Security & compliance

Where is my data stored, and is PhotonSpark GDPR-compliant?

All data in EU datacenters (Bucharest primary, Frankfurt secondary). Fully GDPR-compliant. We are processor for hosted services, controller for our own customer records.

Data residency

PhotonSpark operates exclusively in the EU. Your data is stored in:

  • Primary — Bucharest, Romania (our home datacenters).
  • Secondary / failover — Frankfurt, Germany.
  • Backups — distributed across both regions, off-site.

We do not replicate, mirror, or store customer data outside the EU under any circumstance. This is an architectural property, not a contractual promise we could break.

Controller vs. processor

  • For services you operate using our infrastructure (hosting your app, your VitalSpark tenant, your Private AI deployment), you are the data controller and PhotonSpark is the data processor. DPA available on request.
  • For PhotonSpark's own customer records (your account, contact info, billing), PhotonSpark is the data controller.

Sub-processors

Listed publicly at photonspark.com/privacy under "Processors and service providers." All sub-processors are inside the EU or have equivalent contractual safeguards.

Compliance certifications

We comply with:

  • GDPR (Regulation 2016/679).
  • Romanian Law 190/2018 (national GDPR implementation).
  • NIS2 directive where it applies.

We are not SOC 2 / ISO 27001 certified at the corporate level — we are too small for the audit cost to be reasonable. Specific high-compliance services (SparkTranscript for clinical use) are deployed in environments meeting GDPR Article 9 (health data) requirements.

DPA

Standard DPA available on request at no cost. Send a ticket from the account contact email; signed copy returned within 2 business days.