Our own servers in Europe · GDPR · Support in your language

Infrastructure and security

Our own servers in Europe

No clouds outside the European Union and no surprises in the data processing agreement. You know where your data is and who touches it.

Where the data lives and why it matters

Hosting data inside the European Union avoids the most awkward part of the GDPR: international transfers. When the provider sits outside the European Economic Area you have to rely on an adequacy decision or standard contractual clauses and justify in writing that the safeguards suffice. Kimobox runs on its own infrastructure in European data centres, so that conversation never has to happen.

Content reviewed on

Location
Data centres in the European Union No international transfers requiring Chapter V GDPR safeguards
Backups
Daily, with tested restores A backup never restored is not a backup, it is an assumption
Encryption
In transit and at rest Measure under art. 32.1.a) of the GDPR
Processing agreement
Art. 28 of the GDPR With the list of sub-processors and a breach notification commitment
Continuity
ISO 27001:2022, controls 5.29 and 5.30 ICT security and readiness during disruption

European data centers

Our own infrastructure, not resold hyperscaler capacity.

Verified backups

Daily backups with periodic restore testing.

Encryption and access control

TLS in transit, encryption at rest, two-factor authentication.

GDPR, no fine print

Data processing agreement and a record of processing activities.

Operations


How it's kept running

  • 24/7 monitoring with alerts
  • Planned, communicated updates
  • Separate test and production environments
  • Audit log of support team access
  • Tested continuity and recovery plan
  • Dedicated servers, never shared with third parties
INFRASTRUCTURE IN THE EU EUROPEAN UNION
Dedicated infrastructure
Verified daily backups
Encrypted in transit and at rest
GDPR with no small print

Real examples


The questions that come from the committee

Public sector · tender

Specifications requiring processing in the EU

Before The department's usual tool is hosted outside the EEA. Justifying it means a transfer impact assessment for every tender.

After The European location is evidenced directly in the processing agreement and the requirement is met without further analysis.

ISO 27001 certified manufacturer

Auditing the external provider

Before Gathering provider information takes weeks of emails, and some questionnaire items go unanswered.

After Security documentation, sub-processor list and backup policy available as part of the supplier file.

Multinational group

Recovery after an incident

Before A backup policy exists, but the last test restore was two years ago and nobody knows how long it would really take.

After Restores tested at a defined frequency with measured timings. The recovery objective is a figure, not an aspiration.

Vocabulary


Infrastructure and data terms

International transfer
Sending personal data outside the European Economic Area. It requires an adequacy decision, standard contractual clauses or another Chapter V safeguard, plus an assessment of the destination country.
Sub-processor
A third party the processor engages to process data on the controller's behalf. It must be authorised and bound by the same contractual obligations.
RPO and RTO
Recovery point objective and recovery time objective: how much data can be lost and how long recovery may take. Without both numbers, a continuity plan is a statement of intent.
Encryption at rest
Protection of data while stored. It limits the damage if someone reaches the physical medium or a copy.
High availability
A redundant design that keeps the service running when a component fails. Not the same as backup: one covers the outage, the other the loss.

Frequently asked questions


What people ask us before getting started

How secure are your servers?

Very: they're our own, dedicated servers, with encryption in transit and at rest, two-factor authentication, network segmentation and 24/7 monitoring.

What availability do you offer?

A service commitment with maintenance windows agreed and notified in advance.

Who can see my data?

Only support staff, with logged access and under your authorization.

Why does hosting in the European Union matter?

Because it avoids the most awkward part of the GDPR. When the provider sits outside the European Economic Area you have to rely on an adequacy decision or standard contractual clauses and justify in writing that the safeguards suffice. Hosting inside, that conversation never arises.

How often are backups taken?

Daily, with tested restores. A backup that has never been restored is not a backup: it is an assumption.

Is the data encrypted?

Yes, in transit and at rest. Encryption at rest is what limits the damage if someone were to reach a physical medium or a copy.

Are there sub-processors?

The list of sub-processors forms part of the data processing agreement, with a commitment to communicate any change so the customer can object if they consider it appropriate.

What if we sign up and later want to leave?

The data belongs to the customer. It can be extracted through the API or by bulk export in open formats, and the contract sets out what happens to it when the relationship ends.

Pass our technical spec sheet to your IT lead

We'll show you the module running with data similar to yours.

Request a demo

Sources


Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. Regulation (EU) 2016/679 (GDPR), Chapter V: international transfers EUR-Lex · Applicable since 25 May 2018
  2. ISO/IEC 27001:2022, Annex A (controls 5.29 and 5.30) ISO/IEC · 25 October 2022
  3. Spanish National Security Framework (Royal Decree 311/2022) BOE-A-2022-7191 · 4 May 2022

Hosting on servers in Europe and GDPR compliance

Kimobox is hosted on its own servers located in European data centers, with verified daily backups, encryption in transit and at rest, two-factor authentication and continuous monitoring.

The service is provided under a data processing agreement compliant with GDPR and Spain's LOPDGDD, on a dedicated infrastructure built for maximum security without handing control of the data to a third party.