Mailbox.org
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign This listing EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Berlin-based private email + drive + meet + office bundle (Heinlein Support GmbH); ISO 27001 + BSI C5, €1/mo entry.
Mailbox.org is an EU-owned service hosted in Germany, with no identified CLOUD Act exposure. It is listed under Private email.
Assessment notes
Mailbox.org is operated by Heinlein Support GmbH (Berlin, founded 2014) on own German data centres, holds ISO/IEC 27001:2022 + BSI C5 Type 1 (rare full BSI-standard certification for an SMB email vendor), GDPR-compliant, PGP-supported, 100% renewable energy; entry tier €1/mo; EU-owned, EU-hosted, with no CLOUD Act exposure.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 0 none disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Yes
-
End-to-end encryption: NoOptional PGP (Guard/Mailvelope); mail is not zero-access encrypted by default.
-
Public DPA: Not assessed
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Mailbox.org
Mailbox.org (operated by Heinlein Support GmbH, Berlin) is a procurement-grade German private-email-plus-productivity suite (Mail + Drive + Meet + Office in a single bundled offering), entry tier from €1/mo (Light), business plans from €1/user/mo. The compliance posture is rare: ISO/IEC 27001:2022 + BSI C5 Type 1 (Bundesamt für Sicherheit in der Informationstechnik Type-1 Cloud Computing Compliance certification, the BSI's standard for trusted cloud services in Germany), plus full PGP support for end-to-end-encrypted mail. Servers in own German data centres on 100% renewable energy. Slogan "Ihre Daten. Ihre Kontrolle." For DACH compliance buyers this is one of the cleanest picks across the entire directory.
Sub-processor map · none disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Mailbox.org
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Switzerland · €4/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: Yes Public DPA: Yes Sub-processors: Yes Open source: No -
-
Germany · €3/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: Yes Public DPA: No Sub-processors: Yes Open source: No -
-
Germany · €1/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: No Public DPA: Not assessed Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: Yes
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: Yes
Public DPA: No
Sub-processors: Yes
Open source: No
|
€3/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: No
Public DPA: Not assessed
Sub-processors: Yes
Open source: No
|
€1/mo |