Legal position

The legal basis for Sovryk

Why encrypted communication is a compliance tool, not an escape route · Updated July 2026

Sovryk is not built to help anyone break the law. It is built so that lawyers, doctors, accountants and companies can meet confidentiality duties that the law already imposes on them, under penalty. This page sets out that position in plain terms, with the legal sources behind it.

This page is a statement of our position and general information, not legal advice.

In one paragraph

We provide end-to-end encrypted messaging, calls and file sharing to identified, invoiced customers. We publish our terms, our acceptable use policy and a law enforcement contact. We respond to valid legal process and hand over everything we hold. Message content is not among the things we hold, by architecture, and that is the same design the European Court of Human Rights has held must be protected. We do not sell anonymity and we do not sell impunity.

1. The confidentiality we protect is required by law

Encryption here is not a lifestyle preference. For most of our customers it is how they comply with a duty that carries a criminal or financial penalty if breached.

The short version: the same legal systems that debate encryption also require our customers to use it. Sovryk sits inside that compliance chain, not against it.

2. What Sovryk is, in regulatory terms

Sovryk is a number-independent interpersonal communications service. We do not allocate telephone numbers, we do not route traffic to the public telephone network, and we do not operate a public electronic communications network. That is the same regulatory category as Signal or Wire, and it is a category the European Electronic Communications Code treats differently from traditional telecom operators.

We say this plainly so that no authority has to guess what we are, and so that we can be regulated correctly rather than by analogy.

3. What we do when an authority asks

See our law enforcement guidelines for the full procedure.

4. What we cannot do, and why that is lawful

Content is encrypted end-to-end. The keys exist only on user devices. There is no server-side key escrow, no master key and no recovery path for message content. When we say we cannot produce content, that is a statement of architecture, not a refusal.

This matters legally. Obligations to produce data attach to what a provider holds or controls. And in Podchasov v. Russia, decided on 13 February 2024, the European Court of Human Rights held that requiring a provider to enable decryption of end-to-end encrypted communications is a disproportionate measure that violates Article 8 of the Convention, because a backdoor built for authorities is a backdoor available to everyone.

A provider who cannot read your messages cannot leak them, cannot be pressured into selling them, and cannot lose them in a breach. That is the point of the design.

5. What we do not do

6. Chat Control, stated accurately

We think the EU scanning debate is bad policy, and we say so. We also state its status correctly, because a privacy company that exaggerates the law is not a privacy company anyone should trust.

As of July 2026, the temporary derogation permitting voluntary scanning of unencrypted communications was reinstated by the Council on 2 July 2026 and survived a European Parliament rejection motion on 9 July 2026, running to April 2028. The permanent CSA Regulation, the one that would make detection orders mandatory, is not law: the fifth trilogue ended without agreement on 29 June 2026 and negotiations continue. Separately, the Commission's ProtectEU roadmap on lawful access to encrypted data is due in the second quarter of 2026.

Nothing in force today obliges us to scan anything, and we do not.

7. The full list of legal grounds

The order is the real one: EU primary law first, then the Convention and its case law, then Romanian law. The European Union has no constitution (the constitutional treaty was rejected in 2005), but it has an equivalent with the same legal force: the Charter of Fundamental Rights, which under Article 6(1) of the Treaty on European Union has the same legal value as the Treaties.

Legal sourceWhat it saysWhat it means for Sovryk
EU Charter of Fundamental Rights, Art. 7Everyone has the right to respect for private and family life, home and communications.Confidentiality of communications is a European fundamental right, not a commercial preference.
EU Charter of Fundamental Rights, Art. 8Personal data must be processed fairly, for specified purposes, subject to control by an independent authority.The basis for our data minimisation posture.
EU Charter of Fundamental Rights, Art. 52(1)Any limitation must be provided for by law, respect the essence of the right, and be necessary and proportionate.A general scanning obligation touches the essence of the right, not merely its edges.
TEU Art. 6(1) and TFEU Art. 16The Charter has the same legal value as the Treaties, and data protection is a Treaty right.This is EU primary law, not a political declaration.
Directive 2002/58/EC (ePrivacy), Art. 5(1)Member States must ensure the confidentiality of communications and prohibit interception or surveillance without consent.Confidentiality is the European default. Scanning is the exception that must be justified.
CJEU, Digital Rights Ireland, C-293/12, 8 April 2014Annulled the 2006 Data Retention Directive: fighting serious crime does not justify general and indiscriminate retention.The European basis for our minimal logging posture.
CJEU, Tele2 and Watson, C-203/15 and C-698/15Member States may not impose a blanket obligation on providers to store the metadata of all users.No authority can lawfully impose general retention on us.
CJEU, Commissioner of An Garda Síochána, C-140/20, 5 April 2022Reaffirms the ban on general retention and requires that authority access to retained data be subject to prior review by a court or an independent body.When we require a warrant, we are applying EU law, not obstructing.
Romanian Constitution, Art. 26, 28 and 53Private life and the secrecy of correspondence are inviolable. Any restriction must be by law, necessary and proportionate, without touching the existence of the right.The constitutional basis of the product.
ECHR Art. 8, Podchasov v. Russia, 13 February 2024Requiring a provider to enable decryption of end-to-end encrypted communications is disproportionate and violates Art. 8.We cannot lawfully be compelled to build a backdoor.
Romanian Constitution, Art. 20(2)Human rights treaties take precedence over domestic law.The Podchasov ruling applies in Romania.
Law 51/1995, Art. 35(2) and (3)A lawyer's professional communications may not be intercepted except under the conditions of the law, and the lawyer-client relationship is shielded from technical surveillance.Our lawyer customers hold a protected right that the product serves.
Law 46/2003, Art. 21 to 25, and Criminal Code Art. 227All patient information is confidential. Disclosure without right is punishable by three months to three years or a fine.Our medical customers hold a criminal-law duty that the product serves.
Directive (EU) 2016/943 and Emergency Ordinance 25/2019Information is a protected trade secret only if the holder has taken reasonable steps to keep it secret.Without a protected channel, a company loses the legal protection of its secret in court.
GDPR, Art. 32 and Art. 9Encryption is named explicitly as an appropriate technical measure. Health data is a special category.The product is a GDPR compliance measure, not a way around it.
NIS2, transposed by Emergency Ordinance 155/2024 and Law 124/2025Cryptography and multi-factor authentication where appropriate, with fines up to 10 million euro or 2 percent of worldwide turnover.The state requires of our customers exactly what we sell them.
Criminal Code, Art. 48 and Art. 16(6)Complicity requires intent. A negligent act is an offence only where the law says so expressly.Publicly selling a general-purpose security product is a neutral act.
Criminal Procedure Code, Art. 142 and Art. 170Providers cooperate in executing a surveillance warrant and hand over data held in their possession or under their control.We hand over everything we hold. Content is not in our possession.
Law 198/2022, the European Electronic Communications CodeNumber-independent interpersonal communications services are treated separately from telecom operators.Our regulatory category, declared openly rather than assumed.
Constitutional Court Decisions 1258/2009 and 440 of 8 July 2014Both Romanian data retention laws were struck down as unconstitutional.There is no retention obligation. Minimal logging is consistent with the case law.
Law 535/2004, Art. 9Any legal person who learns of data concerning the commission, support or financing of terrorist acts must notify the competent authorities immediately and provide the necessary assistance.We maintain a written internal procedure for exactly this duty.
Regulation (EU) 2023/1543 and Directive (EU) 2023/1544European Production and Preservation Orders from 18 August 2026, plus the duty to designate a legal representative in the EU.We maintain a published channel, a named person and the capacity to respond in time.
Regulation (EU) 2021/821, Cryptography Note, note 3 to Category 5 Part 2Mass-market cryptography products are exempt from export control.Distributing the product is lawful without an export licence.
Law 51/1991, Art. 3 and Art. 13Lists the threats to national security and the intelligence-gathering methods, which require judicial authorisation.Providing encrypted communications is not among the listed threats.
Does Sovryk help people evade the law?

No. We provide a communications tool to identified customers under published terms, we prohibit illegal use, and we respond to valid legal process. Under Romanian criminal law, complicity requires intent (Criminal Code Art. 48). Selling a general-purpose security product to the public is a neutral act, and we run our business so that it stays one.

Will you give my messages to the police if asked?

We cannot. Content is encrypted end to end and the keys are on user devices only. If served with a valid order we hand over the limited account data we actually hold, and we say clearly what we do not have.

Is end-to-end encryption legal in the EU?

Yes. There is no EU or Romanian law prohibiting the provision or use of end-to-end encryption. Several instruments, including GDPR Art. 32 and NIS2, positively require encryption as a security measure.

Where is the company and where are the servers?

The company is European. Servers are hosted in Iceland, which is outside the European Union but inside the European Economic Area, and therefore inside the GDPR. We do not claim to be beyond any jurisdiction.

Do you keep logs?

We keep the minimum needed to operate the service. Romania has had no data retention law in force since the Constitutional Court struck down Law 82/2012 in Decision 440 of 8 July 2014, following Decision 1258/2009 on the previous law. Our minimal-logging posture is consistent with that case law.

Need this in writing for your compliance file? We provide our legal position statement, a GDPR data processing agreement and our security documentation to prospective business customers on request.