01Certifications we hold
The complete list
None. Bloom Coffee OS holds no ISO 27001 certificate, no SOC 2 report, and no PCI DSS attestation. No external audit of this system has been carried out.
An earlier version of this page said otherwise — it displayed a “CERTIFIED” badge against ISO/IEC 27001 and referenced an external audit in Q1 2026. Neither was true. It has been removed, and we are recording here that it was there, rather than deleting it quietly.
What we do have is a system built on the practices those standards are trying to produce — encryption, least privilege, machine-enforced tenant isolation, tested backups — documented on the security page in enough detail that you can check the claims rather than trust a logo.
PCI DSS does not apply to us for a simple reason: Bloom never touches card data. Payment is settled in person on the merchant's own terminal.
02Where your data is hosted
- Location
- Lauterbourg, France — inside the European Union.
- Provider
- Contabo GmbH, a German hosting company.
- Arrangement
- A dedicated virtual server, not shared hosting. The database is not exposed to the public internet; it is reachable only from the application itself.
- Transfers
- No data is stored outside the EU. The exceptions are the specific outbound services listed in the privacy policy — a message you send through WhatsApp necessarily reaches Meta, because that is what sending it means.
- Redundancy
- One region. Nightly backups, no automatic failover. We would rather say that than imply a resilience we have not built.
03Tunisian data protection law
For a coffee shop operating in Tunisia, the governing law is Loi organique n° 2004-63 du 27 juillet 2004 on the protection of personal data, supervised by the INPDP.
- Processing personal data in Tunisia carries declaration obligations with the INPDP, and biometric processing attracts a stricter authorisation requirement. As the data controller for your shop, those filings are yours to make — we will provide whatever technical description you need for the paperwork.
- Face recognition is off unless you turn it on, precisely because switching it on changes your obligations. Read section 3 of the privacy policy before you enable it.
- Sales and tax records are retained for the period Tunisian accounting law requires, which overrides a deletion request for those specific records.
04GDPR
The GDPR is relevant to us on two counts: the servers are in France, and some shops serve European customers. We have built to its principles — data minimisation, purpose limitation, storage limits, and the access, correction, deletion and portability rights described in the privacy policy.
Being careful about the wording: there is no such thing as being “GDPR certified”. It is a law, not a certification scheme, and any vendor showing you a GDPR certificate is showing you something they bought. What we can do is sign a data processing agreement naming us as your processor, with the sub-processors listed and change notification included. Ask and we will prepare one.
- Your role
- Controller for your staff and customers.
- Our role
- Processor, acting on your documented instructions.
- Sub-processors
- Named individually in the privacy policy, with what each one receives.
- Breach notification
- We notify affected shops within 72 hours of becoming aware.
- Data export
- Your data is yours. You can export it at any time, in a usable format, without asking permission.
05Messaging rules
Notifications sent through WhatsApp run on Meta's official Business Platform, on approved message templates, to recipients who have opted in. We do not automate an ordinary personal WhatsApp account to send business notifications — it violates Meta's terms and gets the number banned, usually at the worst possible moment.
Every recipient can stop messages, and a stop request is honoured immediately and permanently.
06Accessibility
We target WCAG 2.1 AA for colour contrast and keyboard navigation on customer- facing pages. We have not commissioned an independent accessibility audit. If something on this site is unusable for you, tell us and we will fix it — that is a bug like any other.
07What we are working on
Stated as intentions, not as achievements, and without dates we cannot commit to:
- An independent penetration test.
- A documented, regularly rehearsed disaster recovery procedure.
- A second region, so that a single server failure is not an outage.
- A formal information security policy set, as the groundwork for ISO 27001 should we pursue it.
08Asking us for more
If you are evaluating Bloom and need something specific — a data processing agreement, a sub-processor list, a security questionnaire, an architecture description — ask on WhatsApp at +216 20 114 798. If the answer is that we do not have it, that is what you will be told.