Privacy and GDPR
Revizo is developed in Norway and operates exclusively within the EU/EEA. We follow the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act. As a supplier to the accounting industry, we understand that strict privacy requirements are not only a legal obligation — they are a prerequisite for trust.
Roles and responsibilities
Controller and processor
| Role | Who | Responsibility |
|---|---|---|
| Controller | Your organisation (the accounting firm) | Determines the purposes and means of processing client data |
| Processor | Save Solutions AS (Revizo) | Processes data on behalf of the controller, in accordance with the agreement |
When your organisation uses Revizo to process accounting data, Save Solutions AS acts as processor under GDPR Article 28. We never process personal data for our own purposes beyond what is necessary to deliver the service.
For information we collect directly (e.g. contact details of Revizo users), Save Solutions AS is the controller.
Legal basis
| Purpose | Basis (GDPR Art. 6) | Description |
|---|---|---|
| Deliver the service | Art. 6(1)(b) — Contract | Necessary to fulfil the subscription agreement |
| User administration | Art. 6(1)(b) — Contract | Account administration, login, roles |
| Billing | Art. 6(1)(b) — Contract | Payment handling via Stripe |
| Customer support | Art. 6(1)(b) — Contract | Answering enquiries and resolving problems |
| Security and abuse prevention | Art. 6(1)(f) — Legitimate interest | Logging, monitoring, access control |
| AI-assisted reconciliation | Art. 6(1)(b) — Contract | Automatic matching and AI chat as part of the service |
| Email notifications | Art. 6(1)(b) — Contract | Operational messages, status updates, reminders |
| Product improvement | Art. 6(1)(f) — Legitimate interest | Aggregated and anonymised usage statistics |
Your rights
As a Revizo user you have the following rights under GDPR:
Right of access (Art. 15)
You can at any time request an overview of the personal data we process about you. Organisation administrators can download all organisation data directly from Settings → Danger zone → Export all data.
Right to rectification (Art. 16)
You can request that incorrect information be corrected. Profile data can be changed directly in user settings.
Right to erasure (Art. 17)
You can delete your user account and/or organisation data. We offer three options:
- Delete user account only — Your account is removed; organisation data is retained for remaining members
- Delete organisation — All organisation data is deleted after a 30-day grace period
- Delete everything — Both the organisation and the user account are deleted
See Deleting an organisation and account for detailed guidance.
Right to data portability (Art. 20)
You can export all organisation data as a ZIP file in machine-readable formats (JSON and CSV). The export includes companies, accounts, clients, transactions, reconciliations, contacts, matching rules, tasks, reports, and the full audit log.
Right to restriction of processing (Art. 18)
You can request that we restrict processing of your data under certain circumstances, e.g. in a dispute about accuracy.
Right to object (Art. 21)
You can object to processing based on legitimate interest (Art. 6(1)(f)).
How to exercise your rights
- Self-service: Data export and deletion are available directly in Revizo under Settings
- Email: karl@savesolutions.no
- Response time: We respond to all enquiries within 30 days
Personal data we process
User data (Save Solutions AS is the controller)
| Category | Data | Purpose |
|---|---|---|
| Identification | Name, email address | User administration and login |
| Technical | IP address, browser type, operating system | Security and troubleshooting |
| Usage | Login time, actions in the system | Audit log and security |
Service data (Save Solutions AS is the processor)
| Category | Data | Purpose |
|---|---|---|
| Accounting data | Transactions, balances, account numbers, references | Reconciliation and reporting |
| Contact data | Client names, email, phone, roles | Contact management in Revizo |
| Documents | Uploaded files and attachments | Documentation and audit trail |
Data Processing Agreement (DPA)
Organisations that use Revizo to process personal data on behalf of their clients should have a Data Processing Agreement with Save Solutions AS. See our standard Data Processing Agreement (DPA), or contact us at karl@savesolutions.no for a signable version.
The Data Processing Agreement governs:
- Purpose and scope of the processing
- Technical and organisational security measures
- Use of sub-processors (see Sub-processors)
- Notification in the event of a security breach
- Assistance with the exercise of data subjects’ rights
- Deletion and return of data on termination
Data minimisation
We follow the principle of data minimisation (GDPR Art. 5(1)(c)):
- We only collect data that is necessary to deliver the service
- AI features receive only relevant context, not complete datasets
- Error monitoring (Sentry) filters out personal data before submission
- Email notifications contain minimal detail — the user must log in for complete information
Transfers to third countries
All data is stored and processed within the EU/EEA. Some sub-processors (see Sub-processors) may have support functions outside the EU, but data processing takes place in the EU region. Any transfers are secured with EU Standard Contractual Clauses (SCC) in accordance with GDPR Art. 46(2)(c).
Norwegian Data Protection Authority (Datatilsynet)
If you believe that we process personal data in breach of GDPR, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet):
- Website: datatilsynet.no
- Email: postkasse@datatilsynet.no
- Phone: 22 39 69 00
Last updated: March 2026