Beskos

Sovereignty

Where your organisation's work is processed

Where customer data is processed, which law governs the company that operates it, which third parties are involved, how data is exported, and the limits of that position.

The question behind the requirement

The location of the servers and the jurisdiction of the provider are distinct questions. A United States provider may store data in a European data centre and remain subject to United States law, including the CLOUD Act, which applies to the company rather than to the location of the data.

Beskos is operated by a company established in Poland. The contract, the servers and the resulting obligations are governed by the same legal order.

A request for access to customer data is therefore handled under European law, before a European authority, with the remedies provided by European law.

What we operate, and what we buy in

The application, the database, the mailboxes, meetings and document editing run on servers operated by Beskos in Europe. The remaining components are procured from third parties and are listed below with their jurisdiction.

  • Application and database

    EU processing

    netcup GmbH

    European Union

  • Mailboxes (SMTP, IMAP, JMAP)

    EU processing

    netcup GmbH

    European Union

  • Meetings and document editing

    EU processing

    netcup GmbH

    European Union

  • AI assistant and wiki indexing

    EU processing

    TensorX

    European Union

  • Drive files and recordings (encrypted by us)

    EU processing

    BunnyWay d.o.o.

    Frankfurt, Germany

  • Outbound mail delivery

    US provider · SCCs

    Amazon Web Services EMEA SARL

    Dublin, Ireland

  • DNS and content delivery

    EU processing

    BunnyWay d.o.o.

    Frankfurt, Germany

  • Payments and invoicing

    US provider · SCCs

    Stripe Payments Europe, Ltd.

    Dublin, Ireland

Your data is processed and stored in the European Union. Two of the providers above are European entities with parent companies in the United States, and EU Standard Contractual Clauses apply to both; neither holds the content of mailboxes, files or documents. Drive files and recordings are encrypted before they reach the storage provider, which holds ciphertext and no key that opens it. The full list, with purposes and change notifications, is public.

What we do not claim

The limits of the position set out above.

Two sub-processors remain subsidiaries of United States companies

Amazon Web Services EMEA SARL handles the delivery of outbound email, and Stripe Payments Europe, Ltd. handles payments. Both are European entities whose parent companies are established in the United States, and both are therefore within the reach of United States legislation. Each processes data within the European Union under EU Standard Contractual Clauses, and each is named on the sub-processors page. Neither holds the content of mailboxes, files or documents.

No certifications are held

Beskos holds neither ISO 27001 nor SOC 2 certification. The security page sets out the technical and organisational measures in force, in the detail required for an independent assessment.

No contractual service level agreement is offered

The availability target is 99.5% per month, measured externally and published per component. It is an operational objective and not a contractual guarantee; the terms of service state this expressly.

Migration is assisted, not automated

Mailboxes are accessible over IMAP, so historical mail can be transferred using a standard client, and Beskos assists in planning the work. No single-step import is provided.

Answers for an assessment

The questions commonly raised in a security questionnaire, and the document that answers each.

Is there a data processing agreement?

Yes, published in full on the site, with Annex I on the details of processing and Annex II on technical and organisational measures. It does not have to be requested.

Read the DPA

Which sub-processors are involved?

All sub-processors are listed with purpose, location and transfer mechanism, together with the date of the last change. New sub-processors are notified at least 14 calendar days in advance, and the customer may object.

Sub-processors

How is the data protected?

Encryption in transit and at rest, password hashing, mandatory tenant scoping on every query, rate limiting, two-factor authentication and restricted administrative access. Each measure is described in full on the security page.

Security measures

Who is the contracting entity?

Open Solutions, the trading name of a sole trader registered in Poznań, Poland, with VAT number PL7773457857. The legal notice identifies it in full.

Legal notice

What happens to the data on termination?

It is exported by the customer in open formats and deleted according to the retention periods set out in the data processing agreement.

Retention and deletion

What availability can we expect?

We work to 99.5% per month, measured externally and published with ninety days of history. It is an objective and not a contractual guarantee, and the commitments page states exactly which is which.

Service commitments

How hard is it to move an existing organisation?

Mail arrives over IMAP with the folder tree intact, calendars as iCalendar and contacts as vCard. The migration page sets out the steps, the timing and the parts that are not automated.

Migration plan

Is the assistant a risk to this?

The models are open-source and served on European infrastructure. Content is not disclosed to the developers of the models and is not used to train them. An organisation can disable the assistant entirely.

Sub-processors

How the data leaves

The formats in which customer data is exported, each of them read by the destination platforms.

Mail

IMAP, with the full folder structure, using any standard client.

Calendars

iCalendar (.ics), per calendar.

Contacts

vCard or CSV, including custom fields.

Files

Direct download, including entire folders as ZIP.

Domain

The domain, its DNS records and the associated sending reputation remain the property of the customer.

Timing

At any time, without a request, an approval or an export fee.

Assess it against your own requirements.

The legal documents are public and need no request. For a procurement process or a security questionnaire, write to us and we will answer in writing.