savien Legal
Subprocessor List
List of third-party service providers and subprocessors.
Last updated: 2026-05-12
This list describes providers that may process personal data for savien. Optional services are used only where actually enabled or required for the relevant customer.
| Provider | Purpose | Data categories | Location / possible processing | Transfer basis / notes |
|---|---|---|---|---|
| Supabase | Auth, database, storage, realtime, logs where applicable | Account, auth, platform, document and log data | EU/USA depending on project region and provider structure | Review DPA, document project region, SCC/DPF where required |
| Vercel | Hosting, deployment, serverless/edge, logs, Web Analytics, Speed Insights | IP address, request data, technical logs, app data when processed, performance/usage data | USA/EU/global | Review DPA, SCC/DPF where required; document Analytics/Speed Insights separately |
| Stripe | Checkout, subscription billing, invoices, payment management | Billing data, payment status, customer data | USA/EU/global | Stripe may partly act as independent controller; review privacy terms and DPA |
| Resend | Transactional email delivery | Email address, name/company, email content, delivery logs | USA/EU/global | Review DPA, SCC/DPF where required |
| BillBee | Optional ERP integration | BillBee credentials, SKU, item, stock and possibly order data | Germany/EU depending on BillBee structure | Only when activated by customer; review contract/DPA position |
| Vercel (Domain/DNS) | Domain, DNS, certificates | Technical domain and log data | USA/EU | Review DPA; TLS certificates via Vercel |
| Email support (Resend) | Customer support | Email address, support content, delivery logs | USA/EU | DPA reviewed; already listed above |
Changes
Customers are informed about new or replaced subprocessors in accordance with the DPA. Prior notice with a reasonable objection period is intended. For short-term security, legal or operationally necessary changes, notice may be provided afterwards or with a shorter period.
An objection must be based on an important data protection reason. If the objection cannot be resolved through reasonable alternatives, either party may terminate the affected service or contract in accordance with the DPA.
Optional Integrations Not Activated
Optional integrations such as BillBee are used only if the customer actively configures them. Without activation, no transfer to the respective integration provider takes place.
Go-Live Duties
Before publication, at least the following must be finalised:
- Supabase project region and DPA.
- Vercel contract/DPA status, logging, Analytics and Speed Insights.
- Stripe responsibility role and DPA/privacy terms.
- Resend DPA and transfer mechanism.
- BillBee role when integration is activated.
- Actual DNS, support, consent and monitoring providers.