Trust & Compliance
Validemic reviews other vendors’ compliance for a living, so our own has to hold up to the same scrutiny. This page lists exactly where your data lives, who processes it, and under which jurisdiction. Everything below is the same information we provide in procurement questionnaires.
Validemic is built by Avidemic AB, a Swedish company operating under EU law. We act as a processor under Art. 28 GDPR and sign data processing agreements with every institutional customer.
Application data, documents and backups are stored exclusively in the European Union, with primary hosting in Sweden and EU-based infrastructure throughout. Nothing is transferred outside the EU for storage.
Vendor documents and assessments are processed only to deliver the service. Neither we nor our AI subprocessors use your data to train models. Our AI providers run zero-retention inference on EU infrastructure.
Data is encrypted in transit (TLS 1.2+). Nightly backups are encrypted on the server before they are copied to EU storage. Access is role-based.
Everything you upload remains your property. Export all of it at any time from Settings, as JSON plus your original files, and get 30 days to export at contract end before we delete anything.
We routinely complete security questionnaires and DPAs as part of institutional procurement, and provide subprocessor, hosting and retention details on request.
The complete list of companies that process customer data on our behalf. Every one of them is established in the EU, bound by a GDPR data processing agreement, and listed here before we use it. We notify customers before adding or replacing a subprocessor.
| Subprocessor | Purpose | Data location | Safeguards |
|---|---|---|---|
| Hostup AB Sweden | Application hosting (primary) | Stockholm, Sweden | The live application and database stay in Sweden on Swedish-owned infrastructure, under Swedish jurisdiction. GDPR data processing agreement. |
| Hetzner Online GmbH Germany | Encrypted backup storage | Helsinki, Finland (EU) | Stores only encrypted backups. ISO/IEC 27001-certified data centre operations, GDPR data processing agreement, renewable-powered data centres. |
| TensorX Ireland | AI inference (primary) | Dublin, Ireland & Helsinki, Finland (EU) | EU-sovereign inference with zero data retention: prompts and completions are never stored or logged, and never used for training. GDPR processor; TLS 1.2+ / AES-256. |
| Berget AI AB Sweden | AI inference (fallback) | Sweden | Swedish sovereign AI infrastructure: data never leaves EU servers and is never used for training. Runs on certified fossil-free Swedish energy. |
| Lettermint Netherlands | Transactional email (contact & notifications) | European Union (own EU infrastructure) | European email provider running entirely on its own EU infrastructure, including its own network and IP space, with no US hyperscalers. Processes only the messages our forms generate. GDPR data processing agreement. |
No customer data is transferred outside the EU/EEA. There are no third-country subprocessors on this list, so no SCCs or transfer impact assessments are needed for Validemic itself.
Separately from the service, our own email runs on Google Workspace (Google Ireland Limited). It receives the messages you send us, such as contact-form requests and support emails, but never your workspace data. Google may process email outside the EU; those transfers are covered by the EU-US Data Privacy Framework and standard contractual clauses. Please upload vendor documents in your workspace rather than emailing them to us.
Validemic uses AI to read vendor documents, pre-fill answers, draft DPIAs and answer questions about your workspace. Under the EU AI Act (Regulation (EU) 2024/1689) we classify Validemic as a minimal-risk AI system, the lowest of the Act’s risk levels. This is how we reach that conclusion.
Validemic does not manipulate behaviour, score people, identify people by biometrics or recognise emotions. None of the practices banned by Article 5 apply.
Validemic assesses software vendors and their documents, not people. It does not decide on admission to education, evaluate students, monitor exams, make decisions about staff or control access to essential services, and it is not a safety component of a regulated product.
We do not train or place an AI model on the market. We use open-source models run by two European providers, TensorX and Berget AI, so the obligations for general-purpose AI model providers do not fall on us.
You always know when you are dealing with AI. The assistant is labelled as AI, answers the AI pre-fills are marked “Extracted by AI” together with the page or document they came from, and drafts are presented as drafts.
The AI proposes and cites; your staff check and decide. Approvals, rejections and signatures are always made by a person, never by the AI.
This is our own assessment of Validemic itself, which we revisit as guidance under the Act develops. Each review you run in Validemic classifies the vendor’s product separately.
Standard terms for every institutional customer, set out in full in our Terms of Service
If a personal data breach affects your data, we notify your workspace administrators without undue delay and no later than 48 hours after we become aware of it, with what we know at that point, and keep you updated as we learn more. That leaves you well inside the 72 hours the GDPR gives you to report to your authority.
Export everything at any time from Settings, as JSON plus your original files. When a subscription ends you keep export access for 30 days. We then delete the workspace from live systems within 30 days, encrypted backup copies expire within a further 35 days, and we confirm the deletion in writing on request.
Subscriptions run for 12 months and renew for another 12 unless either side gives notice at least 30 days before the renewal date. Any price change for the next period is announced at least 60 days before renewal, so you always have time to decide.
What security and procurement teams usually ask next, answered plainly, including where the answer is no.
We deliberately chose European hosting providers under European ownership, the same standard we help universities hold their own vendors to.
Document analysis runs on TensorX (Dublin & Helsinki) with Berget AI in Sweden as automatic fallback. Both are European sovereign-AI providers: your documents are processed on EU hardware, under EU jurisdiction, with open-weight models we select, and never routed to US model APIs.
Prompts and completions are processed in memory and never stored, logged or persisted by our AI providers, and never used to train models, theirs or anyone else’s. What the AI reads to write your compliance report stays yours.
We answer procurement and security requests promptly. It is, after all, what our product is about.
Contact