Hoppa till huvudinnehållet

Juridisk text på engelska

Vi har ännu inte en certifierad översättning av den juridiska texten på ditt språk. Den engelska och tyska versionen är juridiskt bindande. Om du behöver en certifierad svensk version, kontakta oss.

Subprocessors

Last updated: 2026-08-27

We engage the following processors under Art. 28 GDPR / Art. 9 revFADP. All have signed Data Processing Agreements (DPAs) in place. Material changes (new processor added, processor removed) are notified via email and an in-app banner with 30 days advance notice.

Supabase

Purpose
Database, Auth, Storage
Region
EU (Frankfurt) + US Backups
Transfer basis
EU + US (DPF + SCC)
DPA →

Stripe Payments Europe Ltd. / Stripe, Inc.

Purpose
Payment processing, invoicing, tax determination
Region
EU (IE) + US
Transfer basis
EU + US (DPF)
DPA →

Vercel Inc.

Purpose
Web dashboard hosting, static content delivery
Region
Global Edge
Transfer basis
Global (DPF)
DPA →

Resend

Purpose
Transactional email delivery (login links, invitations)
Region
US
Transfer basis
US (DPF)
DPA →

Google Cloud (Gemini API)

Purpose
AI model provider for solver functions
Region
Global
Transfer basis
Global (DPF + SCC)
DPA →

Anthropic PBC (Claude API)

Purpose
AI model provider for verification (Second-Opinion)
Region
US
Transfer basis
US (DPF)
DPA →

Functional Software, Inc. (Sentry)

Purpose
Error tracking + performance monitoring
Region
US
Transfer basis
US (DPF)
DPA →

Cloudflare, Inc.

Purpose
CDN, DDoS protection, DNS
Region
Global Edge
Transfer basis
Global (DPF + SCC)
DPA →

Transfer mechanisms

For transfers to processors based in the United States we rely on the following safeguards:

  • EU-US Data Privacy Framework (DPF) the relevant processor is certified under the DPF program.
  • Standard Contractual Clauses (SCC, Module 2) Controller-to-Processor clauses per EU Commission Decision 2021/914.
  • Swiss-US DPF / UK Extension for transfers from Switzerland and the United Kingdom respectively.

Right to object

You may object to a new subprocessor within 30 days of notification. Where the objection cannot be reasonably accommodated, you may terminate your subscription with prorated refund.

Verification

Each processor's DPA contains audit/inspection rights pursuant to Art. 28(3)(h) GDPR. We monitor processor compliance through annual SOC 2 / ISO 27001 reports where available.