savien Legal
Subprocessor List
List of third-party service providers and subprocessors.
- Document ID
- subprocessors/en
- Version / Updated
- 2026-09-16
- Effective from
- 16 September 2026
- Contact
- privacy@savien.io
- SHA-256
- 5f0a234a65e954f4695e5cd371630e1dda35ee606a2d6e42bc66429fe5b4deb4
Last updated: 2026-09-16
This list names the service providers savien uses to deliver the platform and that may process personal data in doing so. It is an annex to the Data Processing Agreement (DPA) and is maintained under version control.
Roles used in this list
Not every provider named here is a subprocessor within the meaning of Art. 28 GDPR. We distinguish:
- Subprocessor: processes customer data solely on savien's documented instructions.
- Independent controller: determines the purposes and means of certain processing itself; savien cannot instruct that processing.
- Customer-instructed recipient: becomes involved only if the customer sets up the integration themselves.
Supabase
| Attribute | Detail |
|---|---|
| Legal entity | Supabase Pte. Ltd |
| Address | 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 |
| Role | Subprocessor (Art. 28 GDPR) |
| Task | Authentication, PostgreSQL database, file storage, realtime, technical logs |
| Data categories | Account and authentication data, master data, order, shipment and catalogue data, uploaded documents, technical log data |
| Data subject groups | Customer users and staff, contact persons at connected trading partners, invited contact persons |
| Processing location | Production project in region eu-west-1 (Ireland). Administrative access by the legal entity from outside the EEA is possible. |
| Transfer mechanism | EU Standard Contractual Clauses (Decision 2021/914) under the Supabase DPA, supplemented by UK and Swiss addenda |
| Listed since | 2026-05-12 |
Vercel
| Attribute | Detail |
|---|---|
| Legal entity | Vercel Inc., a Delaware corporation, registration number 5857312 |
| Address | 440 N Barranca Ave #4133, Covina, CA 91723, USA |
| Role | Subprocessor (Art. 28 GDPR) |
| Task | Hosting, deployment, serverless and edge execution, domain and DNS, TLS certificates, application logs and — only after consent — Web Analytics and Speed Insights |
| Data categories | IP address, request and header data, technical application logs, application data processed within the request; for analytics additionally the path of an allowlisted public route plus device and performance values |
| Data subject groups | All website visitors and all users of the application |
| Processing location | USA and global edge locations |
| Transfer mechanism | EU Standard Contractual Clauses (Decision 2021/914) under the Vercel DPA, supplemented by the UK IDTA for UK transfers |
| Listed since | 2026-05-12 |
Vercel Analytics and Speed Insights load only after explicit consent and transmit paths of public routes only. Details are set out in the Cookie Policy.
Stripe
| Attribute | Detail |
|---|---|
| Legal entity | Stripe Payments Europe, Limited (SPEL) |
| Contracting country | Ireland |
| Role | Dual role: subprocessor for processing on savien's instructions; independent controller for fraud prevention, anti-money-laundering and other regulatory checks and its own product improvement |
| Task | Checkout, subscription management, payment processing, invoicing, payment status |
| Data categories | Company and billing data, email address, subscription and payment status, payment method data (held directly by Stripe; savien does not receive full payment method data) |
| Data subject groups | Paying organisations and their authorised representatives |
| Processing location | EU and group locations outside the EEA |
| Transfer mechanism | EU Standard Contractual Clauses under the Stripe DPA. Where Stripe acts as an independent controller, Stripe's own privacy policy applies. |
| Listed since | 2026-05-12 |
Where Stripe acts as an independent controller, savien cannot instruct that processing and is not responsible for it.
Resend
| Attribute | Detail |
|---|---|
| Legal entity | Plus Five Five, Inc. (trading as "Resend") |
| Address | 2261 Market Street #5039, San Francisco, CA 94114, USA |
| Role | Subprocessor (Art. 28 GDPR) |
| Task | Delivery of transactional email: invitations, notifications, order confirmations, support and security messages |
| Data categories | Email address, salutation and company details, content of the respective message, delivery and error logs |
| Data subject groups | Customer users and staff, invited contact persons, waiting-list subscribers, senders of contact requests |
| Processing location | USA |
| Transfer mechanism | EU Standard Contractual Clauses (Module 2) under the Resend DPA; Resend additionally declares certification under the EU-U.S. Data Privacy Framework |
| Listed since | 2026-05-12 |
Billbee
| Attribute | Detail |
|---|---|
| Legal entity | Billbee GmbH, Korbach local court, HRB 2482 |
| Address | Arolser Str. 10, 34477 Twistetal, Germany |
| Role | Customer-instructed recipient; involved only after the customer activates the integration |
| Task | Optional ERP integration: synchronisation of articles, stock levels and orders |
| Data categories | Article, stock and order data covered by the integration, plus the credentials stored by the customer |
| Data subject groups | Customer users and staff to the extent they appear in the synchronised data |
| Processing location | Germany |
| Transfer mechanism | No third-country transfer; processing within the EU |
| Listed since | 2026-05-12 |
Without active setup by the customer, no data is transmitted to Billbee. The customer is responsible for the lawfulness of the connection and for the credentials they store.
Changes to this list
We notify customers with an active DPA at least 30 days before a new or replacing subprocessor is used in production. Notice is sent to the administrator address held in the account, and this page is republished with a new "last updated" date.
Customers may object to the change within 30 days of receiving the notice on important data protection grounds. Objections must be sent to privacy@savien.io with reasons. If the objection cannot be resolved by a reasonable alternative, the customer may terminate the affected contract for cause with effect from the date of the change; fees already paid in advance are refunded pro rata for the unused period.
For a necessary short-notice change, DPA section 9 applies: before use within the advance notice period, we obtain the customer's separate express authorisation. Without it, the agreed information and objection procedure remains applicable.