top of page

TRUST & SECURITY

Security and compliance at CloudOffice®

Your business data is stored within the EU, protected under the GDPR and backed up every night. Here we openly describe how we work with security, data protection and compliance — and which documents you can request.

 Data storage and operations within the EU
GDPR: data processing agreement and a public list of sub-processors
Nightly backups with multi-level retention
Encrypted communication and role-based access control

Open channel for vulnerability reporting

Security Overview and DPA are normally sent within one business day.

Data security in a cloud business system — EU data residency

OPERATIONS

Data storage within the EU

CloudOffice® runs on servers in the EU (Germany and Finland) with an infrastructure provider certified to ISO/IEC 27001. All production data — databases, files and backups — is stored within the EU and never leaves the Union. CloudOffice AB is a Swedish limited company, which means both your contracting party and its supervision are in Sweden.

Servers in the EU

The production environment is located in Germany and Finland. No data is stored outside the EU.

ISO 27001-certified infrastructure

The data centres are operated by a provider certified to ISO/IEC 27001, with 24/7 physical security.

Swedish company

Swedish contracting party, Swedish law, support in Swedish and English.

Data protection and GDPR

When you use CloudOffice, you are the data controller of your data and CloudOffice AB is the data processor. We process personal data only according to your instructions and our data processing agreement (DPA), which is included as an annex to the service agreement. You can export your data at any time, and upon termination all data is deleted or returned as set out in the DPA.

Sub-processors

We use a minimal number of sub-processors and disclose them openly:

Sub-processor

Service

Location

Sub-processor

Hetzner Online GmbH

Service

Server operations and data storage

Location

Germany / Finland (EU)

Sub-processor

Google Ireland Ltd

Service

Email communication (limited scope)

Location

EU

How it works

Our customers already deliver via EDI to:

Order Import Center adapts to your business needs

Encryption

All communication between your browser and CloudOffice is encrypted with TLS. Storage media at our infrastructure provider are encrypted, and backups are protected with encryption

Access control

Access to systems and data is governed by roles and permissions. Administrative access to the server environment is restricted, personal and protected with multi-factor authentication.

24/7 monitoring

The production environment is monitored continuously, around the clock. Deviations in operations, capacity and availability trigger automatic alerts.

Updates and vulnerabilities

Operating systems, databases and platform components are updated continuously according to a fixed routine. Security updates are prioritised and known vulnerabilities are tracked systematically.

How it works

Backing up your business data

Backups are taken automatically every night. Daily copies are kept for one week; thereafter weekly copies are retained, and finally monthly copies for long-term protection. Copies are stored separately from the production environment, within the EU. Restores can be performed both for the entire environment and for an individual customer's data.

INCIDENTS

Incident handling

If a security incident occurs that affects your data, we inform you without undue delay, with a description of the event, its impact and the measures taken. Incidents involving personal data are handled in accordance with the GDPR and our data processing agreement.

Report a vulnerability

Found a security issue in CloudOffice? We accept reports at security@cloudoffice.se and respond promptly. Our contact information for security researchers is also available in machine-readable form per RFC 9116: www.cloudoffice.se/.well-known/security.txt

COMPLIANCE

NIS2, the Swedish Cybersecurity Act and the CRA

CloudOffice AB is a micro-enterprise and is therefore not subject to the registration obligation under the Swedish Cybersecurity Act (2025:1506), which implements the NIS2 Directive. We have nevertheless chosen to work in line with the Act's risk management principles — security measures, incident routines, continuity planning and supplier follow-up — because many of our customers are themselves covered by the Act and place corresponding requirements on their suppliers.

If your company is covered by the Cybersecurity Act and needs to document its suppliers, we are happy to help: request our Security Overview for a consolidated basis for your supplier assessment.

The EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) applies to products with digital elements placed on the market. CloudOffice is provided as a cloud service via a web browser and is therefore not subject to the Regulation's product requirements. We monitor developments and will reassess this position if the service's delivery model changes.

Questions & Answers

  • All production data is stored on servers within the EU, in Germany and Finland. No data is stored or processed outside the EU.

  • CloudOffice AB holds no ISO certification of its own — we are a micro-enterprise, and instead we disclose our security measures openly on this page and in our Security Overview. The data centres we use are operated by an infrastructure provider certified to ISO/IEC 27001.

  • No. As a micro-enterprise, CloudOffice AB is below the thresholds of the Swedish Cybersecurity Act (2025:1506). We nevertheless work in line with the Act's principles and support customers who are themselves covered, with documentation for their supplier assessments.

  • Every night. Daily copies are kept for one week, followed by weekly and monthly copies. Copies are stored separately from the production environment, within the EU.

  •  Yes. Our DPA is included as an annex to the service agreement and can be requested in advance via info@cloudoffice.se. Among other things, it contains the complete list of sub-processors.

  • We use a minimal number of sub-processors: our infrastructure provider for server operations and data storage within the EU, and Google for email communication in a limited scope. The complete and current list is available on this page and in the DPA.

  •  Send a report to security@cloudoffice.se. We confirm receipt, investigate promptly and follow up on remediation. Machine-readable contact information is available at /.well-known/security.txt.

  • We inform affected customers without undue delay, with a description of the event, its impact and the measures taken. Incidents involving personal data are handled in accordance with the GDPR and the DPA, including notification within the applicable time limits.

  • Nothing. The Security Overview and the DPA are provided free of charge to customers and companies in the evaluation phase — contact us.

img-trust-2.jpg

Need input for your supplier assessment?

Request our security documentation or book a walkthrough — we are happy to show how CloudOffice® handles your specific data and to answer your security questionnaire.

Security Overview within one business day
✓ Data processing agreement (DPA)
Answers to your supplier questionnaire
Direct contact with the person who operates the system

bottom of page