Skip to content

Data residency

Your customer data is stored and processed in the EU (Frankfurt, Germany), encrypted in transit and at rest. This page is the honest, detailed version — including where operational functions touch other regions, and what we do not yet offer.

Where your data lives

  • Databases, object storage, and secrets run in the EU (Frankfurt, Germany).
  • The brand domains, keywords, alerts, verdicts, and evidence packs we generate for you are stored in the EU.
  • TLS protects data in transit; managed encryption protects data at rest.

Operational touchpoints outside the EU

We would rather be precise than say “everything is in the EU” and leave out the details. A limited set of operational functions run in US cloud regions by design:

  • The global content-delivery network and TLS certificate management.
  • Inbound email routing.

Your brand-monitoring data itself is stored and processed in the EU. If a sub-processor ever requires a transfer outside the EEA, we document the transfer mechanism before relying on it.

Sub-processors

  • EU-hosted cloud infrastructure, platform services and storage
  • Stripe Ireland, billing and subscription metadata
  • PostHog EU or self-hosted, analytics after opt-in only
  • EU-hosted AI services, verdict synthesis
  • WHOIS, RDAP, CT, and NRD data providers, domain enrichment

Current limits (stated honestly)

  • We run from a single EU region — there is no US or Asia-Pacific in-region hosting option today.
  • SOC 2 and ISO 27001 certifications are on the roadmap, not yet held.
  • If you need in-region hosting or a specific certification, tell us — we will be straight about what we can and cannot do today.

Compliance

GDPR data-subject rights are built in for every user, and a Data Processing Addendum template is available. For our framework control mappings (ISO 27001, NIST CSF 2.0, SOC 2, NIS2) and the DPA, see the security page.

Data residency questions

Where is my data hosted?

Your customer data — databases, object storage, secrets, and the brand domains, alerts, verdicts, and evidence packs we generate for you — is stored and processed in the EU (Frankfurt, Germany). It is encrypted in transit with TLS and at rest with managed encryption.

Does any of my data leave the EU?

Your brand-monitoring data is stored and processed in the EU. A limited set of operational functions run in US cloud regions by design: the global content-delivery network and TLS certificate management, and inbound email routing. If a sub-processor ever requires a transfer outside the EEA, we document the transfer mechanism first.

Can I get US or APAC in-region hosting?

Not today. impersona.io runs from a single EU region, so there is no US or Asia-Pacific in-region hosting option yet. If your organisation requires in-region hosting for a regulated use case, contact us — we would rather be upfront about current limits than overpromise.

Are you SOC 2 or ISO 27001 certified?

Not yet — both certifications are on our roadmap. Today we map to the relevant controls in ISO 27001, NIST CSF 2.0, SOC 2, and NIS2, and GDPR data-subject rights are built in. The control mappings are documented on our security page.

Who are your sub-processors?

EU-hosted cloud infrastructure and storage; Stripe Ireland for billing metadata; PostHog (EU or self-hosted) for opt-in analytics; EU-hosted AI services for verdict synthesis; and WHOIS, RDAP, CT, and NRD providers for domain enrichment.

Do you offer a Data Processing Addendum (DPA)?

Yes. A DPA template is available to review and download from our security page.