Legal
Subprocessors
Last updated: 2026-08-31
To deliver the service, Bitfront AB uses third-party subprocessors to process personal data. Data retention and residency terms may be customized by written agreement. This page covers the Bytesafe Dependency Firewall. SBOM Observer publishes its own subprocessor list.
1. Processing activities
These are the activities carried out on customer data in the service.
| Activity | Purpose | Data | Retention | On termination |
|---|---|---|---|---|
| User account management | Create and manage accounts and access | Name, email, organization, role | Active subscription | Deleted within 30 days after export period |
| Audit and access logs | Security, traceability, diagnostics | Username, IP address, action | 180 days | Deleted within 30 days after export period |
| Backups | Disaster recovery | Encrypted service data | 30 days | Deleted within 90 days after export period |
| Support and issue tracking | Respond to customer requests | Contact details, ticket content | Active subscription | Deleted within 30 days after export period |
| Product analytics | Service improvement | Aggregated usage metrics (no PII content) | 12 months | N/A (aggregated) |
| Billing and invoicing | Financial and compliance | Company name, billing contact, payment info | 7 years (Swedish law) | Deleted after retention period |
2. Data residency
All customer data in the Bytesafe service is stored and processed within the European Union. We select the EU region for every subprocessor that offers a choice, and we do not store customer data outside the EU/EEA.
Two subprocessors of the service, Neon and Sinch Email, are companies established in the United States that process in the EU region we selected. Because a company outside the EEA can in principle access data it processes, we treat that as a transfer and cover it with Standard Contractual Clauses under Article 46 GDPR. The table below states the mechanism for each subprocessor, so you can see exactly which ones this applies to.
You can export your data during your subscription and for 30 days after contract termination. We delete your data from production systems within 30 days after that export period. Backups are deleted within 90 days after the end of the export period.
Our public websites, bytesafe.dev and docs.bytesafe.dev, are operated separately from the service and hold no customer data. They are listed separately below because two of the providers involved are established outside the EEA.
3. Subprocessors: the Bytesafe service
These process customer data. All process within the European Union in the region we have selected.
| Subprocessor | Registered entity | Purpose | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Scaleway SAS | France | Cloud hosting and infrastructure (default) | EU (France) | None needed, EU to EU |
| Amazon Web Services EMEA SARL | Luxembourg | Cloud hosting and infrastructure (optional, on request) | EU (Germany) | None needed, EU to EU |
| Neon, LLC (a Databricks company) | United States | Managed Postgres for authentication and account data | EU (Frankfurt) | Standard Contractual Clauses |
| Stripe Payments Europe Ltd | Ireland | Subscription and payment processing | EU (Ireland) | None needed, EU to EU |
| Sinch Email (Mailgun) | United States | Transactional email delivery | EU (Germany, Belgium) | EU region configured. Standard Contractual Clauses |
| Crisp IM SAS | France | Customer support chat | EU (France, Ireland) | None needed, EU to EU |
4. Subprocessors: our websites
These support bytesafe.dev and docs.bytesafe.dev. They process visitor and enquiry data, not customer data from the service. Where a provider is established outside the EEA, the transfer relies on an adequacy decision under Article 45 GDPR.
| Subprocessor | Registered entity | Purpose | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Vercel Inc. | United States | Website hosting and cookieless web analytics | Functions in EU (Frankfurt). Edge network and backups global | EU-U.S. Data Privacy Framework (Article 45). Standard Contractual Clauses and UK Addendum as fallback |
| PostHog Ltd | United Kingdom | Website and product analytics, on consent only | EU (Frankfurt) | UK adequacy decision (Article 45) |
| Salesforce, Inc. (Slack) | United States | Receives contact and demo form submissions so we can respond | United States | EU-U.S. Data Privacy Framework (Article 45) |
| Crisp IM SAS | France | Website support chat, on consent only | EU (France, Ireland) | None needed, EU to EU |
5. Data processing agreements
All subprocessors operate under Data Processing Agreements in accordance with GDPR Article 28. These agreements require processing only on documented instructions, appropriate security measures, assistance with data subject rights, and data deletion or return on termination.
Our complete Data Processing Agreement is available at /legal/gdpr-dpa.
6. Changes
We may update our subprocessors. Material changes will be communicated by email at least 30 days before the change takes effect. If you object to a new subprocessor on reasonable data protection grounds and we cannot resolve the objection, you may terminate the affected subscription. This follows the same no-refund basis as the rest of these terms.
Questions: support@bytesafe.dev or security@bytesafe.dev.