Data Processing Agreement (DPA)
This Data Processing Agreement (the “Agreement”) governs Save Solutions AS’s processing of personal data on behalf of the customer when using Revizo, in accordance with the EU General Data Protection Regulation (GDPR) Article 28 and the Norwegian Personal Data Act.
The Agreement is an addendum to, and an integral part of, the licence agreement (the “Main Agreement”) between the parties. In the event of conflict between the Main Agreement and this Agreement, this Agreement prevails insofar as it concerns the processing of personal data.
This Data Processing Agreement is an integral part of the licence agreement between the Customer and Save Solutions AS, and is entered into when the Customer signs the licence agreement. No separate signing of this Agreement is required — it is accepted as part of the licence agreement. The parties are identified in the licence agreement. Contact karl@savesolutions.no with questions, or if the Customer requires a separately signed version (PDF).
1. Parties
The Agreement is entered into between the parties as identified in the licence agreement:
| Role | Party |
|---|---|
| Controller (the “Customer”) | The licensee, as specified in the licence agreement |
| Processor | Save Solutions AS |
The Customer is the controller and determines the purposes and means of the processing. Save Solutions AS is the processor and processes personal data exclusively on behalf of and according to documented instructions from the Customer.
2. Definitions
The terms “personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject”, and “personal data breach” have the same meaning as in GDPR Article 4. “the Service” means the Revizo platform delivered by Save Solutions AS.
3. Nature, purpose, and duration of the processing
| Matter | Description |
|---|---|
| Purpose | Deliver Revizo: automatic reconciliation of accounting transactions, task and contact management, reporting, and AI-assisted workflow on behalf of the Customer |
| Nature of processing | Collection, storage, structuring, combination, use, display, and deletion of personal data that forms part of the Customer’s accounting and customer data |
| Duration | Processing continues for as long as the Main Agreement is in force, plus the subsequent period necessary for deletion or return of data, cf. section 10 |
Categories of data subjects and personal data are described in Annex A.
4. Controller’s obligations
The Customer shall:
- Ensure that a valid legal basis (GDPR Art. 6) exists for the personal data made available in the Service.
- Ensure that instructions to the Processor are in accordance with data protection law.
- Safeguard data subjects’ rights, and notify the Norwegian Data Protection Authority (Datatilsynet) and affected data subjects of breaches where required (GDPR Art. 33 and 34).
- Not make special categories of personal data (GDPR Art. 9) available in the Service beyond what is necessary for the purpose.
5. Processor’s obligations
Save Solutions AS shall:
- Process according to instructions — only process personal data according to documented instructions from the Customer, including what follows from this Agreement, the Main Agreement, and use of the Service’s functions. If the Processor is legally obliged to process beyond the instructions, the Customer shall be informed before the processing, unless the law prohibits this.
- Confidentiality — ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory duty of confidentiality.
- Security (Art. 32) — implement appropriate technical and organisational measures to achieve a level of security appropriate to the risk. The measures are described in Annex C.
- Sub-processors — only use sub-processors in accordance with section 7.
- Assistance with data subjects’ rights — insofar as possible, assist the Customer with appropriate measures so that the Customer can fulfil its obligation to respond to requests to exercise data subjects’ rights (GDPR Art. 15–22). The Service gives the Customer self-service access, export (data portability), and deletion directly in the application.
- Assistance with the Customer’s other obligations — assist the Customer in complying with the obligations under GDPR Art. 32–36 (security, breach handling, notification of breaches, and data protection impact assessment), taking into account the nature of the processing and the information available to the Processor.
- Notification of breaches — notify the Customer without undue delay after becoming aware of a personal data breach, and provide the Customer with sufficient information so that the Customer can fulfil its notification duty to the Norwegian Data Protection Authority (Datatilsynet) within 72 hours (GDPR Art. 33). See Incident handling for the procedure.
- Documentation — make available to the Customer all information necessary to demonstrate that the obligations under GDPR Art. 28 have been fulfilled.
6. Use of sub-processors
- The Customer gives the Processor general prior authorisation to use sub-processors to deliver the Service. Current sub-processors are listed in Annex B and on the Sub-processors page.
- The Processor shall impose on every sub-processor the same data protection obligations as follow from this Agreement, through a written agreement.
- The Processor shall notify the Customer at least 30 days before a new sub-processor is taken into use, or before the purpose or region for an existing sub-processor is changed. The Customer may within this deadline object on substantiated grounds. In the event of lasting disagreement, the Customer may terminate the Service for the affected processing.
- The Processor is fully liable to the Customer for sub-processors fulfilling their obligations.
7. Transfers to third countries
All primary data processing takes place within the EU/EEA. Certain sub-processors for AI functions (Anthropic and OpenAI) have data centres in the USA. Transfers outside the EU/EEA are secured with the European Commission’s standard contractual clauses (Standard Contractual Clauses, GDPR Art. 46(2)(c)), and are limited to what is necessary for the relevant function. These providers do not use the Customer’s data to train models. See Sub-processors for details.
8. Audit and supervision
- The Processor shall, on the Customer’s written request, make available documentation showing compliance with this Agreement, including relevant security certifications and reports for the Processor and its sub-processors (e.g. SOC 2 reports).
- The Customer has the right to carry out an audit, including inspection, of the Processor’s processing. An audit shall be notified in reasonable time, carried out during normal business hours, and in a manner that does not unduly disrupt operations. The parties may agree that an independent third party performs the audit.
9. Deletion and return of data on termination
- On termination of the Main Agreement, the Processor shall, at the Customer’s choice, delete or return all personal data processed on behalf of the Customer, and delete existing copies, unless storage is required under EEA or national law.
- The Customer may at any time, and before deletion, export all organisation data in machine-readable formats (JSON and CSV) via Settings → Danger zone → Export all data.
- Deletion of an organisation is carried out with a 30-day grace period, with a reminder 7 days before deletion. After the deadline, all database rows and files are deleted permanently (not soft delete) from all storage systems. Only an anonymised deletion receipt is retained as legal documentation. See Data retention and deletion for details.
10. Liability
The parties’ liability for damage resulting from the processing follows GDPR Article 82 and the liability limitations in the Main Agreement. Liability limitations in the Main Agreement apply correspondingly to this Agreement, insofar as they are compatible with mandatory law.
11. Duration, changes, and governing law
- Duration — The Agreement applies for as long as the Processor processes personal data on behalf of the Customer.
- Changes — Changes that are necessary to comply with regulation or changes in the Service may be made by the Processor with reasonable prior notice. Other changes require agreement between the parties.
- Governing law and venue — The Agreement is governed by Norwegian law. Disputes shall be sought resolved amicably; if unresolved, the venue is [district court].
12. Acceptance of the Agreement
This Agreement requires no separate signing. It is entered into and accepted when the Customer signs the licence agreement, of which this Agreement is an integral part. Acceptance of the licence agreement simultaneously constitutes acceptance of this Data Processing Agreement.
If the Customer requires a separate, signed Data Processing Agreement (for example as PDF), this can be arranged by contacting karl@savesolutions.no.
Annex A — Categories of data subjects and personal data
Categories of data subjects:
- The Customer’s employees and users of Revizo
- The Customer’s clients and their contact persons
- Persons who appear in accounting data the Customer processes (e.g. counterparties in transactions)
Categories of personal data:
| Category | Examples |
|---|---|
| Identification and contact | Name, email address, phone number, role |
| Accounting data | Transactions, balances, account numbers, references, amounts |
| Usage history | Login time, actions in the system (audit log) |
| Documents | Uploaded files and attachments that may contain personal data |
| AI context | Text and summaries sent to AI functions to answer requests |
Special categories of personal data (GDPR Art. 9) are not processed as a planned part of the Service.
Annex B — Sub-processors
The current list is maintained on the Sub-processors page. As of the last update:
| Provider | Purpose | Region |
|---|---|---|
| Supabase (AWS) | Database and file storage | EU (Frankfurt) |
| Clerk | Authentication and user management | EU |
| Vercel | Application hosting and CDN | EU |
| Stripe | Payment handling | EU |
| Anthropic | AI-assisted reconciliation and chat | USA (SCC) |
| OpenAI | Embeddings for semantic search | USA (SCC) |
| Resend | Email sending | EU |
| Sentry | Error monitoring (PII is filtered out) | EU (Frankfurt) |
| Railway | Background jobs | EU |
| Cloudflare | CDN, DDoS protection, document storage (R2) | EU |
Annex C — Technical and organisational security measures
The measures are implemented in accordance with GDPR Article 32. See Data processing and storage, Access control, and Security architecture for a fuller description.
| Area | Measure |
|---|---|
| Encryption in transit | TLS 1.2 or newer for all communication; HSTS enabled |
| Encryption at rest | AES-256 at database and file-storage level; AES-256-GCM at application level for sensitive secrets (e.g. integration tokens) |
| Access control | Authentication via Clerk, role-based access control (RBAC), access on a “need-to-know” basis |
| Tenant isolation | Each organisation has a unique tenant_id; isolation is enforced in the authentication, application, and database layers (Row Level Security) |
| Data location | All primary processing within the EU/EEA |
| Logging and traceability | Audit log for sensitive actions (deletion, role changes, integration changes, data export) |
| Monitoring and breach handling | Real-time monitoring (Sentry with PII filtering), rate limiting, established incident procedure under GDPR Art. 33–34 |
| Backup and recovery | Daily encrypted snapshots and point-in-time recovery; RPO max 1 hour, RTO max 4 hours |
| Input validation | Validation of all external data (Zod), MIME and size validation on file upload |
Last updated: 21 September 2026