Your data stays in the EU.
Cortena hosts your documents and data on infrastructure in the European Union, so your invoices, bookings, and audit trail never leave the region by default.
Where your data lives
Cortena runs on cloud infrastructure located in the European Union. Your captured invoices, coded bookings, and audit trail are stored and processed in the EU, aligned with GDPR from the ground up.
How access is controlled
Access to your data is limited to the people and services that need it to run Cortena, protected by encryption in transit and at rest and by role-based access controls. We log access so it can be reviewed.
Subprocessors and transfers
Where we use subprocessors, we keep processing within the EU wherever possible and hold the appropriate agreements in place. A current list of subprocessors and our transfer safeguards are available on request.
What this means for you
Your data is hosted in the EU without you having to configure anything.
Data is encrypted in transit and at rest, with access limited and logged.
Hosting is built to support your GDPR obligations, not work against them.
Ask for our hosting and subprocessor documentation any time.
Need a DPA or documentation?
We make a data processing agreement (AVV) and supporting documentation available on request. For contracts and DPAs, contact compliance. For privacy and data protection questions, reach our appointed DPO.
This page describes how Cortena works in plain language. It is not legal advice and is not a binding contract. For the official documentation and agreements, contact our team.