Sub-processors
In accordance with GDPR Article 28, Save Solutions AS is obliged to inform about which sub-processors are used to deliver the Revizo service. This page provides a complete overview.
Sub-processors that process personal data must have a DPA before they are used
in production. Agreement status per provider is in the repository’s
docs/SECURITY_CLAIMS_REGISTER.md — do not assume “yes” unless the agreement is in
the archive. Storage location and processing location are not the same; AI calls and R2 are
examples of unconfirmed or non-EEA processing.
Overview of sub-processors
| Provider | Purpose | Data processed | Region | Compliance |
|---|---|---|---|---|
| Supabase (AWS) | Database and file storage | All application data, files, and attachments | EU (Frankfurt) | SOC 2 Type II, GDPR, HIPAA |
| Clerk | Authentication and user management | User identity (name, email), session data | EU | SOC 2 Type II, GDPR |
| Vercel | Application hosting and CDN | Application code, request logs (without PII) | EU (Edge) | SOC 2 Type II, GDPR |
| Stripe | Payment handling | Invoice information, subscription data | EU | PCI DSS Level 1, SOC 2, GDPR |
| Anthropic | AI-assisted reconciliation and chat | Context data for AI requests (see details below) | USA* | SOC 2 Type II |
| OpenAI | Vector database and search (embeddings) | Text fragments for semantic search | USA* | SOC 2 Type II |
| Resend | Email sending | Email addresses, message content (status notifications) | EU | GDPR |
| Sentry | Error monitoring | Error information, anonymised usage context | EU (Frankfurt) | SOC 2 Type II, GDPR |
| Railway | Background jobs | Job data (matching, report generation) | EU | GDPR |
| Cloudflare | CDN, DDoS protection, document storage (R2) | Requests (metadata), stored documents | R2 region: auto — EU binding not confirmed in code | SOC 2 Type II, ISO 27001, GDPR |
| Upstash | Rate-limit counters | User/IP keys, not the customer database | Unconfirmed | — |
* Anthropic and OpenAI have data centres in the USA. Data sent to these services is limited to what is necessary for the AI function (see below). Both providers have committed not to use customer data for model training.
Details of AI data processing
Anthropic (Claude)
Used for the AI chat function in Revizo. Data sent:
- The user’s question/message
- Relevant context to answer the question (e.g. client name, transaction summary)
- No complete datasets are sent — only what is necessary to generate a response
Important: Anthropic does not use customer data to train its models. Data is processed under Anthropic’s terms for commercial use.
OpenAI
Used to generate vector representations (embeddings) for semantic search in the knowledge base. Only short text fragments are sent for vectorisation.
Important: OpenAI does not use data sent via API for model training.
Accounting system integrations
The following integrations involve data transfer with the customer’s accounting system. These process data on behalf of the customer (controller), not Save Solutions AS:
| Integration | Data flow | Description |
|---|---|---|
| Tripletex | Bidirectional | Synchronisation of transactions, accounts, and balances |
| Visma eAccounting (NXT) | Bidirectional | Synchronisation of transactions and accounts |
API tokens for these systems are stored encrypted (AES-256-GCM) in the database and are decrypted only in memory when used.
Notification of changes
We notify affected customers at least 30 days before we:
- Add new sub-processors
- Change the purpose of an existing sub-processor’s processing
- Move data processing to a new region
Notification is sent by email to the organisation’s administrators.
Questions
If you have questions about our sub-processors or want copies of Data Processing Agreements, contact us at karl@savesolutions.no.
Last updated: March 2026