Compliance
One transparent place for how remoteroom.io handles data: who processes what, where it runs, and how it is protected.
Last updated:
Who we are
remoteroom.io is operated by Remoteroom GmbH, Theodorstraße 41P, 22761 Hamburg, Germany. Remoteroom GmbH is the controller for personal data processed on this platform under the GDPR. Full company details are on the imprint, and how we process personal data is described in the privacy policy.
This page lists the third-party processors we use, the infrastructure we run ourselves, our security practices, and the process for putting a data processing agreement in place. For privacy questions, write to office@remoteroom.io.
Subprocessors
We keep the list of third-party processors deliberately short. The providers below process data on our behalf. Providers marked as optional only process data when a customer actively uses that feature.
| Provider | What it does for remoteroom.io | Safeguards / region |
|---|---|---|
netcup GmbH netcup GmbH, Germany ISO/IEC 27001ISO 27701ISO 9001 | Hosting of the application, database, media storage, and streaming/call infrastructure in Nuremberg, Germany. | EU hosting (Germany) |
Cloudflare, Inc. Cloudflare, Inc., USA ISO/IEC 27001ISO 27018ISO 27701SOC 2 Type IIPCI DSS | R2 object storage for review media and transcoded assets, configured for EU data residency; CDN delivery of stored media. | EU Standard Contractual Clauses / EU-U.S. Data Privacy Framework where certified |
bunny.net BunnyWay d.o.o., Slovenia ISO/IEC 27001 | CDN delivery of media files for review rooms and file transfers. | EU entity (Slovenia) |
Stripe Payments Europe, Ltd. Stripe Payments Europe, Ltd., Ireland PCI DSS Level 1SOC 1SOC 2 Type IISOC 3 | Checkout, payment processing, invoices, subscription management, and the customer billing portal. | EU entity (Ireland) |
Google Ireland Limited Google Ireland Limited, Ireland ISO/IEC 27001SOC 2SOC 3 Optional feature | "Sign in with Google" authentication, used only when a customer chooses it. | EU entity (Ireland) |
Resend, Inc. Resend, Inc., USA SOC 2 | Transactional email: onboarding, password reset, and account notifications. | EU Standard Contractual Clauses |
Mistral AI Mistral AI, Paris, France ISO/IEC 27001ISO 27701SOC 2 Type II Optional feature | EU-hosted managed AI for Delivery interpretation, meeting summaries, Roomy, room and sharing assistance, support tickets, transcription, subtitles, and related workflow automation when enabled. | EU-hosted profile; Mistral AI DPA; SCCs for any disclosed feature-dependent transfer |
DeepL SE DeepL SE, Germany ISO/IEC 27001SOC 2 Type II Optional feature | Subtitle translation; processes subtitle text only when a room host runs a translation. | EU entity (Germany) |
ElevenLabs, Inc. ElevenLabs, Inc., USA SOC 2 Type IIISO/IEC 27001 Optional feature | AI subtitle transcription; processes media audio only when a room host runs a transcription. | EU Standard Contractual Clauses |
Where a provider processes data outside the EU, transfers are covered by the EU Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework.
Managed AI with Mistral
Mistral AI is the European LLM provider for our managed AI layer. The configured profile uses Mistral Medium 3.5 on the EU-hosted processing path. Delivery interpretation and meeting summaries are the first connected workflows; Roomy, room organization, share-link preparation, support and ticketing, transcription, subtitle, and automatic Delivery workflows are rolling out on the same boundary.
- Processing scope: only the selected text, transcript, audio, room metadata, or bounded project context needed for the requested feature.
- Region:the managed profile targets Mistral’s EU-hosted path and does not use the US API endpoint.
- Customer control: one account-level switch disables every managed AI feature. When it is off, no new room, media, support, transcript, subtitle, or Delivery content is sent to Mistral.
- Enterprise choice: Business customers can bring their own LLM and their own S3-compatible storage instead of using the managed provider and storage path.
Mistral acts as our processor under its Data Processing Addendum. Its official materials describe EU data hosting and transfer safeguards, privacy controls, and its SOC 2 Type II and ISO 27001/27701 certifications. Mistral notes that some optional provider features can involve temporary transfers outside the EU; our managed launch profile is limited to the disclosed EU processing path.
Self-hosted infrastructure
Most of remoteroom.io does not run on someone else’s cloud service. The core systems below are operated by Remoteroom GmbH on servers we lease from netcup in Germany — the software and the data handling are ours, not a managed third-party service.
LiveKit
Video calls, including the TURN relay for participants behind restrictive networks.
Streaming engine
SRT livestream ingest and low-latency playback, built and operated in-house.
PostgreSQL, file/upload services, and transcoding workers
The database, upload handling, and media transcoding pipeline.
In practice this means livestreams, video calls, uploads, and review media stay on EU servers we control, and calls and streams are not recorded unless a room host starts a recording.
Security practices
We would rather list what we actually do than decorate this page with borrowed badges. These are the measures in place today:
- All traffic is TLS-encrypted, with automatic certificates.
- Passwords are stored bcrypt-hashed. Optional two-factor authentication (TOTP) is available, and 2FA secrets are encrypted at rest (AES-256-GCM).
- Stream and media URLs are HMAC-SHA256 signed with expiry, so links cannot be hotlinked or reused indefinitely.
- Room access for viewers and reviewers works through signed access links — they never need an account.
- API route authentication is classified and checked by an automated audit in the build pipeline.
- No third-party advertising or analytics trackers run on the public website; only functional cookies and browser storage (session, preferences) are used.
- Managed AI is optional and can be disabled account-wide with one switch.
- We run regular database backups.
- The application and primary data are hosted in the EU (Germany).
Certified infrastructure
Every external provider that touches customer data holds current, independently audited certifications — ISO/IEC 27001 and/or SOC 2 Type II across the board, with PCI DSS Level 1 where card payments are involved. The certifications shown in the subprocessor table above are issued to those providers, and their current status is published in each provider’s own trust center.
remoteroom.io itself has not yet completed an independent SOC 2 or ISO 27001 audit — we are a small team and would rather say that plainly than imply otherwise. What we build runs on certified infrastructure, and our own practices are listed above, in plain language.
Data processing agreements
Where we process personal data on your behalf as a processor — for example, footage, review comments, or invitee data in your rooms — we conclude a data processing agreement (DPA) with you pursuant to Art. 28 GDPR. Request it any time at office@remoteroom.io and we will set it up with you.
Data portability and switching
Customers can take their content with them at any time — during the contract and when leaving — in line with the EU Data Act (Regulation (EU) 2023/2854). The exportable data and formats:
- Media files — original uploaded format (plus transcoded versions where generated).
- Review comments and annotations — CSV and PDF exports.
- Notes and playbook documents — PDF export.
- Calendars — ICS files.
- Subtitles — SRT files.
- Other room data (for example chat history) — on request in a structured, commonly used, machine-readable format such as JSON.
Exports run self-service from the room and dashboard tools; anything not covered is provided on request via office@remoteroom.io without undue delay. We do not charge switching or export fees, we support transitions to another provider within at most 30 calendar days, and content remains retrievable for at least 30 calendar days after the contract ends before it is deleted.
Infrastructure jurisdiction
Information pursuant to Art. 28 of the EU Data Act on where our infrastructure runs and which jurisdiction it is subject to:
- The core systems — application, database, uploads and media storage, streaming and call infrastructure — run on servers leased from netcup GmbH in Nuremberg, Germany, operated by Remoteroom GmbH. This infrastructure is subject to German and EU jurisdiction.
- R2 object storage for review media is provided by Cloudflare, Inc. and configured for EU data residency: the data is stored in the EU, while Cloudflare as a US-headquartered company is itself subject to US jurisdiction at the corporate level.
- CDN delivery of media files runs through BunnyWay d.o.o., Slovenia (EU jurisdiction).
- Managed AI requests use Mistral AI’s EU-hosted processing profile. Mistral AI is a French company and processes the selected feature input as our processor under its DPA.
Measures against unlawful governmental access from third countries: EU data-residency configuration for stored media, EU Standard Contractual Clauses (and the EU-U.S. Data Privacy Framework where certified) with our providers, TLS encryption in transit, HMAC-signed expiring media URLs, strict access controls, and Art. 28 GDPR data processing agreements with every provider that touches customer data.
Reporting illegal content
remoteroom.io hosts content that customers and their invitees create. If you believe content on this platform is illegal, report it to info@remoteroom.io with the subject “Report illegal content”. So we can act on your notice (Art. 16 DSA), please include:
- why you consider the content illegal,
- the exact link or location of the content,
- your name and email address (not required for content involving certain serious offences), and
- a statement that your report is made in good faith and is accurate to your knowledge.
We confirm receipt, review reports without undue delay and in a diligent, non-arbitrary way, and inform both the reporter and the affected customer of our decision and the reasons for it.
This address also serves as our electronic point of contact for authorities and for users of the service under Art. 11 and 12 of the Digital Services Act (DSA). You can write to us in English or German.
Supervisory authority
Our competent data protection supervisory authority is:
Hamburg Commissioner for Data Protection and Freedom of Information
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22
20459 Hamburg
Germany
Related pages
- Privacy policy — what we process, why, and your rights.
- Terms of service — the agreement for using remoteroom.io.
- Imprint — company details and contact.