Where is our data stored?

What SaaS companies need to publish

For any business buyer this is a procurement gate. An unanswered version stalls the deal at legal review.

How customers actually ask it

The same intent arrives in wording your page probably does not use. All of these mean the same thing:

  • Where is our data stored?
  • data residency
  • is our data in the EU
  • GDPR
  • do you have a DPA

What a complete answer contains

For SaaS companies specifically, an answer is only complete when it covers all 5:

  1. 1

    The actual region or regions, named

  2. 2

    Whether data residency can be chosen, and on which plan

  3. 3

    Which sub-processors have access, and a link to the current list

  4. 4

    Whether a signed DPA is available and how to get one

  5. 5

    Your position on training AI models on customer data, stated explicitly — this is now asked in almost every review

A worked example

Illustrative — not a real business

Customer data is stored in the EU (Frankfurt). US residency is available on the Enterprise plan. Our sub-processor list is published and we notify 30 days before it changes. A DPA is available from the Legal page. We do not train models on customer data.

Which page should own it

Security / trust page

What silence costs

This blocks deals silently at the legal stage, weeks after your sales team thought the deal was won.

More questions SaaS companies get

Related

Does your site answer this already?

Point RubyRep at your website and ask it this exact question. If it cannot answer, neither can your customers.

https://

Takes about a minute. No credit card.