a month ago
Hi, I run a rendering worker on Railway, and I am completing the data
residency section of my privacy policy. I need a few answers I can state
accurately to my own customers.
My service is a containerised worker
that pulls jobs from an external Postgres database, downloads media,
renders video, and uploads the result back out. It holds no database of
its own.
-
Which region is my service deployed in, and can I pin a service to a
specific region on my plan? I want to confirm what I am reading in the
dashboard rather than assume it.
-
Does anything I process persist on Railway after a run finishes? I am
thinking of the container filesystem between deploys, build caches,
and build artifacts. If something does persist, where is it stored and
for how long?
-
Where are my service's logs stored, how long are they retained, and
are they replicated to any other region?
-
Is any of my data replicated or backed up outside the region my
service runs in, for redundancy or any other reason?
-
Do you offer a Data Processing Agreement, and do you act as a data
processor for customer data that passes through a running service?
If there is a signable version, please point me to it.
-
Where is your current sub-processor list published?
I am asking because I have to describe this accurately to my customers,
not to challenge anything. Questions 1 and 4 are what I need most.
Thanks
1 Replies
a month ago
Your service is deployed in the eu-west (Amsterdam) region, and you can pin a service to any available region from the deploy settings on any plan.
The container filesystem is ephemeral and reset on every deploy, so nothing your worker writes to disk persists between runs. Build artifacts are not retained after the image is produced. Your service has no volume attached, so no data persists on our side after a container stops.
Service logs are retained for 7 days on the Hobby plan and are stored in US-West regardless of your service's deploy region.
Railway primarily runs workloads on its own hardware (Railway Metal) and also uses Google Cloud Platform and AWS for additional capacity. We cannot confirm which underlying provider a specific service is on at any given moment. The current sub-processor list is published at trust.railway.com/item/subprocessors and should be treated as authoritative for your records.
The published DPA at railway.com/legal/dpa covers the processor/controller relationship. It is accepted as published and is not amended or countersigned for individual customers. The full set of legal documents, including the privacy policy, is at railway.com/legal, and additional security and compliance materials are at trust.railway.com.
Status changed to Awaiting User Response Railway • about 1 month ago
a month ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 26 days ago