03 / Sovereignty & architecture
Two questions decide this page: where the data sits and under which law, and what happens when the main system fails. The answers are architectural, not marketing.
The choice is not technical, it is legal. It defines which law your data answers to, and who, ultimately, can demand it. Each scenario has different consequences, and none is universally better: the best one is the one that matches the control you want to keep.
The client's jurisdiction
On the client's own servers. Full control; running the infrastructure stays in-house.
European Union
Dedicated infrastructure, under EU jurisdiction, run by a European provider. Sovereignty without running servers.
Portugal
The data stays on Portuguese territory and under Portuguese jurisdiction, with no exposure to the laws of third countries.
The US CLOUD Act of 2018 allows US authorities to demand data from a provider subject to American jurisdiction, regardless of whether the server sits in Lisbon, Frankfurt or Dublin. The physical location of the disk does not decide jurisdiction; the nationality and structure of the provider does.
This is why digital sovereignty is not «data in Europe»: it is data staying under European jurisdiction, with a provider that cannot be compelled by a foreign law. The distinction looks subtle, but it is the difference between data that answers to Portuguese law and data that, in theory, can be handed to a foreign authority without your organisation even knowing.
The physical location of the disk does not decide jurisdiction. The nationality of the provider does.
Cloud Act / 2018The archive does not replace your recording, identity or ticketing systems. It integrates with them: it imports from the voice, chat and email sources you already have, and connects to your identity management (AD / LDAP / Azure AD) so that access follows your own rules. A single integration point, encrypted at rest and in transit.
Data is encrypted at rest and in transit. Access is profile-based, inherited from your identity management, and every access leaves a trail in the audit trail. ISO 27001 certification is under way; until it is issued we do not present it as complete, but the controls it requires are implemented as standard.
This is DORA's question. The archive is designed for an RTO and an RPO defined with you: how long it may be unavailable and how much data may be lost. Replicas and copies ensure that a failure of the main system is not a loss of access to the history, and that recovery happens within the agreed window, not «when possible».
Self-assessment
Three architecture questions, taken from the full assessment. Answer for what you know today, not for what you would like.
Your level of exposure: ,
Low risk
Clear jurisdiction, recovery with a defined target and access inherited from your identity system. The full assessment confirms the architecture and points out what to review to keep it.
Medium risk
There are dependencies that only show under pressure: an international provider, a recovery with no figure attached, or access outside your identity system. The report shows where the risk lies dormant.
High risk
Without knowing which law the data sits under, or how long recovery takes, a foreign request or a failure at three in the morning would be a real problem. The report sets out what to address first, regulation by regulation.
In practice
uPlayback runs wherever sovereignty requires: on-premises, European private cloud or national cloud, always under European jurisdiction. It integrates with your systems through a single point, encrypts at rest and in transit, inherits access from your identity management and recovers within the agreed RTO and RPO. The control is yours; we give you the architecture to exercise it.

Continue reading
Architecture, integrations and deployment answered live, with your stack on the table and no generic pitch.