Data Residency

Last updated: 13 June 2026

This page provides a detailed breakdown of where each category of data is stored and processed. Customer backup data is stored exclusively in the EU. Some account management services use providers outside the EEA, as detailed below.

Data location by category

Data categoryWhat it includesLocationProviderEncryption
Customer backup dataFiles and objects uploaded via S3 API, restic, or rcloneGermany (EU)Hetzner Online GmbHAES-256 at rest, TLS 1.3 in transit. Client-side encryption supported.
Storage metadataObject names, sizes, timestamps, bucket configurationGermany (EU)Hetzner Online GmbHEncrypted at rest
Application databaseAccounts, organisations, machines, credentials, usage snapshots, audit logsGermany (EU)UpCloud Oy (managed PostgreSQL)Encrypted at rest and in transit
AuthenticationEmail, login events, session tokens, SSO/SAML configurationUnited StatesWorkOS Inc.Encrypted in transit. SCCs in place.
Transactional emailEmail addresses and notification content for account alerts and invitationsUnited StatesResend Inc.Encrypted in transit. SCCs in place.
Payment and billingPayment method, billing address, invoices, subscription statusUnited StatesStripe Inc. (independent controller)PCI DSS Level 1 compliant
Frontend hostingIP address, request metadata, static assetsGlobal CDN (edge nodes)Vercel Inc.Encrypted in transit. SCCs in place. No customer data.

Customer backup data guarantee

Customer backup data (the files and objects you store on NordenVault) is stored exclusively in EU data centres operated by Hetzner Online GmbH in Germany. This data is never transferred outside the EU unless you explicitly initiate a download or restore to a location of your choosing.

When using client-side encryption (e.g., restic), your data is encrypted before it leaves your machine. NordenVault and its infrastructure provider have no ability to read the contents.

Account management services

Authentication, email delivery, and payment processing are provided by third-party services, some of which are based in the United States. These services process account metadata only (email addresses, login events, billing information) and never have access to the contents of your backup data.

For US-based providers, we maintain EU Standard Contractual Clauses (SCCs) as the legal mechanism for data transfers. Stripe operates as an independent data controller under its own privacy policy.

For the full list of third-party providers, see our subprocessor list.

Questions

If you have questions about data residency or need documentation for a compliance review, contact us at contact@nordenvault.com.