A German company builds it. European servers run it, under our own hands. Your files are encrypted with keys held in Europe — and the clause that says so is in the agreement you sign.
A data centre inside a platform with a US parent is still reachable by a foreign order. Where the disk sits is a different question from who can be made to read it.
Most vendors stop at EU hosting. The copy of your client's rate card sits with whoever they subcontracted, and you learn the names during a security review.
Your client's legal team sends the questionnaire: where the data is, who can reach it, is there an agreement, how the keys are held. Answering it from memory costs a week.
European values, EU infrastructure, no company, no certificate, no clause. That is a marketing sentence, not an answer to a vendor review.
Five links, each one written down somewhere you can read.
GRAN Software Solutions GmbH, in Germany. The product carries the Software Made in Europe seal of BITMi, the German federal association for IT small and medium business.
Your workspace sits on a platform we operate ourselves, rather than inside somebody else's — the part the Software Hosted in Europe seal certifies.
Storage and backups stay inside the European Union, with providers located there. The terms put it in one sentence: data is stored exclusively within the EU/EEA.
Every invoice PDF and every attachment gets its own key. That key is kept by a European provider, never beside the file it unlocks.
A data processing agreement under Art. 28 GDPR is concluded when you register. A new sub-processor is announced fourteen days ahead, and you may object.
Software Made in Europe Where it is built. Certificate
Software Hosted in Europe Where your data runs. Certificate Both seals are held by GRAN Software Solutions GmbH for Consulting Cockpit.
Two European providers. Both named in the agreement you sign.
A sovereignty claim is worth exactly the parts of it you can check.
Not EU regions available on request: the terms state that data is stored exclusively within the EU/EEA, on providers located there.
Fourteen days before one is engaged, with the right to object and, if no solution is found, to leave on fourteen days' notice.
Product analytics run on our own European server. There is no advertising network in the product and no tracking cookie to dismiss.
We are not Gaia-X certified and hold no EU Cloud Sovereignty Framework level. The ISO certificates belong to our providers' data centres — that is their audit, not ours.
When a client's auditor asks who changed an hour and when, the answer comes from the record rather than from memory, see Audit Everything
Inside the European Union. The terms state that data is stored exclusively within the EU/EEA, on providers located there, and the two providers we use are named in the data processing agreement you sign.
Only the people needed to run the service, under the processing agreement and tied to a named role. Inside a client workspace, every change is recorded with a name and a timestamp.
No US provider sits in the path of your client data, so there is no US parent to serve an order on. The one US service we rely on is certificate issuance: Let's Encrypt signs our TLS certificates and sees our domain names, never your data.
Yes. One under Art. 28 GDPR is concluded when you register, and it is published so you can read it before you sign up.
Fourteen days in advance. If you object on reasonable data protection grounds and no solution is found, you may end the agreement on fourteen days' notice.
Invoices and timesheets export to CSV at any time. On termination your data is deleted or returned within 30 days, except invoices, which German commercial and tax law requires us to retain.
Start a 30-day trial and read the agreement before a client's vendor review asks for it. Free for 30 days.