Regions and data residency
Data residency is the single most common procurement blocker in education, and the answer differs by country. A German school needs EU hosting. A UK academy trust needs the UK or the EU. A US district asks about FERPA. A Canadian board often has a province-level requirement. An Australian school asks about the Privacy Act.
So there is no company-wide default region. It is settled during the sale, recorded on the deployment, and shown back to you during onboarding to confirm.
Available regions
Section titled “Available regions”| Region | Location | Residency statement |
|---|---|---|
ap-southeast |
Sydney, Australia | Application and regional backup location |
ap-singapore |
Singapore | Application and regional backup location |
ap-south |
Bangalore, India | Application and regional backup location |
eu-central |
Frankfurt, Germany | Application and regional backup location |
eu-west |
Amsterdam, Netherlands | Application and regional backup location |
uk-south |
London, United Kingdom | Application and regional backup location |
ca-central |
Toronto, Canada | Application and regional backup location |
us-east |
New York, United States | Application and regional backup location |
us-west |
San Francisco, United States | Application and regional backup location |
Adding a region is not an architecture change. If you need one that is not listed, ask.
What stays in the region
Section titled “What stays in the region”The managed application database and uploaded files are hosted in the agreed region. Backup destinations and replication must match the deployment agreement.
External connectors, email, external AI inference and edge services have separate processing locations. Billing and support records are separate business records. Count-only usage reporting excludes school records and ticket content, but this does not make all other processing regional. See what we process.
The instance can answer for itself
Section titled “The instance can answer for itself”Admin, Compliance in your own deployment states its configured region, its residency and what each configured connector sends where. It reads this from local configuration, so it still answers while the deployment is cut off from everything else.
This is the page to screenshot for a departmental vendor assessment. See compliance answers.
What each connector sends where
Section titled “What each connector sends where”Residency covers the data we hold. A connector you enable sends data to that vendor, which is a separate question and one an assessment will ask separately.
The compliance page states it per category, because the question is about the kind of data leaving, and a school swapping Jamf for Intune has not changed the answer.
| Category | What leaves |
|---|---|
| MDM | Device serial numbers, models, assignment and compliance state |
| SIS | Student and staff names, year levels, identifiers and email addresses |
| Directory | Names, usernames, email addresses and group membership |
| Message content and recipient addresses | |
| SMS | Phone numbers and message content |
| Ticketing | Ticket subject, body and requester details |
| Warranty | Serial numbers |
| Repair vendor | Serial numbers, fault descriptions and contact details |
| Security | Device identifiers and application approval requests |
| CRM | Account and contact details |
| Printing | Usernames, card numbers and print balances |
| AI | Ticket text and what you ask the assistant. Where it goes depends on which of the three AI connectors you configured |
The AI row is worth reading twice. Where ticket text goes depends on which of the three AI connectors you configured: nowhere at all for the bundled model, to your chosen provider on your own key, or to our inference provider on a managed plan that includes AI. None of that extends to a third-party MCP client you connect, because that client’s model sees whatever it is handed.
Self-hosted
Section titled “Self-hosted”Your data is wherever your server is. The compliance page still works and still states what each connector sends, which is usually the part an assessment asks about.
Changing region
Section titled “Changing region”Supported, and treated as a planned migration: an export, a provision in the new region, an import and a DNS change. The same machinery that moves a customer between self-hosted and managed.
Tell us early. The DNS and identity provider changes have lead times that dwarf the actual data movement.