Plenty of European companies want their team chat data kept in the EU. It is a reasonable wish. Chat holds more of a company's thinking than almost any other system: half-formed plans, customer names, and the occasional password someone should not have pasted.
"EU-hosted" on a pricing page is a start, not an answer. This guide lists what to check, and why.
This is not legal advice. If your company has specific obligations, sector rules or contracts with customers about where data may go, talk to your data protection officer or a lawyer before you decide.
Where the data lives, and who holds it
There are two questions here, and both matter.
Where is the data stored? Not only the main database. Ask about file storage, search indexes, backups, logs and e-mail. A vendor can keep messages in Frankfurt and still send notification e-mails, crash reports or backups somewhere else.
Where is the vendor based, and whose laws does it answer to? A company based outside the EU may be subject to laws in its home country that can require it to hand over data it controls, wherever that data is physically stored. Such laws can conflict with EU data protection rules, and whether they do in a particular case is a question for lawyers. The point for a buyer is simpler: server location alone does not settle who can be compelled to access your data.
You want both answers, in writing.
A signed data processing agreement
Under GDPR Article 28, when a vendor processes personal data on your behalf, there must be a contract setting out how. That contract is the data processing agreement, or DPA.
A good DPA covers what data is processed and why, the security measures in place, how subprocessors are used and approved, how the vendor helps you answer requests from individuals, what happens to data at the end of the contract, and how you can check any of this.
Ask to see it before you buy. A vendor that publishes its standard DPA is making your job easier.
A public subprocessor list
Almost every software vendor relies on other companies: a hosting provider, a payment processor, an e-mail service. Each one that touches personal data is a subprocessor.
You want a list that names each subprocessor, says what it does and where it processes data. You also want to know how you will be told when the list changes, and whether you can object.
Encryption, including what isn't encrypted
Ask precisely, because the word covers several things.
- In transit. All traffic between your browser or phone and the service should use TLS. This is the minimum.
- At rest, at the disk level. Many hosting providers encrypt the disks. That protects against a drive being removed from a data centre. It does very little against someone with access to the running system.
- At rest, in the application. Some vendors encrypt particular fields with their own keys, so the values are unreadable even to someone who can query the database.
Ask which data is protected at which level, and who holds the keys. Then ask what is not encrypted. A chat tool has to read message content to search it, show it and send notifications, so there is a real trade-off between full-text search on the server and end-to-end encryption. A vendor who explains that trade-off plainly is more useful than one who says "bank-grade" and changes the subject.
Who at the vendor can see your data
At some point, someone at the vendor may need to look at your workspace, usually because you asked for help. Ask:
- who can access customer data, and under what process
- whether each access is logged
- whether you can see that log, without having to ask for it
The last point is the one most often missing. A log only the vendor can read is better than nothing. A log your admins can read is better still.
Retention and deletion after you leave
Ask what happens when you cancel. How long is your data kept, and is it then deleted rather than just hidden? Are backups included, and on what schedule do they expire? Will the vendor confirm deletion?
A fixed, published period is a good sign. "We retain data as long as necessary" is not a period.
Getting your data out
Plan your exit before you arrive. Ask what an export contains (messages, files, channels, users), what format it is in, who can run it, and whether your plan includes it.
A checklist for your shortlist
| Question to ask a vendor | Why it matters |
|---|---|
| Where are the database, files, search index, backups and logs stored? | "EU-hosted" sometimes covers only the main database. |
| Where is your company incorporated, and which laws apply to it? | Jurisdiction can matter as much as server location. |
| Is your DPA published, and does it follow GDPR Article 28? | You need one anyway, and you should read it before signing. |
| Is there a public subprocessor list, and how are changes announced? | You are responsible for knowing who handles your data. |
| What is encrypted at the application level, and what is not? | Disk encryption alone protects less than it sounds. |
| Who at your company can access our data, and can our admins see each access? | Support access is normal; invisible support access is the concern. |
| How long after we leave is our data deleted, including backups? | "As long as necessary" is not an answer. |
| What does a data export contain, and which plans include it? | You want a way out before you need one. |
How Tandly handles it
- Who we are. Tandly is made by UHRIK - IT & Event s. r. o., a company based in Žilina, Slovakia.
- Where data lives. Messages and files are stored in data centres in the EU. The privacy policy names each provider and country. Payments are handled by Stripe Payments Europe, in Ireland.
- Contracts. Our DPA and subprocessor list are published, so you can read them before signing up. Push notifications are the exception to EU-only handling: their title and preview pass through Apple, Google or your browser's push service, and the subprocessor list says so.
- Encryption. Secrets we have to read back are encrypted in the application with AES-256-GCM: two-factor authentication seeds, tokens for connected apps, directory-sync keys and SAML keys. Messages and files are not separately encrypted by the application. Whether the storage underneath is encrypted depends on the provider, and the privacy policy says which is which. We would rather say that than let you assume otherwise.
- Support access. Every action Tandly Support takes on your workspace appears in a log your admins can see. This is on every plan, Free included.
- Leaving. Deleted workspaces are purged after 30 days. Admins on the Business plan can export channels and files.
The security overview has more detail.
Questions people ask
Is EU hosting enough to comply with GDPR?
No. Where data is stored is one part of it. GDPR also covers why you process personal data, what you tell people, how long you keep it, how you secure it and which contracts you have with processors. Choosing an EU-hosted tool helps with some of that and does none of the rest for you.
Should team chat be end-to-end encrypted?
It depends on what you need more. End-to-end encryption means the vendor cannot read messages, so the server cannot search them either, and previews in notifications and admin exports become harder. Most companies choose searchable chat with strong access controls. Either choice is fine if it is made knowingly.
What happens to our data if the vendor is acquired?
The DPA should still bind whoever holds the data. Read its clauses on termination and transfer, and keep your own export, so a change of ownership is an inconvenience rather than an emergency.
Can we see when the vendor has accessed our workspace?
Only if the vendor shows you. Ask directly. If the answer is "we log it internally", ask whether your admins can read that log. In Tandly they can, on every plan.