# Data ownership and control

> What stays in the customer estate and what railbase.app needs to operate the contract.

_Updated: 2026-09-22_

Ordinary Suite records, approvals and company audit history live in an
independently encrypted Vault for each company. System holds shared identity,
membership and installation authority. Uploaded files use configured storage.
Existing estates adopt this structure through the verified company migration.
On-premise, the customer operates that infrastructure. Managed Cloud uses
Railbase-operated infrastructure under the Cloud Schedule and DPA; the shared
runtime does not imply a shared company data file.

railbase.app stores only the account, legal-company verification, billing,
entitlement, release, installation-health and support information needed to
operate the commercial relationship and managed distribution path. In Managed
Cloud, Railbase also operates company storage and recovery copies. The Privacy
Policy and Cloud Schedule describe those processing categories and retention
rules. Account shows whether Cloud admission is available.

A screening-data outage is an availability incident, not a detected sanctions
match. It does not by itself cancel or revoke a current paid-period entitlement.
Railbase continues signed licence validation through a heartbeat whose rolling
window is no longer than 24 hours; a confirmed hit follows the separate
suspension and review process described in the Terms.

Managed Cloud additionally requires a current admission permit for each company.
If it cannot be refreshed, the affected company pauses when the permit expires,
within 120 seconds. The on-premise offline window is not a Cloud availability
promise.

## Ending a subscription

Ending a Product stops renewal and, after the applicable term and grace rules,
stops entitled Suite operation. It does not silently delete the customer's
stored records. Export, retention and deletion duties remain subject to the
Product agreement, Order and customer's own data-governance policy.

## Portability

On-premise operators create a complete encrypted installation bundle covering
System, every company, local files, local audit archives and identity material.
External unlock material and operating configuration remain separately protected.
A whole-installation bundle must never be given to one company because it
contains other companies and shared identity. Cloud export and recovery duties
follow the Cloud Schedule. Account data held by railbase.app can be exported through the
Account lifecycle controls described in the Privacy Policy.

## FAQ

### Can Railbase use our operating data to train a public model?

Not by default. AI use follows the provider and policy configured in the private
estate and the applicable agreements. See [AI privacy](/de/learn/trust-ai-privacy).

### Does non-renewal hold our records hostage?

No. The Product entitlement ends, but stored records remain in the customer
environment for the customer to govern and export.
