Duku Infrastructure and Switching Information
This page provides the information required by Article 28 of the EU Data Act and referred to in the Duku EU Data Act Addendum: where Duku’s infrastructure is located, how you can export (switch) your data and in which formats, the restrictions and technical limitations known to us, and the safeguards we use to prevent unlawful access to non-personal data. Capitalised terms have the meaning given in the Addendum.
Jurisdiction and infrastructure location
The Duku Services are hosted on Amazon Web Services in the eu-west-1 (Ireland) region. Customer data is stored in that region, with automated backups and a database replica kept in the same region and no copies in other AWS regions. Two categories of data leave it: a replica of the platform database is maintained in Google Cloud BigQuery in the London (europe-west2) region for analytics and service operation, and captured test content is processed by Duku’s AI model providers, in the European Union through Amazon Bedrock and, for some models and fallback paths, in the United States, as set out in the Duku Sub-Processor List. Usage analytics for signed-in users of the dashboard is processed by PostHog in the United States (see the Duku Privacy Notice).
Exportable Data
Your Exportable Data comprises the following, in each case only to the extent held in your account at the time of export and as made available through the Services’ standard interfaces and export formats:
- Account and configuration data you have provided to the Services: your organisation and user account details, registered applications, target environment settings, and test configurations and schedules.
- Test results generated by your use of the Services: test and exploration run records, issues and errors detected in your applications, and generated test definitions and their execution results.
- Session media artifacts: test session recordings and screenshots, to the extent still retained under our standard retention periods at the time of export.
There are no Digital Assets. The Services are fully managed software-as-a-service: you do not deploy or license applications, machine images, models or containers into our environment.
Switching and porting methods and formats
| Exportable Data | Method | Format |
|---|---|---|
| Account and configuration data | Readable through the authenticated Duku GraphQL API using an API key created in the dashboard, and delivered by Duku as a JSON export on a Switching Request | JSON |
| Test results | Readable through the authenticated Duku GraphQL API, and delivered by Duku as a JSON export on a Switching Request | JSON |
| Session media artifacts | Each recording and screenshot is retrievable through a signed link issued by the Duku API, valid for seven days from issue | Recordings as MP4 (H.264); screenshots as PNG |
Following a Switching Request we use reasonable efforts to make your Exportable Data available in raw form within thirty (30) calendar days after the Switching Date, and we keep it available for retrieval for thirty (30) days after the export is completed. You carry out the export and the retrieval. We do not charge for standard export or deletion. Make a Switching Request by writing to support@duku.ai.
Known restrictions and technical limitations
- Session media is retained for the life of your subscription unless you ask us to delete it; there is currently no automatic expiry. Media deleted at your request is no longer available for export.
- An export reflects the data held at the time it is produced; runs still in progress are included in the state they have reached. Runs that failed for reasons on Duku’s side are not shown to customers and are not included.
- Data derived to operate the Services, such as vector embeddings, state and network fingerprints, internal model evaluation records and job queue state, is Excluded Data under the Addendum and is not exported.
- Generated test definitions are exported in Duku’s JSON schema. They are not converted into other vendors’ test formats.
- Duku may apply fair-use limits to bulk API access during an export and will tell you if it does.
Safeguards against unlawful access to non-personal data
- All customer data is encrypted at rest with AWS KMS keys and in transit to and from the Services with TLS 1.2 or higher.
- Access to production systems is limited to named Duku engineers through single sign-on with multi-factor authentication enforced by our identity provider, and every access is logged.
- Each customer’s data is logically separated by organisation, and every request to the Services is authorised against the caller’s organisation.
- Duku personnel access customer data only to the extent needed to operate and support the Services, and infrastructure and application logs are kept in searchable form for 30 days and archived thereafter.
- Duku does not give any third-country public authority access to non-personal data except where required by applicable law, in which case we will, where lawful, notify you before disclosure and challenge any request we consider unlawful.