What is data residency?

Data residency
Data residency is the question of which country or region data is physically stored in, which matters because the law that applies follows the location.

What data residency means in practice

Regulation drove the whole topic. Several regimes require personal data about their residents to stay within a border, or to leave only under specific arrangements.

Storage is the easy half to answer. Processing is harder, and a system that stores in one region may still process elsewhere for a moment.

Backups are where confident answers fall apart. Replication to a second region is a resilience feature and a residency problem at the same time.

Subprocessors extend the question further. A vendor's own answer says nothing about the speech or language services behind it.

What people get wrong

One Toronto caller, four possible locations

Say you run a physiotherapy clinic in Toronto and a patient asks where her call recording is kept. You check with your phone vendor, and the answer is "AWS, us-east-1", which means Northern Virginia. That's one location. Keep asking and you may find three more. Transcription might run in Oregon. Whichever language model writes the replies could be called in any region with spare capacity. Backups copy nightly to a second region for safety.

So your honest reply to the patient is: stored in Virginia, processed in at least two other US sites, with a backup copy in a fourth. None of that is unusual or careless, because it's how most cloud products are assembled. It's still a different answer from "us-east-1". If a contract you've signed says records stay in Canada, only the full version tells you that you have a problem.

When it matters, and the two-line email that settles it

For most US small businesses serving US customers, residency isn't a legal question at all. A few situations change that. You might serve customers in the EU or the UK, where rules restrict moving personal data abroad without specific safeguards. Perhaps you work for a government body or a hospital whose contract names a location. Or a large customer sends you a security questionnaire with a residency line in it.

If any of those applies, send each vendor two questions in writing. In which regions is our data stored, processed and backed up? Which of your subprocessors handle it, and where do they run? Written answers matter because you may need to show them to somebody later.

A vague reply like "we use secure cloud hosting" means they don't know or won't say, and either way you've learned what you needed. Don't accept a sales call in place of the email.

How GreetKeeper handles it

GreetKeeper makes no residency commitment, and we are not going to invent one for a page.

If you are subject to a residency requirement, ask us directly before you buy rather than after, because the answer may not suit you.

Retention length is the lever that reduces exposure regardless of where records sit.

Data residency questions

Does it matter for a small US business?

Usually not, unless you serve customers in a region with its own rules. It becomes a real question the moment you do.

Is residency the same as sovereignty?

No. Residency is where data sits. Sovereignty is about which government can compel access to it, which can be a different answer entirely.

What about the AI services behind a product?

They have their own regions, and they are the part most often left out of a vendor's answer. Ask about each layer.

Hear it take one of your calls

Two minutes, your own scenario, no card.