Security & Compliance
Security and GDPR compliance you can verify
obqo is built for European educational institutions. Privacy and data sovereignty aren't a feature — they're the foundation.
Data residency
Encryption in transit
Encryption at rest
Authentication
No inbox access
obqo supports coaching workflows without delegated access to mail or calendar:
AI data handling
AI features (session summaries, flow suggestions, congratulations-email drafts, alumni-pulse parsing) use Anthropic's Claude API. Optional session-recording uses OpenAI Whisper for transcription. Both providers are US-based; doorgifte happens under EU SCC + DPF.
Alumni opt-out and unsubscribe
Every outbound alumni mail carries a universal opt-out footer and RFC 8058 one-click headers, so the unsubscribe button in Gmail and Outlook resolves the request without any further interaction.
Yearly re-consent
Once a year — start of the academic year — alumni receive an explicit re-consent mail asking whether they still want to be registered. Three response options drive the next year's communication.
Audit logging
All access to student personal data produces an immutable audit record. Logs are stored in the same EU (Frankfurt) region as primary data and are available to the institution's DPO on request.
Subprocessors
Direct subprocessors engaged in delivering obqo. DPA Bijlage C of the tenant's processor agreement is the authoritative version of this list.
| Service | Purpose | Region | Transfer basis | Certifications |
|---|---|---|---|---|
| Supabase Inc. | Database, storage & authentication | Frankfurt, Germany (EU) | Within EER; EU SCC Module 2 for exceptional support access | SOC 2 Type II |
| Vercel Inc. | Application hosting | EU edge, fra1 Frankfurt (Vercel entity US-domiciled) | EU SCC + DPF for incidental US control-plane access | SOC 2 Type II, ISO 27001 |
| Van Moose (Truncus) | Transactional email (internal subprocessor) | AWS eu-west-1 (Ireland) | Within EER | — |
| Amazon Web Services EMEA SARL | Underlying SES infrastructure for Truncus | eu-west-1 (Ireland) | Within EER; AWS GDPR DPA via Service Terms | ISO 27001, ISO 27017, SOC 2 Type II |
| Anthropic PBC (Claude) | AI features — disabled by default | United States | EU SCC + DPF; engaged only when tenant explicitly enables AI features (off for UvA) | SOC 2 Type II |
| OpenAI LLC (Whisper) | Session-recording transcription — disabled by default | United States | EU SCC + DPF; engaged only when tenant explicitly enables session recording (off for UvA) | SOC 2 Type II |
All subprocessors above have signed a Data Processing Agreement with Van Moose. Signed DPAs are available to the institution's DPO on request via info@obqo.co.
Sub-subprocessors via Supabase
Supabase, in turn, engages the following sub-subprocessors for delivering its service to obqo. The complete list lives in Schedule 3 of the Supabase Data Processing Addendum.
| Service | Purpose | Notes |
|---|---|---|
| Amazon Web Services Inc. | Hosting infrastructure for Supabase databases | EU region for UvA tenant |
| Cloudflare Inc. | Hosting / CDN services | EU edge for UvA tenant |
| Sentry (Functional Software Inc.) | Error monitoring and tracing | Anonymised error reports only |
| OpenAI LLC | Supabase-internal dashboard AI features only | No obqo customer data reaches OpenAI through this path |
Email delivery infrastructure
obqo runs on Truncus, our own EU-native email infrastructure. Every student invitation, mentor notification, and reminder is delivered via AWS SES eu-west-1, with synchronous delivery confirmation (send_sync) and built-in DMARC monitoring on incoming aggregate reports. No third-party email vendors. No data leaving the EU.
Data retention
Personal data is retained no longer than necessary for the documented purpose, in accordance with GDPR Article 5(1)(e). The processor agreement's Bijlage D is the authoritative source for per-category retention windows; the controller (university) sets them.
Cookies & tracking
Rate limiting
Secret scanning & supply-chain controls
Availability
Incident reporting
Report security incidents to info@obqo.co
Response time: acknowledgement within 24 hours.
IB&P classification
obqo meets the IB&P LOW/LOW/LOW classification for availability, integrity and confidentiality. This means the platform is suitable for processing non-sensitive personal data in higher education.
Procurement documentation
The following documentation is available on request:
- Data Processing Agreement (DPA), aligned with the SURF model processor agreement
- Subprocessor list with regions and DPA status
- Security overview and description of controls
- Retention and deletion policy
- Accessibility statement (WCAG 2.1 AA)
Requests: info@obqo.co
Request the procurement pack
Get a complete bundle: DPA, subprocessor list, security overview, retention policy and accessibility statement.
Request documentation