Tenant data stays within the European legal area.
The application and its database run on rented servers in Germany, documents and backups stay inside the EU, and sensitive tenant data is stored encrypted. What that means technically is spelled out on this page.
German servers, storage and AI processing in the EU.
The application and database run on rented servers of Hetzner Online GmbH in Falkenstein (Saxony). Your documents are held in private Cloudflare R2 object storage in a bucket technically restricted to the EU. AI analysis runs on Google Cloud Vertex AI in the europe-west3 region (Frankfurt am Main).
Data processing agreements under Art. 28 GDPR are in place with Hetzner, Cloudflare, Google Cloud, Resend and PostHog. Your content is not used to train the models. The full subprocessor list is published as Annex 3 of the data processing agreement. Hetzner is based in Germany; the contracting party for the Google services is Google Cloud EMEA Limited in Dublin, Ireland. Cloudflare, Resend and PostHog are US companies. Storage and processing are contractually confined to the EU — which still does not rule out access from third countries for support and abuse prevention. Section 13 of the privacy policy names every one of those cases.
AES-256-GCM for sensitive tenant data.
Personal notes, special address entries and confidential tenant information are encrypted with AES-256-GCM before being stored in the database. Even with direct DB access, these fields are not readable in plain text.
Database backups are created every working day and encrypted with our own key before upload (OpenPGP/AES-256) — the private key is kept off the servers. Retention: 30 days.
German tenancy and property law — implemented to the letter of the law.
GDPR
General Data Protection Regulation
ArbZG
Working Hours Act
BUrlG
Federal Leave Act
BetrKV
Operating Cost Regulation
BGB §§ 535-580a
Tenancy law
SKR03
Double-entry accounting
§§ 556, 556a BGB
Operating cost allocation & chargeability
HeizKV
Heating Cost Regulation incl. § 9b
WoFlV
Residential Space Regulation
FAQ
Is Savanika GDPR-compliant?
Yes. The application and database run on servers in Germany; documents and backups are held in private Cloudflare R2 object storage restricted to the EU — the backups additionally encrypted with our own key. Sensitive tenant data is encrypted field by field with AES-256-GCM. The providers we engage ourselves act as processors under Art. 28 GDPR; Annex 3 of the data processing agreement lists them in full. Section 2 of that same annex names the services you engage yourself — postal dispatch via PIN AG, for instance; there you conclude the contract directly with the provider.
How do I share data with my tax advisor?
Savanika imports MT940 and CAMT bank data and matches payments automatically. Entries go to your tax adviser via standard reports and CSV export. For the handover of data on a data carrier under § 147 Abs. 6 AO a machine-readable export is available. And you can export the complete data set yourself at any time as a ZIP archive — free of charge under § 8 of our terms, including when you switch to another provider.
Your tenant data is stored in Europe. And whoever else has access is named in the DPA.
Hosting in Germany, documents and backups inside the EU, sensitive fields encrypted with AES-256-GCM — all of it written down in the data processing agreement.