Security

Sub-processors

Every third party that processes customer data on our behalf, what reaches them, and where they run it. This is the whole list.

Where your data lives

The database, authentication and every uploaded document are in the European Union and do not leave it.

One sub-processor runs outside the EU — the model behind AI review — and it can be switched off per workspace, in which case no document or response text is sent to it.

List version 1.0 · Effective 18 September 2026 · We tell Organization Admins before a new sub-processor starts handling customer data.

Current list

Who processes what.

A sub-processor marked optional handles data only when a workspace has that feature switched on.

Supabase

Core service
Purpose
Database, authentication and document storage. The system of record.
Data processed
All workspace data: providers, services, assessments, evidence documents, contracts, risks, the Register, the audit trail, and account credentials.
Processing location
European Union — Frankfurt (eu-central-1).

Vercel

Core service
Purpose
Application hosting. Runs the server that reads and writes the database.
Data processed
Request data in transit, including anything you view or submit. Application logs. No customer records are stored here.
Processing location
European Union — Frankfurt (fra1) for server execution. Static assets are served from a global edge network.

Anthropic

Optional — off unless enabled
Purpose
Model-assisted review: contract clause analysis against Article 30, assessment response review and evidence extraction.
Data processed
Only the text of the document or response being reviewed, at the moment it is reviewed. Nothing is retained by us on their side, and the content is not used to train models.
Processing location
United States.

Resend

Core service
Purpose
Transactional email: sign-in confirmation, password reset, invitations.
Data processed
Recipient email address and the contents of that message. No workspace records.
Processing location
United States.

Model-assisted review

The one that leaves the EU, and how to stop it.

AI review sends the text of the contract, assessment response or evidence document being reviewed to Anthropic, which processes it in the United States. Nothing else is sent: no provider inventory, no risk register, no Register of Information, no account data.

It is off unless a workspace turns it on. With it off, contract and assessment review run a deterministic rule-based pass instead, every finding is labelled as such, and no document or response text leaves the platform. An Organization Admin can switch it on or off at any time in Settings under Data & retention, and the change is written to the audit trail.

Running inference inside the EU is on our roadmap and is listed as Planned on the security page. We will not claim it before it is true.

Changes

How you hear about a change.

Before a new sub-processor begins processing customer data, we notify Organization Admins by email and update this page. The version and effective date at the top change with it.

Questions, or a copy of a sub-processor's DPA: support@relynt.io.