Skip to main content

Data Processing Agreement (DPA)

This Data Processing Agreement (the “Agreement”) governs Save Solutions AS’s processing of personal data on behalf of the customer when using Revizo, in accordance with the EU General Data Protection Regulation (GDPR) Article 28 and the Norwegian Personal Data Act.

The Agreement is an addendum to, and an integral part of, the licence agreement (the “Main Agreement”) between the parties. In the event of conflict between the Main Agreement and this Agreement, this Agreement prevails insofar as it concerns the processing of personal data.

How the Agreement is entered into

This Data Processing Agreement is an integral part of the licence agreement between the Customer and Save Solutions AS, and is entered into when the Customer signs the licence agreement. No separate signing of this Agreement is required — it is accepted as part of the licence agreement. The parties are identified in the licence agreement. Contact karl@savesolutions.no with questions, or if the Customer requires a separately signed version (PDF).


1. Parties​

The Agreement is entered into between the parties as identified in the licence agreement:

RoleParty
Controller (the “Customer”)The licensee, as specified in the licence agreement
ProcessorSave Solutions AS

The Customer is the controller and determines the purposes and means of the processing. Save Solutions AS is the processor and processes personal data exclusively on behalf of and according to documented instructions from the Customer.


2. Definitions​

The terms “personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject”, and “personal data breach” have the same meaning as in GDPR Article 4. “the Service” means the Revizo platform delivered by Save Solutions AS.


3. Nature, purpose, and duration of the processing​

MatterDescription
PurposeDeliver Revizo: automatic reconciliation of accounting transactions, task and contact management, reporting, and AI-assisted workflow on behalf of the Customer
Nature of processingCollection, storage, structuring, combination, use, display, and deletion of personal data that forms part of the Customer’s accounting and customer data
DurationProcessing continues for as long as the Main Agreement is in force, plus the subsequent period necessary for deletion or return of data, cf. section 10

Categories of data subjects and personal data are described in Annex A.


4. Controller’s obligations​

The Customer shall:

  1. Ensure that a valid legal basis (GDPR Art. 6) exists for the personal data made available in the Service.
  2. Ensure that instructions to the Processor are in accordance with data protection law.
  3. Safeguard data subjects’ rights, and notify the Norwegian Data Protection Authority (Datatilsynet) and affected data subjects of breaches where required (GDPR Art. 33 and 34).
  4. Not make special categories of personal data (GDPR Art. 9) available in the Service beyond what is necessary for the purpose.

5. Processor’s obligations​

Save Solutions AS shall:

  1. Process according to instructions — only process personal data according to documented instructions from the Customer, including what follows from this Agreement, the Main Agreement, and use of the Service’s functions. If the Processor is legally obliged to process beyond the instructions, the Customer shall be informed before the processing, unless the law prohibits this.
  2. Confidentiality — ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory duty of confidentiality.
  3. Security (Art. 32) — implement appropriate technical and organisational measures to achieve a level of security appropriate to the risk. The measures are described in Annex C.
  4. Sub-processors — only use sub-processors in accordance with section 7.
  5. Assistance with data subjects’ rights — insofar as possible, assist the Customer with appropriate measures so that the Customer can fulfil its obligation to respond to requests to exercise data subjects’ rights (GDPR Art. 15–22). The Service gives the Customer self-service access, export (data portability), and deletion directly in the application.
  6. Assistance with the Customer’s other obligations — assist the Customer in complying with the obligations under GDPR Art. 32–36 (security, breach handling, notification of breaches, and data protection impact assessment), taking into account the nature of the processing and the information available to the Processor.
  7. Notification of breaches — notify the Customer without undue delay after becoming aware of a personal data breach, and provide the Customer with sufficient information so that the Customer can fulfil its notification duty to the Norwegian Data Protection Authority (Datatilsynet) within 72 hours (GDPR Art. 33). See Incident handling for the procedure.
  8. Documentation — make available to the Customer all information necessary to demonstrate that the obligations under GDPR Art. 28 have been fulfilled.

6. Use of sub-processors​

  1. The Customer gives the Processor general prior authorisation to use sub-processors to deliver the Service. Current sub-processors are listed in Annex B and on the Sub-processors page.
  2. The Processor shall impose on every sub-processor the same data protection obligations as follow from this Agreement, through a written agreement.
  3. The Processor shall notify the Customer at least 30 days before a new sub-processor is taken into use, or before the purpose or region for an existing sub-processor is changed. The Customer may within this deadline object on substantiated grounds. In the event of lasting disagreement, the Customer may terminate the Service for the affected processing.
  4. The Processor is fully liable to the Customer for sub-processors fulfilling their obligations.

7. Transfers to third countries​

All primary data processing takes place within the EU/EEA. Certain sub-processors for AI functions (Anthropic and OpenAI) have data centres in the USA. Transfers outside the EU/EEA are secured with the European Commission’s standard contractual clauses (Standard Contractual Clauses, GDPR Art. 46(2)(c)), and are limited to what is necessary for the relevant function. These providers do not use the Customer’s data to train models. See Sub-processors for details.


8. Audit and supervision​

  1. The Processor shall, on the Customer’s written request, make available documentation showing compliance with this Agreement, including relevant security certifications and reports for the Processor and its sub-processors (e.g. SOC 2 reports).
  2. The Customer has the right to carry out an audit, including inspection, of the Processor’s processing. An audit shall be notified in reasonable time, carried out during normal business hours, and in a manner that does not unduly disrupt operations. The parties may agree that an independent third party performs the audit.

9. Deletion and return of data on termination​

  1. On termination of the Main Agreement, the Processor shall, at the Customer’s choice, delete or return all personal data processed on behalf of the Customer, and delete existing copies, unless storage is required under EEA or national law.
  2. The Customer may at any time, and before deletion, export all organisation data in machine-readable formats (JSON and CSV) via Settings → Danger zone → Export all data.
  3. Deletion of an organisation is carried out with a 30-day grace period, with a reminder 7 days before deletion. After the deadline, all database rows and files are deleted permanently (not soft delete) from all storage systems. Only an anonymised deletion receipt is retained as legal documentation. See Data retention and deletion for details.

10. Liability​

The parties’ liability for damage resulting from the processing follows GDPR Article 82 and the liability limitations in the Main Agreement. Liability limitations in the Main Agreement apply correspondingly to this Agreement, insofar as they are compatible with mandatory law.


11. Duration, changes, and governing law​

  1. Duration — The Agreement applies for as long as the Processor processes personal data on behalf of the Customer.
  2. Changes — Changes that are necessary to comply with regulation or changes in the Service may be made by the Processor with reasonable prior notice. Other changes require agreement between the parties.
  3. Governing law and venue — The Agreement is governed by Norwegian law. Disputes shall be sought resolved amicably; if unresolved, the venue is [district court].

12. Acceptance of the Agreement​

This Agreement requires no separate signing. It is entered into and accepted when the Customer signs the licence agreement, of which this Agreement is an integral part. Acceptance of the licence agreement simultaneously constitutes acceptance of this Data Processing Agreement.

If the Customer requires a separate, signed Data Processing Agreement (for example as PDF), this can be arranged by contacting karl@savesolutions.no.


Annex A — Categories of data subjects and personal data​

Categories of data subjects:

  • The Customer’s employees and users of Revizo
  • The Customer’s clients and their contact persons
  • Persons who appear in accounting data the Customer processes (e.g. counterparties in transactions)

Categories of personal data:

CategoryExamples
Identification and contactName, email address, phone number, role
Accounting dataTransactions, balances, account numbers, references, amounts
Usage historyLogin time, actions in the system (audit log)
DocumentsUploaded files and attachments that may contain personal data
AI contextText and summaries sent to AI functions to answer requests

Special categories of personal data (GDPR Art. 9) are not processed as a planned part of the Service.


Annex B — Sub-processors​

The current list is maintained on the Sub-processors page. As of the last update:

ProviderPurposeRegion
Supabase (AWS)Database and file storageEU (Frankfurt)
ClerkAuthentication and user managementEU
VercelApplication hosting and CDNEU
StripePayment handlingEU
AnthropicAI-assisted reconciliation and chatUSA (SCC)
OpenAIEmbeddings for semantic searchUSA (SCC)
ResendEmail sendingEU
SentryError monitoring (PII is filtered out)EU (Frankfurt)
RailwayBackground jobsEU
CloudflareCDN, DDoS protection, document storage (R2)EU

Annex C — Technical and organisational security measures​

The measures are implemented in accordance with GDPR Article 32. See Data processing and storage, Access control, and Security architecture for a fuller description.

AreaMeasure
Encryption in transitTLS 1.2 or newer for all communication; HSTS enabled
Encryption at restAES-256 at database and file-storage level; AES-256-GCM at application level for sensitive secrets (e.g. integration tokens)
Access controlAuthentication via Clerk, role-based access control (RBAC), access on a “need-to-know” basis
Tenant isolationEach organisation has a unique tenant_id; isolation is enforced in the authentication, application, and database layers (Row Level Security)
Data locationAll primary processing within the EU/EEA
Logging and traceabilityAudit log for sensitive actions (deletion, role changes, integration changes, data export)
Monitoring and breach handlingReal-time monitoring (Sentry with PII filtering), rate limiting, established incident procedure under GDPR Art. 33–34
Backup and recoveryDaily encrypted snapshots and point-in-time recovery; RPO max 1 hour, RTO max 4 hours
Input validationValidation of all external data (Zod), MIME and size validation on file upload

Last updated: 21 September 2026