Data Residency
This page lists every data subsystem of the platform with its physical region and contractual posture. It is the factual companion to the Data Processing Agreement and the Privacy Policy: where those documents govern, this page declares. We state exactly what lives where — we do not claim a regional pin we do not physically have.
1. Data subsystems
Each subsystem of the platform, what it holds, and where it physically runs.
| Subsystem | What it holds | Region | Posture |
|---|---|---|---|
|
PostgreSQL (primary database) Google Cloud SQL, europe-north1 (Finland) |
All tenant records: users, services, subscriptions, contracts, audit trails | EU | EU-pinned. A single EU instance; row-level security enforces tenant isolation inside it. |
|
Redis (cache, sessions, task broker) Google Cloud Memorystore, europe-north1 (Finland) |
Session data, cache entries, queued background-task payloads | EU | EU-pinned. Transient data only; TLS in transit. |
|
Celery workers (background processing) Google Cloud Run, europe-north1 (Finland) |
Task payloads in flight: notifications, syncs, scheduled jobs | EU | EU-pinned. Background processing runs in the same region as the database. |
|
Media and attachments Google Cloud Storage, europe-north1 (Finland) |
Uploaded files: logos, documents, contract attachments | EU | EU-pinned. Object storage in the same region as the primary stack. |
|
Backups Google Cloud Storage, europe-north1 (Finland) |
Encrypted backup archives of tenant data | EU | EU-pinned. Archives are encrypted under a dedicated backup key and do not leave the EU data plane. |
|
LLM inference (AI features) Google Vertex AI (Gemini), europe-north1 (Finland) |
AI prompts: contract text excerpts, service names and descriptions, incident details | EU | EU-served for all tenants today. Tenants pinned to the US are routed to the EU inference plane until a US inference plane ships; this divergence is documented, and the served region of every AI call is recorded in the AI request log. |
|
Error tracking Sentry (Functional Software, Inc., USA) |
Stack traces, request URLs, browser user-agent (PII suppressed: no cookies, IPs, or user IDs) | US | Declared US carve-out under the 2021 EU SCCs. An EU-region DSN is pending — we declare US processing until it is confirmed in production. |
|
Transactional email Provider selection pending |
Email addresses, names, and message bodies in transit | Global | Declared global carve-out: email transit is not region-pinned until an EU-region provider and DPA are executed. |
|
Web push notifications Browser vendors' push services (Google, Mozilla, Apple) |
Notification payloads in transit to subscribed browsers | Global | Declared global carve-out: payloads are encrypted end-to-end (RFC 8291), but delivery transits the recipient's browser-vendor push service, which is not region-pinned. |
|
Vulnerability intelligence (CVE scanning) OSV.dev API (Google-hosted, no regional pin) |
Component names and version strings from tenant component inventories (no personal data) | Global | Declared global carve-out: vulnerability lookups send component name/version identifiers — never personal data or tenant identifiers — to the public OSV.dev API. NVD links shown in the UI are rendered as URLs only; the platform does not query NVD. |
|
Support tooling ServGrid staff (EU/EEA); no third-party helpdesk platform |
Support conversations and the diagnostic context you share with us | EU | Support access to production data happens through the platform's own audited admin surfaces in the EU plane. Support email inherits the email-transit carve-out above. A helpdesk platform, if adopted, will be added to the sub-processor register first. |
2. Sub-processors by processing region
2 of our 6 registered sub-processors are pinned to the EU/EEA data plane. The authoritative GDPR Art. 28 register, including legal entities and DPA links, is summarised here by the region where processing actually happens.
| Sub-processor | Purpose | Processing region | DPA |
|---|---|---|---|
| Google Cloud Platform | Cloud infrastructure (compute, DB, storage) | EU / EEA | DPA |
| Google Vertex AI (Gemini) | AI inference | EU / EEA | DPA |
| Sentry (Functional Software, Inc.) | Error monitoring | United States | DPA |
| Stripe | Payment processing | United States | DPA |
| Transactional email (SMTP) | Transactional email delivery | Global (provider-managed) | — |
| Customer-selected CRM | CRM sync (customer-initiated) | Customer-controlled region | — |
3. Carve-outs, stated plainly
The following processing is not pinned to the EU plane today. Each entry is a deliberate, documented declaration — not an oversight. The list is derived from the same registries as Sections 1 and 2: every non-EU sub-processor and every non-EU platform subsystem appears here.
- Sentry (Functional Software, Inc.) — United States. Error monitoring. Applies to: Stack traces, request URLs, browser user-agent (send_default_pii=False — no cookies, IP addresses, or user IDs).
- Transactional email (SMTP) — Global (provider-managed). Transactional email delivery. Applies to: Email addresses, names (To: headers), email body content.
- Customer-selected CRM — Customer-controlled region. CRM sync (customer-initiated). Applies to: Company names, contact emails/names, subscription events, contract metadata.
- Stripe — United States. Payment processing. Applies to: Billing admin email, organisation name, tenant slug, plan name; card data is entered on Stripe-hosted Checkout and never touches ServGrid.
- Error tracking — United States. Stack traces, request URLs, browser user-agent (PII suppressed: no cookies, IPs, or user IDs). Declared US carve-out under the 2021 EU SCCs. An EU-region DSN is pending — we declare US processing until it is confirmed in production.
- Transactional email — Global (provider-managed). Email addresses, names, and message bodies in transit. Declared global carve-out: email transit is not region-pinned until an EU-region provider and DPA are executed.
- Web push notifications — Global (provider-managed). Notification payloads in transit to subscribed browsers. Declared global carve-out: payloads are encrypted end-to-end (RFC 8291), but delivery transits the recipient's browser-vendor push service, which is not region-pinned.
- Vulnerability intelligence (CVE scanning) — Global (provider-managed). Component names and version strings from tenant component inventories (no personal data). Declared global carve-out: vulnerability lookups send component name/version identifiers — never personal data or tenant identifiers — to the public OSV.dev API. NVD links shown in the UI are rendered as URLs only; the platform does not query NVD.
AI inference divergence: tenants pinned to the US data region are routed to the EU inference plane until a US inference plane ships. This is a documented divergence between the requested and served region; the served region of every AI call is recorded in the tenant's AI request log.
4. Questions
Data-residency and data-protection queries: privacy@servgrid.net. Sub-processor changes are notified in advance as described in the DPA.