Trust, privacy, and compliance
EU data residency and where your data lives
Ensuring that your personal data remains within the European Union (EU) is a fundamental aspect of data privacy and compliance with regulations such as the GDPR. Unless is designed from the ground up to keep all personal data and sensitive information within the EU, providing strong data residency guarantees. This article explains how Unless manages EU data residency, where your data physically resides, and the safeguards in place to protect it.
what EU data residency means at Unless
Data residency refers to the physical or geographic location where data is stored and processed. For organizations operating in or serving customers in the EU, keeping personal data within EU borders is often a legal requirement under the GDPR and related regulations.
Unless ensures that all personal data and the Privacy Vault — the core component responsible for filtering and tokenizing sensitive information — remain inside the EU/European Economic Area (EEA). This means that your data does not leave the EU at any point during processing or storage. Unlike some platforms that rely on adequacy decisions or transfer impact assessments to move data outside the EU, Unless’s architecture is designed so that data never crosses EU borders, eliminating the need for such measures.
where your data is stored and processed
Unless operates its core infrastructure on cloud providers with data centers located in the EU. Specifically:
- The primary cloud infrastructure runs on Amazon Web Services (AWS) in Ireland.
- Auxiliary workloads run in EU regions of Microsoft Azure and Google Cloud.
All these cloud providers are established EU entities, and their data centers comply with EU data protection standards. This multi-cloud approach within the EU ensures redundancy, reliability, and compliance.
It is important to note that while Unless uses some business tools for its own administration that may be hosted outside the EU, these tools never handle or access end-user personal data. Therefore, your customers’ personal data remains fully protected within the EU environment.
how personal data is protected in transit and at rest
Before any personal data reaches the generative AI models, Unless applies multiple layers of privacy protection through the Privacy Vault:
- PII filtering: Personally identifiable information such as names, emails, and phone numbers is detected and removed or masked.
- Tokenization: Sensitive identifiers are replaced with tokens, so the AI models only see anonymized placeholders.
- Data minimization: Only the minimum necessary data is processed.
- Prompt anonymization: User inputs are anonymized before being sent to AI models.
Because of these measures, raw personal data never leaves the controlled environment of the Privacy Vault, and the generative models never receive identifiable information in a recoverable form.
sub-processors and transparency
Unless uses sub-processors that are all EU-based entities, including AWS, Microsoft Azure, and Google Cloud. The full list of sub-processors is available in your account and updated whenever changes occur. This transparency allows your data protection officer (DPO) and compliance teams to review and audit the data flow and processing partners.
why EU data residency matters
Keeping data within the EU ensures compliance with GDPR’s strict data protection requirements and reduces legal risks associated with international data transfers. It also aligns with the EU AI Act, which adds further obligations for AI systems operating in the EU, especially those interacting with personal data.
By maintaining EU data residency, Unless helps you meet regulatory requirements without the complexity of managing cross-border data transfers or additional legal safeguards.
conclusion
Unless’s commitment to EU data residency means your personal data and sensitive information are stored and processed exclusively within the EU, leveraging trusted cloud providers in Ireland and other EU regions. Combined with robust privacy measures like PII filtering and tokenization, this approach ensures compliance with GDPR and the EU AI Act while protecting your customers’ data sovereignty. This design gives you confidence that your data stays where it belongs — safely inside the EU.