GDPR
Soriku is built by a Dutch company on European infrastructure. GDPR is the baseline, not an afterthought.
What Soriku collects
- Local mode: nothing leaves the device. No telemetry, no analytics, no error reporting.
- Simezu mode: identity and billing data live with Simezu (Dutch entity, EU-region). Soriku itself holds tenant scoping data and your workspace content.
- Soriku Cloud: same as Simezu mode plus your prompts, completions and agent state stored encrypted in EU-region storage.
Data subject rights
Export, rectification, erasure all reachable from the Simezu dashboard (or from the Soriku CLI in local mode). Erasure is hard-delete: no soft-delete recoveries, the data is gone.
Breach notification
72-hour notification window per Article 33. Email goes to the workspace admin contact in Simezu plus a public security advisory if the breach affects multiple tenants.