DRAFT prepared for legal review, not a policy.

# Data residency statement (draft)

Prepared 2026-09-19 for review by counsel. Nothing here is legal advice.

## 1. Where the application runs

Every Limud service is deployed in the Oregon region of the hosting provider,
which is United States West. This covers the web application and all scheduled
jobs: the weekly digest, the at-risk alerts, the telemetry purge, the audit
flush, the subscription sweep, the integrations sync, the retention sweep and
the spend warnings. The region is declared in the deployment manifest
(render.yaml) and is the same for every service in it.

## 2. Where data is stored

The application database is hosted by the managed PostgreSQL provider named in
the subprocessor draft. Uploaded files and generated versions are stored through
the same application.

## 3. Where data is processed by the AI

AI processing is performed by the configured model provider named in the
subprocessor draft. The provider is selected by a single server configuration
value; no user and no district can change it.

## 4. Transfers

Data from users outside the United States, including users in Israel and in the
European Economic Area, is transferred to the United States for hosting and
processing.

## 5. Open items for counsel

1. Confirm the transfer mechanism for European Economic Area users: standard
   contractual clauses, and whether a transfer impact assessment is expected.
2. Confirm the position for Israeli users under the Privacy Protection
   Regulations on transfers abroad; see the Israeli law draft in this packet.
3. Decide whether a European or Israeli deployment region is to be offered, and
   on what commercial terms. Today there is one region and this document says so
   rather than implying a choice that does not exist.
4. Confirm whether any district contract we intend to sign requires in-state or
   in-country residency, which the current deployment cannot satisfy.
