Data protection is not a feature here.
It is the foundation.
nordOFFICE comes from digitalNORD GmbH in Kiel — a team that has advised companies on data protection for years. That is why the platform has been built privacy-first from the very first line: hosted exclusively in Germany, a data processing agreement included, no tracking cookies, no data flows to third countries.
What privacy-first actually means.
Not a tick box in the contract but decisions in the architecture — taken by people who assess data protection consequences every day.
Built by data protection professionals
Behind nordOFFICE stands a company from data protection consultancy. Every module is created with the question our consultants ask their clients in mind: which data is really needed — and who is allowed to see it?
No third-party servers involved
The application loads no external resources: fonts, scripts and maps are held locally. There are no tracking cookies, no tracking pixels and no third-party analytics services — neither in the app nor on this website.
Everything in Germany
Operated exclusively on servers in Germany, backups included. No data is transferred to third parties outside the EU. Anyone who wants to go further runs nordOFFICE entirely on their own infrastructure.
The sovereign alternative to Microsoft 365.
Email, calendar, files with office in the browser, chat, video conferencing and more than 30 further modules — in a platform that belongs to you rather than the other way round.
Digital sovereignty
Your data sits with a provider based in Kiel and is subject exclusively to German and European law — not to the access laws of a third country. You know at all times where your data is and who can reach it.
Independence
No corporate ecosystem that makes every move expensive: an open interface with more than 920 tools, an export of your data at any time, full compatibility with Word and Excel formats — and on-premise operation on request. Your data stays your data.
Price stability
Fixed euro prices per user, modules switched on individually instead of a compulsory bundle. Office in the browser is included — you do not need a Microsoft 365 licence. No dollar exchange rates, no price rounds you learn about from the newspaper.
- One interface instead of a licence jungle: CRM, email, calendar, files, projects, invoices and more
- Office in the browser included — open, edit and share Word and Excel files
- Backup included, no server of your own and no domain controller needed
- No infrastructure of your own required — but possible if you want it
Security built in, not bolted on.
From the sign-in procedure to the individual file — the most important protections are part of the package.
Permissions down to the detail
Groups and individual permissions per module — reading, writing, creating and deleting controlled separately. Anyone who is not allowed to do something does not even see it. The check happens on the server, not just in the interface.
Sign in with the company account
Single sign-on via Microsoft 365 (Entra ID) or your own directory over LDAP — Active Directory, Samba AD, Univention UCS and OpenLDAP. No second password, and a central lockout withdraws access to nordOFFICE as well.
Two-factor sign-in
Every user can add protection to their account with a one-time code app (TOTP) — at no extra cost and without a third-party service.
Encrypted email
S/MIME for signed and encrypted mail, on request with your own certificate authority for the whole team — set up in minutes rather than projects.
Zero-knowledge passwords
The password manager encrypts in the browser; the server knows neither the master password nor the contents. Not even we could read your passwords.
Virus protection for files
Every uploaded file is scanned automatically; anything found goes into quarantine before anyone opens it.
Spam and phishing protection
The built-in spam filter sorts out unwanted mail and visibly warns about suspected phishing. Where needed, an AI provides a second opinion — the mail is anonymised beforehand, so personal data stays in house.
Secrets as a one-time link
Credentials do not belong in an email: secret sending creates self-destructing one-time links whose key never reaches the server.
AI, yes — but on your terms.
nordOFFICE has AI built in without turning your data into a commodity. You choose the model, you set the limits.
Your key, your choice
Claude, ChatGPT or Gemini run on your own API keys — there is no hidden collective account held by the provider. Anyone who does not want AI simply does not enable it.
Local models possible
Through Ollama the AI can run entirely on your own hardware — with tool access to your nordOFFICE data but without a single record leaving the building.
AI with user permissions
Every AI access runs with the permissions of exactly the user who set it up. Sending, invitations and permanent deletion first require a preview and then an explicit confirmation.
GDPR without the paperwork battle.
The documents your data protection officer will ask for are ready and waiting — not only on request.
- A data processing agreement under Art. 28 GDPR included — concluded when the contract is signed, at no additional cost; you remain the controller within the meaning of the GDPR
- Technical and organisational measures (TOMs) — documented and part of the data processing agreement
- Sub-processors set out clearly — transparent in the data processing agreement, no silent hand-overs
- Everything available in advance — the data processing agreement including the TOMs is available on request before you order
Frequently asked questions
Is nordOFFICE GDPR-compliant?
Is nordOFFICE an alternative to Microsoft 365?
Where is the data stored?
Is there a data processing agreement?
Can our people sign in with their company account (SSO)?
How does nordOFFICE handle AI and data protection?
Can I get out again later?
Convince your data protection officer.
Request demo access and examine nordOFFICE with real sample data — you can read the data processing agreement and the TOMs beforehand.