Skip to content

Data residency & storage

Where your data lives, what crosses borders, and why. We believe you should know exactly where your compliance data is stored — especially if you are ourselves subject to GDPR.

Last reviewed: May 2026

Where your data is stored

Core data stays in the EU. All compliance data, documents, evidence, and user records are stored in the EU West (Frankfurt, Germany) region. This data never leaves the EU unless you explicitly request export.

Data typeStorage locationNotes
Customer account data (name, email, billing)🇪🇺 EU (Frankfurt, Germany)Primary Supabase EU region
Compliance assessments and scores🇪🇺 EU (Frankfurt, Germany)Never leaves EU region
Generated compliance documents (policies, DPIAs, AIAs)🇪🇺 EU (Frankfurt, Germany)Row-level security per org
Evidence vault files🇪🇺 EU (Frankfurt, Germany)Encrypted at rest (AES-256)
AI tool inventory and risk assessments🇪🇺 EU (Frankfurt, Germany)Never leaves EU region
Vendor catalog and risk scores🇪🇺 EU (Frankfurt, Germany)Never leaves EU region
Incident and audit logs🇪🇺 EU (Frankfurt, Germany)Retained per your retention policy
Team member data (name, email, role)🇪🇺 EU (Frankfurt, Germany)Linked to org, deleted on removal
Data Subject Request (DSR) records🇪🇺 EU (Frankfurt, Germany)Encrypted; DPO access only
Transactional emails (alerts, reports)🇺🇸 US (Resend infrastructure)Email metadata only; SCCs in place
Payment and billing data🇺🇸 US/EU (LemonSqueezy)Merchant of Record — never touches our servers

International data transfers

A small number of sub-processors operate outside the EU. For each, we have Standard Contractual Clauses (SCCs) in place under GDPR Chapter V.

RecipientCountryTransfer basisDPAData shared
Resend (email delivery)United StatesStandard Contractual Clauses (EU SCCs)SignedRecipient email address, email content
LemonSqueezy (payments)United StatesStandard Contractual Clauses (EU SCCs)SignedName, email, billing address
Cloudflare (CDN / DDoS)United StatesCloudflare EU DPA / SCCsSignedIP addresses (ephemeral), request logs

Our data commitments

EU-first storage

All compliance data stored in EU West (Frankfurt). We do not route EU data through US infrastructure.

Encryption at rest

All data encrypted at rest using AES-256. Database encryption key managed by Supabase.

Encryption in transit

All connections use TLS 1.2+. No unencrypted API endpoints.

No sub-processor surprises

We notify you 30 days before adding a new sub-processor that processes your personal data.

No AI training on your data

Your compliance data is never used to train AI models — ours or anyone else's. Document generation runs on static, deterministic templates; your content is never sent to a third-party AI provider.

Your right to export

You can export all your data at any time from Settings → Export. CSV, JSON, and PDF formats available.