Sovereignty & compliance

The procurement answers, in one place.

Radist Systems AB is a Swedish company running EU infrastructure under EU law. This page covers jurisdiction, data paths, sub-processors, retention, and the paperwork your legal team will ask for. See how this compares to a US vendor's EU region →

Privacy policy

Jurisdiction

Radist Systems AB is a Swedish Aktiebolag (registration number 559586-3878). The company, its production infrastructure, and the real-time data path are governed by EU law — principally the GDPR and the Swedish Data Protection Act (2018:218).

Radist is not a US entity. Service data processed for real-time sessions is not subject to US compelled-disclosure regimes such as the CLOUD Act.

Roles under GDPR

For real-time sessions initiated by your application, you are the controller and Radist Systems AB is your processor. Radist processes data only on your documented instructions — through the API, SDKs, and normal product features.

For Radist's own business operations (website, dashboard accounts, billing), Radist Systems AB acts as controller. See the Privacy Policy for those activities.

Data path & termination locations

All production infrastructure runs in Hetzner data centres in Germany and Finland (EEA). Participants outside the EEA connect to the nearest European edge.

Signaling

Session setup messages between participants. Terminates inside the EEA. Payloads are not stored beyond the live session.

Peer-to-peer calls

Media flows directly between participants when the network allows. Radist coordinates discovery; encrypted media does not pass through Radist servers.

TURN relay

When peers cannot connect directly, encrypted media is relayed through Radist TURN servers inside the EEA. Payloads are not stored.

Multiparty rooms (SFU)

By default, end-to-end encryption (WebRTC Insertable Streams, per-frame AES-GCM) keeps media unreadable in transit: the SFU forwards encrypted frames between participants and only reads unencrypted codec headers. Encryption keys are exchanged directly between participants and never reach Radist. Where a browser lacks Insertable Streams, media falls back to standard DTLS and is decrypted at the SFU hop. Servers run inside the EEA; media is never recorded, transcribed, or persisted.

Data minimisation

  • Media streams are not recorded, transcribed, or stored.
  • Radist does not require name, email, or other directly identifying data for your end users — you supply opaque participant identifiers via tokens.
  • Session metadata (connection IDs, timestamps, byte counts) is retained for 30 days for billing and abuse review, then deleted.
  • Encrypted backups are rotated within 30 days.

Retention

Data categoryRetention
Real-time session metadata30 days, then deleted
Signaling payloadsNot stored beyond the live session
Media (P2P, relay, SFU)Not stored
Account dataWhile active; deleted within 90 days of account closure
Accounting records7 years per Swedish Bokföringslagen
Encrypted database backups30 days, then automatically deleted

Sub-processors

Radist engages the following sub-processors. Customers are notified at least 30 days before any addition or replacement affecting service data processing.

Hetzner Online GmbH

Role
Infrastructure hosting (compute, storage, network, backups) for all Radist services.
Data
All customer personal data processed by the service.
Location
Germany / Finland (EEA)
Transfers
None required (intra-EEA).

Stripe Payments Europe, Ltd.

Role
Subscription billing, payment method storage, invoicing.
Data
Billing contact name, email, billing address, payment card token, transaction history. End-user call data is not shared with Stripe.
Location
Ireland (EEA), with onward processing by Stripe, Inc. in the United States.
Transfers
EU Standard Contractual Clauses (2021/914); transfer impact assessment on file.

Google LLC

Role
OpenID Connect sign-in for dashboard users who choose Google.
Data
Sign-in identifier, email, name. End-user call data is not shared with Google.
Location
United States
Transfers
EU Standard Contractual Clauses; Google Cloud DPA. Applies only when the dashboard user chooses Google sign-in.

GitHub, Inc.

Role
OAuth sign-in for dashboard users who choose GitHub.
Data
Sign-in identifier, email, name. End-user call data is not shared with GitHub.
Location
United States
Transfers
EU Standard Contractual Clauses; GitHub DPA. Applies only when the dashboard user chooses GitHub sign-in.

Schrems II & international transfers

The real-time service data path does not involve transfers outside the EEA. Standard Contractual Clauses are therefore not required for signaling, relay, or multiparty media.

Transfers outside the EEA are limited to ancillary services you may opt into: Google or GitHub sign-in for dashboard accounts, and Stripe for billing. Each is covered by EU SCCs and the respective provider's data processing terms.

CLOUD Act

US-based WebRTC platforms are typically US entities subject to compelled disclosure under the US CLOUD Act. Radist Systems AB is a Swedish company with no US corporate parent. Real-time session data processed on Radist infrastructure is outside US jurisdiction.

DPA & Record of Processing Activities

A signed Data Processing Agreement is available on request before you commit. The DPA includes:

  • Processing details (subject matter, duration, data categories, operations)
  • Sub-processor schedule (mirrored on this page)
  • Technical and organisational security measures
  • Breach notification commitments (within 72 hours of confirmation)

Radist maintains an internal Record of Processing Activities (RoPA) under GDPR Article 30, reviewed at least annually and updated when processing activities materially change.

Security measures

  • TLS 1.2+ for all HTTP and WebSocket traffic
  • DTLS-SRTP for all real-time media
  • Database storage and backups encrypted at rest
  • Per-project scoped API keys; secret keys never logged in plaintext
  • MFA on all administrative and infrastructure access
  • Network isolation between public-facing services and internal datastores

Frequently asked questions

Who is the controller and who is the processor?

You are the controller for your application end users. Radist Systems AB is your processor for real-time session infrastructure. The signed DPA reflects this without modification.

Does real-time data leave the EEA?

No. Signaling, relay, and multiparty media all terminate inside the EEA. Participants outside the Union connect to the nearest European edge — not a US point of presence.

Is Radist subject to the US CLOUD Act?

Radist Systems AB is a Swedish company operating under EU law on EU infrastructure. It is not a US entity and is not subject to US compelled-disclosure orders for service data.

Do I need Standard Contractual Clauses for the real-time service?

No. The real-time data path does not involve transatlantic transfers. SCCs apply only to ancillary services where you opt in — such as Google or GitHub sign-in for dashboard accounts, or Stripe for billing.

Is media recorded or stored?

No. Calls are not recorded or transcribed. Session metadata (identifiers, timestamps, byte counts) is retained for 30 days for billing and abuse review, then deleted.

How do I get a DPA?

Email to request a signed Data Processing Agreement before you commit. The DPA includes processing details, sub-processor schedules, and technical and organisational measures.

What retention periods apply?

Real-time session metadata: 30 days, then deleted. Account data: while the account is active, deleted within 90 days of closure. Accounting records: 7 years per Swedish Bokföringslagen. Encrypted backups: rotated within 30 days.

Can I review sub-processors before signing?

Yes. The current list is published below. Radist notifies customers at least 30 days before adding or replacing a sub-processor for service data processing.

Contact

Data protection and DPA requests:

Privacy questions: