Trust at Renewly

Where your data lives and who touches it

Renewly is a dual-region service. You choose your region at signup and your contracts, account data, and audit logs stay in that region for the life of the workspace. This page is the canonical map of the sub-processors that handle your data. No extraction stage crosses region.

Data residency

EU or US, set at signup, immutable from the UI

European Union

eu-central-1
  • Storage: Supabase eu-central-1 (AWS Frankfurt)
  • Primary extraction: Google Vertex in the EU region

Your contracts and account data are stored in the EU on Supabase eu-central-1 (AWS Frankfurt). Contract data extraction runs in the EU region via Google Vertex.

United States

us-east-1
  • Storage: Supabase us-east-1 (AWS N. Virginia)
  • Primary extraction: Google Vertex in the US region

Your contracts and account data are stored in the United States on Supabase us-east-1 (AWS N. Virginia). Contract data extraction runs in the US region via Google Vertex.

Region is set at signup time and cannot be changed from the in-app settings UI. To migrate a workspace between regions, contact support and operations runs the cutover process.

What crosses region

Nothing in the extraction pipeline

No extraction stage crosses region. PDF reading, field extraction (Google Vertex) and the validation pass (Claude on AWS Bedrock) all run in the region you chose at signup. The PDF text-extraction stage that previously crossed region has been retired. Other services in the sub-processor table below (hosting, email, billing, support chat, operational logs) may process the limited data listed there outside your primary region.

Primary sub-processors

Who processes your contract data

ProviderPurposeData sharedResidency
SupabaseDatabase, file storage, authenticationAccount data, contracts, extracted metadata, uploaded filesCustomer-selected region: EU eu-central-1 (AWS Frankfurt) or US us-east-1 (AWS N. Virginia)
VercelApplication hostingRequest logs, IP addressesSingle-instance; operational logs may transit regions Vercel operates in.
StripePayment processingEmail, billing details (no contract data)Global. Stripe handles payments under PCI Level 1.
ResendEmail notificationsEmail address, notification contentUS-based GDPR-compliant email service.
Google Vertex (Gemini)Structured field extraction (primary LLM)The contract PDF and its text onlyRuns in-region: Google Vertex in the EU region for EU customers, in the US region for US customers. Zero retention and no model training on data, per Google Vertex terms.
Anthropic Claude (via AWS Bedrock)opt-outCross-check / validation pass (secondary LLM)Parsed contract text onlyRuns on AWS Bedrock in the customer's own region: within EU AWS regions only for EU customers, and in the US for US customers. Prompts and outputs are not retained, and the model provider has no access to them, per AWS Bedrock data protection terms. Per-org opt-out available.
CrispLive chat supportEmail address, chat messagesSingle-instance.

Operational logs and infrastructure vendors

The operational shadow you should know about

Your contract data lives in your selected region. A small number of infrastructure vendors that we use for hosting, error reporting, job orchestration, and rate limiting are single-instance services. Their operational logs (request metadata, IDs, region tags) may transit outside your primary region even though contract content itself does not. Contract content is not logged.

VendorPurposeData sharedPosture
SentryError and exception trackingStack traces and error context (PII redacted before logging)Single-instance; events may transit outside the customer's primary region.
InngestBackground job orchestrationJob payloads (region tag, IDs); contract content is not logged.Single-instance worker plane; the `region` field on payloads is honoured so jobs run against the correct project.
Upstash RedisRate limitingCounter keys (org/user identifiers) and counts; no contract content.Per-region keys; the service itself is single-instance.

Encryption and retention

In transit
TLS 1.3
At rest
AES-256
Audit log retention
3 years for security and compliance.
Account deletion
30-day grace period. Backups purged after 30 days.

Breach notification

Renewly notifies the ICO within 72 hours of becoming aware of a personal data breach, as required by UK GDPR Article 33. Affected customers are notified within 24 hours, the commitment in our Data Processing Agreement. Every notification sets out the nature of the breach, its likely consequences, and the remediation steps taken.

Third-party processing

Our LLM extraction providers (Gemini via Google Vertex, Claude via AWS Bedrock) operate under a zero data retention policy - contract text is not retained or used to train models after processing, per Google Vertex terms and AWS Bedrock data protection terms.

Compliance posture

Per-provider attribution

SOC 2 infrastructure

Vercel + Supabase, SOC 2 Type II

Our hosting providers (Supabase and Vercel) hold SOC 2 Type II certification. Renewly itself is not in audit scope; the certifications belong to our infrastructure vendors.

ISO 27001 infrastructure

Supabase carries ISO/IEC 27001:2022

Supabase is certified to ISO/IEC 27001:2022 across its full information security management system. Renewly itself is not in audit scope.

GDPR

Compliant

Renewly is GDPR compliant. EU and EEA users have full rights to access, correct, delete, and export their personal data. We have a signed DPA with Supabase.

CCPA

California residents have the right to know, access, and delete their personal information. We do not sell personal data.

Stripe

PCI Level 1

Payments are processed by Stripe under PCI Level 1.

Data processing agreement and transfers

We have a signed DPA with Supabase. A Renewly DPA is available on request for customers that require one - contact security@renewly.gg.

For data transfers out of the EEA (and the UK), Renewly relies on Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) with the sub-processors listed above.

If Renewly stops being available

Renewly is run by one person. Here is what protects you from that.

Your data is never locked in
Every contract, its extracted fields, and your full audit history can be exported at any time, by you, without asking us and without a support request.
Export does not depend on us being available
Export is a self-serve function inside the product, not a manual process a person has to run for you. It does not require Renewly staff to be reachable.
Deleting your account gives you a grace period
Account deletion is scheduled rather than immediate, with a 30-day window in which it can still be reversed before data is destroyed.
Your data sits in your own region's database
Contracts, files and login accounts live in the Supabase project for your region, held by SOC 2 Type II certified infrastructure providers rather than on hardware we run ourselves.

More detail

For authentication, access control, and audit logging, see /security. For data-residency questions in plain language, see the help article.