EU data residency
GDPR Art. 15 / 17Compliance is where your data lives
For regulated buyers, trust is the product. my-iris keeps critical-alert data in the EU by architecture, supports GDPR export and erasure, and records every step in an audit-ready event log — so an inspection is a query, not a scramble.
- Jurisdiction
- eu
- Compute
- Cloudflare edge · EU
- State store
- Durable Object · EU
- Retention
- configurable
EU data residency
By architecture, not by addendum
my-iris runs on Cloudflare’s EU edge. Each alert’s state is held in a Durable Object created with jurisdiction: "eu" — so the data that matters lives and runs inside the EU by default.
US-headquartered clouds can add an EU region, but the control plane, support model and legal exposure remain US-anchored. Residency you can point to at the infrastructure level is a structural property — not something an incumbent retrofits with a contract clause.
Why this is hard to retrofit
- Residency at the data layerState is pinned to EU jurisdiction at creation, not routed to an EU region after the fact.
- One EU-native platformEdge compute, state and the marketing surface share Cloudflare — no US control plane in the path.
- Built in, not bolted onOpt-out, retention and audit logging are part of the platform, not add-on services.
What’s built in
The trust controls, implemented
Each of these is part of the platform today. We label only what ships — nothing here is aspirational.
- 01
EU data residency by architecture
Alert state lives in Cloudflare Durable Objects pinned to EU jurisdiction (jurisdiction: "eu"). Residency is where your data physically runs — not a contractual promise layered on a US region.
- 02
GDPR Art. 15 — data export
Export the personal data held for a recipient or tenant on request, in a portable format, to satisfy subject-access requests — including the my-iris app’s data: registered phones and messages posted on alerts.
- 03
GDPR Art. 17 — erasure
Erase or pseudonymise personal data when a recipient exercises the right to be forgotten, while preserving the audit record’s integrity. The person’s my-iris app account and devices are deleted; their messages on alerts are pseudonymised.
- 04
DPA available on request
A Data Processing Agreement is available on request.
- 05
Push without alert content
A push to the my-iris app carries no alert text and no personal data, only an encrypted reference. The app fetches the alert from my-iris over an authenticated connection.
- 06
STOP/START opt-out · 7 languages
Recipients can opt out of voice calls and SMS end reports with the STOP keyword, and back in with START, recognised in all 7 supported languages and enforced automatically. Opting out is not a way to answer an alert.
- 07
Configurable retention & purge
Self-select a retention tier — 30, 90 or 365 days — for alert logs and the my-iris app’s messages and end reports, or arrange up to 5 years for audit purposes. Data purges automatically when the window closes.
- 08
Daily backups, tested restore
Automated daily backups of your account data to a dedicated EU region, with a tested, confirmation-gated restore procedure — dry-run by default, nothing is overwritten without explicit typed confirmation.
- 09
Audit-ready event log
Every step — push, call, acknowledge or skip, escalate, resolve — is recorded with who, what and when. Audit-ready and exportable for GxP, HACCP and ISO inspections.
- 10
Log scrubbing & phone masking
Operational logs scrub sensitive content and mask phone numbers, so diagnostics never become a data-leak surface.
- 11
Multi-tenant isolation
Each customer is a separate tenant with isolated data and configuration — no cross-tenant access by design.
- 12
Named sub-processors, change notices
Cloudflare hosts my-iris; Twilio carries voice calls, SMS and transactional email; Apple and Google deliver push notifications to the my-iris app. Tenants get a notice when the list changes.
Audit-ready
An event log built for inspectors
Every push, call, answer, escalation and resolution is recorded with its actor and timestamp, and every alert ends with an end report. The log is designed to be audit-ready for GxP, HACCP and ISO processes — evidence that an alert reached a person, was acknowledged and was resolved.
We frame this honestly: my-iris produces audit-ready records. It does not, by itself, make you certified, and we do not hold an ISO 27001 or SOC 2 certificate. What we do have today: every release goes through a structured internal security review before it ships.
- 02:00:04push · Anna · my-iris appCritical
- 02:05:04call · Anna · fi · no answerEscalating
- 02:06:04push · Mikael · my-iris appEscalating
- 02:07:11acknowledged · Mikael · appAcknowledged
- 02:07:11resolved · end report writtenEnded
Regulatory tailwinds
The rules are moving our way
EU regulation increasingly rewards keeping personal and operational data inside the EU. That is exactly where my-iris already runs.
GDPR
EU residency, export, erasure and opt-out built into the platform.
EU Data Act
Data portability and access align with the Data Act’s direction of travel.
EHDS
Health-data residency in the EU supports European Health Data Space readiness.
Schrems II
Alert state and records stay in the EU; the providers that place calls and deliver SMS and pushes are named, with their transfer safeguards, on the sub-processor page.
Bring your auditors the proof
Request our DPA and sub-processor details, or talk to us about what your auditors need to see.
This page describes the controls my-iris implements and the regulatory context we operate in. It is not legal advice, and my-iris does not hold an ISO 27001 or SOC 2 certificate. MeshWorks Wireless Oy is based in Finland.