Data protection & GDPR

Where your client data is stored, and who else can touch it

Two different questions get bundled together as “is it GDPR compliant”. The first is where the data physically sits. The second is which other companies process it on the vendor’s behalf — the sub-processors — and where they sit. A vendor can answer the first well and still route your client list through half a dozen companies you have never heard of.

The check that separates a real answer from marketing is whether the vendor publishes the full sub-processor register with locations. A list naming only the flattering entries is worse than no list, because it reads like disclosure. Ask for the whole register, including the parts that are not in Europe — every serious vendor has some.

What to check, in three steps

  1. Find out where the database actually is

    Not where the company is registered, and not where a page says “European”. Where the primary database and file storage physically sit. The answer should be a named region or city, not a continent.

  2. Read the sub-processor register, not the privacy policy

    The privacy policy describes intent; the register names companies. Look for the count, each one’s location, and what it is used for. If there is no register at all, that is itself the answer.

  3. Check you can get the data out, and get it erased

    Export and erasure are rights rather than features, but they are only real if a working control exists. Try both before committing: a request that lands in a support inbox is not the same as a button that produces a file.

What ClientFlow answers

The primary database and file storage are in Frankfurt, Germany, so customer data is stored in the EU. Client records export on demand from the dashboard. Deleting an account performs a permanent erasure of personal data and returns a receipt recording what was removed. Audit logs are append-only, enforced by a database trigger rather than by policy — updates and deletes are rejected by the database itself, not merely avoided in code.

The part most vendors leave out

ClientFlow uses 13 sub-processors and publishes all of them with their locations. Two are in Germany. Eight are in the United States, including AI inference, payments, email delivery and error monitoring. The remaining three sit on an EU-primary edge network, in Ireland, and in Turkey. That is why we say customer data is stored in the EU rather than calling the whole service European — it is not, and the register names the inconvenient entries alongside the rest.

Built so the answer is checkable

Customer data stored in the EU, a public sub-processor register, on-demand data export, permanent account erasure with a receipt, and append-only audit logs enforced at the database. A data processing agreement is available, and the privacy documentation names what each sub-processor is used for.

Common questions

Is customer data stored in the EU?

Yes — the primary database and file storage are in Frankfurt, Germany. We do not describe the whole service as European, because some sub-processors, including AI inference, payments, email delivery and error monitoring, operate from the United States. The public register names them.

Can I export or delete everything?

Both. Data export runs from the dashboard and produces a file. Deleting an account performs a permanent erasure of personal data and returns a receipt recording what was removed.

Where is the sub-processor list?

Published on this site, with all 13 entries and each one’s location and purpose, linked from the privacy documentation.