muono
ReferenceSecurity specification
Revision AStatus Current

Data residency

For your IT and OT reviewers
Purpose

The region is fixed, and it does not move.

Residency is a contractual property of a deployment, not a setting somebody could change later. This page states where data sits in each model, what leaves the region, and how GDPR obligations are met.

Region

Named at deployment and fixed. Data at rest, backups and logs stay in that region. Changing region is a migration with a new agreement, not a configuration change.

Fixed at deployment

What leaves

In on-premise, nothing needs to. In hybrid, the collector passes only the readings and records the model needs, and raw history stays inside your perimeter. In hosted and your-cloud models, data stays in the named region.

Named in the document

GDPR

Supported in every deployment model, including subject access and deletion. Personal data in an industrial record is usually incidental, such as who signed a permit or who closed a work order, and it is handled as personal data rather than as plant data.

Every model

Sub-processors

Listed, with what each one does and where it runs. The list is part of the agreement, and additions are notified rather than assumed.

Listed in the agreement

Retention and exit

Retention is set by you. At the end of an agreement the record is exported in a documented format and deleted on a stated timetable. You should not need our goodwill to get your own plant data back.

Exportable on exit

Residency is usually the shortest clause to clear.

If your policy names a region, say so in scoping and the deployment is shaped around it.