SECURITY & HOSTING ]

Where the data actually sits

Written against the running infrastructure, not against an intention. Where the posture falls short of EU residency, it says so.

Region: not EU, and that matters

[ RESIDENCY: NON-EU ]

The 4Sight database, authentication store and file storage run in AWS Canada (Central), Montréal, Canada. This is not an EU region. Any statement that 4Sight is EU-hosted would be false today.

The transfer is lawful rather than unlawful: European Commission adequacy decision for Canada (2002/2/EC), PIPEDA scope. An adequacy decision means personal data may move there without additional safeguards. It is still a migration we intend to make.

[ OPEN ITEM: MIGRATE THE PROJECT TO AN EU REGION ]

The application layer is served from Cloudflare edge network, request served from the nearest point of presence. Requests from Europe terminate at European points of presence, but the origin data store is the fact that counts, and it is in Canada.

Several reasoning and search vendors process in the United States. Those transfers rely on the EU-US Data Privacy Framework or on standard contractual clauses, and the register lists which agreements are actually in place and which are still outstanding.

Encryption

Access control

Every table carries row-level security, and the default is denial. A 4Sight, its dossier, its intake files and its report are readable only by the account that created them. There is no shared workspace read, no organisation-wide default, and no ambient admin read of report content.

Retention, enforced

These windows are not a statement of intent. A scheduled sweep deletes past them, and the sweep reports what it removed.

Engine trace logs (model, latency, cost per call)

Automatic sweep

90 DAYS ]

Usage records

Automatic sweep

180 DAYS ]

Sparring-partner transcripts

Automatic sweep

180 DAYS ]

4Sights, intake files, uploads and reports

Automatic sweep, or immediately on request

24 MONTHS FROM CREATION ]

Account record (email, display name)

Deleted on erasure request

LIFE OF THE ACCOUNT ]

Credit and payment ledger

Kept for Latvian accounting law, with the link to the person removed on erasure

5 YEARS ]

Proof-of-erasure receipt

A one-way hash and a date. Holds no name, email or content

INDEFINITE ]

Cookies and analytics

There is no analytics product, no advertising pixel and no third-party tracker on this site. The only browser storage 4Sight writes is the session token that keeps you signed in, which is strictly necessary for a service you asked for and therefore needs no consent banner. Clearing it signs you out.

If something goes wrong

On confirming a personal-data breach, Rizz Group notifies the Latvian Data State Inspectorate within 72 hours where the breach is likely to present a risk, and notifies affected people directly without undue delay where the risk is high. The notice states what happened, what data was involved, what we have done, and what you should do. Report a suspected weakness to engine@vetted.rizzgroup.org. Good-faith reports will not be pursued.

Known gaps

Last reviewed 2026-08-23 · Rizz Group, Latvia · engine@vetted.rizzgroup.org