Data residency of South African sensitive data -

Hi LK team,

This question is an adapted version of this ( Data residency for Deepgram STT when using LiveKit Inference in India region ) where i am handling financial data for a company and supplying a service to them built on LK. The system stores data within South Africa (RSA) and does processing on LK (no storage). I must guarantee the data is never stored and kept safe according regulations, ie, I need an agreement.

Questions:

  1. Do you supply a SLA for data handling within the “Ship” tier of your product suite?

  2. Where will the data processing be done, given the customers are in RSA?

  3. Once the room gets closed, does the buffer immediately get wiped and with it all data associated with that room? I plan to put observability off.

For context: the POPIA law (similar to GDPR in EU) requires all data to be stored locally, and hence my ability to use your service for this case is predicated on where and how data is handled. Also the price of your services affects whether I can supply my service to these users at a reasonable price, hence asking about the “Ship” tier. Thanks for any insights you can supply me.

Cheers

Hi, this is not legal or regulatory advice as I am just an engineer, but my feedback:

  • You can find the LiveKit Data Processing Addendum here, which will answer some of your questions: Data Processing Addendum | LiveKit
  • Region pinning, available on Scale+, will keep your media data within region, but ‘operational metrics’ as described in the DPA out outside of this.
  • On the ship tier, region pinning is not available, so we would also not be able to meet your pricing concerns.
  • Although all countries are on our eventual roadmap for data residency and compliance, there are regions above RSA in the list of priorities.

Based on an initial read of your requirements, I believe self-hosting LiveKit may be the most logical approach.

Hope that helps, sorry I didn’t have a better answer for you

Thanks @darryncampbell . I get that local setup makes sense in this context.

Having read your DPA, seems even the Scale+ tier requires some level of storage of data for telephony or other purposes. You remarked on these being of the “operation metrics” classification.

I have two further clarifications:

  1. Can i then safely assume the livekit cloud service for the RSA region is most suitable for less compliant intensive applications?

  2. A follow up: which regions are already able to support high compliance work loads?

Thanks for the help with this! :slight_smile:

Can i then safely assume the livekit cloud service for the RSA region is most suitable for less compliant intensive applications?

Sorry but I’m not comfortable answering that question on a public forum as it’s beyond my area of expertise and I am unfamiliar with POPIA

A follow up: which regions are already able to support high compliance work loads?

The focus so far has been on the US, and EU, and we will continue to support other regions and regulatory requirements in the future.

Sorry my question is very direct, totally understand it not being ideal to answer on this forum.

Thanks for the information, helps a lot to filter my options.

Cheers!