Location, authority and control
Data sovereignty and residency
Effective 24 August 2026 · Version 1.0
Residency commitment
Primary processing, replicas, backups, logs, monitoring and support access must be mapped for each institution deployment. The signed order form identifies any binding geographic restriction.
Institution authority
Tenant authority comes from validated staff identity and server-side institution mapping, never from a hostname or custom domain. Institutions remain responsible for approving data sources, purposes and permitted users.
Production evidence
- Primary database and object-storage regions.
- Backup, replica and disaster-recovery locations.
- Logging, analytics and security-monitoring locations.
- Subprocessor and remote-support access locations.
- Transfer mechanism, encryption and key-management responsibilities.
- Exit, export and deletion procedures.
Current public environment
The public website and illustrative demonstration must not be used to infer the architecture or residency of a future institution production deployment.
Questions and formal requests
Email compliance@duruj.io for privacy and data-subject matters, or sales@duruj.io for institutional enquiries. Contract notices must use the address specified in the applicable agreement.