Nozbe vs Stackfield

Comparez Nozbe et Stackfield sur les capacités, la juridiction, les garanties et l'adéquation pour les acheteurs européens.

Tous deux listés comme alternatives à: Microsoft Teams, Slack

Logo: Nozbe

Nozbe

Poland· Groupware

Needs review

Shortlist Nozbe when a small remote or hybrid team wants a simple Polish SaaS for GTD-style projects, tasks, and comments—with German primary hosting and a public B2B DPA. Skip when you need self-hosting, published ISO/SOC attestation, enterprise portfolio PM, or a path free of US-group cloud/SaaS subprocessors; consider Nextcloud (self-host) or a chat-first peer such as Fleep instead.

EU-operated (Poland)Task-based collaborationMulti-workspaceOffline appsPublic B2B DPAFree tier + seat SaaS
Logo: Stackfield

Stackfield

Germany· Groupware

Needs review

Shortlist Stackfield when you need a German-operated all-in-one (chat + PM + meetings + docs) with optional client-side E2E rooms, Germany hosting, and a BSI C5 / ISO story for regulated teams. Skip when you need open-source DIY (prefer Nextcloud), Slack-scale app ecosystem depth, or pure secure messaging without project management (consider ginlo Business).

EU-operated (DE)Optional client-side E2EGermany hosting (IONOS)ISO 27001 + BSI C5 (claimed)Commercial on-premiseChat + PM + video
Nozbe vs Stackfield: Aperçu
CaractéristiqueLogo: NozbeNozbeLogo: StackfieldStackfield
Pays d'originePolandGermany
CatégorieGroupwareGroupware
Open sourceNonNon
Auto-hébergéNonOui
SiègePolandGermany
Entité légaleNOZBE sp. z o.o., ul. Spacerowa 31/5, 81-521 Gdynia, Poland (NIP PL5862383639, KRS 0000987269)Stackfield GmbH, Maximiliansplatz 17, 80333 München, Germany
Droit applicablePolandNon indiqué
Maison mère / contrôle USAucune maison mère US connueAucune maison mère US connue
Exposition CLOUD Act (indicative)MoyenMoyen
Hébergement / résidencePrimary app servers on Hetzner (Germany). Encrypted DB backups and file storage on Amazon S3 (Paris/Frankfurt; DPA also cites AWS/Hetzner regions in Germany, Ireland, France). Cloudflare for printing. Privacy also lists Mailgun, GetResponse, Google Analytics/Sign-In/GCal, Facebook marketing, Gmail/Sugester support, Stripe/Verifone/Przelewy24 payments.Product data claimed stored in Germany; infrastructure provider IONOS SE (DE). Vendor states no AWS/GCP/Azure product subcontractors. Named EU processors: Inxmail (email, DE), Myra Security (edge protection, DE). Mobile push uses Apple APNs and Google push services (US platforms). Optional admin-enabled Giphy (US). Marketing site uses Google/Bing ads (not workspace content path). Optional customer-keyed external AI leaves Stackfield’s IONOS-hosted model path.
Résumé

Polish task and project management SaaS with task-based communication, multi-workspace separation, offline apps, and vendor-hosted EU primary infrastructure.

German all-in-one collaboration suite (chat, tasks/projects, video, docs) with optional client-side end-to-end encryption and Germany-hosted cloud or commercial on-premise.

Tags
En un coup d'œil: Nozbe vs Stackfield
En un coup d'œilLogo: NozbeNozbeLogo: StackfieldStackfield
HQGdynia, PolandMunich, Germany
Legal entityNOZBE sp. z o.o.Stackfield GmbH (HRB 199536)
Founded2007 (vendor history)2012 (vendor claim)
DeploymentMulti-tenant SaaS (not self-hosted)SaaS cloud + commercial on-premise
Primary hostingHetzner, GermanyNon indiqué
Commercial modelFree tier + seat-based Premium/BusinessSeat-based plans; trial; AI/Office add-ons
HostingNon indiquéGermany; IONOS SE (vendor-named)
Open sourceNon indiquéNo
Key capabilities: Nozbe vs Stackfield
Key capabilitiesLogo: NozbeNozbeLogo: StackfieldStackfield
EU-operated (Poland)OuiOui
Task-based collaborationOuiNon indiqué
Multi-workspaceOuiNon indiqué
Offline appsOuiNon indiqué
Public B2B DPAOuiNon indiqué
Free tier + seat SaaSOuiNon indiqué
Optional client-side E2ENon indiquéOui
Germany hosting (IONOS)Non indiquéOui
ISO 27001 + BSI C5 (claimed)Non indiquéOui
Commercial on-premiseNon indiquéOui
Chat + PM + videoNon indiquéOui

Nozbe

  • Task-based communication (projects → tasks → comments)

    Work is organized as projects containing tasks; discussion, checklists, @mentions, reactions, attachments, and task links live on the task so context does not scatter across email or chat. Suited to teams that want asynchronous ownership without a heavy workflow engine.

  • Multiple workspaces for work and life

    Create separate spaces for a company, department, or personal life under one account. Free plan starts with one free space; Premium adds capacity; Business is positioned for unlimited workspaces when you run several teams or businesses.

  • Email-to-task capture and project templates

    Each user can forward mail to a personal Nozbe address to turn messages and attachments into tasks. Recurring workflows (onboarding, reports, orders) can be saved as project templates and re-instantiated instead of rebuilding checklists by hand.

  • Offline-capable multi-platform apps

    Dedicated clients for Windows, Mac, iOS, and Android plus the web app at nozbe.app; About also lists Linux. Apps sync with servers in Germany and are marketed as usable offline for hybrid and mobile work.

  • Shared and joint projects across spaces

    Invite-only projects (Premium) restrict visibility inside a space; joint projects let you collaborate with other Nozbe spaces (clients, subcontractors) without migrating everyone onto one workspace. Complements space-level multi-tenant style separation.

  • Optional AI project bootstrap and time tracking

    Premium-oriented features include Create using AI (describe a project or import CSV to generate tasks), time tracking, and richer history/storage limits than Free. Confirm current plan gates on the official feature comparison before procurement.

Stackfield

  • Optional client-side E2E rooms (AES-256 + RSA-2048)

    Rooms and direct messages can add browser-side end-to-end encryption so Stackfield cannot read covered content at rest. Admins can force E2E, ban it, or let creators choose. Trade-offs include room-password recovery after login resets, limited lock-screen/email previews, and client-side search cost—plan org policy before migrating sensitive rooms.

  • Tasks, Gantt, portfolios, and workflows in the same rooms as chat

    List/Kanban/Gantt views, milestones, dependencies, automatic scheduling, critical path, custom fields, time tracking, reports, and project portfolios sit next to room chat and discussions. Suited to PMOs that refuse a separate tool silo; less deep than specialist ALM suites for software engineering pipelines.

  • Video conferences, screen share, and guest/external roles

    Built-in audio/video/screen-sharing (plan-dependent) plus guest and external roles that only see assigned rooms. Useful for law firms, agencies, and public-sector projects with outside counsel or contractors without granting full org access.

  • Germany cloud (IONOS) plus commercial on-premise

    Cloud tenants store data in German data centres; Stackfield names IONOS SE as infrastructure provider and claims no AWS/GCP/Azure product subprocessors. On-premise is a paid subscription (vendor-installed/updated, high minimum seat count) for air-gapped or policy-bound estates—test first in cloud; local PoC installs are not offered.

  • Enterprise access controls and in-product DPA

    Higher tiers add enforced 2FA (including YubiKey options), IP allowlists, password policies, SSO, API provisioning, org-wide exports, and compliance-confirmation workflows. Organisation admins can conclude the GDPR DPA inside settings and download the signed PDF once per organisation.

Assurance & compliance: Nozbe vs Stackfield
Assurance & complianceLogo: NozbeNozbeLogo: StackfieldStackfield
Independent security / no-logs audit
Not found

Vendor describes restricted staff access and internal/external security tests; no public independent audit report found.

Partial

Vendor claims regular penetration tests and APPVISORY Trusted App for mobile; no public independent no-logs or full security audit report found.

ISO 27001
Not found

No ISO 27001 claim or certificate located on official site.

Vendor claimed

Vendor states ISO 27001 (plus 27017/27018) with certificate download on security page; not independently registry-verified in this draft.

SOC 2 / SOC 3
Not found

No SOC 2/3 report advertised on official legal/security pages.

Not found

No SOC 2/3 claim found on primary security pages reviewed.

GDPR / EU data protection
Vendor claimed

Polish controller; GDPR-oriented privacy terms; public Art. 28 DPA PDF; EU hosting for primary app data.

Vendor claimed

EU controller Stackfield GmbH; Germany hosting claims; in-product DPA; public privacy policy with processor list fragments.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but AWS S3 backups/files, Mailgun, Google, Facebook, Stripe/Verifone, and Cloudflare create US-group processing paths. Not legal advice.

Partial

EU entity, no known US parent, core hosting claimed via IONOS DE without AWS/GCP/Azure. Residual paths: Apple/Google mobile push; optional Giphy; optional customer external AI. Assessment only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Downloadable GDPR DPA at nozbe.com/gdpr; customer signs and returns. Also available on request via support language in privacy policy.

Vendor claimed

Organisation admins can conclude DPA inside Organisation Settings and download signed PDF; one DPA per organisation.

EU AI Act
Not applicable

Optional Create using AI feature; product is primarily task/project management, not an AI system as core offering. Reassess if AI features expand.

Not applicable

Optional text-assist AI add-on; not an AI-centric product. Revisit if agents expand into high-risk use cases.

BSI C5Non indiqué
Vendor claimed

Vendor claims BSI C5 attestation on homepage and security page; obtain current report in procurement.

Considerations & known limitations: Nozbe vs Stackfield
Considerations & known limitationsLogo: NozbeNozbeLogo: StackfieldStackfield
US-group cloud and SaaS subprocessors
Medium

Core tasks run on Hetzner DE, but encrypted backups/files use Amazon S3 and privacy lists Mailgun, Google, Facebook, Stripe/Verifone, and Cloudflare. EU HQ does not eliminate US-group provider exposure for procurement policies that ban those vendors.

Non indiqué
No public ISO/SOC or independent audit report
Medium

Security practices are described by the vendor (encryption, backups, limited staff access, external tests) without published certificates. Enterprise security questionnaires may stall until documents are shared under NDA.

Non indiqué
SaaS-only; no self-host option
Medium

Data and availability depend on Nozbe’s multi-tenant service. Air-gapped or customer-controlled deployment is not offered publicly.

Non indiqué
Narrow feature surface vs enterprise PM
Low

Deliberately simple projects/tasks/comments model may lack portfolio, advanced automation, or complex permission matrices expected in large PMO tools—confirm fit before migrating from Asana/Jira-class suites.

Non indiqué
E2E is optional and irreversible per roomNon indiqué
Medium

Without org policy, creators may leave sensitive rooms unencrypted. Encryption mode cannot be changed after creation; password recovery after login reset needs disciplined room-key handling.

Mobile push and optional US integrationsNon indiqué
Medium

Privacy policy documents Apple/Google push for mobile notifications and optional Giphy (US). Even with German content hosting, notification metadata and optional GIF traffic can touch US platforms—document in DPIA.

Certifications vendor-assertedNon indiqué
Low

ISO and BSI C5 are claimed with a downloadable certificate; treat as claimed until your auditor verifies scope, dates, and which systems are in-bounds.

On-premise is commercial, not DIY open sourceNon indiqué
Low

Self-host means a paid on-prem product with vendor install/update and high seat minimums—not a free community edition. Budget implementation and support tickets accordingly.

AI features require content decryption for processingNon indiqué
Medium

Stackfield AI decrypts client-side content for the request path (then claims immediate deletion). External AI via customer keys is a separate transfer. Disable AI if zero-knowledge must never leave the client.

Adéquation

Nozbe

Best fit when

  • Small businesses and service teams that want projects → tasks → comments instead of channel chat or heavy PM suites
  • Remote/hybrid groups that need coherent desktop and mobile clients with offline capture
  • Buyers who want a Polish legal entity, German primary hosting, and a downloadable Art. 28 DPA
  • People who separate work and personal life via multiple workspaces in one product
  • Teams that capture actionable email as tasks and reuse project templates for repeat client work

Poor fit when

  • Organizations that require self-hosted or fully air-gapped deployment
  • Procurement that mandates public ISO 27001 or SOC 2 reports before shortlisting
  • Enterprises needing portfolio resource management, complex automations, or deep Kanban/Gantt tooling
  • Buyers whose policy forbids US-group cloud providers even for EU-region backups, email, or analytics
  • Teams seeking a full Microsoft 365 / Google Workspace replacement (mail, docs, meetings) rather than a task system

Consider instead when

  • When: You must self-host collaboration data and control subprocessors yourself

    Consider: Nextcloud

    Broader content collaboration hub; operational ownership shifts to your team.

  • When: You need Swiss-hosted classic groupware (mail, calendar, contacts) more than task PM

    Consider: Kolab Now

    Different product shape; not a drop-in Nozbe substitute.

  • When: Chat-first team messaging with conversation tasks is enough and you prefer Estonia HQ

    Consider: Fleep

    Messenger-centric; weaker as a full multi-workspace project system.

  • When: Your org is already standardized on Microsoft collaboration and only needs lightweight tasks

    Consider: Microsoft Teams / Microsoft 365 Planner-style workflows

    Lower integration friction; different jurisdiction and product philosophy.

Stackfield

Best fit when

  • German/EU orgs that want one tool for projects and communication instead of Slack + separate PM
  • Teams that need optional zero-knowledge rooms for highly sensitive matters (legal, M&A, HR, clinical ops)
  • Buyers requiring German legal entity, DPA in-product, and claimed ISO/BSI C5 for procurement questionnaires
  • Public sector, banking, insurance, and professional services evaluating cloud with an on-prem exit path
  • Orgs that will enforce 2FA/SSO/IP allowlists and guest-only access for externals

Poor fit when

  • Teams that need always-on E2E with full rich push previews and third-party calendar feeds without trade-offs
  • Engineering orgs standardised on Jira/GitHub-style ALM depth and automation
  • Buyers who require fully open-source, community-supported self-host without a commercial on-prem contract
  • Global enterprises whose primary requirement is the Slack/Teams integration marketplace
  • Very small teams needing only free-tier messaging with no seat-based SaaS commitment

Consider instead when

  • When: You need open-source self-host and full operational control of files/collab apps

    Consider: Nextcloud

    More DIY ops; broader app ecosystem; different PM depth.

  • When: You mainly need regulated secure messaging, not Gantt/portfolios

    Consider: ginlo Business

    Messaging-first German B2B chat; thinner project suite.

  • When: You already run Microsoft 365 and identity is non-negotiable

    Consider: Microsoft Teams (incumbent) or stay in M365 with EU data boundaries

    Teams wins on suite lock-in; loses on independent German vendor + optional client E2E story.

  • When: You want lighter EU team chat without full PM suite

    Consider: Fleep

    Chat-centric; different residency/subprocessor profile—verify separately.

Open questions for due diligence

Nozbe

  • Will the vendor provide a current subprocessor list with legal entities and transfer mechanisms (SCCs) for AWS, Mailgun, Google, and payment providers?
  • Are independent penetration-test or ISO/SOC materials available under NDA for enterprise procurement?
  • What is the exact production region set today for Ireland vs Germany/France relative to the DPA wording?
  • What retention, export formats, and support SLAs apply on Business vs Premium for regulated clients?
  • How is optional Nozbe AI implemented (model provider, data used for training, opt-out)?

Stackfield

  • Will the vendor provide the current BSI C5 report, ISO certificate scope, and full subprocessor annex under NDA if not already in the DPA PDF?
  • Which fields remain outside E2E (metadata, search indexes, analytics) in your planned room configuration?
  • For mobile fleets: is APNs/FCM push acceptable, or must notifications be disabled/restricted?
  • On-premise: exact supported OS/hypervisor matrix, backup model, and upgrade cadence for your estate?
  • Is Stackfield AI (or customer external AI) allowed under your policy for rooms that contain special-category data?