Trust bij Renewly

Waar uw gegevens zich bevinden en wie ze aanraakt

Renewly is een dual-region dienst. U kiest uw regio bij registratie en uw contracten, accountgegevens en auditlogs blijven in die regio gedurende de hele levensduur van de workspace. Deze pagina is de canonieke kaart van de subverwerkers die uw gegevens verwerken. Geen enkele extractiefase kruist de regiogrens.

Dataresidentie

EU of VS, vastgelegd bij registratie, onveranderbaar vanuit de UI

European Union

eu-central-1
  • Opslag: Supabase eu-central-1 (AWS Frankfurt)
  • Primaire extractie: Google Vertex in the EU region

Your contracts and account data are stored in the EU on Supabase eu-central-1 (AWS Frankfurt). Contract data extraction runs in the EU region via Google Vertex.

United States

us-east-1
  • Opslag: Supabase us-east-1 (AWS N. Virginia)
  • Primaire extractie: Google Vertex in the US region

Your contracts and account data are stored in the United States on Supabase us-east-1 (AWS N. Virginia). Contract data extraction runs in the US region via Google Vertex.

De regio wordt bij registratie vastgelegd en kan niet worden gewijzigd via de instellingen in de app. Om een workspace tussen regio's te migreren, neemt u contact op met support; operations voert dan het cutover-proces uit.

Wat de regiogrens kruist

Geen enkele extractiefase

Geen enkele extractiefase kruist de regiogrens. Het lezen van de PDF, de veldextractie (Google Vertex) en de validatieronde (Claude op AWS Bedrock) draaien allemaal in de regio die u bij registratie heeft gekozen. De PDF-tekstextractiefase die voorheen de regiogrens kruiste, is uitgefaseerd. Andere diensten in de subverwerkerstabel hieronder (hosting, e-mail, facturering, supportchat, operationele logs) kunnen de daar genoemde beperkte gegevens buiten uw primaire regio verwerken.

Primaire subverwerkers

Wie uw contractgegevens verwerkt

ProviderDoelGedeelde gegevensResidentie
SupabaseDatabase, file storage, authenticationAccount data, contracts, extracted metadata, uploaded filesCustomer-selected region: EU eu-central-1 (AWS Frankfurt) or US us-east-1 (AWS N. Virginia)
VercelApplication hostingRequest logs, IP addressesSingle-instance; operational logs may transit regions Vercel operates in.
StripePayment processingEmail, billing details (no contract data)Global. Stripe handles payments under PCI Level 1.
ResendEmail notificationsEmail address, notification contentUS-based GDPR-compliant email service.
Google Vertex (Gemini)Structured field extraction (primary LLM)The contract PDF and its text onlyRuns in-region: Google Vertex in the EU region for EU customers, in the US region for US customers. Zero retention and no model training on data, per Google Vertex terms.
Anthropic Claude (via AWS Bedrock)opt-outCross-check / validation pass (secondary LLM)Parsed contract text onlyRuns on AWS Bedrock in the customer's own region: within EU AWS regions only for EU customers, and in the US for US customers. Prompts and outputs are not retained, and the model provider has no access to them, per AWS Bedrock data protection terms. Per-org opt-out available.
CrispLive chat supportEmail address, chat messagesSingle-instance.

Operationele logs en infrastructuurleveranciers

De operationele schaduw die u moet kennen

Uw contractgegevens bevinden zich in de door u gekozen regio. Een klein aantal infrastructuurleveranciers dat wij gebruiken voor hosting, foutrapportage, job-orkestratie en rate limiting is single-instance. Hun operationele logs (request-metadata, ID's, regiotags) kunnen buiten uw primaire regio passeren, ook al doet de contractinhoud zelf dat niet. Contractinhoud wordt niet gelogd.

LeverancierDoelGedeelde gegevensStatus
SentryError and exception trackingStack traces and error context (PII redacted before logging)Single-instance; events may transit outside the customer's primary region.
InngestBackground job orchestrationJob payloads (region tag, IDs); contract content is not logged.Single-instance worker plane; the `region` field on payloads is honoured so jobs run against the correct project.
Upstash RedisRate limitingCounter keys (org/user identifiers) and counts; no contract content.Per-region keys; the service itself is single-instance.

Versleuteling en bewaring

Tijdens verzending
TLS 1.3
In rust
AES-256
Bewaartermijn auditlogs
3 jaar voor beveiliging en compliance.
Accountverwijdering
Respijtperiode van 30 dagen. Back-ups worden na 30 dagen gewist.

Melding van datalekken

Renewly informeert de ICO binnen 72 uur na kennisname van een inbreuk in verband met persoonsgegevens, zoals vereist door artikel 33 UK GDPR. Getroffen klanten worden binnen 24 uur geïnformeerd, conform de toezegging in onze verwerkersovereenkomst. Elke melding beschrijft de aard van de inbreuk, de waarschijnlijke gevolgen en de genomen herstelmaatregelen.

Verwerking door derden

Onze LLM-extractieproviders (Gemini via Google Vertex, Claude via AWS Bedrock) hanteren een zero data retention-beleid - contracttekst wordt na verwerking niet bewaard en niet gebruikt om modellen te trainen, conform de voorwaarden van Google Vertex en de gegevensbeschermingsbepalingen van AWS Bedrock.

Compliance-positie

Attributie per provider

SOC 2 infrastructure

Vercel + Supabase, SOC 2 Type II

Our hosting providers (Supabase and Vercel) hold SOC 2 Type II certification. Renewly itself is not in audit scope; the certifications belong to our infrastructure vendors.

ISO 27001 infrastructure

Supabase carries ISO/IEC 27001:2022

Supabase is certified to ISO/IEC 27001:2022 across its full information security management system. Renewly itself is not in audit scope.

GDPR

Compliant

Renewly is GDPR compliant. EU and EEA users have full rights to access, correct, delete, and export their personal data. We have a signed DPA with Supabase.

CCPA

California residents have the right to know, access, and delete their personal information. We do not sell personal data.

Stripe

PCI Level 1

Payments are processed by Stripe under PCI Level 1.

Verwerkersovereenkomst en gegevensdoorgiften

Wij hebben een ondertekende DPA met Supabase. Een Renewly-DPA is op verzoek beschikbaar voor klanten die er een nodig hebben - neem contact op via security@renewly.gg.

Voor gegevensdoorgiften buiten de EER (en het VK) steunt Renewly op Standard Contractual Clauses (en waar van toepassing het UK International Data Transfer Addendum) met de hierboven genoemde subverwerkers.

Als Renewly niet meer beschikbaar is

Renewly wordt door een enkele persoon gerund. Dit is wat u daartegen beschermt.

Your data is never locked in
Every contract, its extracted fields, and your full audit history can be exported at any time, by you, without asking us and without a support request.
Export does not depend on us being available
Export is a self-serve function inside the product, not a manual process a person has to run for you. It does not require Renewly staff to be reachable.
Deleting your account gives you a grace period
Account deletion is scheduled rather than immediate, with a 30-day window in which it can still be reversed before data is destroyed.
Your data sits in your own region's database
Contracts, files and login accounts live in the Supabase project for your region, held by SOC 2 Type II certified infrastructure providers rather than on hardware we run ourselves.

Meer detail

Voor authenticatie, toegangscontrole en audit logging, zie /security. Voor vragen over dataresidentie in gewone taal, zie het helpartikel.