Saltar para o conteúdo

Providers and jurisdictions

"Your data stays in the EU" is only worth something if you can check it. This page lists every company involved in running ReefOffice, what each one actually does, what data reaches it, and whose courts it answers to. It is the sub-processor list required by Article 28 of the GDPR, written to be read rather than filed.

ProviderWhat it doesWhat data reaches itJurisdictionIndependent certification
Contabo GmbH Munich, Germany · Amtsgericht München HRB 180722Hosts your private serverEverything you store — at rest it is LUKS2-encrypted with a key Contabo does not hold🇩🇪 GermanyISO/IEC 27001 — data centres (supplier statement)
Hetzner Online GmbH Gunzenhausen, GermanyEncrypted off-site backups, and the control plane that manages your serverRestic-encrypted backup archives. Hetzner sees ciphertext only🇩🇪 GermanyISO/IEC 27001:2022 (ISMS, all hosting services and data centres) · BSI C5 Type 2
OVH SAS (OVHcloud) Roubaix, FranceDNS records for your domainYour subdomain name; and, only on Managed AI, the text sent to an AI feature. Synchronous input/output is not stored, reused or used for training🇫🇷 France · group support perimeter: EU, UK and CanadaISO/IEC 27001, 27017, 27018 and 27701
IONOS Cloud GmbH Montabaur, Germany · inference in the Berlin data centreManaged EU AI inference when you enable itOnly on Managed AI, the text sent to an AI feature. Synchronous input/output is not stored, reused or used for training.🇩🇪 GermanyISO/IEC 27001
o2switch Clermont-Ferrand, FranceEmail delivery for notifications and supportYour email address and the content of messages we send you🇫🇷 FranceOwns and operates its Clermont-Ferrand datacenters, built to Tier 4-aligned availability requirements
Mollie B.V. Amsterdam, Netherlands · payment institution supervised by De Nederlandsche BankProcesses the first checkout, payment mandate and recurring subscription paymentsYour billing name, email, payment details and payment history. Never your business data🇳🇱 NetherlandsPayment institution supervised by DNB · PCI DSS Level 1

A IONOS Cloud publica um anexo contratual que nomeia os subcontratantes autorizados a intervir nos seus serviços. Qualquer terceiro tem de constar aí ou nas condições específicas do serviço. Subcontratantes IONOS Cloud — anexo UAV v6.2 ↗

About these certifications

Each entry links to the provider's own certification page, so you can check it rather than take our word for it. Two things are stated precisely on purpose. A certification held by a data centre is not the same as one held by the company operating it. And a certification that covers one product line does not cover the rest — OVHcloud's SecNumCloud qualification, for example, applies to its Hosted Private Cloud offering, which is not the service ReefOffice uses, so it is not claimed here. ReefOffice itself holds no security certification; it is too small to have been audited, and saying so is more useful than implying otherwise.

IA gerida: modelo e condições de utilização

O Managed EU AI encaminha atualmente Essential e Plus para o Mistral Small 24B Instruct na infraestrutura alemã da IONOS Cloud. Os pesos do modelo são abertos sob licença Apache 2.0. Antes da primeira utilização, cada cliente aceita as condições de IA da ReefOffice em vigor, a licença do modelo e as condições de utilização dos serviços de IA da IONOS.

Condições de utilização aceitável de IA da ReefOffice →

Why the jurisdiction matters, not just the location

A server in Frankfurt owned by a US company can still be reached by a US legal order under the CLOUD Act, because that law follows the company rather than the hardware. That is the gap most "EU region" marketing leaves open. Every supplier below is an EU-incorporated company operating EU infrastructure, so both the data and the company answer to EU law.

Who is not on this list

No advertising network, no analytics product, no US hyperscaler, and no AI provider that trains on customer data. ReefOffice runs no third-party tracking scripts on this website — there is nothing to consent to because nothing is collected.

Changes

We give at least 30 days' notice by email before adding or replacing any provider on this list. If you object and we cannot resolve it, you may terminate without penalty and take your data with you. See the Data Processing Agreement for the full terms.

Data Processing Agreement · Política de Privacidade · Segurança

Question about a specific provider?

Ask, and we will answer with the contract terms rather than a summary.

Contact us