What residency actually means for a support inbox, where "EU region" stops being enough, and the concrete questions to put to any vendor.
Data residency has become a checkbox on every vendor comparison, which means it has also become vague. For a customer-support tool the stakes are unusually concrete, because a support inbox is one of the most sensitive datasets a company holds. This is a short, practical guide to what residency means for that inbox and what to actually ask.
A support conversation is not metadata. It contains names, email addresses, account details, screenshots, order histories, and often the exact problem a customer is anxious about. People disclose things to support they would never put in a form. Under the GDPR all of that is personal data, some of it arguably sensitive, and your company is the controller responsible for it. Every tool that touches the inbox, the helpdesk, the AI that drafts replies, the email sender, the transcription for a call, is a processor acting on your instructions, and each one is a place the data can come to rest or pass through.
Data residency is a claim about where data is stored and processed, at rest and in transit. It is not the same as encryption, and it is not the same as a privacy policy. Under GDPR, moving personal data outside the EU or EEA is a transfer that needs a legal basis and safeguards, and the Schrems II ruling made clear that a data processing agreement alone is not enough when a transfer exposes data to foreign government access. Keeping the data in the EU removes an entire category of that risk rather than papering over it.
Most vendors will tell you they run in an EU region. That is better than nothing, but read it carefully. It usually means their servers sit in an EU data center while the company, its support staff, its subprocessors, and its AI providers may sit elsewhere. Region tells you where a disk lives. It does not tell you who can reach it, which subprocessors see the data on the way, or whether your content trains someone's model. A US-headquartered vendor running in Frankfurt can still be subject to access demands that reach that Frankfurt data. Region is a necessary answer, not a complete one.
The stronger model is for the data to live in accounts you control. Today that is real for email: connect your own AWS SES and every reply leaves from your account, in the region you chose, under a contract with your name on it. You are not trusting a residency promise, you are holding the key. We are extending the same model to the other channels — tenant credentials for telephony and voice are stored and verified today, but provisioning still runs on our accounts, and we would rather say so than let you assume otherwise. Ask any vendor, us included, which parts are actually your infrastructure and which are just their region setting.
Where is customer data stored at rest, and in which specific region. Where is it processed, including by the AI model that generates replies, and is any of it used to train models. List every subprocessor and its location. Can we use our own storage, email, and telephony credentials so the content stays in our accounts. What legal basis and safeguards cover any transfer outside the EEA. Where are your support staff located and what can they see. Do you sign a data processing agreement naming all of the above.
Residency is not about patriotism or paranoia. It is about knowing exactly where your customers' words live and who can reach them, so that when someone asks, and in the EU they increasingly will, you can answer with a fact instead of a hope.