Security & privacy
Your data, kept short.
The short version first, then the details an IT or procurement reviewer can check.
- Stored in the EU
- Deleted 30 days after sending
- Nothing sent without your approval
Summary
- Your documents are stored in the EU: the database in Ireland, the PDFs in Cloudflare R2 with EU jurisdiction.
- A Document's PDF and values are deleted 30 days after sending by default. Your Admin can set anywhere from 1 to 365 days.
- Nothing is sent to your system until someone approves it. Auto-Send is off by default.
- Two subprocessors are in the United States. We list them below with exactly what they receive.
Where your data lives
- The app runs in Finland (Hetzner, Helsinki).
- The database is in Ireland (Convex, AWS eu-west-1). It holds everything except the PDFs.
- PDFs are stored in Cloudflare R2 with EU jurisdiction.
- Reading happens with Gemini on Vertex AI, in Google Cloud's EU multi-region.
Matching the read text to your Fields happens at TypeSafe in the United States, and sign-in emails go through Resend in the United States. See Who processes it.
How long we keep it, and deletion
- 30 days after sending by default. Your Admin can set anywhere from 1 to 365 days.
- Documents never approved are deleted 90 days after upload.
- Rejected Documents are deleted 30 days after rejection.
- Unsaved Form Proposals are deleted after 7 days, with their sample PDF.
- Deletion removes the PDF, what Vink read, all values and the Payload.
- We keep a short record (file name, who uploaded and approved it, dates, delivery status), never the document or its values.
An Admin can delete any Document right away, approved ones included. Pending retries for it are cancelled.
To close your account or Organisation, email us. We delete everything within 30 days.
Who processes it
Every party that handles your data, what for, where, and what it receives.
| Name | Purpose | Region | Data |
|---|---|---|---|
| Hetzner | Hosting the app | Finland (EU) | Passes through all traffic |
| Convex | Database and backend | Ireland (EU) | Everything except PDFs |
| Cloudflare R2 | PDF storage | EU | The PDFs |
| Google Cloud Vertex AI | Reading the PDF | EU | The PDF |
| TypeSafe (Jev) | Matching read text to your Fields | United States | The read text. May keep logs under its own terms. |
| Resend | Sign-in and invitation emails | United States | Email address and those emails |
| Cloudflare Email Routing and Workers | Receiving documents sent to an Intake Address | To confirm | Emails sent to an Intake Address, with their PDF attachments |
Transfers to the United States rely on the EU–US Data Privacy Framework or Standard Contractual Clauses.
Access and accounts
Each Organisation only sees its own Documents. Every request is checked against a Membership, and this is covered by automated tests.
There are two roles, Admin and Member. Only Admins can:
- invite and remove members, and change roles
- create and change Forms, including Auto-Send and the Review Threshold
- add, change and remove Integrations, and see their secrets
- change the Organisation's name and retention period
- delete Documents and send failed Deliveries again
Auto-Send is off by default. An Admin turns it on per Form, and it only sends Documents with no unsure values.
Sign-in is by email link, which expires after 5 minutes, or by password. Sessions last 7 days.
In transit and at rest
- HTTPS only, with HSTS.
- Links to a PDF expire after 5 minutes.
- Integration endpoints must use HTTPS.
- Integration secrets are encrypted (AES-256-GCM) with a key kept outside the database.
- Data at rest is encrypted by the providers.
- Payloads are signed with HMAC-SHA256, with one secret per Integration and a timestamp against replays. See Verify the signature.
- A test-send only sends example values or an approved Document.
What we don't have yet
- No SOC 2 or ISO 27001 certification yet.
- No two-factor sign-in or SSO yet.
- A data processing agreement is available on request.
Reporting a problem and contact
Found a security problem? Email [email protected]. We read every report and reply to you directly. Our security.txt has the same details.
Questions about privacy, or need the DPA? Contact us.