Last updated: June 1, 2026

GDPR Compliance

stored.ge is committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page describes how our service maps to GDPR requirements. For the full legal framework, see our Privacy Policy and Data Processing Agreement.

Contents

Article 5 — Data Processing Principles

stored.ge adheres to the core GDPR principles in the design and operation of our service:

Article 17 — Right to Erasure

Data subjects have the right to request deletion of their personal data. stored.ge supports this through:

Object Lock exemption: Objects protected by Object Lock (WORM retention) cannot be deleted until the retention period expires. This is a legal compliance mechanism — if you use Object Lock for regulatory retention, erasure requests are deferred until the retention period concludes.

Article 20 — Data Portability

stored.ge provides full data portability through multiple channels:

Article 25 — Data Protection by Design

Privacy and security are built into stored.ge from the ground up:

Article 28 — Data Processing

When you use stored.ge, FairForge LLC acts as a Data Processor on your behalf. Our processing obligations are formalized in our Data Processing Agreement, which covers:

To execute a DPA for your organization, visit our DPA page or contact privacy@stored.ge.

Article 32 — Security of Processing

stored.ge implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk:

Articles 33/34 — Breach Notification

stored.ge maintains a breach response workflow compliant with GDPR Articles 33 and 34:

For HIPAA-covered entities, our Business Associate Agreement provides additional breach notification commitments.

Data Residency

Default storage is in the United States (Dallas, Texas: region us-central-1) through our infrastructure partner iDrive e2. Additional regions are enabled per deployment and offered in the bucket-creation region picker; regions that are not enabled cannot be selected. The regions our partner operates are:

Region Location
us-central-1Dallas, United States (default)
us-west-2Los Angeles, United States
us-west-4Oregon, United States
us-southwest-1Phoenix, United States
us-southeast-1Miami, United States
us-midwest-1Chicago, United States
us-east-1Virginia, United States
eu-west-1Ireland
eu-west-3London, United Kingdom
eu-west-4Paris, France
eu-central-1Frankfurt, Germany
eu-south-1Milan, Italy
ap-northeast-1Tokyo, Japan

A bucket's region is fixed at creation and its objects are stored only in that region: EU regions keep data within the European Union and United Kingdom as labelled above. International data transfers are governed by Standard Contractual Clauses as described in our DPA.

Sub-processors

stored.ge engages the following sub-processors in delivering the service:

Sub-processor Purpose Location
iDrive Inc. Object storage infrastructure United States / EU
Stripe Inc. Payment processing and billing United States
Resend Inc. Transactional email delivery United States

Changes to sub-processors are communicated with at least 30 days' notice. The full sub-processor list and notification process are documented in our DPA.

Contact

For GDPR-related inquiries, data subject requests, or to exercise your rights: