Data Processing Locations and Jurisdictions
1. Where the infrastructure operates
| Service | Infrastructure jurisdiction | Scope |
|---|---|---|
| Core LiteTMS Platform | European Union; the law of the Member State where the infrastructure is located and EU law | Application, core databases, configuration, and operational Customer-data storage on hosting infrastructure selected in the EU. |
| Files and backups | European Union for primary storage; infrastructure providers may also be subject to the law of their state of establishment | Attachments, object storage, encrypted backups, and the disaster-recovery repository configured for LiteTMS. |
| Network, CDN, and traffic protection | Globally distributed network, including the EU and — depending on the user's location — other jurisdictions | DNS, TLS termination, attack protection, rate limiting, and content delivery. Core application data remains stored in the EU. |
| Communications, maps, payments, and invoicing | EU/EEA and, depending on the activated service, the United States or another jurisdiction identified before processing begins | Only data needed to send a communication, calculate a map or route, process a payment, or issue an invoice. |
| AI and transcription | EU/EEA or United States; an additional jurisdiction only where required by the selected model provider and identified before use | Request content, necessary context, and output for a feature deliberately invoked by the user. Text requests routed through OpenRouter require zero-retention routing and rejection of endpoints identified as collecting content. |
| Customer-selected integrations | The jurisdiction of the provider selected or configured by the Customer | Scope depends on the integration. Provider, location, and safeguard information is supplied before that integration first processes data. |
An exact location may change within the stated jurisdiction without reducing the level of protection. If a change introduces a new jurisdiction material to a Customer's service, we update this page and give any notice required by law.
2. Measures against conflicting third-country governmental access
- core data and backups are kept in the EU, and data supplied to ancillary services is limited to what is necessary;
- we use transport encryption, role- and need-based access, multi-factor authentication for privileged access, environment isolation, and security-event logging;
- providers and contract terms are selected with confidentiality, security, onward-processing, and governmental-request cooperation obligations;
- we assess the legal basis, scope, authority, and proportionality of a request and, where grounds exist, challenge a request that conflicts with EU or applicable Member State law;
- we disclose only data covered by an enforceable legal duty and notify the Customer where legally permitted;
- for personal data, we additionally apply the GDPR Chapter V mechanisms described in the DPA and Privacy Policy.
3. Scope of this information
Data Act Article 28 concerns, in particular, international governmental access to non-personal data held in the EU. This page does not publish server addresses, network topology, keys, or security configurations where disclosure would weaken security.