Trama / Company / Security and data residency

Where the data lives, and who can read it.

A brand's supply-chain data is sensitive material: it says who they buy from, at roughly what price, and how easily they could switch. This page says where it physically sits and who can see it.

DatabaseIreland, Dublin
DocumentsItaly, Milan
ModelsEuropean inference profiles
Logged-in screensNever transit a node outside the European Union

All processing happens in the European Union

This is not a preference, it is a build constraint. The database is in Dublin, uploaded documents are in Milan, and the models that read those documents run on European inference profiles. There is no copy of your data outside the Union, and no emergency path that would put one there.

The screens you log into never cross a node outside the Union. The public passport page, on the other hand, may be delivered from a global network, because it contains no personal data and because being reachable everywhere is part of the obligation.

Who sees what

  • Your team sees your whole supply chain, according to the role you assign.
  • A supplier sees their own request and a preview of what the brand will see. They do not see other suppliers, they do not see your prices, and they do not see the chain downstream.
  • The public sees only the published passport, which contains what the regulation asks for and nothing else.
  • We access your data to deliver the service, and for nothing else: the regulation forbids a service provider to sell or reuse it beyond that, absent your specific agreement.

How we count scans

When somebody scans one of your product codes, we record a count: the country in coarse form, the device type, the browser's main language and the hour of the day. We do not record the IP address, we do not record the city, we do not identify the visitor and we do not tell a returning visitor from a first-time one.