Opens in a new tab

Don't take our word for it. Verify.

Demonstrable compliance, verifiable certifications and auditable infrastructure: the documentation your DPO, your auditor or a public tender panel needs.

  • GDPR
  • eIDAS
  • Decree-Law 12/2021
  • FIPS 140-2 Level 3
Desktop monitor with code and data tables in a bright office, with the Sooma symbol
Hands typing on a laptop keyboard lit by pink light

Legal framework

Built within European law, not adapted to it.

The three legal pillars that frame the service, and what each one guarantees in practice.

GDPR: Regulation (EU) 2016/679

Data processing in the EU (Portugal), with no transfers to third countries. Full traceability, data minimisation and records of processing available to clients who need to include them in their own compliance records.

eIDAS: Regulation (EU) No 910/2014

Certified communications (Registered Email) rely on qualified certificates issued by providers on the EU Trust List, with cross-border legal validity in all 27 Member States.

Decree-Law No. 12/2021

The platform's certified electronic communications are treated as equivalent to registered mail with acknowledgement of receipt, with evidential value in court in Portugal.

Technical certifications

Cryptography is not a promise. It is audited hardware.

The technical certifications behind certified communications, verifiable by any auditor.

Thales HSM: FIPS 140-2 Level 3

Cryptographic operations for certified communications run on Hardware Security Modules certified to FIPS 140-2 Level 3, the same standard used in banking. Keys never leave the hardware, not even in the event of an attack.

Qualified certification authorities

Qualified certificates are issued by Asseco and Multicert, trust service providers on the EU Trust List, supervised by the competent national authorities.

SSL/TLS certificates

Sooma also partners with the certification authorities Asseco and Multicert to issue Wildcard SSL/TLS certificates for clients: the same chain of trust that protects our own infrastructure.

Due diligence

Documentation for your evaluation process.

If you are evaluating Sooma in a procurement process, audit or public tender, the team provides the compliance documentation you need: technical description of the infrastructure, data processing agreement, privacy policy and evidence of the applicable certifications. Talk to us and tell us what your process requires.

Request documentation →

Frequently asked questions

Certifications and compliance

The questions DPOs, auditors and tender panels ask us most often.

Yes. Under Decree-Law No. 12/2021, certified electronic communications are treated as equivalent to registered mail with acknowledgement of receipt, and eIDAS qualified certificates are admissible as evidence in court in Portugal and the EU.

Qualified trust service providers (Asseco and Multicert), on the EU Trust List and supervised by the competent authorities.

Yes. We provide the information needed for our clients' records of processing and compliance assessments. Talk to the support team.

No. Sooma is a Portuguese company, with infrastructure in Portugal, subject exclusively to Portuguese and European law, unlike providers subject to US jurisdiction, regardless of where their servers are located.

Compliance that is verified, not rubber-stamped.

Request the documentation your process needs from our team in Europe.

Talk to the team

Leave us a message

Privacy policy