eclipso Mail Europe vs Posteo

Compare eclipso Mail Europe and Posteo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: eclipso Mail Europe

eclipso Mail Europe

Germany· Email Services

Needs review

Shortlist when you want German-hosted mail with direct IMAP/SMTP, optional OpenPGP/S/MIME free on all tiers, prepaid freemium cost control, and a small business suite (drive, calendar, hybrid SMS/fax/post). Skip when you need zero-access defaults, published ISO/SOC audits, or large-enterprise identity—consider Posteo, Tuta, Proton Mail, or mailbox.org instead.

Germany-hosted (claimed)OpenPGP + S/MIMEIMAP/SMTP nativePrepaid freemiumOwner-operated DEBusiness DPA (Art. 28)
Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
eclipso Mail Europe vs Posteo: Snapshot
FeatureLogo: eclipso Mail Europeeclipso Mail EuropeLogo: PosteoPosteo
Country of originGermanyGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersGermanyGermany
Legal entityClaus-Peter Beringer (eclipso Mail Europe), Grubstr. 9b, 95445 BayreuthPosteo e.K., Methfesselstr. 38, 10965 Berlin
Governing lawGerman / EU law (GDPR, BDSG); BayLDA supervisory authority named in privacy noticeGerman / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyPrimary hosting claimed exclusively in Germany; privacy policy names Speedloc Datacenter (Görlitz) with AVV. Optional SMS/fax/post: Commify Germany, CM.com Germany, letterei.de (all DE). Payments: Stripe Payments Europe and PayPal (Europe). Site: Google reCAPTCHA; marketing ad partners documented; Matomo self-hosted analytics.Self-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).
Summary

Owner-operated German email and cloud suite with IMAP, optional OpenPGP/S/MIME, prepaid freemium, Drive/organizer, and hybrid SMS/fax/post—hosted in Germany.

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Tags
At a glance: eclipso Mail Europe vs Posteo
At a glanceLogo: eclipso Mail Europeeclipso Mail EuropeLogo: PosteoPosteo
HQBayreuth, GermanyBerlin, Germany
Legal entityClaus-Peter Beringer (owner-operated)Posteo e.K. (HRA 47592 B)
Founded2003 (vendor)2009
HostingGermany; Speedloc Datacenter (Görlitz) named in privacy policySelf-operated servers in Germany
Open sourceNoNot listed
Self-hostedNo (SaaS)Not listed
Commercial modelFreemail (ad-supported) + prepaid paid tiersPrepaid paid service; no free tier
EncryptionOptional OpenPGP + S/MIME; TLS in transitNot listed
ProtocolsNot listedIMAP, POP3, SMTP, CalDAV, CardDAV
Self-hostNot listedNo (hosted service)
EnergyNot listed100% green energy (Green Planet Energy, claimed)
Key capabilities: eclipso Mail Europe vs Posteo
Key capabilitiesLogo: eclipso Mail Europeeclipso Mail EuropeLogo: PosteoPosteo
Germany-hosted (claimed)YesNot listed
OpenPGP + S/MIMEYesNot listed
IMAP/SMTP nativeYesNot listed
Prepaid freemiumYesNot listed
Owner-operated DEYesNot listed
Business DPA (Art. 28)YesNot listed
Self-operated DE serversNot listedYes
Data-minimising signupNot listedYes
IMAP / CalDAV / CardDAVNot listedYes
BSI TR-03108 (verified)Not listedYes
Optional crypto mail storageNot listedYes
Ad-free, user-fundedNot listedYes

eclipso Mail Europe

  • Native OpenPGP and S/MIME in every plan

    OpenPGP (RFC 4880/9580) key wizard and import work in webmail and apps, free from Freemail upward; S/MIME accepts user-supplied X.509 certificates for business clients. E2EE only applies when both sides use it—plain IMAP mail is not zero-access by default. Private keys for webmail PGP are held in the account under a passphrase for multi-device use.

  • Standard IMAP, POP3, SMTP plus CalDAV/CardDAV

    Direct protocol access for Thunderbird, Outlook, Apple Mail, and mobile clients without a bridge product. Calendar and contacts sync via CalDAV/CardDAV; Premium and Business add WebDAV for the cloud drive. Suits teams that refuse locked-in web-only mail.

  • German-hosted suite: mail, drive, organizer

    One account covers webmail, eclipso Drive file storage with link sharing, Media Center, calendar, address book, notes, and tasks. Vendor claims exclusive Germany data centres (privacy policy names Speedloc Datacenter, Görlitz). Storage and address limits scale by prepaid tariff; WebDAV and higher quotas need paid tiers.

  • Prepaid freemium with optional hybrid channels

    Freemail signs up without credit card or phone number and is ad-supported; paid Connect/Premium/Business terms are prepaid and end automatically after a reminder. Credits enable SMS, fax, and hybrid physical post through named German gateways—useful for crafts and SMEs still on those channels.

  • Business domain and Art. 28 DPA on Business plan

    Business includes a custom mail domain option, higher alias counts, daily send limits suitable for small campaigns, and an in-product Art. 28 GDPR DPA download per vendor docs. Not a full enterprise workspace: no public SCIM/SSO pack or multi-org admin model documented.

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Assurance & compliance: eclipso Mail Europe vs Posteo
Assurance & complianceLogo: eclipso Mail Europeeclipso Mail EuropeLogo: PosteoPosteo
Independent security / no-logs audit
Not found

No public third-party security or no-logs audit PDF located on official pages

Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

ISO 27001
Not found

No ISO 27001 claim found on official security/about pages at research time

Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

SOC 2 / SOC 3
Not found

No SOC 2/3 report referenced on official site

Not found

No SOC 2/3 report advertised on primary pages.

GDPR / EU data protection
Vendor claimed

German controller, DPO contact, BayLDA authority, GDPR rights language in privacy policy; servers claimed in Germany

Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

US CLOUD Act exposure (indicative)
Partial

EU/DE owner-operated entity with DE hosting (Speedloc), but Stripe, PayPal, and Google reCAPTCHA/ad tooling introduce US-group processing paths for payment and website data. Not legal advice.

Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Art. 28 DPA described as included and downloadable on Business plan; confirm for lower tiers

Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

EU AI Act
Not applicable

Email/cloud suite; not an AI system product

Not applicable

Conventional email/PIM service; not an AI product.

BSI TR-03108 Secure Email TransportNot listed
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Considerations & known limitations: eclipso Mail Europe vs Posteo
Considerations & known limitationsLogo: eclipso Mail Europeeclipso Mail EuropeLogo: PosteoPosteo
Not zero-access by default
Medium

Without OpenPGP/S/MIME, mailbox content is accessible to the operator like traditional IMAP hosts. Webmail PGP private keys are stored in-account under a passphrase—review threat model vs pure local keys.

Not listed
US-group payment and site tooling
Medium

Stripe, PayPal, Google reCAPTCHA, and documented ad partners process personal data outside pure DE mailbox hosting. Material for CLOUD Act and transfer diligence even if mail servers stay in Germany.

Not listed
No public ISO/SOC or independent audit
Medium

Security assurance is first-party documentation only. Regulated buyers will need questionnaires, AVVs, and possibly on-request evidence.

Not listed
Freemail is ad-supported
Low

Free tier includes advertising as a service component. Paid tiers are marketed as ad-free; verify current footer/banner behaviour on the live product.

Not listed
Owner-operated scale limits
Low

Independent DE operator (not VC-backed hyperscale). Expect SME-grade support hours and product depth rather than global enterprise SLAs.

Not listed
No custom domainsNot listed
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Encryption is layered, not default E2EENot listed
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

No customer Art. 28 DPANot listed
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Password loss risk with crypto featuresNot listed
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Payment processors outside pure DE mail pathNot listed
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Fit

eclipso Mail Europe

Best fit when

  • Individuals and freelancers who want German mail with Thunderbird/Outlook IMAP and optional OpenPGP without a bridge
  • SMEs needing a custom domain, German server claims, and an Art. 28 DPA on the Business plan
  • Buyers who prefer prepaid terms that end automatically over auto-renewing Big Tech suites
  • Users who still send SMS, fax, or hybrid physical post from the same account
  • Teams migrating from Gmail/Outlook that value CalDAV/CardDAV and a bundled drive/organizer

Poor fit when

  • Orgs that require zero-access architecture where the provider never stores decryptable mailbox keys by default
  • Enterprises needing public ISO 27001/SOC 2 reports, SCIM/SSO, or multi-tenant admin
  • Buyers who refuse any US-group payment or website tooling (Stripe, PayPal, Google reCAPTCHA/ads)
  • Users seeking open-source or self-hosted mail only

Consider instead when

  • When: You want a simple paid-only German privacy mailbox without freemium advertising

    Consider: Posteo

    Posteo is ad-free paid; eclipso differentiates with freemail and hybrid channels

  • When: You prioritise always-on encryption over standard IMAP clients

    Consider: Tuta or Proton Mail

    Tuta uses proprietary E2EE clients; Proton needs Bridge for full IMAP-style access

  • When: You need a broader paid German workplace suite with stronger enterprise packaging

    Consider: mailbox (formerly mailbox.org)

    Compare admin, audit, and collaboration depth on current vendor docs

  • When: You need Google/Microsoft collaboration depth more than EU operator control

    Consider: Gmail or Microsoft 365

    Different jurisdiction and data-use models

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Open questions for due diligence

eclipso Mail Europe

  • Can non-Business tariffs obtain a signed Art. 28 DPA and full subprocessor list on request?
  • Is Speedloc the sole host for mailbox content (not only the marketing site), and are backup/DR locations exclusively in Germany?
  • Are independent penetration tests or ISO plans available under NDA for enterprise buyers?
  • What exact data minimisation applies to freemail advertising versus paid ad-free tiers (inbox content vs account metadata)?
  • How are OpenPGP private keys encrypted at rest in the account store, and is export/deletion documented for offboarding?

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?