Data residency & transfers

Ask where data is stored and where people can access it.

ActLume plans to host production customer data in an approved EU region. The application is not deployed, so we cannot yet name the live region, provider paths, or transfer safeguards.

The production data map

Trace the whole data path.

Check the service, database, storage, backups, logs, support access, and every processor that can receive or reach customer data.

01

Primary systems

Application compute, authoritative database, and customer file storage.

02

Operational copies

Backups, recovery material, logs, exports, and temporary processing.

03

Human access

Support, administration, incident response, and authorised remote access.

04

Service providers

Email, billing, monitoring, delivery, support, and other processors actually used.

Before the application launches

ActLume will publish these details before launch.

The final disclosure will describe the deployed release, including exceptions and access paths. A planning diagram is not enough.

Location and scope

  • named production region for each customer-data service;
  • backup, log, and disaster-recovery locations;
  • data categories covered by each statement;
  • exceptions and operational access paths.

Transfer transparency

  • processors and subprocessors;
  • support and administrative access;
  • applicable transfer mechanism and safeguards;
  • change-notification and review process.

Buyer review

Six questions to ask a SaaS provider.

01Which data and which service does the residency statement cover?

02Where are backups, logs, exports, and recovery copies kept?

03Can support or provider personnel access the data from another country?

04Which subprocessors receive data, and for what purpose?

05What transfer mechanism applies, and how is it reviewed?

06How will customers be told when the data map changes?

Current status

Live hosting details will arrive with the application.

View application status