PolicyWatcherPublic evidence laboratory
Back to Trust & Quality
Beta 31 · legal-resilience evidence

Residency and processor evidence, without inferred certainty

This dated pack separates provider documents, operator declarations, deployment-dependent facts and missing evidence. A public provider DPA does not by itself prove where the active PolicyWatcher deployment or its backups run.

Interpretation boundary

This pack distinguishes public documents, operator declarations, configuration-dependent facts and open evidence. It is not a DPA, transfer impact assessment, legal opinion, provider certification or proof of the live deployment region.

Record-level status

Processing and storage register

Every record states both what is known and what the available evidence cannot establish.

hostingOperator declaration

Primary web application hosting

Data
Application runtime, HTTP requests and hosting-level logs
Location
Active deployment region must be confirmed from the current hosting control plane.
Evidence
The repository identifies Hostinger as the deployment provider and supplies a dated provider DPA reference.
Limit
A provider contract or general data-center list does not prove the region selected for the running deployment.
storageDeployment dependent

Production SQLite database

Data
Subscriber preferences, public-evidence records and protected operational records
Location
Co-located with the configured application filesystem unless deployment evidence shows otherwise.
Evidence
The application validates an absolute production database path and exposes only sanitized readiness state to authenticated operators.
Limit
The source tree cannot prove the physical volume region, encryption-at-rest control or current host configuration.
backupEvidence open

Database backup copies

Data
Encrypted application export when an administrator explicitly creates one; provider backups remain provider-controlled
Location
Not publicly verified.
Evidence
PolicyWatcher includes administrator-only encrypted export and local verification tooling.
Limit
The application does not attest that provider backups exist, are current, encrypted, restorable or retained in a specific region.
retrievalDeployment dependent

Optional browser renderer VPS

Data
Public official-source URLs and rendered public policy HTML
Location
Deployment-controlled and not publicly verified.
Evidence
The renderer is a separate bearer-protected service and is optional when direct retrieval succeeds.
Limit
The evidence pack does not infer VPS region, hosting provider or retention from application configuration.
aiPublic document reviewed

Google Gemini API

Data
Explicit assistant question text; Word clause text and browser-extension notice content are excluded from this path
Location
May be processed outside the EEA under the applicable Google service terms.
Evidence
The public privacy policy names the assistant transfer and the provider DPA describes processing-location and transfer terms.
Limit
This register does not assert a selectable EU-only Gemini processing location for the configured API use.
emailDeployment dependent

Configured SMTP delivery provider

Data
Subscriber email address and requested alert content when email delivery is enabled
Location
Depends on the deployment-selected SMTP provider and account configuration.
Evidence
SMTP is deployment configured; no provider identity or region is hard-coded in the application contract.
Limit
A provider-specific DPA, subprocessor list, retention setting and transfer assessment require deployment evidence.
Dated source register

Documents reviewed

Links identify the reviewed source; applicability still depends on the contracted service and live configuration.

Closure criteria

Evidence still required

  1. Attach a dated hosting control-plane record identifying the active application and database region.
  2. Attach current backup-region, retention, encryption and restore-test evidence.
  3. Record the configured SMTP provider, applicable DPA and transfer controls before asserting its processing location.
  4. Re-review provider DPA and subprocessor references after a provider or material service change.