Last updated: August 30, 2026
Privacy policy
This policy describes how Pavora (the service at pavora.se), owned and operated by org. no. 559189-2897, processes personal data under the EU General Data Protection Regulation (GDPR).
See for yourself
- No analytics or ad telemetry loads on pavora.se.
- No third-party tracking pixels.
- Only the cookies required for sign-in and language.
Where the books live
Production books live with Fortnox, Visma, Kleer, or Bokio — they are the statutory archive. Pavora stores no readable copy of the books: vouchers we fetch for reports are encrypted with AES-256-GCM in your browser, as are private chats and receipts in the vault. Choose encrypted cloud and we hold a copy we cannot open.
Private chats are visible only to you — colleagues cannot even see that they exist. When you share a chat with selected members, content is end-to-end encrypted: a key is generated in your browser and unlocked individually for each invitee — we only ever store ciphertext and cannot open it, not even for support.
Exception: receipts emailed to the org inbox are held encrypted for 30 days so every member can pull them into their vault. We hold that key — we can open the transit copy, unlike the vault. After 30 days it is deleted.
In our database, Pavora Huvudbok (the demo environment), agent proposals, OCR extractions, audit logs, and notifications are envelope-encrypted per organization (AES-256-GCM) — we can technically open them with the same server-held key. If any bookkeeping in the demo environment is older than 24 hours, the entire demo environment for that organization is wiped automatically every night. What stays readable is account structure, status, dates, and integration metadata (connected systems — not token or key values; those are client-encrypted ciphertext in the org vault). SIE and snapshot files in export/import history are stored as client-encrypted ciphertext in object storage (same org vault DEK) — we cannot read file contents at rest; metadata in the audit log is envelope-encrypted. Stripe integration keys for nightly sync are an exception: server-encrypted so cron can run without a signed-in user.
OAuth tokens, BYOK keys, and masked LLM text pass our server in flight per request (X-Pavora-Vault header or proxy to bookkeeping/Claude). “We do not store plaintext” is not the same as “we never see it.”
Controller
The controller is org. no. 559189-2897, which owns and operates Pavora (pavora.se). Contact us at kontakt@pavora.se.
What data we process
- Account details: name, email address, and password (stored hashed).
- Payment and credit: subscription status, balance, and transaction history. Card details are handled by Stripe — we do not store full card numbers.
- Usage: chat messages, uploaded documents (e.g. receipts and invoices), AI suggestions, approvals, and technical logs.
- Receipt inbox: attachments emailed to the organisation’s inbox address. Held encrypted with us for 30 days so every member can pull them into their vault, and read by AI when they arrive.
- Integrations: connections to bookkeeping systems (e.g. Fortnox, Kleer, Bokio; Visma coming soon). OAuth and API tokens and SIE/snapshot history are stored client-encrypted in the organisation's shared org vault (AES-256-GCM ciphertext with us). On each API call your browser decrypts the token and sends it in flight via the X-Pavora-Vault header; we use it in memory for that call.
- Session and device data needed for sign-in and desktop linking.
Purposes and legal bases
- Contract — to provide the account, AI assistant, bookkeeping features, and support.
- Legal obligation — bookkeeping and accounting of our own business transactions.
- Legitimate interest — to protect the service against abuse, troubleshoot, and improve the product (in a way that does not override your rights).
AI — which model and what they retain
By default, chat and document analysis go through Anthropic's API with Pavora's key. They do not train on API data. Default retention is 30 days (flagged prompts up to 2 years). We have no Zero Data Retention agreement.
On Pro you can connect your own key (Anthropic, OpenAI, Mistral, or Google); then that provider's terms and any ZDR agreement you have apply, and Pavora tokens are not deducted.
Auto-masking is on by default: personal ID numbers, company registration numbers, IBANs, email, phone, bank account numbers, addresses, person names, and supplier and customer names are replaced with random placeholders before anything is sent to the model.
When the agent reads the ledger through tools, it pauses — the tool result goes back to your browser, is masked there, and only then does the agent continue.
On Pro the organisation owner can connect their own key (Anthropic, OpenAI, Mistral, or Google). It is stored client-encrypted in the same shared org vault as OAuth tokens — ciphertext with us, key material only on devices that can unlock the vault. Everyone in the organisation uses it for chat. On each call the browser decrypts the key and sends it in flight (X-Pavora-Vault); we use it in memory and do not store plaintext. Removing the key in Pavora only deletes our ciphertext — rotate or revoke the key at the provider if you want to shut off access.
| Model | Provider | Trains on API data | Retention | Purpose |
|---|---|---|---|---|
| Claude Sonnet 5 | Anthropic | No | 30 days | Chat and document analysis |
| Claude Haiku 4.5 | Anthropic | No | 30 days | Topic filter before the main model runs |
Processors
We share data with providers needed to run the service, including: Bookkeeping providers you connect yourself (Fortnox and others; Visma when support launches)
| Provider | Role | Region |
|---|---|---|
| Supabase | Database and file storage | EU |
| Vercel | Hosting, serverless functions | EU (Stockholm) |
| Stripe | Payments | EU / US with SCC |
| Anthropic | AI models (Claude) — default, or your own key | US with SCC |
| OpenAI | AI models — only if you connect your own key | US with SCC |
| Mistral | AI models — only if you connect your own key | EU |
| AI models (Gemini) — only if you connect your own key | US/EU with SCC | |
| Fortnox / Visma / Kleer / Bokio | Bookkeeping you connect yourself | Per their terms |
| Postmark | Transactional email and any receipt inbox | US with SCC |
Some providers may process data outside the EU/EEA. In that case appropriate safeguards are used, e.g. the European Commission’s standard contractual clauses, where required.
Cookies and sign-in
We only use necessary cookies. No analytics, no ads, no third-party telemetry in the browser. You can verify this in DevTools.
| Name | Where | Contents | Purpose | TTL |
|---|---|---|---|---|
| redovis_session | cookie | Opaque session key | Keep you signed in | 30 days |
| NEXT_LOCALE | cookie | sv | en | Language preference | 1 year |
How long we keep data
| Data | Period | Basis |
|---|---|---|
| Account and profile | While the account is active | Contract |
| Inactive account | 24 months without activity, then email and deletion after 30 days. Active subscriptions are excluded. | Storage limitation (GDPR art. 5) |
| Chat and receipts in the vault | On your device, AES-256-GCM. The server holds empty stubs, or ciphertext if you chose encrypted cloud. Conversations from before the vault existed are migrated into it automatically the first time you open the app with it unlocked — the server is zeroed for those too. | Contract |
| Receipt inbox (transit) | Up to 30 days after the email arrives. Encrypted with us using a key we hold, so every organisation member can pull a copy into their vault. The transit copy is then deleted. What is already in the vault follows the row above. | Contract |
| Conversation title | Generated locally from your own first message, not by the server. The server never sees the content it comes from. | Contract |
| Shared chats | End-to-end encrypted (AES-256-GCM), key held only by invited devices — we cannot open it. Kept until the conversation is unshared or deleted. | Contract |
| Bookkeeping system connection (Fortnox, Visma, Bokio, Kleer) | Client-encrypted in the organisation's shared org vault (AES-256-GCM ciphertext with us). OAuth for Fortnox and Visma; API tokens for Bokio and Kleer. Decrypted in the browser and sent in flight per call (X-Pavora-Vault). Kept until you disconnect or the organization is deleted — disconnecting deletes our ciphertext, not the token at the provider (rotate there if you want to shut off access). | Contract |
| SIE / snapshot history (export, import, pre-clear backup) | File bytes client-encrypted in object storage with the org vault DEK (AES-256-GCM) — we cannot open contents at rest. Metadata (filename, period) envelope-encrypted in the audit log. Kept until the organization is deleted. | Contract |
| Own AI key (BYOK) | Client-encrypted in the same org vault as OAuth tokens. The organisation owner saves the key under Settings → Language model; all members use it. Sent in flight per call (X-Pavora-Vault). Kept until the owner removes it — then our ciphertext is deleted; rotate or revoke the key at the provider separately. | Contract |
| Reports from Fortnox and others | In your on-device vault. No readable copy with us. | Contract |
| AI usage (tokens, amounts, model — not prompt text) | As long as billing requires, then anonymized | Contract / our own accounts |
| Our own payment records (Stripe) | 7 years | Swedish Bookkeeping Act |
| Session | 30 days | Security |
| Anthropic (prompt + completion) | 30 days at Anthropic | Their API terms |
Your rights (GDPR)
You have the right to:
- receive information about and access to your personal data
- request correction of inaccurate data
- request erasure ("the right to be forgotten")
- request restriction of processing
- object to processing based on legitimate interest
- receive data in a portable format (data portability)
- lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se imy.se
Download your data
You can download a copy of your personal data under Account (/app/account/konto) when signed in — the "Download my data" button. That is the primary way. If you need help, email kontakt@pavora.se from the account address.
Delete account
You can delete your account and related personal data at any time. Do it primarily under Account (/app/account/konto) when signed in. If you cannot access the account, email from the address linked to the account to kontakt@pavora.se with the subject line "Delete my Pavora account". We confirm and carry out deletion without undue delay, normally within 30 days, unless law requires certain data to be kept longer (e.g. payment records).
Contact
Questions about personal data, your rights, or this policy: kontakt@pavora.se. Terms of use and the bookkeeping disclaimer are under Terms of use. Terms of use.