FAQs
Compliance
Please explain your compliance with U.S. regulations regarding data privacy and storage.
InfStones is a U.S. company. We process personal data under our published Privacy Policy and comply with the privacy laws that apply to us, including U.S. state comprehensive privacy legislation such as the CCPA/CPRA, CAN-SPAM, and the GDPR and UK GDPR where applicable. Transfers of personal data out of the EEA or UK rely on the mechanisms valid at the time of transfer — including Standard Contractual Clauses with supplementary measures where needed, and the EU-U.S. Data Privacy Framework where applicable. Enterprise customers can request our Data Processing Addendum.
Where are your servers located?
Our infrastructure platform runs on servers and cloud services from providers including AWS and OCI, across multiple regions in North America, Europe and Asia. The regions in use change as we scale — enterprise customers can request the current list, and data residency requirements can be discussed during onboarding.
What is your regulatory compliance status regarding sanctioned countries and entities?
InfStones localizes its operations to the laws and regulations of each jurisdiction in which it operates. We comply with the sanctions regimes that apply to us, including OFAC programs and, where applicable, UN, EU and UK sanctions: we do not operate in comprehensively sanctioned jurisdictions, do not do business with companies, partners, vendors or contractors based there, and screen against SDN and equivalent restricted-party lists.
Not seeing your question answered?
SUBMIT A REQUEST