For teams buying software in the European Union
GDPR-compliant task routing, hosted in the EU
Fivexer is an Estonian company. The cloud runs in Frankfurt, the standard DPA is published rather than negotiated, this site sets no cookies — and the open-source engine self-hosts, which removes the processor question altogether.
- Company: Testreel OÜ, Estonia
- Cloud region: Frankfurt, Germany (fra1)
- Engine: open source (MIT), self-hostable

What crosses the border, and what doesn't
Every class of data the platform holds, on one side of the border or the other — the same subprocessor list the security page publishes, so the two cannot disagree. Set it to how you would actually run it. Two of these rows are your choice rather than a condition of using Fivexer.
How you would run it
The hosted platform with every feature turned on. This is the state the rest of this page describes.
- Account recordsNames, email addresses, password hashes, session records.StaysDigitalOcean
- Workspace configurationTeams, skills, routing rules, API keys, worker identities.StaysDigitalOcean
- Task contentEverything you send us to route, including its description and comments.StaysDigitalOcean
- AttachmentsFiles uploaded against a task, in object storage.StaysDigitalOcean
- Routing stateQueues, backlogs, who holds what right now.StaysDigitalOcean
- Decision tracesWho was eligible for each task, who was ruled out, and why.StaysDigitalOcean
- Control-plane backupsAutomated database backups, same region as the database.StaysDigitalOcean
- Routing-state backupsAppend-only-file persistence on a volume in the same cluster.StaysDigitalOcean
- Marketing-site analyticsAnonymous pageviews on the public site. Never the console, never the API.StaysPostHog
- Transactional emailThe recipient address and the message — verification, resets, portal invitations. No task content.CrossesSendGrid (Twilio) — United StatesSafeguardStandard Contractual Clauses in the provider’s data processing addendumRemove itSelf-host the engine: there is no Fivexer account, so there is no email to send.
- Worker-Portal Studio promptsOnly the prompts and portal source files exchanged while building a portal. Opt-in feature.CrossesDigitalOcean Inference — United StatesSafeguardStandard Contractual Clauses in the provider’s data processing addendumRemove itLeave the Studio switched off. A workspace that never opens it never reaches the inference endpoint.

Two doors, and the second has no processor at all
Fivexer Cloud is the convenient answer. The open-source engine is the absolute one. They are the same routing engine — the difference is whose infrastructure it runs on.
Fivexer Cloud
We are your processor. You stay the controller.- Runs in Frankfurt, Germany — one region, no US failover.
- The Article 28 DPA is published and already in force via the terms.
- Four subprocessors, all named, two of them outside the EEA with safeguards.
- Free to start, and nothing to install.
The self-hosted engine
No processor relationship. Nothing to assess.- Runs on your Redis, in your infrastructure, in whichever region you choose.
- No personal data reaches Fivexer, so there is no DPA to sign with us and no transfer analysis to file.
- Decision traces stay in your Redis — evidence for your own records of processing, not ours.
- MIT-licensed as the npm package assignment-user-matcher. No licence server, no telemetry, nothing to audit but the code.
What we commit to, in numbers
The figures a data protection officer writes into a register — each one a promise the operation keeps, which is why none of them is an availability percentage.
A human answers you
1 working day
Support and procurement requests alike. Service-affecting issues are worked the day they are reported.
An account deletion is completed within
30 days
Deleting a single workspace is self-serve and takes effect immediately — you do not need to ask us.
A security report is acknowledged within
3 days
Acknowledgement, not resolution — only one of them can be put on a clock in advance.
Notice before launch pricing changes
60 days
In writing, to the account email — and the launch allowance survives a further 6 months past that notice for workspaces created during launch.
Cookies this site sets
0
There is no consent banner here because there is nothing to consent to. The marketing pages use cookieless analytics on PostHog's EU cloud; the console and the API carry no analytics at all. The one thing this site keeps on your device is your light-or-dark choice.
What we don't have
The gaps, printed where you will find them now rather than in diligence later.
- No SOC 2 or ISO 27001 yetWhat covers it today: the routing engine is open source and publicly auditable, and the full test suite gates every npm publish. A certificate is the plan, not the current state.
- No uptime SLAA human answers support and procurement requests within 1 working day, and service-affecting issues are worked the day they are reported. A contractual availability percentage is not offered yet.
- Two flows still leave the EEATransactional email (SendGrid) and the optional AI portal builder, which runs on DigitalOcean's own inference platform rather than a third-party AI provider — three companies in the chain, not four. Both are under Standard Contractual Clauses and named on the ledger above, because a subprocessor list that omits one is worse than none at all.
- One region, and no choice of regionFivexer Cloud runs in Frankfurt for every customer. If your own rules require data in a particular country, self-host the engine and pick the region yourself.
The questions a DPO asks
The GDPR questions a data protection officer asks first — hosting region, DPAs, transfers, cookies — answered in one place.
Is Fivexer GDPR compliant?
Fivexer is the processor for your routing data and you stay the controller. The platform runs in Frankfurt, Germany, the standard Article 28 DPA is published at /dpa, and the subprocessor list is on /security — including the two flows that leave the EEA, with their transfer safeguards.
Where is my data hosted?
All platform data — accounts, workspaces, tasks, routing state, decision traces — is hosted in Frankfurt, Germany (DigitalOcean region fra1). Transactional email goes through SendGrid in the United States, and the optional AI portal builder through DigitalOcean’s own inference platform, which has no EU region — both under Standard Contractual Clauses.
Do we need a DPA with Fivexer?
For Fivexer Cloud, yes — the standard Article 28 DPA is published at /dpa and already in force via the terms. If you self-host the open-source engine instead, no personal data reaches Fivexer at all, so there is no processor relationship and no DPA to sign with us.
Does this website use cookies or trackers?
No. The marketing pages use cookieless analytics on PostHog's EU cloud — nothing is stored on your device, so there is no consent banner. The console and the API carry no analytics at all.
What does Fivexer do about Schrems II?
Routing data does not leave the EU. Two flows do — transactional email and the optional AI portal builder — both under Standard Contractual Clauses and named on /security. The portal builder runs on DigitalOcean’s own inference infrastructure rather than a third-party AI provider, so three companies are involved in total, not four. Self-hosting the engine removes even those: nothing is transferred because nothing is shared.
Is Fivexer a European company?
Yes. Fivexer is operated by Testreel OÜ, a company registered in Estonia, an EU member state. There is no US parent and no US entity in the contract chain — the agreement you sign is with an EU company, governed by EU law.
Can we run the routing engine ourselves?
Yes. The engine is the MIT-licensed npm package assignment-user-matcher and it runs on your own Redis, in your own infrastructure. There is no licence server and no telemetry, so no personal data reaches us and there is nothing to put through a transfer assessment.
Do you hold SOC 2 or ISO 27001?
No, and neither is claimed anywhere on this site. What covers it today: the routing engine is open source and publicly auditable, and the full test suite gates every release. The complete list of what we do not hold is printed on /security rather than left for diligence to find.
What you get
- The standard Article 28 DPA, as a document you can circulate
- The subprocessor list, each one's location and its safeguard
- The residency table: every store, its region, its backups
- The two transfers outside the EEA, and the change that removes each
- What we do not hold — SOC 2, ISO 27001, an uptime SLA — in writing
One email from a person, within 1 working day. Nobody rings you unless you ask.