Legal position
The legal basis for Sovryk
Sovryk is not built to help anyone break the law. It is built so that lawyers, doctors, accountants and companies can meet confidentiality duties that the law already imposes on them, under penalty. This page sets out that position in plain terms, with the legal sources behind it.
This page is a statement of our position and general information, not legal advice.
In one paragraph
We provide end-to-end encrypted messaging, calls and file sharing to identified, invoiced customers. We publish our terms, our acceptable use policy and a law enforcement contact. We respond to valid legal process and hand over everything we hold. Message content is not among the things we hold, by architecture, and that is the same design the European Court of Human Rights has held must be protected. We do not sell anonymity and we do not sell impunity.
1. The confidentiality we protect is required by law
Encryption here is not a lifestyle preference. For most of our customers it is how they comply with a duty that carries a criminal or financial penalty if breached.
- Legal professional privilege. In Romania, where our company is established, Law 51/1995 Art. 35(2) provides that a lawyer's professional communications may not be intercepted or recorded except under the conditions and procedure laid down by law, and Art. 35(3) shields the lawyer-client relationship from technical surveillance unless the lawyer is themselves suspected. The European Court of Human Rights has repeatedly held that Article 8 protects lawyer-client correspondence, including in Pruteanu v. Romania and Michaud v. France.
- Medical secrecy. Romanian Law 46/2003 Art. 21 to 25 makes all information about a patient confidential, including after death. Disclosure without right by a professional bound to secrecy is a criminal offence under Art. 227 of the Romanian Criminal Code, punishable by three months to three years of imprisonment or a fine. Under the GDPR, health data is a special category under Art. 9.
- Trade secrets. Under Directive (EU) 2016/943, transposed in Romania by Government Emergency Ordinance 25/2019, information only qualifies as a protected trade secret if three conditions are met cumulatively, and the third is that the holder has taken reasonable steps to keep it secret. A company that discusses a confidential project over an unprotected channel can lose the legal protection of that secret entirely.
- Security of processing. GDPR Art. 32 names encryption explicitly as an appropriate technical measure. The NIS2 Directive, transposed in Romania by Emergency Ordinance 155/2024 and extended by Law 124/2025, requires cryptography and multi-factor authentication where appropriate, with administrative fines of up to 10 million euro or 2 percent of worldwide turnover for essential entities.
2. What Sovryk is, in regulatory terms
Sovryk is a number-independent interpersonal communications service. We do not allocate telephone numbers, we do not route traffic to the public telephone network, and we do not operate a public electronic communications network. That is the same regulatory category as Signal or Wire, and it is a category the European Electronic Communications Code treats differently from traditional telecom operators.
We say this plainly so that no authority has to guess what we are, and so that we can be regulated correctly rather than by analogy.
3. What we do when an authority asks
- We respond to valid legal process. Court orders, warrants and, from 18 August 2026, European Production and Preservation Orders under Regulation (EU) 2023/1543, with the response deadlines that regulation sets.
- We publish a channel. A dedicated legal contact, a named responsible person and a written internal procedure, so that a lawful request reaches a process instead of a void.
- We hand over everything we hold. Not more, not less, with a written record of what was provided.
- We preserve. Once we are notified of a request, automatic deletion is suspended for the data concerned. Destroying evidence is an offence. Encryption is not.
- We keep a register and we report. Every request is logged, and we intend to publish periodic transparency reporting.
- We enforce our acceptable use policy. Illegal use is prohibited and reported abuse leads to suspension or termination.
See our law enforcement guidelines for the full procedure.
4. What we cannot do, and why that is lawful
Content is encrypted end-to-end. The keys exist only on user devices. There is no server-side key escrow, no master key and no recovery path for message content. When we say we cannot produce content, that is a statement of architecture, not a refusal.
This matters legally. Obligations to produce data attach to what a provider holds or controls. And in Podchasov v. Russia, decided on 13 February 2024, the European Court of Human Rights held that requiring a provider to enable decryption of end-to-end encrypted communications is a disproportionate measure that violates Article 8 of the Convention, because a backdoor built for authorities is a backdoor available to everyone.
A provider who cannot read your messages cannot leak them, cannot be pressured into selling them, and cannot lose them in a breach. That is the point of the design.
5. What we do not do
- We do not market to people who want to hide criminal activity, and we do not sell through informal or anonymous channels.
- We do not offer remote wipe on demand as a way to destroy evidence.
- We do not modify hardware to disable cameras, microphones or location.
- We do not promise anonymity from lawful investigation. Encryption protects content, not identity.
- We do not claim to be outside any jurisdiction. We are a European company and we say so.
6. Chat Control, stated accurately
We think the EU scanning debate is bad policy, and we say so. We also state its status correctly, because a privacy company that exaggerates the law is not a privacy company anyone should trust.
As of July 2026, the temporary derogation permitting voluntary scanning of unencrypted communications was reinstated by the Council on 2 July 2026 and survived a European Parliament rejection motion on 9 July 2026, running to April 2028. The permanent CSA Regulation, the one that would make detection orders mandatory, is not law: the fifth trilogue ended without agreement on 29 June 2026 and negotiations continue. Separately, the Commission's ProtectEU roadmap on lawful access to encrypted data is due in the second quarter of 2026.
Nothing in force today obliges us to scan anything, and we do not.
7. The full list of legal grounds
The order is the real one: EU primary law first, then the Convention and its case law, then Romanian law. The European Union has no constitution (the constitutional treaty was rejected in 2005), but it has an equivalent with the same legal force: the Charter of Fundamental Rights, which under Article 6(1) of the Treaty on European Union has the same legal value as the Treaties.
| Legal source | What it says | What it means for Sovryk |
|---|---|---|
| EU Charter of Fundamental Rights, Art. 7 | Everyone has the right to respect for private and family life, home and communications. | Confidentiality of communications is a European fundamental right, not a commercial preference. |
| EU Charter of Fundamental Rights, Art. 8 | Personal data must be processed fairly, for specified purposes, subject to control by an independent authority. | The basis for our data minimisation posture. |
| EU Charter of Fundamental Rights, Art. 52(1) | Any limitation must be provided for by law, respect the essence of the right, and be necessary and proportionate. | A general scanning obligation touches the essence of the right, not merely its edges. |
| TEU Art. 6(1) and TFEU Art. 16 | The Charter has the same legal value as the Treaties, and data protection is a Treaty right. | This is EU primary law, not a political declaration. |
| Directive 2002/58/EC (ePrivacy), Art. 5(1) | Member States must ensure the confidentiality of communications and prohibit interception or surveillance without consent. | Confidentiality is the European default. Scanning is the exception that must be justified. |
| CJEU, Digital Rights Ireland, C-293/12, 8 April 2014 | Annulled the 2006 Data Retention Directive: fighting serious crime does not justify general and indiscriminate retention. | The European basis for our minimal logging posture. |
| CJEU, Tele2 and Watson, C-203/15 and C-698/15 | Member States may not impose a blanket obligation on providers to store the metadata of all users. | No authority can lawfully impose general retention on us. |
| CJEU, Commissioner of An Garda Síochána, C-140/20, 5 April 2022 | Reaffirms the ban on general retention and requires that authority access to retained data be subject to prior review by a court or an independent body. | When we require a warrant, we are applying EU law, not obstructing. |
| Romanian Constitution, Art. 26, 28 and 53 | Private life and the secrecy of correspondence are inviolable. Any restriction must be by law, necessary and proportionate, without touching the existence of the right. | The constitutional basis of the product. |
| ECHR Art. 8, Podchasov v. Russia, 13 February 2024 | Requiring a provider to enable decryption of end-to-end encrypted communications is disproportionate and violates Art. 8. | We cannot lawfully be compelled to build a backdoor. |
| Romanian Constitution, Art. 20(2) | Human rights treaties take precedence over domestic law. | The Podchasov ruling applies in Romania. |
| Law 51/1995, Art. 35(2) and (3) | A lawyer's professional communications may not be intercepted except under the conditions of the law, and the lawyer-client relationship is shielded from technical surveillance. | Our lawyer customers hold a protected right that the product serves. |
| Law 46/2003, Art. 21 to 25, and Criminal Code Art. 227 | All patient information is confidential. Disclosure without right is punishable by three months to three years or a fine. | Our medical customers hold a criminal-law duty that the product serves. |
| Directive (EU) 2016/943 and Emergency Ordinance 25/2019 | Information is a protected trade secret only if the holder has taken reasonable steps to keep it secret. | Without a protected channel, a company loses the legal protection of its secret in court. |
| GDPR, Art. 32 and Art. 9 | Encryption is named explicitly as an appropriate technical measure. Health data is a special category. | The product is a GDPR compliance measure, not a way around it. |
| NIS2, transposed by Emergency Ordinance 155/2024 and Law 124/2025 | Cryptography and multi-factor authentication where appropriate, with fines up to 10 million euro or 2 percent of worldwide turnover. | The state requires of our customers exactly what we sell them. |
| Criminal Code, Art. 48 and Art. 16(6) | Complicity requires intent. A negligent act is an offence only where the law says so expressly. | Publicly selling a general-purpose security product is a neutral act. |
| Criminal Procedure Code, Art. 142 and Art. 170 | Providers cooperate in executing a surveillance warrant and hand over data held in their possession or under their control. | We hand over everything we hold. Content is not in our possession. |
| Law 198/2022, the European Electronic Communications Code | Number-independent interpersonal communications services are treated separately from telecom operators. | Our regulatory category, declared openly rather than assumed. |
| Constitutional Court Decisions 1258/2009 and 440 of 8 July 2014 | Both Romanian data retention laws were struck down as unconstitutional. | There is no retention obligation. Minimal logging is consistent with the case law. |
| Law 535/2004, Art. 9 | Any legal person who learns of data concerning the commission, support or financing of terrorist acts must notify the competent authorities immediately and provide the necessary assistance. | We maintain a written internal procedure for exactly this duty. |
| Regulation (EU) 2023/1543 and Directive (EU) 2023/1544 | European Production and Preservation Orders from 18 August 2026, plus the duty to designate a legal representative in the EU. | We maintain a published channel, a named person and the capacity to respond in time. |
| Regulation (EU) 2021/821, Cryptography Note, note 3 to Category 5 Part 2 | Mass-market cryptography products are exempt from export control. | Distributing the product is lawful without an export licence. |
| Law 51/1991, Art. 3 and Art. 13 | Lists the threats to national security and the intelligence-gathering methods, which require judicial authorisation. | Providing encrypted communications is not among the listed threats. |
Does Sovryk help people evade the law?
No. We provide a communications tool to identified customers under published terms, we prohibit illegal use, and we respond to valid legal process. Under Romanian criminal law, complicity requires intent (Criminal Code Art. 48). Selling a general-purpose security product to the public is a neutral act, and we run our business so that it stays one.
Will you give my messages to the police if asked?
We cannot. Content is encrypted end to end and the keys are on user devices only. If served with a valid order we hand over the limited account data we actually hold, and we say clearly what we do not have.
Is end-to-end encryption legal in the EU?
Yes. There is no EU or Romanian law prohibiting the provision or use of end-to-end encryption. Several instruments, including GDPR Art. 32 and NIS2, positively require encryption as a security measure.
Where is the company and where are the servers?
The company is European. Servers are hosted in Iceland, which is outside the European Union but inside the European Economic Area, and therefore inside the GDPR. We do not claim to be beyond any jurisdiction.
Do you keep logs?
We keep the minimum needed to operate the service. Romania has had no data retention law in force since the Constitutional Court struck down Law 82/2012 in Decision 440 of 8 July 2014, following Decision 1258/2009 on the previous law. Our minimal-logging posture is consistent with that case law.
Need this in writing for your compliance file? We provide our legal position statement, a GDPR data processing agreement and our security documentation to prospective business customers on request.