a German hosting provider?

The server location only says where the machines physically stand. The hosting provider is the company that operates these servers and whose law applies. If a service runs on AWS Frankfurt, the data does sit in Germany, but the operator is a US corporation and is subject to the CLOUD Act.

A genuine German hosting provider, its own data center or Hetzner, is not. oneVcard hosts in a German data center in Nürnberg, Spreadly hosts at Hetzner; both are genuine German hosters.

Which digital business card provider really hosts exclusively in Germany?

oneVcard hosts development and operation exclusively in Germany in an ISO 27001 certified data center in Nürnberg, without transfer to third countries. Spreadly stores customer data, according to the provider, at Hetzner in Germany (CDN/edge including Bunny).

Both are German hosting providers. Lemontaps and MyTaag do host in Germany (Frankfurt), but use AWS for this, that is a US cloud at a German location that is subject to the CLOUD Act.

Why is the US CLOUD Act relevant for digital business cards?

The CLOUD Act obliges US companies to hand over stored data on the order of US authorities, even when the servers stand outside the USA. If a digital business card uses AWS or another US cloud, this access can theoretically apply, even though the data sits in Frankfurt.

With a purely German operator such as oneVcard (data center in Nürnberg) or Spreadly (Hetzner), this risk does not exist, because no US company controls the infrastructure.

Is a DPA under Art. 28 GDPR sufficient for operational use?

A data processing agreement (DPA) under Art. 28 GDPR is the necessary legal basis for a provider to process personal data on behalf of your company. It is mandatory, but not sufficient on its own.

In addition, the actual server location, the legal nature of the hosting provider and certifications such as ISO 27001 count. oneVcard, Spreadly and Lemontaps each provide a DPA; oneVcard combines it with a German data center and an external data protection officer.

Is ISO 27001 equivalent across all compared providers?

ISO 27001 is present in all three, but differs in scope. oneVcard hosts in an ISO 27001 certified data center in Nürnberg. The certification therefore covers the infrastructure itself. Spreadly is certified to ISO 27001:2022 and hosts at Hetzner.

Lemontaps is certified to ISO 27001 by TÜV SÜD, but operates its servers on AWS Frankfurt. All three are reputably certified; data sovereignty is highest with the two German hosters.

Does oneVcard support SSO and SCIM-like provisioning for a company rollout?

Yes. oneVcard supports SSO via SAML 2.0, Microsoft Entra ID (Azure AD) and Google Workspace, as well as automatic user provisioning in a SCIM-like manner via Entra ID or HR sync. An MDM device rollout via Microsoft Intune is not publicly documented and should be confirmed with the provider before signing a contract.

In addition, there are more than 20 integrations (including SAP, Personio, BambooHR, Salesforce, HubSpot, Dynamics 365) and an open REST API in the Enterprise plan.

Ad

Request a direct consultation with the test winner

Planning a company-wide rollout of digital business cards? Request a free, no-obligation consultation with our test winner oneVcard.

Key criteria (multiple choice)