Participant or customer? Click here to log in!
Compliance

DPA, GDPR and hosting in Düsseldorf. Everything your IT team needs to approve the platform.

Everything IT, Data Protection and Compliance need for approval is usually available by the next day. Documentation will not slow the process down.

German hosting. Based in Düsseldorf since 2001.

We operate our own servers in an ISO 27001-certified data centre in Germany. Event data is not hosted in a US cloud or on infrastructure shared with large third-party cloud providers. No transfer of data to third countries. Event data remains in Germany.

  • Hosting 100% in Germany
  • ISO 27001 certified data centre in Düsseldorf
  • Proven operating record since the company was founded in 2001
  • Scalable up to 5,000 simultaneous participants
100 %
Hosted in Germany
Since 2001
Proven operating history
25
years owner-managed
22k+
events each year
Evidence of compliance

Everything your review team needs—in one place.

The standards we follow and the documents you can pass directly to IT, Data Protection and Legal. On request, the complete package is usually available within 24 hours.

Standards and regulatory requirements

BSI

We follow guidance from Germany’s Federal Office for Information Security (BSI). Our data centre is ISO 27001 certified.

GDPR

Designed for GDPR-compliant operations and reviewed repeatedly. We provide a Data Processing Agreement (DPA), including technical and organisational measures and, where required, an addendum under the Digital Operational Resilience Act (DORA).

Designed for organisations regulated by Germany's Federal Financial Supervisory Authority (BaFin)

Designed for use as an external service provider to regulated financial institutions, and used by banks, insurers and asset managers.

Critical Infrastructure

Used in production by critical-infrastructure operators in the energy and telecommunications sectors.

IDD (Insurance Distribution Directive) / Germany's ‘gut beraten’ continuing-education framework for insurance brokers

Complete participation documentation with time stamps, usable for broker training.

Documents that you receive from us

  • Data Processing Agreement (DPA) A standard template ready for legal review and signature.
  • Subprocessor list Complete overview of all sub-processors. No hidden third parties.
  • Technical and organisational measures Documentation of security measures in accordance with Article 32 GDPR.
  • ISO 27001 certificate The current ISO 27001 certificate for our data centre, including its validity date.
  • Digital Operational Resilience Act (DORA) addendum An addendum under the Digital Operational Resilience Act (DORA), relevant to regulated financial organisations.
  • Firewall allowlisting A complete guide to allowlisting CSN in your firewall for consistently reliable events.
  • Records of processing activities Available on request to support your organisation’s GDPR documentation.

After testing several tools for managing, delivering and recording webinars, EWE chose CSN as an integrated platform. It is easy to use, practical for day-to-day work and represented a significant improvement from a data-protection perspective. As Data Protection Officer, I recommend it for external webinars and for internal training that needs to be recorded.

Stefan Marburg Data Protection Officer
Where is the data hosted?
Exclusively on our own servers in an ISO-certified data centre in Düsseldorf. No transfer of data to third countries.
Can regulated financial institutions use CSN as an external service provider?
Yes. Banks, insurers and investment companies use CSN productively and thus meet their supervisory requirements. We provide all the documents you need for outsourcing to an external service provider.
Who has technical access to event data?
Only the group of people designated by the customer and a narrowly limited CSN operations team with documented access. All access is logged and auditable.
How long is participation data stored?
The retention period is configurable. After expiry, data will be automatically deleted.
Does CSN work without software installation?
Yes. Participants only need a current browser. No plugin or app installation, no admin rights on the corporate laptop necessary.
Which ports and URLs need to be allowlisted in the corporate firewall?
HTTPS only (port 443). The technical documentation includes a complete list of CSN domains for allowlisting.

Your next business-critical online event may be only days away.

Will it blend in with every other online meeting—or feel unmistakably yours?