Privacy
A GDPR-ready team inbox: what SMBs should check about EU hosting
June 2026 · 9 min read
A mailbox holds some of the most sensitive material a company has: customer requests, contracts, invoices, personal data. Anyone introducing a shared team inbox should therefore not treat data protection as an afterthought. This checklist helps with the selection - and with the conversation with your own data protection officer.
Why server location matters
If personal data is transferred to a third country (e.g. into a US cloud), it needs a solid legal basis - and the situation around that has been in flux for years. Even the question of whether a US provider could access data triggers documentation and assessment duties. A provider that hosts entirely in the EU avoids this risk from the outset and considerably simplifies your own compliance: less transfer impact assessment, less uncertainty, less effort.
The checklist
1. EU hosting
Where are the servers? Ideally exclusively in the EU, with no third-country transfer in normal operation.
2. Encryption at rest
Are credentials and tokens stored encrypted (e.g. AES-256-GCM)? Credentials must never sit in plaintext - and must not appear in log files either.
3. Data processing agreement (Art. 28 GDPR)
Is there a DPA? Who are the sub-processors (hosting, payment provider)? A serious provider discloses this list and signs a DPA with you - that's not a nice-to-have, it's mandatory.
4. No reading along, no logging of content
Mail content should be processed solely to deliver the service and not logged or analysed for advertising. Ask specifically what ends up in logs.
5. Data minimisation & deletion
Can mailboxes, content and accounts be cleanly separated and fully deleted?
6. Data subject rights
Are access, export and deletion practically feasible - not just promised in theory?
7. Data sovereignty and exit
The strongest safeguard is the one you do not need: does the mail stay in the company's own mailbox instead of moving to yet another provider? And can the data the service creates - templates, notes, assignments - be exported at any time?
The special case of AI: don't undermine privacy
AI features are convenient but privacy-relevant - after all, text leaves the system. Watch two points: first, only the context actually needed should go to the AI, not the entire mailbox. Second, the AI provider should be named and contractually bound: in Astreo, Mistral AI SAS (Paris) acts as a processor, processing takes place in the EU, and a data processing agreement is in place. That keeps AI a feature you steer - not an unpredictable data leak.
No lock-in as a trust anchor
"Trust us" is a weak promise in data protection. An architecture that needs little trust is stronger: Astreo is an email client, not a mailbox provider. The mail stays in the company's own mailbox - in Microsoft 365 or on its own IMAP server. Astreo connects via OAuth, stores credentials encrypted at rest and never logs mail content. Switching away means nothing has to be recovered, because nothing was ever moved: templates, notes and assignments can be exported - the communication itself always stayed with the customer.
Quick checklist for the selection meeting
- Are all servers in the EU? Are there any third-country transfers?
- Are credentials stored encrypted at rest?
- Is there a DPA including a sub-processor list?
- Is mail content logged or analysed?
- How do export and deletion work in practice?
- Does the mail stay in your own mailbox, and can the remaining data be exported?
Conclusion
GDPR compliance doesn't come from a single checkbox but from the interplay of hosting, encryption, clear contracts and lean processing. A team inbox hosted in the EU that leaves your mail where it is makes that proof far easier than an opaque cloud solution - and takes a lot of documentation work off your plate day to day.
Note: this article is general orientation and does not constitute legal advice.
A team inbox, hosted in the EU
Astreo runs in the EU, stores credentials encrypted at rest and leaves the mailboxes where they are.
Try for free