Trust & Compliance

Everything you need to approve Validemic as a vendor

Validemic reviews other vendors’ compliance for a living, so our own has to hold up to the same scrutiny. This page lists exactly where your data lives, who processes it, and under which jurisdiction. Everything below is the same information we provide in procurement questionnaires.

GDPR by design

Validemic is built by Avidemic AB, a Swedish company operating under EU law. We act as a processor under Art. 28 GDPR and sign data processing agreements with every institutional customer.

All data hosted in the EU

Application data, documents and backups are stored exclusively in the European Union, with primary hosting in Sweden and EU-based infrastructure throughout. Nothing is transferred outside the EU for storage.

Never trained on your data

Vendor documents and assessments are processed only to deliver the service. Neither we nor our AI subprocessors use your data to train models. Our AI providers run zero-retention inference on EU infrastructure.

Encryption and access control

Data is encrypted in transit (TLS 1.2+). Nightly backups are encrypted on the server before they are copied to EU storage. Access is role-based.

You own your data

Everything you upload remains your property. Export all of it at any time from Settings, as JSON plus your original files, and get 30 days to export at contract end before we delete anything.

Procurement-ready

We routinely complete security questionnaires and DPAs as part of institutional procurement, and provide subprocessor, hosting and retention details on request.

Subprocessors

The complete list of companies that process customer data on our behalf. Every one of them is established in the EU, bound by a GDPR data processing agreement, and listed here before we use it. We notify customers before adding or replacing a subprocessor.

SubprocessorPurposeData locationSafeguards
Hostup AB
Sweden
Application hosting (primary)Stockholm, SwedenThe live application and database stay in Sweden on Swedish-owned infrastructure, under Swedish jurisdiction. GDPR data processing agreement.
Hetzner Online GmbH
Germany
Encrypted backup storageHelsinki, Finland (EU)Stores only encrypted backups. ISO/IEC 27001-certified data centre operations, GDPR data processing agreement, renewable-powered data centres.
TensorX
Ireland
AI inference (primary)Dublin, Ireland & Helsinki, Finland (EU)EU-sovereign inference with zero data retention: prompts and completions are never stored or logged, and never used for training. GDPR processor; TLS 1.2+ / AES-256.
Berget AI AB
Sweden
AI inference (fallback)SwedenSwedish sovereign AI infrastructure: data never leaves EU servers and is never used for training. Runs on certified fossil-free Swedish energy.
Lettermint
Netherlands
Transactional email (contact & notifications)European Union (own EU infrastructure)European email provider running entirely on its own EU infrastructure, including its own network and IP space, with no US hyperscalers. Processes only the messages our forms generate. GDPR data processing agreement.

No customer data is transferred outside the EU/EEA. There are no third-country subprocessors on this list, so no SCCs or transfer impact assessments are needed for Validemic itself.

Separately from the service, our own email runs on Google Workspace (Google Ireland Limited). It receives the messages you send us, such as contact-form requests and support emails, but never your workspace data. Google may process email outside the EU; those transfers are covered by the EU-US Data Privacy Framework and standard contractual clauses. Please upload vendor documents in your workspace rather than emailing them to us.

EU AI Act: minimal risk

Validemic uses AI to read vendor documents, pre-fill answers, draft DPIAs and answer questions about your workspace. Under the EU AI Act (Regulation (EU) 2024/1689) we classify Validemic as a minimal-risk AI system, the lowest of the Act’s risk levels. This is how we reach that conclusion.

Not a prohibited practice (Art. 5)

Validemic does not manipulate behaviour, score people, identify people by biometrics or recognise emotions. None of the practices banned by Article 5 apply.

Not high-risk (Art. 6, Annexes I and III)

Validemic assesses software vendors and their documents, not people. It does not decide on admission to education, evaluate students, monitor exams, make decisions about staff or control access to essential services, and it is not a safety component of a regulated product.

No general-purpose model of our own

We do not train or place an AI model on the market. We use open-source models run by two European providers, TensorX and Berget AI, so the obligations for general-purpose AI model providers do not fall on us.

Transparent by design (Art. 50)

You always know when you are dealing with AI. The assistant is labelled as AI, answers the AI pre-fills are marked “Extracted by AI” together with the page or document they came from, and drafts are presented as drafts.

People decide

The AI proposes and cites; your staff check and decide. Approvals, rejections and signatures are always made by a person, never by the AI.

This is our own assessment of Validemic itself, which we revisit as guidance under the Act develops. Each review you run in Validemic classifies the vendor’s product separately.

Our contractual commitments

Standard terms for every institutional customer, set out in full in our Terms of Service

Breach notification within 48 hours

If a personal data breach affects your data, we notify your workspace administrators without undue delay and no later than 48 hours after we become aware of it, with what we know at that point, and keep you updated as we learn more. That leaves you well inside the 72 hours the GDPR gives you to report to your authority.

Your data back at contract end

Export everything at any time from Settings, as JSON plus your original files. When a subscription ends you keep export access for 30 days. We then delete the workspace from live systems within 30 days, encrypted backup copies expire within a further 35 days, and we confirm the deletion in writing on request.

Predictable renewal

Subscriptions run for 12 months and renew for another 12 unless either side gives notice at least 30 days before the renewal date. Any price change for the next period is announced at least 60 days before renewal, so you always have time to decide.

Straight answers to the other questions

What security and procurement teams usually ask next, answered plainly, including where the answer is no.

Security incidents
No security incident or personal data breach has affected Validemic or its customers’ data to date. If one ever does, the 48-hour notification above applies.
Certifications
Validemic does not hold an ISO 27001 certificate or a SOC 2 report. Our backup provider Hetzner runs ISO/IEC 27001-certified data centres. We complete security questionnaires such as HECVAT and describe our technical and organisational measures in writing on request.
Availability
We do not offer a financially backed uptime SLA. Our target is 99.5% availability per month. We plan maintenance outside Nordic office hours where we can, and announce planned maintenance expected to last more than 30 minutes by email at least 24 hours ahead. If a material fault stays unresolved, you are entitled to a proportional price reduction (Terms of Service, section 8).
Insurance
We do not currently carry professional or cyber liability insurance. Liability between us and our customers is set out in section 14 of our Terms of Service.
Integrations
Validemic is a standalone web app for staff, so it does not connect to learning management or library discovery systems. It connects to your identity provider for single sign-on (SAML or OIDC, set up on request), and everything can be exported: decision memos as Word files, DPIA drafts as Markdown, signed agreements as PDF and the whole workspace as JSON with the original files.
Usage statistics and analytics
There is no separate usage report. Admins see members and roles on the Team page, and every review keeps a timeline of who did what. To find and fix problems we use our own server logs, kept on our own servers. We use no external analytics, tracking or advertising tools.

Where your data physically lives

We deliberately chose European hosting providers under European ownership, the same standard we help universities hold their own vendors to.

Hostup (Stockholm, Sweden)

  • 100% Swedish-owned, independent hosting provider with no non-EU parent company, so no exposure to extraterritorial disclosure laws such as the US CLOUD Act.
  • All servers physically located in Sweden; the live application and database never leave Swedish soil. Only encrypted backups are copied to Finland.
  • Modern infrastructure: KVM virtualisation, NVMe storage with replicated redundancy and included backups.

Hetzner (Helsinki, Finland)

  • ISO/IEC 27001-certified data centre operations, with independently audited information-security management.
  • German company under EU law; we use its Helsinki region only, for encrypted backups.
  • Data centres powered by renewable energy, with industry-leading physical security and redundancy.

How our AI handles your documents

EU inference only

Document analysis runs on TensorX (Dublin & Helsinki) with Berget AI in Sweden as automatic fallback. Both are European sovereign-AI providers: your documents are processed on EU hardware, under EU jurisdiction, with open-weight models we select, and never routed to US model APIs.

Zero retention, zero training

Prompts and completions are processed in memory and never stored, logged or persisted by our AI providers, and never used to train models, theirs or anyone else’s. What the AI reads to write your compliance report stays yours.

Need a DPA, security questionnaire or more detail?

We answer procurement and security requests promptly. It is, after all, what our product is about.

Contact