Skip to content
Data protection & server location

Tenant data stays within the European legal area.

The application and its database run on rented servers in Germany, documents and backups stay inside the EU, and sensitive tenant data is stored encrypted. What that means technically is spelled out on this page.

Server locationGermanyFalkenstein · 50.478°N 12.371°E

German servers, storage and AI processing in the EU.

The application and database run on rented servers of Hetzner Online GmbH in Falkenstein (Saxony). Your documents are held in private Cloudflare R2 object storage in a bucket technically restricted to the EU. AI analysis runs on Google Cloud Vertex AI in the europe-west3 region (Frankfurt am Main).

Data processing agreements under Art. 28 GDPR are in place with Hetzner, Cloudflare, Google Cloud, Resend and PostHog. Your content is not used to train the models. The full subprocessor list is published as Annex 3 of the data processing agreement. Hetzner is based in Germany; the contracting party for the Google services is Google Cloud EMEA Limited in Dublin, Ireland. Cloudflare, Resend and PostHog are US companies. Storage and processing are contractually confined to the EU — which still does not rule out access from third countries for support and abuse prevention. Section 13 of the privacy policy names every one of those cases.

AES-256-GCM for sensitive tenant data.

Personal notes, special address entries and confidential tenant information are encrypted with AES-256-GCM before being stored in the database. Even with direct DB access, these fields are not readable in plain text.

Database backups are created every working day and encrypted with our own key before upload (OpenPGP/AES-256) — the private key is kept off the servers. Retention: 30 days.

Implemented per

German tenancy and property law — implemented to the letter of the law.

GDPR

General Data Protection Regulation

ArbZG

Working Hours Act

BUrlG

Federal Leave Act

BetrKV

Operating Cost Regulation

BGB §§ 535-580a

Tenancy law

SKR03

Double-entry accounting

§§ 556, 556a BGB

Operating cost allocation & chargeability

HeizKV

Heating Cost Regulation incl. § 9b

WoFlV

Residential Space Regulation

FAQ

Is Savanika GDPR-compliant?

Yes. The application and database run on servers in Germany; documents and backups are held in private Cloudflare R2 object storage restricted to the EU — the backups additionally encrypted with our own key. Sensitive tenant data is encrypted field by field with AES-256-GCM. The providers we engage ourselves act as processors under Art. 28 GDPR; Annex 3 of the data processing agreement lists them in full. Section 2 of that same annex names the services you engage yourself — postal dispatch via PIN AG, for instance; there you conclude the contract directly with the provider.

How do I share data with my tax advisor?

Savanika imports MT940 and CAMT bank data and matches payments automatically. Entries go to your tax adviser via standard reports and CSV export. For the handover of data on a data carrier under § 147 Abs. 6 AO a machine-readable export is available. And you can export the complete data set yourself at any time as a ZIP archive — free of charge under § 8 of our terms, including when you switch to another provider.

Your tenant data is stored in Europe. And whoever else has access is named in the DPA.

Hosting in Germany, documents and backups inside the EU, sensitive fields encrypted with AES-256-GCM — all of it written down in the data processing agreement.

Security & compliance | Savanika