Where is our data stored, and who operates the infrastructure?
On OVHcloud infrastructure in Paris, France. The servers are rented; everything running on them (mail, files, identity, meetings) is operated by us, not by a third party. Customer Data stays within the EU/EEA at all times, and no sub-processor is established outside it.
Is Email.eu ISO 27001 or SOC 2 certified?
No. ISO 27001 and ISO 27701 are targeted for 2026; SOC 2, NIS2 and SecNumCloud are on the roadmap. GDPR processor obligations are met today and set out in our DPA. The architecture is built to those frameworks from the start, but the certificates are not yet held, and the status on this page is the live one.
Who are your sub-processors?
Three, all EU entities: OVHcloud (OVH SAS, France) for infrastructure, Mollie B.V. (Netherlands) for payments, and Moneybird B.V. (Netherlands) for invoicing. The complete list, including what each one processes, is published at email.eu/subprocessors, and the DPA commits us to 30 days advance notice before any addition or replacement.
Is Email.eu subject to the US CLOUD Act?
No. Remails B.V. is a Dutch company with no US parent, subsidiary or affiliate, and no US provider sits anywhere in the supplier chain, payments included. A US authority therefore has no domestic entity to serve. Lawful requests for Customer Data go through a European court and through us; we report the totals in our quarterly transparency report.
Is mail end-to-end encrypted?
Not between correspondents, and we do not market it that way. On Business plans, mail is encrypted at rest with PGP or S/MIME keys that you hold, which means we cannot read what is stored. In transit, connections use TLS 1.3 with forward secrecy. Customer-managed keys via KMIP or HSM are on the Enterprise roadmap.
Do you train AI models on our data?
No. The service has no AI features, and Customer Data is never used to train models, ours or anyone else's. That is a contractual commitment in the DPA rather than a policy that can quietly change. If we ever ship AI features they will be opt-in, EU-hosted and tenant-isolated.
How do we report a vulnerability?
Mail security@email.eu. We run a coordinated-disclosure program: we confirm receipt within 24 hours, keep you updated through the fix, credit you if you want the credit, and publish post-incident write-ups within seven days where appropriate.