kontinent / compliance index

B

OVHcloud

OVH SAS · FR · Last reviewed: 2026-07-27

82

Data Protection Contracts

83/100

OVHcloud provides a Data Processing Agreement (DPA) under Art. 28 GDPR that automatically also covers AI Endpoints.

ja

Source: OVHcloud AVV DE v8.0 (Stand 17.10.2025), Geltungsbereich (automatisch für alle Dienste inkl. AI Endpoints) (reviewed 2026-07-24)

OVHcloud has EU Standard Contractual Clauses (Module 3, Decision 2021/914) in place as an annex to its Data Processing Agreement.

ja

Source: OVHcloud AVV DE v8.0 (Stand 17.10.2025), SCC-Anhang (Modul 3, Processor-to-Processor) (reviewed 2026-07-24)

OVHcloud is contractually committed to reporting security incidents 'without delay'; no fixed hourly deadline is specified.

teilweise

Source: OVHcloud AVV DE v8.0 (Stand 17.10.2025), Art. 5.1 (Incident-Meldung) (reviewed 2026-07-24)

Data Residency & Sovereignty

83/100

OVHcloud allows region selection at order time and AI Endpoints are documented as running in Gravelines (FR); however, there is no explicit contractual EU-only guarantee for remote access/maintenance of AI Endpoints.

teilweise

Source: OVHcloud BVB Public Cloud v25.0 (Stand 12.04.2026) / AVV DE v8.0, BVB Art. 5.5 (Regionswahl); AVV Art. 6.1/6.2 (Standort/Fernzugriff) (reviewed 2026-07-24)

OVHcloud publishes a sub-processor list (v3.0) with a 30- or 90-day advance notice period and a right to object to changes.

ja

Source: OVHcloud Sub-Processor-Liste DE v3.0, Vorankündigungs- und Widerspruchsregelung (reviewed 2026-07-24)

OVHcloud is part of the French OVHcloud Group (OVH SAS), headquartered in France.

ja

Source: OVHcloud AGB DE v10.0 (Stand 17.01.2025), Vertragspartei-Angaben (OVHcloud-Gruppe, Frankreich) (reviewed 2026-07-24)

Data Use

100/100

For AI Endpoints, OVHcloud contractually guarantees zero retention: inputs and outputs are not stored, not backed up, and not accessed; an exception applies only to the separate Batch API mode.

ja

Source: OVHcloud BVB Public Cloud v25.0, Anhang 10 (Stand 12.04.2026), Anhang 10, Art. 2 und Art. 5 (reviewed 2026-07-24)

OVHcloud contractually does not use customer data (prompts/outputs) in any way, including not for model training.

ja

Source: OVHcloud BVB Public Cloud v25.0, Anhang 10 (Stand 12.04.2026), Anhang 10, Art. 5 (reviewed 2026-07-24)

Since OVHcloud does not reuse customer data by default, no separate opt-out is required — this is the contractual default.

ja

Source: OVHcloud BVB Public Cloud v25.0, Anhang 10 (Stand 12.04.2026), Anhang 10, Art. 5 (reviewed 2026-07-24)

Certifications

50/100

OVHcloud holds ISO 27001, 27017, 27018 and 27701 certification; the product list names 31 services including 'Managed Containers' but does not list AI Endpoints as its own entry. An OVHcloud staff member stated in the public product roadmap repository in January 2026 that AI Endpoints is officially ISO 27001 certified, by virtue of the certified Managed Containers it runs on. The certification therefore rests on the underlying platform rather than on the inference service being named in the certification scope.

teilweise

Source: OVHcloud Security Certifications (docs.ovhcloud.com/fr/guides/account-and-service-management/account-information/security-certifications, Abruf 14.08.2026); OVHcloud Compliance-Produktseite; OVHcloud AVV Annex II (TOM); Roadmap-Issue ovh/public-cloud-roadmap#995, Die Zertifizierungsliste nennt 31 Produkte mit ISO/IEC 27001:2022, 27017:2015, 27018:2019 und 27701:2019 — darunter 'Managed Containers', aber NICHT 'AI Endpoints'. Auch die Scope-Liste der Compliance-Seite (Public Cloud Compute, Storage, Managed Kubernetes, AI & machine learning, Data Processing, Logs Data Platform, VPS) nennt AI Endpoints nicht eigenständig. GEGENLÄUFIGE ANBIETERAUSSAGE: Im öffentlichen Roadmap-Issue #995 ('AI Endpoints ISO/HDS Certification', eröffnet 10.11.2025) schreibt DavidDelebecque als COLLABORATOR am 28.01.2026: 'AI endpoint service is officially certified ISO 27001 / HDS (Hébergement Données de Santé)', mit Verweis auf die Zertifizierungsseite und dem Zusatz '(managed containers)'. Die Zertifizierung wird dort also über das Substrat begründet, auf dem AI Endpoints läuft, nicht über eine eigene Scope-Zeile. (reviewed 2026-08-14)

OVHcloud lists SOC and C5 attestations in its TOM annex; the specific certification scope for the AI Endpoints platform has not yet been fully verified.

teilweise

Source: OVHcloud AVV Annex II (TOM), TOM-Anhang, Zertifizierungsliste (reviewed 2026-07-24)

AI Act Readiness

n/a

Pure inference/hosting provider: the AI Act's Article 53 documentation duty falls on the provider of the GPAI model, not on whoever runs the inference. This provider cannot discharge it for third-party models; the duty sits with the respective model provider.

nicht_anwendbar

Source: Verordnung (EU) 2024/1689 (KI-VO), Art. 53 Abs. 1 i. V. m. Art. 3 Nr. 3 – Pflichten des Anbieters eines GPAI-Modells (reviewed 2026-08-04)

Pure inference/hosting provider: the GPAI Code of Practice is open to providers of general-purpose AI models. A provider that merely operates third-party models is not eligible to sign, so an absent signature is not a shortcoming.

nicht_anwendbar

Source: Verordnung (EU) 2024/1689 (KI-VO), Art. 53 Abs. 1 i. V. m. Art. 3 Nr. 3 – Pflichten des Anbieters eines GPAI-Modells (reviewed 2026-08-04)

Contract Quality & Transparency

67/100

OVHcloud publishes its contract documents (Terms, DPA, Public Cloud special conditions) publicly accessible.

ja

Source: OVHcloud AGB DE v10.0 (contract.eu.ovhapis.com), Öffentlich abrufbare Vertragsdokumente (reviewed 2026-07-24)

OVHcloud publishes a per-model SLA for AI Endpoints (at least 99.5% availability, 10-30% credits); the SLA does not apply to models in test-service status.

ja

Source: OVHcloud BVB Public Cloud v25.0, Anhang 10 (Stand 12.04.2026), Anhang 10, Art. 4 (reviewed 2026-07-24)

OVHcloud's liability is capped at 6 months' revenue of the affected service.

nein

Source: OVHcloud AGB DE v10.0 (Stand 17.01.2025), Art. 10.3.2 (Haftungsdeckel) (reviewed 2026-07-24)

Do you represent OVHcloud and think something is inaccurate? Write to legal@kontinent.ai. We check every report and correct verified errors with full transparency.

Report error

Methodology Version 2.0