SOC 2 Type II audit in progress · EU, US and India data residency · a DPA you can sign

Trust Center

// solutions / eu data residency

A ticketing system that keeps your data in the EU

Your ticket data — storage, backups, and AI processing — stays in the region you pick at signup. EU, US, or India.

A DPA covers your Article 28 obligations, everything is encrypted in transit and at rest, and every automated action Tux AI takes is logged and attributable.

Region pinning, chosen at signup

Pick your region once at signup. Storage, backups, and AI processing all stay inside it.

Tickets are among the most sensitive records a company keeps. A single queue can hold employee names, customer complaints, internal system details, and screenshots nobody meant to share — so where that sits, and who can reach it, is a GDPR question before it is a product question.

With automated triage, "where is it stored" is only half the question. Processing honors the same boundary as storage.

Your Article 28 paperwork, handled

A region setting is not a contract. You get a DPA, disclosed sub-processors, and SCCs where a transfer mechanism is required.

Under GDPR you are the controller and your ticketing vendor is a processor. Article 28 requires that relationship to be governed by a contract — not a marketing page. The FlowTux DPA covers scope, sub-processors, security measures, and deletion.

Sub-processors are disclosed rather than buried. If a request must cross a border for a specific, disclosed reason, it runs on a recognized transfer mechanism instead of quietly leaving the region.

What your auditor will actually ask — and where it lives

Reviews rarely stop at the region label. Every action, human or automated, leaves a trail you can reconstruct.

Residency is not the same as sovereignty

FlowTux offers residency, not sovereignty. For most EU and Dutch buyers that is enough — if it is not, you should know now, not in month three.

Vendors blur this, so to be precise: residency means data physically sits in a chosen region. Sovereignty is the stronger claim — that no foreign jurisdiction can compel access regardless of where bytes live. Residency plus SCCs and a DPA satisfies the large majority of EU and Dutch buyers, including most public-sector procurement.

If your mandate is full sovereignty — a specific national cloud, or a legal guarantee against foreign access — raise it during evaluation. That is a different architecture, and you deserve a straight answer up front.

What you get

at signup

Region chosen once

Pick your storage region when the workspace is created — processing and at-rest storage both honor it.

in-region

Backups stay inside

Backups inherit the boundary, not just the primary store. The part auditors check first.

Article 28

DPA on request

A data processing agreement covering scope, security measures, sub-processors, and deletion.

published

Disclosed sub-processors

Who else touches your data is listed, not buried in a footnote.

in transit + at rest

Encrypted throughout

Including backups inside the regional boundary.

every action

Auditable automation

Allow-listed in advance and logged with its result.

Set up EU-resident ticketing today

  1. 1

    Create your workspace

    Pick your EU storage region. Free 14-day trial.

  2. 2

    Request the DPA

    Review it and the sub-processor list with your DPO or counsel.

  3. 3

    Point intake at FlowTux

    Support email, Slack, and portal.

  4. 4

    Approve the allow-list

    Start narrow — nothing runs that you have not permitted.

  5. 5

    Export the audit log

    Confirm the trail meets your retention requirements.

Step two is the one your legal review cares about, and it does not block the rest — you can run the trial while the DPA is in review.

Related

Frequently asked questions

Can I choose where FlowTux stores my ticket data?

Yes. You choose your storage region when you create the workspace, and ticket data and backups stay inside that regional boundary for both processing and at-rest storage.

Is FlowTux GDPR compliant?

Yes, on the processor side — with one honest caveat: GDPR compliance is a property of how you operate, not a badge a vendor can hand you. FlowTux provides what you need to hold up your side: an EU storage region, a DPA covering Article 28 processor obligations, disclosed sub-processors, encryption in transit and at rest, audit logs on every action, and Standard Contractual Clauses where a transfer mechanism is required.

Does my ticket data leave the EU for AI processing?

No. Processing honors the region you chose, so AI triage does not move your tickets out of it. Where a specific disclosed sub-processor requires a transfer, it runs on a recognized transfer mechanism such as Standard Contractual Clauses — disclosed in the DPA rather than left implicit.

Do you offer a DPA?

Yes. The DPA covers processing scope, security measures, sub-processors, deletion, and the transfer mechanisms used where data must cross a border. See the DPA page or request a countersigned copy during your trial.

Is data residency the same as data sovereignty?

No. Residency means your data physically sits in a region you chose. Sovereignty is a stronger claim — that no foreign jurisdiction can compel access regardless of location. FlowTux offers residency with a DPA and SCCs, which covers most EU and Dutch requirements. If your mandate is full sovereignty on a specific national cloud, raise it during evaluation.

Ready to stop
fighting fires?

14-day free Pro trial. Every team up and running the same day.
No credit card. No sales call. No implementation consultant.