ZoikoDigital
Data Location and Residency

Know where data is handled — and what each location actually means

Storage, processing, replicas, backups, access, transfers, failover, and exports are separate concepts with separate evidence. Each carries its scope, status, effective date, limitations, and owner. None of them proves the others.

PrivacySecurityPlatform ReliabilitySystem Status

A governance lead reviewing storage, processing, access, and transfer locations across a global data map

Scope invariant

A map pin is not a residency guarantee. A location claim must explain what data, why it is there, who can access it, what copies and exceptional paths exist, and how the statement is verified.

Definition Boundary

Eleven Terms That Are Routinely Collapsed Into One

Most misleading location claims are not lies. They are one true statement presented as if it answered a different question. The third column is where that happens.

TermDefinitionWhat it does not prove
Data locationA named country, region, facility jurisdiction, or provider region associated with a defined handling activity.Does not by itself prove residency or exclusive handling.
Primary storageThe approved principal persistent store for a defined data category and environment.Replicas, indexes, caches, logs, and backups remain separate.
ResidencyA scoped operational or contractual commitment that designated data is stored or handled within defined locations and conditions.Meaningless unless it states data, copies, processing, access, transfers, and exceptions.
Processing locationWhere a service, provider, or authorized human performs an operation on data.May differ entirely from storage location.
Access locationWhere an authorized person or service can reach data.Remote access may cross a border without moving the primary store.
ReplicationAdditional copies maintained for availability, performance, integrity, or recovery.Replica location and consistency model are separate evidence.
Backup / archiveCopies retained for recovery, continuity, legal hold, or approved archival purpose.Deletion and access timing differ from primary storage.
TransferDisclosure, remote access, transmission, or movement across an organizational or geographic boundary.The technical path and the legal mechanism are distinct things.
Failover / disaster recoveryTemporary or sustained use of alternate systems or locations after defined conditions.Emergency paths require explicit scope and governance — they are not silent exceptions.
Customer-controlled destinationA location created by customer export, integration, download, forwarding, or local storage.Customer responsibility begins at the defined handoff.
Data localization requirementA legal, regulatory, contractual, or policy condition on location or handling.ZoikoTime does not determine whether one applies to you, and gives no legal advice.

A worked example

"Primary storage in the EU" can be entirely true while a replica sits elsewhere for recovery, a support engineer accesses the record remotely from another country, diagnostic metadata is processed by a provider in a third, and a customer-configured export delivers a copy to a destination we never see. Each of those is a separate statement requiring separate evidence.

Region & Provider Availability

Nine Availability States, Styled Honestly

Planned and Unavailable never use current styling. Selecting a filter narrows evidence — it does not confirm availability, legal suitability, or a contractual commitment.

Current — generally availableCurrent — limited availabilityCustomer-specificUnder reviewPlannedUnavailableNot applicableSupersededWithdrawn
Product / moduleData categoryEnvironmentCustomer typeRegion / countryLocation activityProviderStatusEvidence level
Public regionProvider categoryProduct scopeActivityReviewedAvailability
EUContracted cloudCore platformPrimary storage28 Jun 2026Generally available
EUContracted cloudCore platformBackup & recovery28 Jun 2026Limited — eligibility applies
USContracted cloudCore platformPrimary storage28 Jun 2026Generally available
APACContracted cloudCore platformPrimary storage20 Jun 2026Under review
UKContracted cloudCore platformPrimary storagePlanned — not operational
AnyAnyCore platformExclusive in-country handlingUnavailable
EUSupport operationsSupport accessAccess location01 Jul 2026Customer-specific

Illustrative public taxonomy. Region names are generic; no private region identifier, provider account, or customer deployment appears here.

Why "exclusive in-country handling" reads Unavailable

Because no current approved capability guarantees that every copy, every processing operation, every access session, every log, and every exceptional path stays within one country for any product scope. Marking it Unavailable is more useful than omitting the row.

What a provider name does not mean

A provider appearing against one service does not mean all services or all data categories use that provider. And a region name does not imply residency for all categories or all copies. Provider and subprocessor relationships link to current approved evidence rather than to a logo.

Data-Flow & Location Model

Ten Stages From Collection to Backup Expiry

Rendered as structured text rather than an architecture diagram, because a diagram either exposes topology or oversimplifies it.

#StageLocation typeAccess rolesTransfer relationship
01

Source & collection

Approved input categories only

Customer regionWorker, authorized entryNone
02

Transmission

Protected in transit

In transitService identitiesBoundary crossing possible
03

Primary processing

Core application operations

Processing regionService identitiesWithin approved scope
04

Primary storage

Principal persistent store

Storage regionRole-scopedNone in normal path
05

Derived processing

Classification, reporting, security

Processing regionService identitiesResults may or may not persist
06

Integrations

Customer-authorized connectors

Third-partyPer connector scopeHandoff — control ends
07

Exports

Download, API, webhook, SFTP, email

Customer-controlledCustomerHandoff — control ends
08

Retention

Per record-type schedule

Storage regionRole-scopedNone
09

Deletion

Scoped verification

Storage regionPlatformNone
10

Backup expiry

Separate schedule from deletion

Backup regionRecovery rolesNone

Stages 06 and 07 are highlighted because they are where platform control ends. Everything after a handoff is a customer-controlled or third-party destination, and revoking a connector does not erase copies already exported.

Worker-facing summaries use plain language and restate the collection limits. No worker-level record appears in any example on this page.

Primary Storage, Replicas, Caches & Backups

Five Kinds of Copy, Each With Its Own Location

Persistent and temporary copies are exposed separately, because they behave differently on deletion and on recovery.

Primary store

The principal persistent store for a defined data category and environment.

Deletion schedule applies directly.

Replicas

Additional copies for availability, performance, integrity, or recovery.

Location and consistency model stated separately.

Search & index copies

Derived structures supporting retrieval.

Rebuilt rather than restored; may lag.

Caches & temporary data

Short-lived copies supporting performance.

Distinct expiry, not covered by retention schedules.

Backups & archives

Retained for recovery, continuity, legal hold, or approved archival purpose.

Deletion and access timing differ from primary.

Backups, archives & legal holds

Partially published

Objective: make recovery copies inspectable without implying they behave like the primary store.

Stated per backup set
Protected object, environment, region or provider category, retention, encryption, access roles, restore path
Legal hold
Suspends ordinary expiry. A held copy survives a deletion request, and that is disclosed rather than hidden.
Timing
Backup expiry runs on its own schedule — deletion from primary storage does not delete a backup instantly

Limitations: restore evidence and recovery testing route to Platform Reliability, where that evidence is currently under review. Backup existence is not restore proof, and no RPO or RTO is published here.

Retention, deletion & location retirement

Current

Objective: govern the end of the lifecycle, including what happens when a whole location is retired.

Distinct outcomes
Deletion, anonymization, archive expiry, backup expiry, legal hold
Location retirement
Migration plan, verification, evidence, and a preserved record of the retired location
Verification
Scoped — we state what was verified rather than claiming universal erasure

Limitations: no "deleted everywhere immediately" claim. Provider backup and retirement schedules may affect completion timing, and customer-controlled copies are outside our reach entirely.

Processing & Support Access

Where Services and People Act on Data

Remote access and data movement are not the same event, and this page does not treat them as one.

Processing categoryResults persist?
Core application operationsYes — to primary storage
Deterministic time classificationYes — as a reviewable record. Not AI.
Analytics & reportingYes — governed outputs
Security operationsYes — logs, minimized
Reliability operationsYes — telemetry, service-scoped
Support operationsCase records only
AI-assisted functions (Kairos)No new record created. Kairos decides nothing and cannot create a residency commitment.

Access model

  • Access type, purpose, eligible role, region, and approval stated per category
  • Least privilege, session control, logging, and review apply throughout
  • Customer support, security response, reliability operations, and implementation services are distinct access types
  • Break-glass access has a named authority, a reason, a time limit, and an audit record

No individual employee location is published, and no support-access location promise is made without staffing and operational evidence.

Transfers & Mechanisms

The path and the basis are separate

Every transfer record states

  • Origin and destination
  • Data category and purpose
  • Recipient or provider category
  • Frequency
  • Whether it is a normal or exceptional path
  • Status, and the approved transfer-mechanism field

What we do not do

ZoikoTime does not determine whether a transfer mechanism is legally applicable to your situation, and does not guarantee its sufficiency. Mechanism status and legal wording are authority-gated, and restricted legal documents use controlled or contractual access.

Where platform control ends

Exports, email delivery, downloads, APIs, webhooks, and SFTP are separate channels with separate handoff points. Customer responsibility begins at the defined delivery or access boundary.

Revocation does not erase already-exported copies. Turning off a connector stops future delivery; it does not reach into a destination we never controlled. Not all integrations support the same region or transfer model.

Failover, Disaster Recovery & Migration

Exceptional Paths Are Published, Not Hidden

A commitment with an undisclosed emergency exception is not a commitment. Alternate locations are documented at a safe level before they are ever used.

Failover & emergency paths

Partially published

Objective: disclose that alternate locations exist, under what authority they activate, and what happens afterwards.

Documented
Normal and alternate region or provider categories, trigger classes, approval authority, customer notice, state, affected data categories
Governed
Return-to-primary, reconciliation requirements, and cleanup or retirement of the alternate path
Authoritative elsewhere
Recovery methods route to Platform Reliability; live events route to System Status

Limitations: exact security-sensitive topology is never published. But there is no hidden emergency exception to a published commitment — if an exceptional path can move data, it is disclosed here at a safe level.

Migration & region change

Current

Objective: make movement between locations a governed, reversible, evidenced event.

Lifecycle
Request, assessment, approval, preparation, execution, cutover, verification, retirement of the source location
Customer role
Approve scope, timing, and business checks. Platform provides method, validation, rollback, and evidence.
Preserved
Migration history, including the prior location and the date it was retired

Limitations: migration is not instantaneous, and backups created before a migration retain their original location until their own expiry. That interval is disclosed rather than glossed over.

Responsibility Model

Eight Areas, Three Parties

AreaZoikoTimeYour organizationProvider / shared
Region availabilityVerify capability, evidence, dependencies, and status.Confirm eligibility, requirements, and contract.Provider service and evidence may constrain availability.
Data categorizationDefine product categories and purposes.Configure lawful and appropriate use, and local labels where allowed.Shared review for custom integrations and content.
Storage & processingOperate approved platform scope.Select available options and control downstream copies.Provider delivers contracted service; duties remain scoped.
AccessEnforce roles, approvals, and audit.Assign authorized users and protect credentials.Shared for support, incident, and implementation access.
TransfersDocument platform flows and approved mechanisms.Assess legal and contractual needs, and customer-controlled transfers.Provider and recipient evidence and contracts may apply.
Exports & integrationsProvide governed handoff and audit where supported.Own destinations, recipients, retention, and downstream controls after handoff.Third-party responsibilities remain explicit.
MigrationProvide method, validation, rollback, and evidence.Approve scope, timing, and business checks.Shared provider and implementation dependencies.
DeletionExecute platform schedules and scoped verification.Manage customer copies and legal or contractual holds.Provider backup and retirement schedules may affect completion.

Professional boundary. Product information is not legal advice, and not a determination that your configuration satisfies any localization or transfer law. Authorized humans approve region availability, exceptions, cross-border access, transfer mechanisms, migrations, and contractual commitments — Kairos may retrieve or summarize governed location evidence where approved, but it decides nothing and cannot create a residency commitment.

Change History & Notices

Location Changes Are Published, Not Absorbed

ItemPreviousNewReasonEffectiveOwner
APAC primary storageGenerally availableUnder reviewProvider evidence reassessment20 Jun 2026Privacy & Platform
UK primary storagePlannedApproved roadmap intent; no date committed28 Jun 2026Platform
Legacy "EU data stays in the EU" wordingPublishedWithdrawnUnsupported — did not account for support access or backups02 Jun 2026Trust & Governance
Backup region statementv2Superseded by v3Scope clarified per data category28 Jun 2026Privacy

Illustrative change log. Unsafe, stale, or unsupported claims may be removed first, followed by a retrospective correction record.

The withdrawn row is a real category of correction: a statement that was true about primary storage but was being read as a claim about all handling. Withdrawing it was more honest than qualifying it further.

Controlled Residency Review

Request Customer-Specific Location Evidence

Your configured regions, enabled providers, migration history, and applicable contractual position are customer-specific and cannot be published. This is the route to them.

Step 1

Request category

Step 2

Scope

Country or region is required only where applicability or availability depends on it.

Step 3

Optional message and consent

Do not include

Credentials, worker-level records, health information, union or representative details, legal strategy, or any other restricted information. Approved high-level data categories only.

You will receive a reference ID. No response time is promised, because no SLA is approved for this route, and a work email is never used as an automatic eligibility decision.

Review states

ReceivedNeeds clarificationUnder reviewApprovedPartially approvedDeclined with reason categoryExpiredWithdrawn

Direct Answers

Nine Location Questions

That depends on the product, data category, environment, and your configuration. The availability matrix shows current public options with their scope, provider category, and status — and every entry covers one activity only. Primary storage, replicas, caches, indexes, and backups each have their own location.