Trust Center
Everything your procurement, legal and security teams need to evaluate ResiPlan — without writing us first.
Sub-processors
Current list of sub-processors handling data on behalf of Cryptaguard BV (Article 28 GDPR).
| Sub-processor | Purpose | Data location | Transfer outside the EU |
|---|---|---|---|
| Convex | Database, serverless functions, real-time sync and file storage | European Union — AWS eu-west-1 (Ireland), dedicated EU deployment | Data hosted in the EU; US support access covered by SCCs (2021/914) |
| OVHcloud | Application hosting (web server of the Service) | European Union — France | No transfer outside the EU |
| Resend | Transactional email delivery (invitations, notifications, alerts) | United States | SCCs (2021/914) |
| Stripe | Subscription payments and billing | European Union, with intra-group transfers to Stripe, Inc. (United States) | SCCs (2021/914) and, where applicable, an active DPF certification |
| Anthropic | Default AI provider (assistant, plan generation, analyses) — no training on customer data | United States | SCCs (2021/914) and, where applicable, an active DPF certification; per-organization "EU-only AI" option available |
| OpenAI | Selected AI features and optional cloud transcription of crisis sessions (local alternative available) | United States | SCCs (2021/914) and, where applicable, an active DPF certification; per-organization "EU-only AI" option available |
| Mistral AI | "EU-only AI" option: substitute AI provider configurable per organization | European Union — France | No transfer outside the EU |
| Plausible Analytics | Aggregate, cookieless audience measurement (website and application) | European Union | No transfer outside the EU |
| Microsoft Clarity | Heatmaps and anonymized session replay on the marketing site — consent-gated | European Union, with possible intra-group transfers to Microsoft Corporation (United States) | SCCs (2021/914) and, where applicable, an active DPF certification |
Sub-processor change notifications are sent 30 days in advance to the administrators of every organization.
Key commitments
- Customer data hosted in the European Union by default (OVH France / Convex EU).
- SHA-256 chained audit log — any tampering is cryptographically detectable.
- Automated anomaly detection (brute-force, credential stuffing, unusual-country login).
- No customer data used to train AI models.
- RFC 9116 vulnerability disclosure procedure documented.
Need our Data Processing Agreement (DPA)?
GDPR art. 28 DPA with a DORA art. 30 annex, technical measures and the sub-processor list — download it directly, no need to write us.