SBOM Observer Docs logoSBOM Observer Docs
Service usage policies

SBOM Observer Subprocessors

SBOM Observer Subprocessors and Data Processing

Version 1.2 • Updated November 7, 2025


To deliver our SBOM Observer SaaS Platform services, SBOM Observer (Bitfront AB) uses third-party subprocessors to process personal information. Data retention and residency terms may be customized by written agreement for specific use cases.

Overview of Processing Activities

Processing ActivityPurposeDataRetention PeriodTermination
User account managementCreate and manage user accounts and access permissionsName, email address, organization, roleActive subscription periodDeleted within 90 days after termination
Audit and access logsSecurity, traceability, service diagnosticsUsername, IP address, action180 daysDeleted within 90 days after termination
BackupsDisaster recovery and business continuityEncrypted service data30 daysDeleted within 90 days after termination
Support and issue trackingRespond to customer requestsContact details, ticket contentActive subscription periodDeleted within 90 days after termination
Product analyticsService improvement and reliabilityAggregated usage metrics (no PII content)12 monthsN/A (Aggregated or anonymized)
Billing and invoicingFinancial and compliance purposesCompany name, billing contact, payment info7 years (per Swedish law)Deleted after retention period

Data Residency

All customer data is stored and processed within the European Union (Germany). No personal data is transferred or stored outside the EU/EEA without explicit prior written consent.

  • Data deletion: Within 90 days after contract termination
  • Backup deletion: Automatically overwritten within 30 days

Subprocessors

SubprocessorRegistered Entity / CountryPurposeLocation
Amazon Web Services EMEA SARLLuxembourg / Sweden (Nordic ops)Cloud hosting and infrastructureEU (Germany)
VercelUnited StatesFrontend hostingEU
Stripe Payments EuropeIrelandSubscriptions managementEU (Ireland)
PostHogUnited KingdomProduct analytics, Onboarding automationEU (Ireland)
Mailgun (Sinch)United StatesEmail deliveryEU (Germany)
SentryUnited StatesError tracking and application performance monitoringEU (Germany)

Data Processing

All subprocessors operate under Data Processing Agreements (DPAs) in accordance with GDPR Article 28. These agreements ensure:

  • Processing only on documented instructions
  • Appropriate technical and organizational security measures
  • Assistance with data subject rights requests
  • Data deletion or return upon service termination

Our complete Data Processing Agreement is available online.

Changes

We may update our list of subprocessors. Material changes will be communicated via email with 15 days' notice. If you object to a new subprocessor, you may terminate your account per our Terms of Service.

For questions, contact support@sbom.observer or security@sbom.observer.