Security & data sovereignty

Where your data lives. And which law applies to it.

Two questions decide an organisation’s data sovereignty: where the servers are, and who owns the company that runs them. On this page we answer both.

Hosting & operation

Operated in Germany. By a German company.

The platform services run on servers in Germany, operated by ScaleUp Technologies from Hamburg. No service runs on infrastructure from Amazon Web Services, Microsoft Azure or Google Cloud.

The individual services are built on open-source software: their source code is publicly visible and reviewed by a broad expert community, instead of disappearing into a closed system. The portal that connects these services we develop ourselves.

Which services those are in detail

For your records

Data protection officers and auditors need paper, not a brochure. On request you receive:

  • A data processing agreement under Art. 28 GDPR
  • An overview of technical and organisational measures under Art. 32
  • A list of the service providers used
  • Documentation from our data-centre operator, including its ISO/IEC 27001 certification

How data is backed up and restored is set out in the data processing agreement. A transfer to a third country is not envisaged, so standard contractual clauses and a transfer impact assessment are unnecessary.

Data centres
Germany
Infrastructure
ScaleUp Technologies
Operator
czichos.net GmbH, Berlin
US hyperscalers
none in use
Legal framework
GDPR, German law
CLOUD Act
no US ties on the operator’s side
Individual services
open-source software
Data portability
export in open formats

As of July 2026

Data sovereignty

Location alone isn’t enough. What matters is who owns the company.

Many offerings sound European because the servers are in Europe. What’s decisive, though, is which law the operator is subject to. How that compares with American providers we’ve written up in our guide.

US provider with an EU data centre

Servers in the EU. Corporation in the US.

  • The server location really is in the EU
  • Limitation: The parent company is subject to US law
  • Limitation: Under the CLOUD Act, disclosure can be ordered
  • Limitation: How to deal with this legal situation is legally disputed

Connecteeva

Servers in Germany. Company in Berlin.

  • Server location in Germany
  • The operator is czichos.net GmbH, a German company
  • No US parent company, so the CLOUD Act doesn’t apply to us
  • On request, operation in a data centre of your choice, for larger organisations

What is the CLOUD Act?

The “Clarifying Lawful Overseas Use of Data Act” of 2018 requires US companies to hand over data on the order of American authorities, regardless of where that data is physically stored. This also covers subsidiaries and infrastructure operated by US corporations outside the US. For a German operator with no US parent, this obligation doesn’t apply.

That doesn’t mean no one may ask: we too are bound by information requests from German authorities. The difference is that German law applies, with a transparent basis and German legal remedies.

Encryption

Encrypted where it counts. Not just email.

The path between your devices and our servers is always encrypted to current standards. Beyond that, you can specifically encrypt what’s especially worth protecting.

Encrypted email

Emails can be encrypted using the open standards PGP and S/MIME, in the mailbox or in your usual program. Included in the mailbox at no extra charge.

This requires the other party to use PGP or S/MIME as well.

Encrypted files

Confidential documents can be stored and shared encrypted, using the same open methods as email.

Video calls on request

For counselling and confidential meetings, we set up your video calls encrypted on request.

One secure login

All services sit behind a single sign-in. With two-factor login per person on request, at no extra charge.

Betrieb

What we commit to. And what the data-centre operator commits to.

Availability, response times and backups — the figures a board needs for a decision and an auditor needs for the records.

Infrastructure

Committed by ScaleUp Technologies, on whose infrastructure Connecteeva runs.

Availability
99.9 % monthly averagecloud and web hosting
Full outage
60 minutes response timeMon–Fri 9am–6pm
Major impairment
120 minutes response timeMon–Fri 9am–6pm
Technical support by phone
around the clock, seven days a week

The response times apply to reports by phone and denote the time to first handling, not to restoration. Outside business hours they double. The availability commitment applies to the server pool operated by ScaleUp; the applications on top of it are our responsibility. Source: SLA by ScaleUp Technologies, retrieved in July 2026.

Connecteeva

What we commit to ourselves, on top of the infrastructure.

Support
email on working daysusually a reply within 24 hours; a dedicated contact from larger user numbers
Backup
dailythe Connecteeva system; for additionally operated services we set up backups on request
Two-factor login
enabled per personvia user administration, at no extra charge
Roles and rights
per organisation leveldelegable, with no access to other levels

Leaving

If you want to leave, we help you leave.

A provider that promises independence has to describe the way out, too.

  • After cancellation we make your data available as an export: mailboxes, calendars, contacts and files.
  • After the contract ends, the data is kept for at least 30 days, so you can migrate in peace.
  • All services are built on open-source software and open standards. Whatever you take with you can be run elsewhere.
  • Your domain is yours. A move is a small technical step, not a fresh start.

Traceability

Who changed what, and when?

In every account

Connecteeva logs administrative actions in the system. Who created an account, granted rights or enabled a service can be traced later, especially in organisations where several levels are allowed to administer.

  • Traceable changes to accounts, roles and services
  • Written continuously, entries are added and can’t be changed after the fact via the interface
  • Data-minimal, what’s logged is what’s needed for the record
  • Usable for audits by internal audit, treasurers or data protection officers
Administration · change log
The log view of an account in Connecteeva administration: events such as “user created”, “profile picture changed”, “service requested” and “tags changed”, each with a date and the responsible person.
A real view from administration: the change log of an account.

Questions about security? We answer in writing.

Data protection officers, audits and boards need solid information. Tell us what you have to demonstrate, and we’ll answer as specifically as we can. Who we are is on our About page.

We set up a trial and usually send the login details to your contact email within one working day.

No contract and no payment details. You decide whether it stays an enquiry or you try Connecteeva right away.

Prefer to reach us directly? Send an email · call 030 994048000

Address czichos.net GmbH
Königsweg 220
14129 Berlin