Our Journey to Data Sovereignty and Self-Hosting or: Why we left Big Tech behind

18th September 2026
10 minute read
Data Sovereignty and Self-Hosting

For years, Ethical Pixels® operated using the same stack most of our peers did. Google Workspace for email and docs, a handful of US-based SaaS tools stitched together, the major players for hosting/compute and a quiet assumption that “everyone uses these, so they must be the safe choice.”

Big tech has been the obvious default for many. Reliable, affordable, feature-rich, and backed by companies supposedly “too big to fail”.

That assumption has been quietly decaying for some time. 

Over the past year, we’ve moved our entire operational stack away from US big tech and onto self-hosted, European-based infrastructure. Some of our clients are now not far behind. This post is about why – and why we think more businesses should be asking the same questions we did.

The cracks were always there

Big tech got big by being genuinely good at what it does (and as a result of having the budgets to throw at it). But “good at what it does” and “good for you” aren’t necessarily the same thing. Especially once you’re a small customer in a company of millions (or even billions) of users.

Our concerns began to include:

  • The value of our business to big tech, and the quality of relationship and support we could expect
  • Pure profit and shareholder mentality, resulting in enshittification and increasingly degraded service over time
  • Lack of choice and control over new features and access to critical data
  • Privacy concerns in sending data to the US and poor privacy practices
  • Not wanting to be beholden to US-headquartered tech providers who can’t be trusted to continue service if it isn’t in their political interests
  • Ethical considerations – not contributing to companies that are enabling organisations like ICE or Flock
  • Cost implications – the hidden cost of big tech can actually make it significantly more expensive

The value gap

At the scale big tech operates, you’re not really in a customer relationship. Realistically, you’re a line in a spreadsheet, served by a support system designed for statistical averages, not for your specific problem.

We saw this play out with a company we know well. They’d cancelled a contract with Google, and Google charged them for it twice instead. Not a huge sum, but clearly wrong. Getting it fixed should have been routine. Instead, because the contract was already cancelled, they’d lost access to the support channels that might have helped. They were outside the loop, with no account manager, no clear escalation path, and no human accountable for resolving the situation. Just a chatbot that sent them round in circles. 

Their only real option was a chargeback on their credit card. Google’s response was to get difficult with them, even though a chargeback was the only route left open to them. There was likely no malice in this, probably just process. But that’s exactly the point: at that scale, there doesn’t need to be malice for you to get burned. You’re simply not big enough to matter when something goes wrong.

Profit motive

It’s also worth naming the thing a lot of businesses feel but don’t say out loud: it’s hard to trust that a US tech giant will have your back when the numbers say otherwise. These are, overwhelmingly, publicly traded companies answering to shareholders first. When a bigger opportunity, a bigger government contract, or a friendlier relationship with whoever holds power is on the table, “small fry” customers like us are not the priority. We’re the ones least likely to be defended if a bigger interest points the other way.

We’ve watched plenty of the same companies that market themselves on values, openness, and “don’t be evil”-era slogans quietly soften their public positions, take on lucrative contracts, and align themselves with an administration whose policies plenty of their own customers and staff strongly disagree with – including agencies and initiatives that a lot of us would rather not be indirectly funding through a monthly subscription. That’s not really a partisan statement so much as an observation about incentives for these firms: when profit and principles come into conflict at that scale, principles seem to lose.

We can’t control who these companies choose to do business with, but we can control who we choose to do business with.

Enforced features

There’s a specific type of powerlessness that comes with hosted platforms – features get pushed to you, not chosen by you.

When Google made Gemini a default part of Workspace, we went into the admin console to switch it off for every user. This wasn’t straightforward to do and, even when following the documentation, it still seemed to show up for users inside the tools. Other users found they couldn’t even get the setting and had to reach out to support to have it disabled.

All the while, AI features were already live in Gmail, Docs and Drive by default, sitting on top of client data, confidential documents, and privileged conversations.

If you’re a legal, medical, financial, or any client-confidentiality-bound business, “our AI vendor’s assistant has been quietly reading through documents we didn’t ask it to touch, and we couldn’t fully turn it off” is a real problem. A compliance one, a confidentiality one, and (depending on what’s in those documents) potentially a legal one. 

Privacy problems

Reports through late 2025 and into 2026 about Gmail and Workspace quietly expanding what AI tools can access (email content, drive documents, chat history) for “smart features” that are opt-out rather than opt-in, made something uncomfortable clear: the terms of the relationship can change under you, on their timeline, not yours. Whether or not you trust the specific privacy claims, the pattern is the real issue. The default keeps shifting in the direction that serves the platform’s AI ambitions, and the burden of noticing and opting out falls on you.

None of this is really about one bad support ticket or one privacy policy update. It’s about recognising that when a handful of US-headquartered companies control the infrastructure most of the world’s businesses run on, your continuity, your privacy, and your data are ultimately subject to decisions made in boardrooms you have no visibility into.

Decisions that get made in their interest, not necessarily yours.

What we actually did

We didn’t rip everything out overnight. We moved deliberately, service by service, replacing big tech dependencies with self-hosted, open-source, or EU-based alternatives.

There is a serious lack of options for businesses looking for something like Google Workspace of Microsoft 365 that isn’t owned by US companies. Providers like Proton and Mailbox do a good job for individuals or families, but are lacking a fully-featured productivity suite. Nextcloud is evolving all the time, but requires a lot of effort and maintenance to host. 

Ultimately, we moved our email and productivity tools to Infomaniak’s kSuite – a value-led firm that hosts their offering on directly owned infrastructure in Switzerland. We’ve been very impressed with the service so far.

We then gradually moved services like authentication, password management, our CRM and internal tools, knowledge base, task management, code hosting, uptime monitoring, and our VPN – all brought onto infrastructure we control or that sits firmly within EU jurisdiction.

The details of the exact stack matter less than the principle behind it: everywhere we had a choice, we’ve chosen a provider or a self-hosted tool where we decide what happens to our data, not a distant platform whose incentives may or may not line up with ours.

We're not alone in thinking this way

This isn’t a fringe position anymore, it’s becoming a mainstream one, including at a governmental level. France’s national digital agency announced in April 2026 that it’s moving all government workstations from Windows to Linux, with every ministry required to formalise a plan to cut reliance on non-European tech providers.

Germany’s Schleswig-Holstein region got there first, migrating around 30,000 workstations to Linux and saving an estimated €15 million in licensing costs along the way. Denmark, Austria, and the Netherlands are all moving in the same direction, and the EU as a bloc has formally adopted a digital sovereignty charter.

Governments don’t move this way for fun. Procurement cycles are slow and political risk is real. When national governments start treating dependence on US tech infrastructure as a strategic vulnerability worth the cost and disruption of migration, it’s a strong signal that the underlying concern is legitimate, not paranoid.

Why it matters to us

A few things pulled us in this direction at the same time:

  • Control and sovereignty – our data (and our clients’ data) now sits with providers bound by EU law, on infrastructure we understand and, in most cases, control directly.

  • Resilience – we’re no longer betting our operations on the continued goodwill of a company that could change pricing, policy, or product direction overnight, with no obligation to consider what that does to a customer our size.

  • Cost – self-hosting and EU alternatives have, in most cases, worked out cheaper than the big tech equivalents once you account for the tiers, add-ons, and per-seat pricing creep that comes with the incumbent platforms.

  • Privacy and GDPR – working with EU-based providers and infrastructure we control gives us a much cleaner, more defensible privacy posture, with fewer questions about where data actually lives and who can access it.

  • Ethics – somewhat harder to quantify but a pivotal concern for us. Some of the same companies we were paying every month are also the ones building infrastructure and AI systems used by US immigration enforcement and other questionable parts of the current US administration’s agenda. We don’t think that should be a footnote. Where we can choose not to fund that with our subscription fees (however small they might be in the grand scheme) we will.

What this means for you

We’re not saying every business needs to self-host everything tomorrow – that’s not realistic for most people, and it wasn’t a walk in the park for us either.

However, we’d encourage anyone reading this to ask themselves the question: if your main provider changed the rules tomorrow, would you be fine? If the honest answer is no, it’s worth understanding what your options actually are.

We went through this transition ourselves, tool by tool, and learned a fair amount about what’s genuinely ready for a business to rely on and what still needs careful handling. If you’re curious about what a similar move could look like for your organisation, whether that’s a full migration or just reducing exposure in a few key areas, we’re happy to talk it through. No sales pitch, just a conversation about what data sovereignty could realistically mean for you.

Get in touch if you’d like to chat.

Written by:

Larry

Managing Director

Larry is a published UX specialist with an extensive track record of creating award-winning online solutions.

More like this...

Do you find our insights useful?

We hope you did. You can share it easily with your network, or if you’d like to know when we have similar insights to share, you can subscribe to our mailing list. We only email a handful of times a year and never share your data with third parties. Read about Privacy.

Share on:

or