Our position, stated plainly
We would rather tell you exactly what we do than imply more than we have. Saveron holds no SOC 2 report and no ISO 27001 certificate today. What follows is what is actually in place, so you can judge it for yourself and put it in front of your own reviewers.
Where your data lives
Production runs on dedicated hardware operated by Hetzner Online GmbH in Germany — inside the European Union, on mirrored NVMe storage. Backups stay in the same jurisdiction. We do not move customer data to other regions without telling you.
Subprocessors
These are the third parties that may process personal data on our behalf:
- Hetzner Online GmbH (Germany) — hosting and backup.
- Cloudflare, Inc. (USA) — DNS, TLS termination and denial-of-service protection.
- Stripe, Inc. (USA) — payment processing, where a product takes card payments.
- Messaging carriers — WhatsApp Business and SMS gateways, only for messages you choose to send.
- An affiliated regional operating partner — deployment and support for customers in its territory, under a written processing agreement.
We will give notice before adding a subprocessor that touches customer data. Ask us for the current list in writing at any time.
Security controls
- TLS everywhere in transit; sensitive fields encrypted at rest.
- Role-based access control, with administrative actions written to an append-only audit log.
- Credentials hashed with a modern password hash; access tokens short-lived and revocable.
- Separate databases per product, least-privilege database users, and no shared admin logins.
- Operating system and dependency patching on a regular cycle, with a firewall limiting the externally reachable surface to what each service needs.
- Automated backups with periodic restore checks.
Data protection rights
We support access, correction, export, restriction and deletion requests under the GDPR, the UK GDPR and the CCPA/CPRA. Send the request to info@saveron.co; we respond within 30 days. We do not sell or share personal information as those laws define it, so there is nothing to opt out of — but you may ask us to confirm that in writing.
Data processing agreements
We will sign a DPA with any customer that needs one, including the European Commission's Standard Contractual Clauses for transfers out of the EEA. Write to us and we will send our standard form.
Breach notification
If we identify a personal data breach we will notify affected customers without undue delay and, where the law requires it, the relevant supervisory authority within 72 hours of becoming aware. Notification will say what happened, what data was involved and what we are doing about it.
Mobile applications
Our applications declare their data collection in the Apple App Store privacy label and the Google Play data safety form. Where an application collects identity documents or a signature — for staff onboarding, for example — that is stated in the declaration and the files are stored privately and served only to the person they belong to and to authorised reviewers.
Reporting a vulnerability
If you believe you have found a security problem, email info@saveron.co with enough detail to reproduce it. We will acknowledge within three working days. Please give us a reasonable opportunity to fix the issue before disclosing it publicly, and do not access or modify data that is not yours while testing.
Contact
Saveron Digital Inc.
192 Bear Christiana Rd 2271
Bear, DE 19701, United States
Email info@saveron.co
Phone +1 (302) 554-9492
