Security

Sub-processors

Every third party that processes customer data on our behalf, what reaches them, and where they run it. This is the whole list.

Where your data lives

The database, authentication and every uploaded document are in the European Union and do not leave it.

One sub-processor runs outside the EU: the model behind AI review. It can be switched off per workspace, in which case no document or response text is sent to it.

Error reporting and email are the only other third parties, and neither receives the contents of your workspace.

List version 1.1 · Effective 21 September 2026 · We tell Organization Admins before a new sub-processor starts handling customer data.

Current list

Who processes what.

A sub-processor marked optional handles data only when a workspace has that feature switched on.

Supabase

Core service
Purpose
Database, authentication and document storage. The system of record.
Data processed
All workspace data: providers, services, assessments, evidence documents, contracts, risks, the Register, the audit trail, and account credentials.
Processing location
European Union. Frankfurt (eu-central-1).

Vercel

Core service
Purpose
Application hosting. Runs the server that reads and writes the database.
Data processed
Request data in transit, including anything you view or submit. Application logs. No customer records are stored here.
Processing location
European Union. Frankfurt (fra1) for server execution. Static assets are served from a global edge network.

Anthropic

Optional, off unless enabled
Purpose
Model-assisted review: contract clause analysis against Article 30, assessment response review and evidence extraction.
Data processed
Only the text of the document or response being reviewed, at the moment it is reviewed. Nothing is retained by us on their side, and the content is not used to train models.
Processing location
United States.

Sentry

Core service
Purpose
Error reporting. Tells us when something in the application fails, with the stack trace needed to fix it.
Data processed
The error message, the stack trace, the URL path and the account identifier of whoever hit it. Never cookies, request bodies, form contents or session recordings.
Processing location
European Union, Frankfurt (Sentry EU region).

PostHog

Core service
Purpose
Audience measurement on the public pages, so we can tell which of them are read. The application is not measured.
Data processed
The path of a public page and, where a visit came from an advertisement, the campaign parameters in the link. No cookie is set, no identifier is stored on the device, the IP address is not retained and nothing is carried to another site.
Processing location
European Union (PostHog EU Cloud, Frankfurt).

Google

Optional, off unless enabled
Purpose
Advertising measurement, and only where a visitor has agreed to it. Records that a visit which began with an advertisement reached something worth reaching.
Data processed
That a click on an advertisement led to a page on this site, with the identifier Google puts in the link. Nothing is sent unless the visitor has agreed, and a refusal means the tag is never loaded.
Processing location
United States.

Resend

Core service
Purpose
Transactional email: sign-in confirmation, password reset, invitations.
Data processed
Recipient email address and the contents of that message. No workspace records.
Processing location
United States.

Model-assisted review

The one that leaves the EU, and how to stop it.

AI review sends the text of the contract, assessment response or evidence document being reviewed to Anthropic, which processes it in the United States. Nothing else is sent: no provider inventory, no risk register, no Register of Information, no account data.

It is off unless a workspace turns it on. With it off, contract and assessment review run a deterministic rule-based pass instead, every finding is labelled as such, and no document or response text leaves the platform. An Organization Admin can switch it on or off at any time in Settings under Data & retention, and the change is written to the audit trail.

Running inference inside the EU is something we will offer when we can state it as a fact rather than an intention. Ask us where it stands, support@relynt.io.

Changes

How you hear about a change.

Before a new sub-processor begins processing customer data, we notify Organization Admins by email and update this page. The version and effective date at the top change with it.

Questions, or a copy of a sub-processor's DPA: support@relynt.io.

Sub-processors | Relynt