Skip to main content
ResiPlan

Trust Center

Everything your procurement, legal and security teams need to evaluate ResiPlan — without writing us first.

Sub-processors

Current list of sub-processors handling data on behalf of Cryptaguard BV (Article 28 GDPR).

Sub-processorPurposeData locationTransfer outside the EU
ConvexDatabase, serverless functions, real-time sync and file storage
European Union — AWS eu-west-1 (Ireland), dedicated EU deployment
Data hosted in the EU; US support access covered by SCCs (2021/914)
OVHcloudApplication hosting (web server of the Service)
European Union — France
No transfer outside the EU
ResendTransactional email delivery (invitations, notifications, alerts)
United States
SCCs (2021/914)
StripeSubscription payments and billing
European Union, with intra-group transfers to Stripe, Inc. (United States)
SCCs (2021/914) and, where applicable, an active DPF certification
AnthropicDefault AI provider (assistant, plan generation, analyses) — no training on customer data
United States
SCCs (2021/914) and, where applicable, an active DPF certification; per-organization "EU-only AI" option available
OpenAISelected AI features and optional cloud transcription of crisis sessions (local alternative available)
United States
SCCs (2021/914) and, where applicable, an active DPF certification; per-organization "EU-only AI" option available
Mistral AI"EU-only AI" option: substitute AI provider configurable per organization
European Union — France
No transfer outside the EU
Plausible AnalyticsAggregate, cookieless audience measurement (website and application)
European Union
No transfer outside the EU
Microsoft ClarityHeatmaps and anonymized session replay on the marketing site — consent-gated
European Union, with possible intra-group transfers to Microsoft Corporation (United States)
SCCs (2021/914) and, where applicable, an active DPF certification

Sub-processor change notifications are sent 30 days in advance to the administrators of every organization.

Key commitments

  • Customer data hosted in the European Union by default (OVH France / Convex EU).
  • SHA-256 chained audit log — any tampering is cryptographically detectable.
  • Automated anomaly detection (brute-force, credential stuffing, unusual-country login).
  • No customer data used to train AI models.
  • RFC 9116 vulnerability disclosure procedure documented.

Need our Data Processing Agreement (DPA)?

GDPR art. 28 DPA with a DORA art. 30 annex, technical measures and the sub-processor list — download it directly, no need to write us.

Trust Center — ResiPlan