A company, that not only immensely obstructs transparency, but also falls into the jurisdiction of foreign / non-EU institutions.
In the US, companies contracted by the federal government must comply with data storage location requirements that DO keep the data strictly within their territory and under national jurisdiction. i believe this falls under FedRAMP regulations. I'm 95%+ certain that major EU countries have equivalent policies (probably even better ones, considering the GDPR and so forth).
That correction aside, I completely agree with the larger concern here.
Right? That's exactly why I give my business automations names like SupaWubbaDubbaHappyTimeAuthyWauthyTeeHeeSecurityWorkflow.