Skip to content

Regions and data residency

Data residency is the single most common procurement blocker in education, and the answer differs by country. A German school needs EU hosting. A UK academy trust needs the UK or the EU. A US district asks about FERPA. A Canadian board often has a province-level requirement. An Australian school asks about the Privacy Act.

So there is no company-wide default region. It is settled during the sale, recorded on the deployment, and shown back to you during onboarding to confirm.

RegionLocationResidency statement
ap-southeastSydney, AustraliaData stays in Australia
ap-singaporeSingaporeData stays in Singapore
ap-southBangalore, IndiaData stays in India
eu-centralFrankfurt, GermanyData stays in the EU, under GDPR
eu-westAmsterdam, NetherlandsData stays in the EU, under GDPR
uk-southLondon, United KingdomData stays in the UK, under UK GDPR
ca-centralToronto, CanadaData stays in Canada, under PIPEDA
us-eastNew York, United StatesData stays in the United States
us-westSan Francisco, United StatesData stays in the United States

Adding a region is a host plus an entry in the control plane, not an architecture change. If you need one that is not listed, ask.

Everything that is your data. The database, its backups, and any files you upload. Backups replicate within the region only.

Not the control plane. It is global, and it holds counts, versions and billing records. No names, no records, no ticket content. See the control plane.

The distinction matters for an assessment form. “Is any data processed outside the region” has a precise answer: the number of technician accounts and managed devices, the list of enabled modules, and the version, all attached to a deployment id. Nothing that identifies a person.

Admin, Compliance in your own deployment states its region, its residency and what each configured connector sends where. It reads this from local configuration rather than by calling home, deliberately, so it can still answer while cut off from everything, including during the incident where somebody is most likely to ask.

This is the page to screenshot for a departmental vendor assessment. See compliance answers.

Residency covers the data we hold. A connector you enable sends data to that vendor, which is a separate question and one an assessment will ask separately.

The compliance page states it per category, because the question is about the kind of data leaving, and a school swapping Jamf for Intune has not changed the answer.

CategoryWhat leaves
MDMDevice serial numbers, models, assignment and compliance state
SISStudent and staff names, year levels, identifiers and email addresses
DirectoryNames, usernames, email addresses and group membership
EmailMessage content and recipient addresses
SMSPhone numbers and message content
TicketingTicket subject, body and requester details
WarrantySerial numbers
Repair vendorSerial numbers, fault descriptions and contact details
SecurityDevice identifiers and application approval requests
CRMAccount and contact details
PrintingUsernames, card numbers and print balances
AIWhatever you ask the assistant, to a model you host

The AI row is worth reading twice. The in-product assistant runs against a model you host, and nothing is sent to an external AI provider. That guarantee is about the assistant. It does not extend to a third-party MCP client you have chosen to connect, because that client’s model sees whatever it is handed.

Your data is wherever your server is, and that is the whole answer. The compliance page still works and still states what each connector sends, which is usually the part an assessment actually cares about.

Supported, and treated as a planned migration: an export, a provision in the new region, an import and a DNS change. The same machinery that moves a customer between self-hosted and managed.

Tell us early. The DNS and identity provider changes have lead times that dwarf the actual data movement.