Privacy

Governance

Data residency, regional processing guarantees, and cross-border data transfer policies.

Data Governance

Skytells operates under strict data governance policies to ensure your data remains in the region where it originates. When you send a prediction request, the infrastructure routing, inference processing, and output delivery all occur within the same geographic region — your data never silently crosses borders.


Regional Processing

When a prediction request reaches the Skytells API, it is routed to the nearest regional inference cluster based on the request origin. The entire prediction lifecycle — input processing, model inference, and output generation — executes within that region.

API Request EU origin US origin APAC origin Output Output Output Your Application Edge Router EU Inference Cluster US Inference Cluster APAC Inference Cluster EU CDN Edge US CDN Edge APAC CDN Edge

What Stays Regional

Data typeRegional guarantee
Input data (prompts, uploaded files)Processed in-memory within the regional cluster. Never transferred to another region.
Model inferenceGPU workloads execute exclusively on regional compute nodes.
Generated outputsStored on regional CDN origin storage during the 5-minute retention window.
CDN deliveryOutputs are served from edge nodes within the same geographic region.

What May Be Global

Certain operational data — by its nature — is managed centrally. This data does not include your prompts, inputs, or generated content:

Data typeReason
Account managementUser accounts, authentication, and team management are centralized for consistency.
Billing and invoicingPayment processing runs through a centralized billing system (Stripe).
Aggregated analyticsAnonymized, aggregated usage metrics (total requests, average latency by region) for capacity planning. No individual request content is included.

Supported Regions

RegionIdentifierInferenceCDN Delivery
United StatesusUS-East, US-WestNorth America edge network
European UnioneuEU-West (Frankfurt, Amsterdam)European edge network
Asia-PacificapacAPAC (Tokyo, Singapore)Asia-Pacific edge network

Region selection is automatic based on the originating request's geographic location. Enterprise customers can explicitly pin workloads to a specific region via project-level configuration.


Data Sovereignty

Skytells enforces the following data sovereignty guarantees:

GuaranteeDetail
No silent cross-border transferCustomer content (inputs and outputs) never leaves the processing region unless explicitly configured by the customer.
Regional compute isolationInference GPU nodes are provisioned and operated within each region. No shared compute pools across regions.
Regional storageCDN origin storage for prediction outputs is regional. Files are not replicated to other regions.
Compliant transfers onlyWhere central services require transfer of operational metadata (billing, account info), transfers comply with applicable frameworks — EU SCCs, UK IDP Addendum, or recognized adequacy decisions.
Subprocessor transparencyAll subprocessors and their processing locations are documented and available upon request.

Cross-Border Data Transfers

For data that requires centralized processing (account management, billing), Skytells relies on the following legal mechanisms:

FrameworkScope
EU Standard Contractual Clauses (SCCs)Transfers of personal data from the EEA to non-adequate countries. Incorporated into the Skytells DPA.
UK International Data Transfer AddendumTransfers from the UK under post-Brexit requirements.
Adequacy decisionsWhere the European Commission or UK Secretary of State has recognized a country as providing adequate protection, transfers proceed under that recognition.

What Is NOT Transferred Cross-Border

Regardless of legal mechanism, the following data categories never leave the processing region:

  • Input prompts and parameters
  • Uploaded files (images, reference material)
  • Generated outputs (images, audio, video)
  • Inference logs or GPU telemetry

Compliance by Region

RegulationRegionHow Skytells Complies
GDPREU / EEARegional processing in EU clusters. DPA with SCCs available. Right to deletion honored within 30 days.
UK GDPRUnited KingdomEU infrastructure with UK IDP Addendum.
CCPA / CPRACalifornia, USANo sale of personal data. Deletion and access rights supported.
LGPDBrazilData minimization and purpose limitation enforced. DPA available.
PIPEDACanadaConsent-based processing. Data access and correction rights supported.
APPIJapanAdequacy decision recognized. Regional processing available via APAC cluster.
Privacy Act 1988AustraliaAPAC processing. Data breach notification obligations met.

Enterprise Governance

For organizations with strict regulatory requirements, Skytells offers:

FeatureDescription
Dedicated regional deploymentPin all workloads — including account management — to a single jurisdiction.
Custom DPATailored Data Processing Addendum reflecting your specific regulatory obligations.
Subprocessor notificationsAdvance notice before any subprocessor change takes effect, with the right to object.
Audit rightsContractual right to audit Skytells data handling practices or review third-party audit reports (SOC 2, ISO 27001).
Data residency attestationWritten confirmation of where your data is processed and stored.

Visit skytells.ai/contact to discuss governance requirements for your organization.


How is this guide?

On this page