Made in Luxembourg
Why a European collaboration platform
Coviqo is developed and operated in Luxembourg and runs on servers in the EU. This page explains where your data lives, how it is protected, what leaves the EU – and why.
- Operator based in Luxembourg
- Servers in Germany
- Content encrypted per space
- AI on our own servers
Data sovereignty: which law applies
Where a provider is based determines which laws it has to follow. Coviqo is operated from Luxembourg, so the General Data Protection Regulation (GDPR) and Luxembourg law apply to us. Requests from authorities are assessed under EU and Luxembourg law.
The US CLOUD Act of 2018 allows US authorities to require providers subject to US jurisdiction to disclose data in their possession, custody or control – even if that data is stored outside the United States.
That is why we store and process your content on EU infrastructure and run the core of the platform ourselves. Where US companies are involved – for network protection or payments – we name them openly below, together with what they process.
This page describes our own set-up and is not legal advice. A factual comparison with other providers – based on their public information – is on the page “Why Coviqo”.
Where your data lives
Everything that makes up your workspace is stored and processed on servers in the EU.
Servers in the EU
Web app, API, database, real-time services and the media servers for calls run in data centres in Germany.
File storage
Files and recordings are kept in object storage on the same EU infrastructure – encrypted per space.
Backups
Backups are made daily, stored in the EU and kept for no more than 12 months. The content inside them stays encrypted per space.
AI features
Transcription, translation and AI summaries run on our own servers. Your content is not sent to external AI services and is not used to train third-party models.
Encryption at rest – per space
Every space has its own 256-bit data key. Messages, notes, tasks, files, recordings, transcripts and AI summaries are stored with AES-256-GCM – in the database and in file storage alike.
Space keys are only stored in wrapped form, protected by a master key that is kept separately from the database and the backups. Keys can be rotated; when a space is permanently deleted, its key is deleted with it.
Honestly put: this is server-side encryption, not end-to-end encryption. Our servers decrypt content while you use it so that search and AI summaries work. It protects your data if storage media, database copies or file storage are exposed. All connections are TLS-encrypted. If you need more: from the Business plan, individual rooms can be end-to-end encrypted. Messages, files, notes, whiteboards and calls are then decrypted only on the members' devices – Coviqo cannot read them either; AI, full-text search and recordings are not available in those rooms.
What leaves the EU – and why
We keep this list short and honest. In these cases data is processed by companies based outside the EU or with a parent company outside the EU:
Cloudflare – network protection and CDN
Cloudflare, Inc. (USA) protects the website and the app against attacks and delivers static files faster. Connections pass through its network, which therefore processes connection data such as IP addresses and requests. API and real-time traffic is not cached; your stored content stays on our servers in the EU.
Stripe – payments
Paid plans are billed through Stripe Payments Europe Ltd. (Ireland). Stripe may transfer data to Stripe, Inc. in the USA. Card details go directly to Stripe – we never see them. Only relevant if you buy a paid plan.
Sign-in with Google, Microsoft & co. – only if you choose it
If you sign in with an external account, the provider confirms your identity and shares basic profile data such as your name and e-mail address. Some of these providers are based in the USA or have a US parent company. Signing in with e-mail and password works without them.
Integrations you connect
Calendar sync (Google, Microsoft 365), GitHub, Jira and linked cloud files only exchange data with the provider once you or your organisation connect them.
Other providers from the list below whose location is outside the EU are marked there.
Such transfers are based on the EU–US Data Privacy Framework where the recipient is certified under it, otherwise on the EU standard contractual clauses – details in our privacy policy.
Subprocessors
The same list as in our privacy policy, maintained in one place.
| Provider | Purpose | Location |
|---|---|---|
| HetznerHosting | Hosting | EU (Germany) |
| Stripe Payments Europe, Ltd.Processor | Payment processing | EU / USA (EU standard contractual clauses)Outside the EU |
| CoviqoProcessor | Transactional e-mail | EU |
| Cloudflare, Inc.Processor | CDN, DDoS protection | Global (EU standard contractual clauses)Outside the EU |
- Hetzner
- Purpose
- Hosting
- Location
- EU (Germany)
- Stripe Payments Europe, Ltd.
- Purpose
- Payment processing
- Location
- EU / USA (EU standard contractual clauses)Outside the EU
- Coviqo
- Purpose
- Transactional e-mail
- Location
- EU
- Cloudflare, Inc.
- Purpose
- CDN, DDoS protection
- Location
- Global (EU standard contractual clauses)Outside the EU
Data processing agreement (DPA)
Organisations that use Coviqo for their teams are the controller for their content; we process it on their behalf under Article 28 GDPR. On the Business and Enterprise plans, admins can read, download and conclude the DPA directly in the organisation settings.
Questions about the DPAQuestions about security or privacy?
Write to us – we answer questions about data protection, hosting and security personally.