Servers in Frankfurt
Core processing services run in configured EU regions, with Frankfurt as the primary location.
Security & privacy
KontoCSV processes sensitive financial documents with defined retention periods, encrypted transfer and documented service providers. This page summarizes the key information for businesses, accounting teams and tax firms.
Core processing services run in configured EU regions, with Frankfurt as the primary location.
Files are transferred via SSL/TLS and processed using the security standards of the providers involved.
Original files, chunks and intermediate formats are automatically permanently deleted no later than within seven days, often earlier after processing finishes.
KontoCSV does not require bank logins or TANs for conversion.
The publicly documented measures include:
The following core services are documented in the current processing path. Full purposes, legal bases and contractual safeguards are listed in the privacy policy.
| Provider | Purpose | Region / note |
|---|---|---|
| Supabase | Authentication, database, jobs, private object storage | eu-central-1, Frankfurt |
| Google Cloud Storage / Vertex AI | Temporary document processing and AI-assisted extraction | europe-west3, Frankfurt |
| Render | Python backend / job processing | Frankfurt |
| Stripe | Payment processing | Stripe Payments Europe |
| Resend | Transactional email | see privacy policy |
| PostHog | Cookieless web analytics | see privacy policy |
A Data Processing Agreement under Article 28 GDPR is available for business customers and tax firms. If your organisation requires a DPA, contact us for the current version for review and signature.
Request a DPA