Book a Demo

Home / Trust / Data Residency

Data Residency

Customer data is pinned to the region the customer chooses at workspace creation. It does not leave that region for primary processing or backups. The choice is permanent — Appice does not migrate workspaces between regions without an explicit customer-driven project.

Three regions

India (IN)

api.in.appice.io

Mumbai (ap-south-1) and Hyderabad (ap-south-2) availability zones. Backups in-country.

  • Hosted on AWS India
  • Compliant with India DPDP Act 2023
  • Aligned with RBI Cyber Security Framework
  • Data never leaves India

GCC

api.gcc.appice.io

Bahrain and Saudi Arabia availability zones. Backups in-region.

  • Hosted on AWS Bahrain (me-south-1) and AWS Saudi Arabia (me-central-1)
  • Aligned with SAMA, CBUAE, CBB cybersecurity frameworks
  • Saudi data resident in Saudi Arabia for KSA-regulated customers
  • Data never leaves GCC

EU

api.eu.appice.io

Frankfurt (eu-central-1) and Ireland (eu-west-1) availability zones.

  • Hosted on AWS EU
  • GDPR Standard Contractual Clauses for any onward transfers to sub-processors
  • Backups in-region
  • Data never leaves EU/EEA

What stays in-region

What can cross regions (with customer authorization)

How regional isolation is enforced

LayerControl
NetworkEach region is a separate VPC with no cross-region peering for data planes
StoragePer-region database clusters and object storage buckets
IdentityPer-region IAM, separate KMS keys, no cross-region key sharing
BackupsPer-region S3 / Azure Blob with regional retention policies
MonitoringAggregated metrics only — no raw events leave the region

Choosing a region

The correct region is usually obvious from where the data subjects live and the regulator the customer reports to. Some examples:

Related