docs(legal): align in-repo privacy and DPA pages with actual AI subprocessor facts (#1770)

* docs(legal): align in-repo privacy and DPA pages with actual AI subprocessor facts

The published marketing-site DPA claimed Anthropic PBC and OpenAI Inc (USA)
as AI subprocessors. Ground truth: AI inference runs Anthropic Claude models
operated by AWS via Amazon Bedrock in eu-north-1 (Stockholm); no data is sent
to Anthropic as a company and there is no third-country transfer. This commit
updates the in-repo /privacy and /dpa pages to state that fact explicitly,
discloses PostHog deny-by-default session-replay masking, and bumps the
last-updated dates to 2026-08-20. The marketing-site pages are outside this
repo and still need manual edits.

Part of #1674

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(legal): fix systemdokumentation AI integration row, defer page wording to #1766

Resolves the CodeRabbit findings on PR #1770 in one pass:

- public/docs/systemdokumentation-mall.md said transaction and document
  data flows Accounted -> Anthropic -> Accounted. Corrected to Amazon
  Bedrock (AWS, eu-north-1 Stockholm) with Anthropic Claude models
  running inside Bedrock; data does not leave the EU.
- The privacy and DPA page edits this PR originally carried are dropped:
  PR #1766 merged the same #1674 alignment first with wording pinned by
  app/(public)/privacy/__tests__/ai-and-replay-disclosures.test.ts,
  which forbids the DPA naming Anthropic and forbids the Bedrock row
  asserting sub-processor status either way. Both pages are now
  byte-identical to main.

Part of #1674

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(legal): self-host note in systemdokumentation template AI row

Swedish compliance review on PR #1770: the blanket 'datan lamnar inte EU'
claim in the Amazon Bedrock integration row is only true for the hosted
default configuration. A self-hosted operator running AI_PROVIDER=anthropic
or a custom AI_BASE_URL endpoint who fills in this template unchanged would
produce systemdokumentation that misstates the data flow (BFNAR 2013:2
kap 8 requires the documentation to describe the actual system). Adds a
bracketed template note, in the same style as the existing integrations
placeholder, telling self-hosted operators to update the row to their
actual provider, region and data flow.

Part of #1674

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-08-21 16:59:14 +02:00
committed by GitHub
co-authored by Claude Fable 5
parent f93152c397
commit a2c9a12cfc
2 changed files with 5 additions and 1 deletions
+3 -1
View File
@@ -252,13 +252,15 @@ Momsperiod: [ ] Månad [ ] Kvartal [ ] Helår
|---|---|---|
| Enable Banking (PSD2) | Bankkontosynkronisering | Bank -> Accounted (läsning av transaktioner och saldon) |
| Skatteverket | Momsdeklaration, arbetsgivardeklaration (AGI), skattekonto | Accounted -> Skatteverket (inlämning signeras med BankID) |
| Anthropic (Claude) | Maskinell kategorisering av transaktioner och avläsning av underlag | Accounted -> Anthropic -> Accounted (transaktions- och dokumentdata skickas, förslag returneras) |
| Amazon Bedrock (AWS) | Maskinell kategorisering av transaktioner och avläsning av underlag. Modellerna som används är Anthropics Claude-modeller, körda inom Bedrock (eu-north-1, Stockholm) | Accounted -> Amazon Bedrock -> Accounted (transaktions- och dokumentdata skickas, förslag returneras; datan lämnar inte EU) |
| Resend | E-postutskick | Accounted -> Resend -> mottagare (fakturor, påminnelser) |
| BankID (via identitetsleverantör) | Inloggning och signering | Accounted -> leverantör -> Accounted |
| PostHog | Användningsstatistik för tjänsten | Accounted -> PostHog |
[ANGE YTTERLIGARE INTEGRATIONER OM TILLÄMPLIGT, t.ex. import från Fortnox, Visma, Bokio, Björn Lundén eller Briox]
[SJÄLVHOSTAD DRIFT: raden för Amazon Bedrock ovan beskriver den hostade tjänstens standardkonfiguration. Om din installation använder en annan AI-leverantör (t.ex. AI_PROVIDER=anthropic med direkt Anthropic-API, eller en egen endpoint via AI_BASE_URL) gäller inte skrivningen "datan lämnar inte EU" automatiskt; uppdatera raden så att den beskriver din faktiska leverantör, region och ditt faktiska dataflöde]
**Notering om maskinell behandling:** förslag från maskinella hjälpmedel bokförs aldrig automatiskt utan att en användare har granskat och godkänt dem. Godkännandet loggas i behandlingshistoriken.
## 12. API-nycklar och maskinell åtkomst