Trust & compliance

Hosted and stored in the European Union.

European data residency by default, with GDPR built in — data minimisation, export, and erasure on request.

For most European institutions, where research data physically lives is not a preference — it is a policy requirement. Stellacris is hosted and stored within the European Union by default, with GDPR obligations built into how the system operates rather than bolted on afterwards.

If your policy is stricter still, the identical system runs on-premises behind your own firewall, so the data never leaves your walls. Either way, data is isolated per institution and remains fully exportable and under your control.

Why it matters

Compliance without compromise

EU infrastructure

Managed SaaS is hosted and stored within the European Union, with data isolated per institution.

GDPR by design

Data minimisation, export, and erasure on request are built into how the system works.

On-premises option

For the strictest policies, the identical system runs behind your own firewall.

Always exportable

Wherever it is hosted, your data stays portable and fully within your control.

In practice

Residency, privacy, and control

The concrete controls that let your data protection officer and IT security sign off: where data lives, how it is isolated, and what rights are built in.

  • Managed SaaS hosted and stored within the European Union.
  • Data isolated per institution, with per-tenant separation.
  • GDPR built in — data minimisation, export, and erasure on request.
  • On-premises deployment for policies that keep data in-house.
  • Standard exports always available, so data is never held hostage.
  • A single strictly necessary cookie on the public site; no third-party tracking.
Common questions

Questions, answered

Where is our data stored?

In the managed SaaS, within the European Union. If your policy requires it to stay on your own infrastructure, the identical system runs on-premises behind your firewall.

How do you handle GDPR requests?

Data minimisation, export, and erasure on request are built in. Institutional data is processed under a data-processing agreement; the marketing site itself collects only what you submit through the contact form.

Is our data isolated from other institutions?

Yes. Each institution’s data is isolated, with per-tenant separation, so one client’s record is never mixed with another’s.

Get started

See your institution’s research, mapped.

A 30-minute walkthrough with your own entity types — concrete, friendly, and on your schedule.