Skip to main content

Privacy and GDPR

Revizo is developed in Norway and operates exclusively within the EU/EEA. We follow the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act. As a supplier to the accounting industry, we understand that strict privacy requirements are not only a legal obligation — they are a prerequisite for trust.


Roles and responsibilities​

Controller and processor​

RoleWhoResponsibility
ControllerYour organisation (the accounting firm)Determines the purposes and means of processing client data
ProcessorSave Solutions AS (Revizo)Processes data on behalf of the controller, in accordance with the agreement

When your organisation uses Revizo to process accounting data, Save Solutions AS acts as processor under GDPR Article 28. We never process personal data for our own purposes beyond what is necessary to deliver the service.

For information we collect directly (e.g. contact details of Revizo users), Save Solutions AS is the controller.


PurposeBasis (GDPR Art. 6)Description
Deliver the serviceArt. 6(1)(b) — ContractNecessary to fulfil the subscription agreement
User administrationArt. 6(1)(b) — ContractAccount administration, login, roles
BillingArt. 6(1)(b) — ContractPayment handling via Stripe
Customer supportArt. 6(1)(b) — ContractAnswering enquiries and resolving problems
Security and abuse preventionArt. 6(1)(f) — Legitimate interestLogging, monitoring, access control
AI-assisted reconciliationArt. 6(1)(b) — ContractAutomatic matching and AI chat as part of the service
Email notificationsArt. 6(1)(b) — ContractOperational messages, status updates, reminders
Product improvementArt. 6(1)(f) — Legitimate interestAggregated and anonymised usage statistics

Your rights​

As a Revizo user you have the following rights under GDPR:

Right of access (Art. 15)​

You can at any time request an overview of the personal data we process about you. Organisation administrators can download all organisation data directly from Settings → Danger zone → Export all data.

Right to rectification (Art. 16)​

You can request that incorrect information be corrected. Profile data can be changed directly in user settings.

Right to erasure (Art. 17)​

You can delete your user account and/or organisation data. We offer three options:

  • Delete user account only — Your account is removed; organisation data is retained for remaining members
  • Delete organisation — All organisation data is deleted after a 30-day grace period
  • Delete everything — Both the organisation and the user account are deleted

See Deleting an organisation and account for detailed guidance.

Right to data portability (Art. 20)​

You can export all organisation data as a ZIP file in machine-readable formats (JSON and CSV). The export includes companies, accounts, clients, transactions, reconciliations, contacts, matching rules, tasks, reports, and the full audit log.

Right to restriction of processing (Art. 18)​

You can request that we restrict processing of your data under certain circumstances, e.g. in a dispute about accuracy.

Right to object (Art. 21)​

You can object to processing based on legitimate interest (Art. 6(1)(f)).

How to exercise your rights​

  • Self-service: Data export and deletion are available directly in Revizo under Settings
  • Email: karl@savesolutions.no
  • Response time: We respond to all enquiries within 30 days

Personal data we process​

User data (Save Solutions AS is the controller)​

CategoryDataPurpose
IdentificationName, email addressUser administration and login
TechnicalIP address, browser type, operating systemSecurity and troubleshooting
UsageLogin time, actions in the systemAudit log and security

Service data (Save Solutions AS is the processor)​

CategoryDataPurpose
Accounting dataTransactions, balances, account numbers, referencesReconciliation and reporting
Contact dataClient names, email, phone, rolesContact management in Revizo
DocumentsUploaded files and attachmentsDocumentation and audit trail

Data Processing Agreement (DPA)​

Organisations that use Revizo to process personal data on behalf of their clients should have a Data Processing Agreement with Save Solutions AS. See our standard Data Processing Agreement (DPA), or contact us at karl@savesolutions.no for a signable version.

The Data Processing Agreement governs:

  • Purpose and scope of the processing
  • Technical and organisational security measures
  • Use of sub-processors (see Sub-processors)
  • Notification in the event of a security breach
  • Assistance with the exercise of data subjects’ rights
  • Deletion and return of data on termination

Data minimisation​

We follow the principle of data minimisation (GDPR Art. 5(1)(c)):

  • We only collect data that is necessary to deliver the service
  • AI features receive only relevant context, not complete datasets
  • Error monitoring (Sentry) filters out personal data before submission
  • Email notifications contain minimal detail — the user must log in for complete information

Transfers to third countries​

All data is stored and processed within the EU/EEA. Some sub-processors (see Sub-processors) may have support functions outside the EU, but data processing takes place in the EU region. Any transfers are secured with EU Standard Contractual Clauses (SCC) in accordance with GDPR Art. 46(2)(c).


Norwegian Data Protection Authority (Datatilsynet)​

If you believe that we process personal data in breach of GDPR, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet):


Last updated: March 2026