This question is an adapted version of this ( Data residency for Deepgram STT when using LiveKit Inference in India region ) where i am handling financial data for a company and supplying a service to them built on LK. The system stores data within South Africa (RSA) and does processing on LK (no storage). I must guarantee the data is never stored and kept safe according regulations, ie, I need an agreement.
Questions:
Do you supply a SLA for data handling within the “Ship” tier of your product suite?
Where will the data processing be done, given the customers are in RSA?
Once the room gets closed, does the buffer immediately get wiped and with it all data associated with that room? I plan to put observability off.
For context: the POPIA law (similar to GDPR in EU) requires all data to be stored locally, and hence my ability to use your service for this case is predicated on where and how data is handled. Also the price of your services affects whether I can supply my service to these users at a reasonable price, hence asking about the “Ship” tier. Thanks for any insights you can supply me.
Thanks @darryncampbell . I get that local setup makes sense in this context.
Having read your DPA, seems even the Scale+ tier requires some level of storage of data for telephony or other purposes. You remarked on these being of the “operation metrics” classification.
I have two further clarifications:
Can i then safely assume the livekit cloud service for the RSA region is most suitable for less compliant intensive applications?
A follow up: which regions are already able to support high compliance work loads?