European data centers
Our own infrastructure, not resold hyperscaler capacity.
Infrastructure and security
No clouds outside the European Union and no surprises in the data processing agreement. You know where your data is and who touches it.
Hosting data inside the European Union avoids the most awkward part of the GDPR: international transfers. When the provider sits outside the European Economic Area you have to rely on an adequacy decision or standard contractual clauses and justify in writing that the safeguards suffice. Kimobox runs on its own infrastructure in European data centres, so that conversation never has to happen.
Our own infrastructure, not resold hyperscaler capacity.
Daily backups with periodic restore testing.
TLS in transit, encryption at rest, two-factor authentication.
Data processing agreement and a record of processing activities.
Operations
Real examples
Public sector · tender
Before The department's usual tool is hosted outside the EEA. Justifying it means a transfer impact assessment for every tender.
After The European location is evidenced directly in the processing agreement and the requirement is met without further analysis.
ISO 27001 certified manufacturer
Before Gathering provider information takes weeks of emails, and some questionnaire items go unanswered.
After Security documentation, sub-processor list and backup policy available as part of the supplier file.
Multinational group
Before A backup policy exists, but the last test restore was two years ago and nobody knows how long it would really take.
After Restores tested at a defined frequency with measured timings. The recovery objective is a figure, not an aspiration.
Vocabulary
Frequently asked questions
Very: they're our own, dedicated servers, with encryption in transit and at rest, two-factor authentication, network segmentation and 24/7 monitoring.
A service commitment with maintenance windows agreed and notified in advance.
Only support staff, with logged access and under your authorization.
Because it avoids the most awkward part of the GDPR. When the provider sits outside the European Economic Area you have to rely on an adequacy decision or standard contractual clauses and justify in writing that the safeguards suffice. Hosting inside, that conversation never arises.
Daily, with tested restores. A backup that has never been restored is not a backup: it is an assumption.
Yes, in transit and at rest. Encryption at rest is what limits the damage if someone were to reach a physical medium or a copy.
The list of sub-processors forms part of the data processing agreement, with a commitment to communicate any change so the customer can object if they consider it appropriate.
The data belongs to the customer. It can be extracted through the API or by bulk export in open formats, and the contract sets out what happens to it when the relationship ends.
We'll show you the module running with data similar to yours.
Keep exploring
Encryption, access control, an audit log, verified backups, and a data processing agreement that reads…
Own infrastructure in Europe, ERP connectivity, electronic signature, AI automation and blockchain…
Kimobox records the digital fingerprint of critical documents and records on a public blockchain. Anyone can…
Asset inventory, risk analysis and Annex A controls, each with its status and owner.
Sources
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
Kimobox is hosted on its own servers located in European data centers, with verified daily backups, encryption in transit and at rest, two-factor authentication and continuous monitoring.
The service is provided under a data processing agreement compliant with GDPR and Spain's LOPDGDD, on a dedicated infrastructure built for maximum security without handing control of the data to a third party.