No internet connection — some features may be unavailable

Compliance

Where we
actually stand.

Which rules apply to us, what we hold, and what we do not hold. This page used to claim certifications we had never obtained; it now claims none that we cannot produce on request.

Last updated 31 July 2026

01Certifications we hold

The complete list

None. Bloom Coffee OS holds no ISO 27001 certificate, no SOC 2 report, and no PCI DSS attestation. No external audit of this system has been carried out.

An earlier version of this page said otherwise — it displayed a “CERTIFIED” badge against ISO/IEC 27001 and referenced an external audit in Q1 2026. Neither was true. It has been removed, and we are recording here that it was there, rather than deleting it quietly.

What we do have is a system built on the practices those standards are trying to produce — encryption, least privilege, machine-enforced tenant isolation, tested backups — documented on the security page in enough detail that you can check the claims rather than trust a logo.

PCI DSS does not apply to us for a simple reason: Bloom never touches card data. Payment is settled in person on the merchant's own terminal.

02Where your data is hosted

Location
Lauterbourg, France — inside the European Union.
Provider
Contabo GmbH, a German hosting company.
Arrangement
A dedicated virtual server, not shared hosting. The database is not exposed to the public internet; it is reachable only from the application itself.
Transfers
No data is stored outside the EU. The exceptions are the specific outbound services listed in the privacy policy — a message you send through WhatsApp necessarily reaches Meta, because that is what sending it means.
Redundancy
One region. Nightly backups, no automatic failover. We would rather say that than imply a resilience we have not built.

03Tunisian data protection law

For a coffee shop operating in Tunisia, the governing law is Loi organique n° 2004-63 du 27 juillet 2004 on the protection of personal data, supervised by the INPDP.

  • Processing personal data in Tunisia carries declaration obligations with the INPDP, and biometric processing attracts a stricter authorisation requirement. As the data controller for your shop, those filings are yours to make — we will provide whatever technical description you need for the paperwork.
  • Face recognition is off unless you turn it on, precisely because switching it on changes your obligations. Read section 3 of the privacy policy before you enable it.
  • Sales and tax records are retained for the period Tunisian accounting law requires, which overrides a deletion request for those specific records.

04GDPR

The GDPR is relevant to us on two counts: the servers are in France, and some shops serve European customers. We have built to its principles — data minimisation, purpose limitation, storage limits, and the access, correction, deletion and portability rights described in the privacy policy.

Being careful about the wording: there is no such thing as being “GDPR certified”. It is a law, not a certification scheme, and any vendor showing you a GDPR certificate is showing you something they bought. What we can do is sign a data processing agreement naming us as your processor, with the sub-processors listed and change notification included. Ask and we will prepare one.

Your role
Controller for your staff and customers.
Our role
Processor, acting on your documented instructions.
Sub-processors
Named individually in the privacy policy, with what each one receives.
Breach notification
We notify affected shops within 72 hours of becoming aware.
Data export
Your data is yours. You can export it at any time, in a usable format, without asking permission.

05Messaging rules

Notifications sent through WhatsApp run on Meta's official Business Platform, on approved message templates, to recipients who have opted in. We do not automate an ordinary personal WhatsApp account to send business notifications — it violates Meta's terms and gets the number banned, usually at the worst possible moment.

Every recipient can stop messages, and a stop request is honoured immediately and permanently.

06Accessibility

We target WCAG 2.1 AA for colour contrast and keyboard navigation on customer- facing pages. We have not commissioned an independent accessibility audit. If something on this site is unusable for you, tell us and we will fix it — that is a bug like any other.

07What we are working on

Stated as intentions, not as achievements, and without dates we cannot commit to:

  • An independent penetration test.
  • A documented, regularly rehearsed disaster recovery procedure.
  • A second region, so that a single server failure is not an outage.
  • A formal information security policy set, as the groundwork for ISO 27001 should we pursue it.

08Asking us for more

If you are evaluating Bloom and need something specific — a data processing agreement, a sub-processor list, a security questionnaire, an architecture description — ask on WhatsApp at +216 20 114 798. If the answer is that we do not have it, that is what you will be told.