Skip to main content
Volcan MediaVolcan Media
Back to Learn
Data SovereigntyGDPRMake.com

Data Sovereignty for Nezasa Automation: Why Your Data Should Never Leave Your Own Accounts

Sebastian Höing·

Key takeaway: In a properly built Nezasa automation, every account involved — Make.com, SharePoint, Google Workspace — is owned and controlled by the client, not the automation provider. Booking data flows directly from Nezasa into the client’s own workspace and is never stored on third-party infrastructure. This design means the automation keeps running even if the working relationship with the provider ends.

What does “you own everything” mean in a Nezasa automation project?

“You own everything” means the client registers and pays for every account involved in the automation — the Make.com account, the destination SharePoint site or Google Drive — and the automation provider is added only as a limited team member for build purposes, never as the account owner. This structure prevents a common failure mode in freelance or agency-built automations, where the provider’s departure breaks the system because credentials or ownership were never actually transferred to the client.

Why does data sovereignty matter for German-speaking DMCs specifically?

Data sovereignty matters for German-speaking DMCs specifically because their client base and often their own management are subject to DSGVO (the German implementation of GDPR), which imposes specific requirements on how personal and booking data is processed, stored, and transferred. An automation architecture where data never passes through or is stored on a third party’s infrastructure — flowing directly from Nezasa into the client’s own Microsoft 365 or Google Workspace — is structurally easier to reason about from a compliance standpoint than one that introduces an intermediate storage layer.

What happens to the automation if the freelancer relationship ends?

If the working relationship ends, the automation continues running unchanged, because it operates entirely inside the client’s own Make.com account using the client’s own connections to Nezasa, SharePoint, or Google Workspace — nothing about the provider’s involvement is a runtime dependency. This is only true if the account ownership was structured correctly from the start; it is not automatic in every automation engagement, which is why it’s worth confirming explicitly before implementation begins.

Is Make.com DSGVO/GDPR compliant?

Make.com offers EU-based data processing options and is compatible with DSGVO/GDPR requirements when the automation is configured correctly — including choice of processing region and appropriate data processing agreements — which is a configuration decision made during setup, not an automatic property of the platform. A DMC evaluating a Make.com-based automation should confirm the processing region and request documentation of what data passes through the platform, even briefly, during execution.

Data sovereignty principle What it looks like in practice
Client owns all accounts Make.com, SharePoint/Google Workspace registered and paid for by client
No third-party storage Data flows Nezasa → client workspace directly, nothing persisted elsewhere
No dependency on provider Automation keeps running if the provider relationship ends
Full documentation delivered Client (or any future provider) can maintain the system independently

Frequently asked questions

Does Volcan Media store my booking data?

No. Data flows directly from Nezasa into the client's own SharePoint or Google Workspace environment; it is not stored on Volcan Media infrastructure at any point.

Is Make.com GDPR-compliant?

Make.com provides EU data processing options and can be configured to meet DSGVO/GDPR requirements, but compliance depends on correct configuration during setup rather than being automatic by default.

What access does Volcan Media need during implementation?

Typically, temporary access to a dedicated setup account in the client's M365 or Google Workspace environment, scoped to only what is strictly necessary for the build, along with Nezasa API credentials — documented and revocable after go-live.

Want this working for your team?

Book a free 30-minute call and I'll tell you honestly what can — and can't — be automated.

Book a free 30-min call