1. In short
This page describes how Frontier Solutions protects Taktbygg. It is written for customers and for anyone reviewing a supplier. It is a public overview. It is not a certificate, not a penetration-test report, and not a promise of uptime.
Frontier Solutions is established in Sweden. Taktbygg is the product name.
When a customer company uses Taktbygg, the company is responsible for the project data. Frontier processes that data on the company's instructions. That processing is governed by the data processing agreement. Frontier's own processing of visits and accounts is described in the privacy policy.
More detailed material, such as the security annex to the agreement, is given to the customer. It is not published here.
Taktbygg has no AI feature of its own and does not send customer data directly to an AI provider. For ordinary email, Resend states that content is not sent to Anthropic. Resend also states that RunPod processes a small sample of emails for trust and safety on dedicated infrastructure. According to Resend, neither Resend nor these subprocessors use customer content to train or fine-tune models.
2. Who is responsible
| Supplier | Mikael Persson, who carries on a sole trader business under the name Frontier Solutions. Taktbygg is the product name. |
|---|---|
| Address | Myrbacksgatan 27c, 703 81 Örebro, Sweden |
| Website | https://www.taktbygg.se |
| Security and vulnerabilities | mikaelperssonx@outlook.com |
| Personal data | mikaelperssonx@outlook.com |
| Support | support@taktbygg.com |
| Data protection officer | No data protection officer has been appointed. |
3. What the service handles
| Type | Examples |
|---|---|
| Account | Name, email and organisation name. Phone number, organisation number and profile image if the user provides them. Passwords are stored as a hash, not in plain text. |
| Organisation, project and access | Roles, invitations, verified contractor email addresses, and the status and validity of shareable information-screen links. |
| Project data | Schedule, zones, activities, notes, possible staffing, mentions and notifications. |
| Files | Drawings and other documents the customer uploads. |
| Service email | Recipients, subject, content and delivery data for notices, mentions and hindrances. A generated schedule PDF may be attached. Uploaded drawings and other project files are not sent as attachments. |
| Operational logs | IP address, user agent, time and request metadata at the hosting providers. Some schedule changes also have audit records in the project database. |
The service is not intended for special categories of personal data, such as health data.
4. Where the data is processed
| Part | Provider | Location |
|---|---|---|
| Web application | Vercel Inc. | Functions run in Stockholm (arn1). Requests first enter Vercel's global CDN and edge network and may pass through an entry point outside Sweden or the EU/EEA. Static application files may be served close to the user; the CDN is not the store for project data. Runtime log: 1 day on the current Pro plan without Observability Plus. |
| Database, sign-in and files | Supabase Pte. Ltd. | The contracting entity is established in Singapore. The primary database, authentication and object storage are in Stockholm (eu-north-1). Supabase platform logs are kept for 7 days. Remote platform and support access may be a transfer. |
| Authentication email | Supabase Auth | Supabase Auth sends the invitation as account confirmation, and password reset, through Resend (SMTP, mail.taktbygg.se). Sending from Ireland, storage in the USA according to Resend. Invitations to external customer addresses were delivered that way, read in Resend on 24 September 2026. Password reset uses the same sending. |
| Service email | Plus Five Five, Inc. (Resend) | Sending from Ireland (eu-west-1). Content and logs are stored in the United States, according to Resend. |
The direct subprocessors are Supabase, Vercel and Resend. They in turn engage sub-processors for purposes including cloud infrastructure, CDN/cache, logging, backup, monitoring and e-mail infrastructure. The current list is in Taktbygg’s sub-processor register.
Customers with a data processing agreement are notified at least 30 days before Frontier adds or replaces a direct subprocessor. Notice for providers further down the chain depends on the direct provider's notice.
A transfer outside the EU/EEA is supported by the EU standard contractual clauses, module 3, in the relevant provider's data processing agreement. Vercel and Resend also state that they are certified under the EU–US Data Privacy Framework. That statement is the provider's own.
Physical security in the data centres is handled by these providers. A database in Stockholm does not mean that every processing step stays in Sweden. Remote access for operations and support can also be a transfer.
5. Sign-in and access
Sign-in uses email and password. The password is stored as a hash by the authentication provider, not in plain text at Frontier. For signed-in accounts, project data becomes available only after the authentication provider has confirmed the email address. Multi-factor authentication is not offered to the customer's users. Frontier's accounts at Supabase, Vercel and Resend have it turned on. There is no sign-in through a customer's own identity service.
Normal access is decided on the server, by organisation and project role, with row-level control in the database. A confirmed email address that the customer has recorded as a verified contractor address can also provide read access. Frontier has a specially privileged operator role. The isolation has not been reviewed in an external penetration test.
A project administrator can create a shareable read-only link to a limited PPU or takt display. A person holding the link does not need an account and can share it further. The default validity is 30 days and the maximum is two years. The link can be revoked or replaced. The display shows the schedule, completion, contractor names and hindrances. It does not show uploaded drawings, email addresses or passwords. The customer is responsible for who receives the link and for revoking it when it is no longer needed.
The customer invites the people who should have access. Frontier accesses customer data for support, security or a legal need, after a request from the customer or when there is a documented operational need.
Drawings and other uploaded files are kept in private object storage. They are fetched with time-limited links. The customer decides who may see the documents.
Browser notifications are not part of the ordinary service. The feature is off in the application code unless it is explicitly switched on. New subscriptions therefore cannot be created, and sending to a browser push service is not an approved data flow.
6. Encryption
Traffic between the browser and Taktbygg uses HTTPS with TLS 1.2 and TLS 1.3 through Vercel. Traffic to Supabase uses TLS according to that provider.
Data at rest is encrypted with AES-256 according to Supabase, for the primary database, authentication and object storage in Stockholm. The keys are managed by the provider. Frontier does not use customer-managed keys. Frontier therefore cannot rule out that a provider with lawful access can decrypt the data.
7. Copies and recovery
The database is backed up daily at Supabase. On the current Pro plan the last seven days are kept. The copies do not include uploaded files, only data about them. Uploaded files are not restored. The customer shall keep its own originals of drawings and other files.
A database restore can be requested through the provider. There is no scheduled restore test with the customer. Frontier does not commit to a target for how much data may be lost or how long a restore takes. There is no uptime promise.
Email content and delivery logs at Resend are kept for 30 days. Resend states that backups are kept for seven days. After the Resend account is closed, remaining customer data is deleted within 90 days under Resend’s data processing agreement.
8. Testing and operations
Production is separate from a test environment. Automated tests run in the repository, including checks that privileged keys are not exposed to the browser. Changes to access control are tried in the test environment before production.
Logs at Vercel and Supabase are reviewed when there is an incident, a support case or a security event. There is no continuous security monitoring and no scheduled external penetration test.
9. Incidents
Towards a customer with a data processing agreement, Frontier notifies a personal-data breach without undue delay and in any event within 24 hours of Frontier becoming aware of it. Another security incident that materially affects the customer's data is notified within 72 hours. Awareness may come from a vulnerability report, from the customer, or from a provider. There is no round-the-clock monitoring. The notice contains what is known at the time. More may follow. The customer notifies the supervisory authority when the customer is the controller. Frontier assists with the information it has.
10. What is not in place
- Frontier has no ISO 27001 certification and no SOC 2 report. Those attestations concern how a company is governed, not the code itself. Resend publishes its own SOC 2 material. That is Resend's report, not Frontier's.
- No external penetration test has been carried out.
- Multi-factor authentication is not offered to the customer's users. It is turned on for Frontier's accounts at Supabase, Vercel and Resend.
- The customer cannot bring its own encryption keys.
- No uptime promise, and no target for restore time or data loss.
- No scheduled test that a backup can be restored.
11. What the customer is responsible for
- Appointing who administers the project.
- Inviting only people who may see the schedule and the documents.
- Judging how sensitive its own documents are.
- Telling us when a person should be removed.
- Keeping its own originals of uploaded files.
12. Report a vulnerability
Write to mikaelperssonx@outlook.com. Describe what you saw and how it can be repeated. Do not attach other people's personal data or files. Say how we can reach you.
Reports concern www.taktbygg.se and the Taktbygg application. They do not concern other customers' data, attempts to manipulate staff or customers, physical access, or the infrastructure of Vercel, Supabase, Resend or their subprocessors. Those matters belong with the relevant provider.
Do not enter a project where you do not have a role. Do not change or delete data that is not yours. Do not disrupt the service, for example by overloading it.
We ask for 90 days from the report before the issue is made public, so that we can fix it. We do not pay a reward. We acknowledge the report when we have read it.
We will not take legal action against a person who reports in good faith and stays within the limits above. The limits protect other customers' data and the operation of the service. They are not permission to enter someone else's project or to disrupt the service.
13. Changes
The date and version number above change when this text changes. The page is reviewed when the protection changes in a material way, and at least once a year. A customer with a contract is told about a change that concerns that customer.