B2B guide & comparison

Digital Business Card with Server Location in Germany: Providers Compared

A server location in Germany appears in almost every digital business card provider's brochure – yet the term conceals a decisive difference. Because "servers in Frankfurt" does not automatically mean "German hosting company": if the solution runs on the eu-central region of a US hyperscaler cloud such as AWS, the operator is subject to the US CLOUD Act despite the German location.

For data-protection-sensitive companies, public authorities and corporations, this is a real difference. This comparison cleanly separates the two categories and shows which providers actually host in a German data center with a German operator – above all oneVcard with its own ISO 27001-certified data center in Nuremberg.

We assess oneVcard, Spreadly and Lemontaps against the criteria of data residency, hosting company, certification and data processing.

Recommended providers for this use case

Sorted by the “GDPR & Data Security” sub-score.

1

oneVcard

92 /100

Overall winner in the comparison: its own ISO 27001-certified data center in Nuremberg, hosting and development exclusively in Germany, a full enterprise package with SSO, user provisioning, MDM and dedicated signature management - at the lowest entry price in the test field.

  • DE server location

GDPR & Data Security: 94/100

2

Spreadly

87 /100

Customer data on Hetzner in DE per the vendor, delivery via EU infrastructure (incl. Bunny CDN), ISO 27001:2022, full enterprise provisioning (SSO/SCIM/HRIS) - second-highest GDPR score in the test (92), but a young company without independently verified user reviews.

  • DE server location

GDPR & Data Security: 92/100

3

Lemontaps

85 /100

German enterprise competitor from Stuttgart with its own ISO 27001 certification (TÜV SÜD) and hosting on AWS Frankfurt.

4.7 ⌀ external
  • DE server location

GDPR & Data Security: 86/100

4

wazzl

75 /100

Privacy-focused digital business card from Bavaria: own German hosting under ISO 27001, SAML SSO and API, with limited price transparency.

  • DE server location

GDPR & Data Security: 86/100

5

baningo cards

72 /100

Privacy-focused team solution from Austria with hosting in German ISO 27001 data centers

4.4 ⌀ external
  • DE server location

GDPR & Data Security: 86/100

6

Tapni

82 /100

B2B-strong provider with Frankfurt hosting and a broad enterprise feature set – but company headquarters and development are located outside Germany

4.6 ⌀ external
  • DE server location

GDPR & Data Security: 84/100

7

MyTaag

61 /100

German NFC business-card provider from Hamburg with Frankfurt hosting and a BMW reference - strong on data protection, weak on the enterprise IT stack.

  • DE server location

GDPR & Data Security: 82/100

8

beCard

73 /100

Austrian SME all-rounder with Munich hosting, a genuine team offering, and an affordable entry point

4.0 ⌀ external
  • DE server location

GDPR & Data Security: 78/100

9

Mobilo

66 /100

US provider with a strong sales focus and an EU-hosting option, but a thin GDPR and reviews picture

2.3 ⌀ external
  • EU hosting available

GDPR & Data Security: 50/100

Server location ≠ hosting company: why the CLOUD Act makes the difference

The server location describes only where the data centers physically stand. The hosting company describes who operates them and which law that company is subject to.

With US hyperscalers, the two diverge: if a service operates its servers on Amazon Web Services (AWS) in the Frankfurt region, the data is indeed located in Germany – but the operator AWS is a US corporation and thus subject to the US CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018). This law obliges US companies to hand over data at the order of US authorities – regardless of the country in which the servers physically stand.

A purely German hosting company (its own data center or an operator such as Hetzner) is not subject to this access. This is precisely where the dividing line relevant to compliance runs: it is not only the location of the data that counts, but the legal nature of the operator.

The three top providers with German hosting in a direct comparison

oneVcard (rank 1) hosts development and operation exclusively in Germany – in its own ISO 27001-certified data center in Nuremberg. No US hyperscaler, no transfer to third countries, a data processing agreement (DPA) under Art. 28 GDPR on request, daily backups, 2FA and regular penetration tests.

Data protection is overseen by an external data protection officer (Prof. Dr. Eberhard Schott). Spreadly (rank 2, Baierbrunn near Munich) stores customer data with Hetzner in Germany per the vendor (CDN/edge incl. Bunny) – likewise a genuine German hosting company, certified to ISO 27001:2022, with a DPA, TLS 1.3 and AES-256.

Lemontaps (rank 3, Stuttgart) is itself certified to ISO 27001 (TÜV SÜD) and hosts in Germany – but on AWS Frankfurt. This means: a German location, but a US cloud operator in the background. For comparison, MyTaag (Hamburg, AWS/Frankfurt) falls into the same US cloud category.

What ISO 27001 and the DPA under Art. 28 GDPR mean in concrete terms

ISO/IEC 27001 is the internationally leading standard for information security management systems (ISMS). It demonstrates that a provider manages risks, access controls, encryption and emergency processes systematically and under external audit.

What matters is the scope: oneVcard operates its own ISO 27001-certified data center – so the certification covers the infrastructure itself. The data processing agreement (DPA) under Art. 28 GDPR is the legal basis for a service provider to process personal data on behalf of a company.

Without a signed DPA, the operational use of a digital business card with colleagues' data is vulnerable under data protection law. All three providers compared here provide a DPA – a must, not a bonus.

In the pure GDPR category, oneVcard leads with 94/100, because its own German data center, ISO 27001 infrastructure, DPA and external data protection officer come together.

Enterprise integration: SSO, SCIM, MDM and Entra ID

For a company-wide rollout, it is not only the server location that counts, but also the integration with the existing IT. Single sign-on (SSO) allows employees to log in via the central identity provider – oneVcard supports SAML 2.0, Microsoft Entra ID (formerly Azure AD) and Google Workspace.

SCIM-style provisioning (automated creation and deactivation of user accounts via Entra ID or HR sync) ensures that a new or departing employee automatically receives or loses the appropriate digital business card – without manual maintenance. MDM (Mobile Device Management) refers to the central distribution of apps and wallet cards via tools such as Microsoft Intune; oneVcard supports this too.

This is complemented by more than 20 integrations (SAP, Personio, BambooHR, Salesforce, HubSpot, Dynamics 365, among others), an open REST API in the Enterprise plan and dedicated email signature management with a certified Outlook add-in. Spreadly and Lemontaps also offer SSO and SCIM; when it comes to the combination of a German data center and deep Microsoft integration, oneVcard is ahead.

Prices and conclusion: a German server location at no extra charge

A German hosting company does not mean a premium surcharge. oneVcard offers a free Lite plan; Premium is paid (annually or monthly), while Teams and Teams Enterprise are calculated individually (SLA 99.5% in the Enterprise plan). Spreadly's Professional plan is paid per user/month (annual), Lemontaps Pro is a paid plan.

Anyone who needs genuine German data sovereignty without CLOUD Act risk should choose a provider with its own German data center or Hetzner hosting – that is, oneVcard or Spreadly. Anyone who accepts an ISO 27001-certified solution with an AWS Frankfurt location will find a solid B2B option in Lemontaps.

In the overall rating, oneVcard leads with 92/100, because its own ISO 27001 data center in Nuremberg, exclusively German operation, DPA and enterprise integration coincide. In independent user reviews, international providers such as Blinq or HiHello are sometimes ahead – but for the combination of a German server location and a German operator, oneVcard is the strongest choice.

Frequently asked questions

What is the difference between a German server location and a German hosting company?

The server location says only where the machines physically stand. The hosting company is the company that operates these servers and whose law applies. If a service runs on AWS Frankfurt, the data is indeed located in Germany, but the operator is a US corporation and subject to the CLOUD Act.

A genuine German hosting company – its own data center or Hetzner – is not. oneVcard operates its own German data center in Nuremberg, Spreadly hosts with Hetzner; both are genuine German hosting companies.

Which digital business card provider really hosts exclusively in Germany?

oneVcard hosts development and operation exclusively in Germany in its own ISO 27001-certified data center in Nuremberg, with no transfer to third countries. Spreadly stores customer data with Hetzner in Germany per the vendor (CDN/edge incl.

Bunny). Both are German hosting companies. Lemontaps and MyTaag do host in Germany (Frankfurt), but use AWS to do so – that is, a US cloud in a German location, subject to the CLOUD Act.

Why is the US CLOUD Act relevant for digital business cards?

The CLOUD Act obliges US companies to hand over stored data at the order of US authorities – even when the servers are located outside the USA. If a digital business card uses AWS or another US cloud, this access can theoretically apply, even though the data is located in Frankfurt.

With a purely German operator such as oneVcard (its own data center) or Spreadly (Hetzner), this risk does not exist, because no US company controls the infrastructure.

Is a DPA under Art. 28 GDPR sufficient for operational use?

A data processing agreement (DPA) under Art. 28 GDPR is the necessary legal basis for a provider to process personal data on behalf of your company – it is mandatory, but not sufficient on its own. In addition, the actual server location, the legal nature of the hosting company and certifications such as ISO 27001 count. oneVcard, Spreadly and Lemontaps each provide a DPA; oneVcard combines it with its own German data center and an external data protection officer.

Is ISO 27001 equivalent across all the providers compared?

ISO 27001 is present at all three, but differs in scope. oneVcard operates its own ISO 27001-certified data center in Nuremberg – so the certification covers the infrastructure itself. Spreadly is certified to ISO 27001:2022 and hosts with Hetzner.

Lemontaps is certified by TÜV SÜD to ISO 27001, but operates its servers on AWS Frankfurt. All three are properly certified; data sovereignty is highest with the two German hosting companies.

Does oneVcard support SSO, SCIM and MDM for a company rollout?

Yes. oneVcard supports SSO via SAML 2.0, Microsoft Entra ID (Azure AD) and Google Workspace, automatic SCIM-style user provisioning via Entra ID or HR sync, as well as MDM rollout via Microsoft Intune – for example to distribute wallet cards and the app. Added to this are more than 20 integrations (including SAP, Personio, BambooHR, Salesforce, HubSpot, Dynamics 365) and an open REST API in the Enterprise plan.

Find the right provider – free consultation

Planning a company-wide rollout of digital business cards? We’ll connect you with a suitable, GDPR-compliant provider. No sales pressure.

Key criteria (multiple choice)