Trust & Privacy

Data Processing at ScanKit — Concrete and Verifiable

This page answers the questions that decision-makers ask in vendor reviews and GDPR assessments. Updated: September 2026.

1. Hosting Region

ScanKit processes documents in the EU (Heroku region eu, data center in Ireland). No document content leaves the EU for processing. This applies to the API scan path, the hosted scanner, and the SDK — all run on the same infrastructure.

2. Processing vs. Storage

Documents are processed transiently at ScanKit and are not stored:

  • The upload (photo or PDF) is read into the memory of the processing server
  • Cleanup (perspective correction, cropping, flattening) runs entirely in-memory (BytesIO)
  • Only the result is returned — the cleaned scan (JPG or PDF)
  • The original upload no longer exists on any storage medium after the response

The only persistent use of user files on the platform is scanner logos (branding images a customer deliberately uploads for their hosted scanner) — these are not documents and are not part of scan processing.

3. Deletion Policy

Immediately after processing. Since documents are never written to a storage medium, there is no retention period, no backup remnant, and no debug cache containing document content. There is simply nothing to delete — processing is in-memory and ends with the HTTP response.

4. Encryption

  • In transit: TLS 1.2+ for all uploads and downloads (api.scankit.io, www.scankit.io)
  • At rest: Documents are not stored (see point 2); for the only stored non-document data (accounts, keys, logos, usage metadata), the hosting provider's encrypted storage mechanisms apply

5. Subprocessors

The following service providers process data in ScanKit operations:

ProviderPurposeRegionDocument content?
Heroku (Salesforce)App hosting + processingEU (Ireland)Yes — transient (in-memory)
StripePayment processing (credit packs)EU/USNo — payment data only
SentryError monitoringEU/USNo — technical error details only, no documents
S3-compatible storage (scanner logos)Hosted scanner branding imagesconfiguredNo — logos only

This list is updated when changes occur.

6. Logging and Metadata

Only technical usage data without document content is logged: endpoint, timestamp, API key ID, status code, credit usage. Document files, content, or content hashes are not logged.

7. DPA (Data Processing Agreement)

A DPA is available. Contact: info@scankit.io — we deliver it within one business day.

8. Incident and Support Process

  • Contact: Martin Stämmler (operator), info@scankit.io
  • Response time: within one business day
  • Data-related incidents: affected customers are notified directly by email as soon as confirmed

This page is updated when infrastructure or providers change. Questions about specific points are answered directly: info@scankit.io.

Questions about a specific point?

We answer vendor-review questions directly and deliver the DPA within one business day.

Contact us