Trust
Trust Center
Last reviewed: October 7, 2026
Bannervora is a product of RUNEX DIGITAL SDN BHD, Malaysia. This page is for procurement, security and legal teams evaluating us. It complements our Security overview and our Privacy Policy.
Sub-processors
Third parties that may process customer data on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online | Application servers and primary PostgreSQL database | Germany (EU) |
| Cloudflare | CDN, TLS and edge protection; R2 object storage for generated assets (default storage provider) | Global edge network |
| Stripe | Subscription billing and payments (card data never reaches our servers) | Global |
| Resend | Transactional email (verification, notifications, contact form) | United States |
| Sentry | Application error monitoring | United States |
| Anthropic | AI template generation (only when you use AI features) | United States |
| Google (Gemini API) | AI background artwork generation (only when you use AI features) | Global |
| Google (Fonts API, OAuth) | Font catalog for the template editor; optional Sign in with Google | Global |
If you connect your own storage (AWS S3, Google Cloud Storage, Firebase) or integrations such as Slack, those providers process data under your own agreement with them, in the region you choose.
Data residency
Our application servers and primary database are hosted in the European Union (Germany). Generated assets are stored in Cloudflare R2 by default, or in the storage bucket and region you configure for your workspace.
Data protection: GDPR and PDPA
For account data we act as controller; for the content in your workspace (feeds, templates, generated assets) we act as processor on your instructions. We design our data handling around the principles of the EU/UK GDPR and Malaysia's Personal Data Protection Act 2010 (PDPA). Where data is transferred outside the EEA/UK, we rely on the recipient's Standard Contractual Clauses or equivalent safeguards. We do not sell personal data. Legal bases and your rights are set out in the Privacy Policy.
Security practices
- TLS for all traffic, terminated at Cloudflare with strict origin certificates.
- Workspace storage credentials encrypted with AES-256-GCM.
- Passwords hashed with bcrypt; rate-limited authentication.
- Daily database backups.
Full details are on the Security page. We do not currently hold SOC 2 or ISO 27001 certification.
DPA and security questionnaires
A Data Processing Agreement and completed security questionnaires are available on request. Email [email protected].