NIS2 checkContact

European delivery

Your contacts in Amsterdam, delivery in Bulgaria

Think Smart Europe is a Dutch company with an engineering organisation in Bulgaria. Client contact, the CISO service and contractual accountability sit in Amsterdam. Engineering, the service desk and 24-hour monitoring are carried out from Sofia, Varna and Stara Zagora. All our own locations are inside the European Union. You enter into one agreement with Think Smart Europe B.V. under Dutch law.

The model

A Dutch company with European engineering

A managed service consists of client-facing work and technical delivery.

From Amsterdam we provide the named CISO, the meetings with your board and management, site surveys, workshops, audit support, contract arrangements and escalations.

From Bulgaria we provide engineering, implementation, day-to-day platform operations, the service desk and 24-hour monitoring.

This work falls under one agreement, one SLA and one escalation path. Think Smart Europe remains accountable for the agreed service, whichever location a particular task is carried out from.

AmsterdamHead office and the client-facing team. Your named CISO, board sessions, site surveys, workshops, audit support and the contract itself.
Sofia, Varna and Stara ZagoraEngineering, implementation, the service desk and round-the-clock monitoring. Capacity that scales with volume instead of with a hiring round.
One point of accountabilityOne legal entity, one SLA, one escalation path. Which centre a pair of hands sits in is our problem to organise, not yours to manage.

Who does what, and where

Who does what, per service

Where each part of the service is carried out. Where the work happens is one of the first things procurement asks.

Think Smart Europe delivery locations by capability
CapabilityDelivered fromWhy there
Named CISO, board reporting and audit supportAmsterdamThis work requires knowledge of your organisation and regular contact with your board and management.
Site surveys, workshops and onsite incident coordinationAmsterdam and your own locationsThis work sometimes requires physical presence.
Contract, invoicing, escalation and accountabilityAmsterdamYou contract with Think Smart Europe B.V. under Dutch law.
Service deskSofiaThe service desk handles day-to-day questions and faults within the agreed hours and languages.
Engineering, implementation and platform operationsSofia, Varna and Stara ZagoraThis is where the engineering teams that implement and manage the solutions work.
Monitoring, assessment and responseBulgariaThe SOC provides the agreed monitoring and incident response.
Client data, telemetry, log files and backupsRegions inside the European UnionThe regions used are recorded in the service description.
Reporting and evidenceAssembled in Bulgaria and discussed from AmsterdamThe data comes out of the management systems. Your named contact discusses the results with you.

Varna and Stara Zagora also provide separation from Sofia. That matters for continuity rather than for cost.

Sovereignty

Four questions you will ask

Four practical questions about data and access, as they appear in a tender document or a DPIA. Each has a factual answer.

Where the data sits

Log data, telemetry, case records and backups that we process as part of the service are stored in regions inside the European Union. The specific regions are named in the service description.

Who can reach it

Administrative access is granted to named staff registered inside the European Union. Rights are limited to what the work requires and are withdrawn when they are no longer needed. Where support by a platform vendor may require access to your environment, we record this in advance.

Which law the contract sits under

You contract with Think Smart Europe B.V. in Amsterdam. Dutch law applies to the agreement. The Bulgarian locations are delivery locations, not separate contracting parties.

Which GDPR documentation is needed

For our own delivery there is no transfer to a country outside the European Union. For that part, no adequacy decision, standard contractual clauses or separate transfer impact assessment is required.

If you use platform vendors that themselves process or hold access outside the European Union, that remains a separate point of attention. We include those vendors and data flows in the documentation. The commitment here is about our own delivery, because that is the part we determine.

Nearshore versus offshore

Nearshore, not offshore

Delivery from a country outside the European Union requires additional arrangements for international data transfers, and larger time differences can affect consultation and escalation. An offshore model can suit work that runs largely independently and outside Dutch working hours.

Delivery from outside the EU
  • A third-country transfer, so an adequacy decision or standard contractual clauses, plus a transfer impact assessment to keep current
  • Local data protection law alongside the GDPR, with the gap between the two to assess and document
  • A real cost advantage, and time zones far enough apart that work can be handed over at the end of a day
  • Six to twelve hours of difference, so most escalations happen in writing and are answered while you sleep
  • A flight of eight hours or more on the days when something needs a person in the room

For batch work that runs overnight and rarely needs a conversation, this is often the sensible arrangement.

Delivery from Bulgaria
  • Inside the European Union since 2007, so no third-country transfer and no transfer mechanism to maintain
  • One regulation, the GDPR itself, with one set of rights and one supervisory structure
  • One hour of time difference, so the Dutch and Bulgarian working days overlap almost entirely
  • An escalation is a call during your own afternoon, with your Amsterdam CISO on the same call
  • Under three hours of flying time, and people do travel in both directions

Engineering hours are cheaper than in Amsterdam. That is part of the arrangement.

The practical detail

What you will want to know before you sign anything

The practical arrangements we make in an intake call, in writing, so you can check them against the contract.

How the service works day to day
What you want to knowHow it works
Who is my point of contact?You get a named CISO in Amsterdam for strategy, reporting and escalation, with a named deputy. On the Managed CISO retainer that is two blocks of eight hours a month. Day-to-day user requests go to the service desk.
Which language is used?Client meetings, reports, board sessions and incident calls can be in Dutch or English. The service desk and the monitoring team work in English as standard. Dutch-language service desk support can be agreed separately, so raise it during scoping rather than after signature.
Which service hours apply?The service desk works during the agreed Dutch business hours. Monitoring is available 24 hours a day at SmartCyber Advanced and above. Dutch and Bulgarian public holidays fall on different dates, so the rota is planned against both calendars.
How does escalation run?An alert goes from the analyst to the duty engineer and then, when the severity warrants it, to your named CISO. Highest-priority alerts carry an agreed 15-minute response time, set in the SLA rather than a measured average.
Who owns an incident?Think Smart Europe, whichever centre the work happens in. If you are in scope for NIS2 we draft the 24-hour early warning and the 72-hour notification with you, because that clock runs while you are still containing the damage.
Can we visit the locations?Yes, in Amsterdam and in Sofia. A visit is scheduled in advance and access and privacy arrangements apply, because it is a working operations floor with other clients' data on the screens.
What happens on termination?Export formats, the handover period, the retention periods and evidence of deletion are recorded in the service description before you start, rather than negotiated once you have decided to go.

Where an answer above depends on the SmartCyber level you have chosen, the recorded service description decides it. The intake call is where that gets settled.

The offices

Where we are

Amsterdam is the head office and the base for the client-facing work. Sofia is the largest delivery center. Varna and Stara Zagora add engineering capacity and geographic separation. Addresses and direct numbers are below, and a visit to any of them can be arranged.

Amsterdam Head office

Vijzelstraat 68, 1017 HL, Amsterdam, Netherlands
+31 (0)20 210 1552 · info@thinksmart.eu

Sofia Delivery centre

Mladost 1A, 9 "Anna Ahmatova" str., 1729, Sofia, Bulgaria
0700 12 999 · office@thinksmart.bg

Varna Delivery centre

9 Radost str., Varna, Bulgaria

Stara Zagora Delivery centre

151 M. T. Kavaldzhiev str., Stara Zagora, Bulgaria

Frequently asked

Frequently asked questions

Think Smart Europe is new. Why would we hand it our estate?

Because the Dutch entity is the new part, and the engineering organisation behind it is not.

The engineering organisation it delivers with was registered in Sofia on 19 December 2019 and has been running managed IT and security operations since. The certified management systems, the vendor partnerships and the engineering depth sit there.

Ask us for the register entry, the certificate scope and references for the delivery organisation.

Which certifications apply to the service?

The service falls under the certified management systems of our parent organisation: ISO 27001 for information security, ISO 27701 for privacy, ISO 9001 for quality and ISO/IEC 20000-1 for IT service management. Think Smart Europe B.V. is not separately certified at this time.

On request you receive, per certificate, the certificate number, the standard version, the certified legal entity, the exact scope, the period of validity and the certification body. We supply these in writing and in any tender response, rather than as a logo on a website.

Can our current Dutch IT supplier stay involved?

Yes. Security monitoring, compliance advice and board reporting can be set up on top of the existing service without replacing it.

It does have to be clear in advance who is accountable for work and evidence that falls between the contracts. The conversation that matters is about who produces the evidence when a regulator or a customer asks for it.

Which processing countries do we name to procurement?

For our own service you name the Netherlands and Bulgaria. Both are European Union member states. The processing documentation also records the relevant roles, locations and any subprocessors.

Where a platform vendor you have chosen processes outside the European Union, that party is listed separately, because a list that is quietly incomplete is worse for you than a list that is inconvenient.

Is onsite work included?

Scheduled CISO days, agreed visits and attendance during a serious incident fall within the agreed service. Extensive surveys across multiple sites and travel outside the Netherlands are quoted separately.

What is included is written into your service description.

Your data stays in the EU

One call with our CISO covers the delivery model, the processing locations and what your procurement team will need in writing.

Cyber Incident