Of the tools in this comparison, Modjo has the strongest EU-residency story, and an honest page says so. Modjo is a French company (RINGO SAS), it hosts on AWS in France and the EEA, its published AI sub-processors run in EU data centers under a contractual no-training guarantee, and it is SOC 2 Type II certified. It is straightforwardly usable in a GDPR-compliant way. The nuance for a sovereignty buyer is ownership, not location: its named AI sub-processors (OpenAI, Microsoft, Google) are US-headquartered companies operating in EU regions, and its own Privacy Policy reserves the right to make data accessible outside the EU under Standard Contractual Clauses. This piece quotes Modjo's own current documents, retrieved 2026-07-26.
Is Modjo GDPR compliant?
Of the tools in this comparison, Modjo has the strongest EU-residency story, and an honest page says that clearly. Modjo is a French company, it hosts on AWS in France and the EU, its published AI sub-processors run in EU data centers under a contractual no-training guarantee, and it is SOC 2 Type II certified. For an EU controller, that is a genuinely strong starting point, and Modjo is straightforwardly usable in a GDPR-compliant way.
The nuance a sovereignty-focused buyer should understand is about ownership rather than location. Modjo's named AI and recording sub-processors, including OpenAI, Microsoft, and Google, are US-headquartered companies operating in EU regions. EU data residency is not the same as EU corporate control, and a US-owned processor in an EU region can still sit within reach of US extraterritorial law. Modjo's own Privacy Policy also reserves the right to make data accessible to service providers outside the EU under Standard Contractual Clauses. Those are the only defensible caveats, and they are narrow.
Who Modjo is and where it processes data
Modjo is operated by a French entity. Its DPA identifies it as "RINGO (trading under the name MODJO), a simplified joint stock company ... registered in the trade and companies register of Nanterre under number 879 606 283, and whose registered office is located at 59, avenue Sainte-Foy - 92200 Neuilly-sur-Seine, France." That is an EU corporate home, subject to French and EU law, with a named data protection officer at dpo@modjo.ai.
On hosting, Modjo's DPA states: "Personal data processed by RINGO on behalf of the Client and RINGO's websites and databases are hosted by Amazon Web Services on servers located in the European Economic Area." The Privacy Policy narrows this further to France: it states Modjo "requires its hosting service providers to host the data entrusted to it in France," on AWS servers "located in France and in the European Union." Storage residency in the EU is documented in more than one primary document.
Sources, retrieved 2026-07-26: modjo.ai DPA, modjo.ai/en/legals/privacy.
Modjo's DPA and EU hosting
Modjo's Data Processing Agreement is a genuine Article 28 processor agreement written against the GDPR and its French implementation.
The Modjo DPA states it "shall be read and interpreted in the light of the provisions of GDPR" and references "the provisions of Article 28, in particular paragraphs 3 and 4." On transfers it provides: "Any transfer of data to a third country or an international organization by RINGO shall be done only on the basis of this Contract or in order to fulfil a specific requirement under Union or Member State law ... and shall take place in compliance with Chapter V of GDPR." Storage is committed to the EEA, with the safeguard for any onward transfer being Chapter V of the GDPR.
That is a stronger residency commitment than the US-headquartered tools offer, which authorize transfer to the US as the default. Here, EU storage is the default and extra-EEA access is the exception.
Sources, retrieved 2026-07-26: modjo.ai DPA.
The real nuance: EU residency versus EU ownership
Modjo publishes a dedicated sub-processor page, which is more transparency than several competitors offer. Every vendor is labeled with an EU location. Its AI transparency article is explicit: "Modjo works with multiple subcontractors: Microsoft (Azure OpenAI), Google Cloud Platform, and OpenAI," and adds "we ensure that your data is processed exclusively within the European Union. All of our subcontractors operate data centers located in the EU," with a contractual no-training guarantee and data "retained for up to 90 days for abuse and misuse monitoring purposes."
Two points keep this accurate rather than glowing. First, the named AI, recording, and analytics sub-processors, including OpenAI, Microsoft, Google Cloud, Recall, Datadog, and Sentry, are US-headquartered companies. Modjo's claim is EU data-center location, not EU corporate ownership, and a US-owned processor operating in an EU region can still fall within US extraterritorial reach such as the CLOUD Act. Second, Modjo's Privacy Policy reserves an exception: if data "is transmitted or made accessible to RINGO's service providers located outside the European Union, RINGO first ensures that these service providers guarantee an adequate level of protection," relying on "the European Commission's standard contractual clauses." That softens a flat "exclusively in the EU" reading. One more honest gap: the specific speech-to-text transcription vendor is not named in the documents we could fetch.
Sources, retrieved 2026-07-26: modjo.ai subprocessors, help.modjo.ai AI subcontractors, modjo.ai/en/legals/privacy.
Where Modjo is genuinely solid
This is a strong EU competitor, and the sourced facts should be stated without hedging.
- French entity, French registration. RINGO SAS, Nanterre RCS 879 606 283, HQ in Neuilly-sur-Seine. GDPR-native, with an EU corporate home.
- EU hosting stated across documents. AWS in France and the EEA, committed in the DPA, Privacy Policy, and trust center.
- EU-region AI with a no-training guarantee. Azure OpenAI, Google Cloud, and OpenAI run in EU data centers per Modjo's disclosure, contractually excluded from model training, with a 90-day retention window for abuse monitoring.
- SOC 2 Type II, annual third-party penetration testing, encryption in transit and at rest, and a transparent, dedicated sub-processor page.
For many EU buyers, that posture is sufficient. The residual question is narrow and specific: whether US-owned AI processors operating in EU regions meet your sovereignty bar, or whether you need the AI and transcription layers to run on infrastructure with no US corporate nexus at all.
The EU-native alternative
If US-owned AI processors operating in EU regions do not meet your sovereignty bar, the remaining gap is the corporate nexus of the AI layer itself. The structural answer is a provider with no US hosting and no US AI provider in the analysis loop. Numi is a sovereign meeting assistant built on that principle: EU data residency, self-hosted open-source transcription, no US AI provider in the loop, and a GDPR Article 28 processor agreement (Auftragsverarbeitungsvertrag) behind it. For the full field of EU-native options, see our guide to Gong alternatives for the DACH region in 2026, and compare the data practices of the major tools on our compliance comparison hub.