Skip to content
my-iris

EU data residency

GDPR Art. 15 / 17

Compliance is where your data lives

For regulated buyers, trust is the product. my-iris keeps critical-alert data in the EU by architecture, supports GDPR export and erasure, and records every step in an audit-ready event log — so an inspection is a query, not a scramble.

tenant · data residencyEU · edge
Jurisdiction
eu
Compute
Cloudflare edge · EU
State store
Durable Object · EU
Retention
configurable
alert state held in the EU

EU data residency

By architecture, not by addendum

my-iris runs on Cloudflare’s EU edge. Each alert’s state is held in a Durable Object created with jurisdiction: "eu" — so the data that matters lives and runs inside the EU by default.

US-headquartered clouds can add an EU region, but the control plane, support model and legal exposure remain US-anchored. Residency you can point to at the infrastructure level is a structural property — not something an incumbent retrofits with a contract clause.

Why this is hard to retrofit

  • Residency at the data layer
    State is pinned to EU jurisdiction at creation, not routed to an EU region after the fact.
  • One EU-native platform
    Edge compute, state and the marketing surface share Cloudflare — no US control plane in the path.
  • Built in, not bolted on
    Opt-out, retention and audit logging are part of the platform, not add-on services.

What’s built in

The trust controls, implemented

Each of these is part of the platform today. We label only what ships — nothing here is aspirational.

  1. 01

    EU data residency by architecture

    Alert state lives in Cloudflare Durable Objects pinned to EU jurisdiction (jurisdiction: "eu"). Residency is where your data physically runs — not a contractual promise layered on a US region.

  2. 02

    GDPR Art. 15 — data export

    Export the personal data held for a recipient or tenant on request, in a portable format, to satisfy subject-access requests — including the my-iris app’s data: registered phones and messages posted on alerts.

  3. 03

    GDPR Art. 17 — erasure

    Erase or pseudonymise personal data when a recipient exercises the right to be forgotten, while preserving the audit record’s integrity. The person’s my-iris app account and devices are deleted; their messages on alerts are pseudonymised.

  4. 04

    DPA available on request

    A Data Processing Agreement is available on request.

  5. 05

    Push without alert content

    A push to the my-iris app carries no alert text and no personal data, only an encrypted reference. The app fetches the alert from my-iris over an authenticated connection.

  6. 06

    STOP/START opt-out · 7 languages

    Recipients can opt out of voice calls and SMS end reports with the STOP keyword, and back in with START, recognised in all 7 supported languages and enforced automatically. Opting out is not a way to answer an alert.

  7. 07

    Configurable retention & purge

    Self-select a retention tier — 30, 90 or 365 days — for alert logs and the my-iris app’s messages and end reports, or arrange up to 5 years for audit purposes. Data purges automatically when the window closes.

  8. 08

    Daily backups, tested restore

    Automated daily backups of your account data to a dedicated EU region, with a tested, confirmation-gated restore procedure — dry-run by default, nothing is overwritten without explicit typed confirmation.

  9. 09

    Audit-ready event log

    Every step — push, call, acknowledge or skip, escalate, resolve — is recorded with who, what and when. Audit-ready and exportable for GxP, HACCP and ISO inspections.

  10. 10

    Log scrubbing & phone masking

    Operational logs scrub sensitive content and mask phone numbers, so diagnostics never become a data-leak surface.

  11. 11

    Multi-tenant isolation

    Each customer is a separate tenant with isolated data and configuration — no cross-tenant access by design.

  12. 12

    Named sub-processors, change notices

    Cloudflare hosts my-iris; Twilio carries voice calls, SMS and transactional email; Apple and Google deliver push notifications to the my-iris app. Tenants get a notice when the list changes.

Audit-ready

An event log built for inspectors

Every push, call, answer, escalation and resolution is recorded with its actor and timestamp, and every alert ends with an end report. The log is designed to be audit-ready for GxP, HACCP and ISO processes — evidence that an alert reached a person, was acknowledged and was resolved.

We frame this honestly: my-iris produces audit-ready records. It does not, by itself, make you certified, and we do not hold an ISO 27001 or SOC 2 certificate. What we do have today: every release goes through a structured internal security review before it ships.

event logalert #A-2291
  1. 02:00:04push · Anna · my-iris appCritical
  2. 02:05:04call · Anna · fi · no answerEscalating
  3. 02:06:04push · Mikael · my-iris appEscalating
  4. 02:07:11acknowledged · Mikael · appAcknowledged
  5. 02:07:11resolved · end report writtenEnded
Every row carries who, what and whenexportable · EU

Regulatory tailwinds

The rules are moving our way

EU regulation increasingly rewards keeping personal and operational data inside the EU. That is exactly where my-iris already runs.

GDPR

EU residency, export, erasure and opt-out built into the platform.

EU Data Act

Data portability and access align with the Data Act’s direction of travel.

EHDS

Health-data residency in the EU supports European Health Data Space readiness.

Schrems II

Alert state and records stay in the EU; the providers that place calls and deliver SMS and pushes are named, with their transfer safeguards, on the sub-processor page.

Bring your auditors the proof

Request our DPA and sub-processor details, or talk to us about what your auditors need to see.

This page describes the controls my-iris implements and the regulatory context we operate in. It is not legal advice, and my-iris does not hold an ISO 27001 or SOC 2 certificate. MeshWorks Wireless Oy is based in Finland.