Says it is GDPR compliant - but I don't see it explained how?
You say you would use "Standard Data Protection Clauses" if the data goes outside of the US ... but I don't want my data in the US in the first place, so is this really a US only service?
How would those clauses be implemented?
Does every node have a contractual agreement with you?
How would you know if someone took their computer with them on holiday to another country?
Also, how is the data encrypted? "State of the art encryption" is just marketing fluff :)
Comments
Says it is GDPR compliant - but I don't see it explained how?
You say you would use "Standard Data Protection Clauses" if the data goes outside of the US ... but I don't want my data in the US in the first place, so is this really a US only service? How would those clauses be implemented? Does every node have a contractual agreement with you? How would you know if someone took their computer with them on holiday to another country?
Also, how is the data encrypted? "State of the art encryption" is just marketing fluff :)
We plan on launching regions outside of the U.S. that only store data outside of the U.S. soon.
AES256 and/or xsalsa20poly1305.
You can also use SSE-C to provide our servers with a key to encrypt the data (which our servers then promptly forget). https://docs.aws.amazon.com/AmazonS3/latest/userguide/Server...
Thanks.
How do you handle the data leaving the country? With someone just taking their machine on holiday etc