---
title: "EU Data Residency for Internal AI Assistants: 9 Vendors Compared (2026)"
description: "Not one of nine internal AI assistant vendors promises that AI inference happens inside your chosen EU region. Storage residency and inference residency are different products, and only one vendor documents a control over the second. Glean, Dust, Guru, Sana, Microsoft 365 Copilot, Gemini, Notion AI, Slack AI and Atlassian Rovo, every cell quoted from the vendor. Verified 6 September 2026."
url: "https://ainora.lt/blog/internal-ai-assistant-eu-data-residency-2026"
published: "2026-09-06"
author: "Justas Butkus"
---

# EU Data Residency for Internal AI Assistants: 9 Vendors Compared (2026)

**Not one of the nine internal AI assistant vendors we checked promises that AI inference happens inside your chosen EU region.** All of them will tell you where your data is stored. That is a different question, and the gap between the two is where EU procurement decisions go wrong. Google is the only vendor in the set with a documented processing-region control, and it is gated to the top editions. Microsoft documents the opposite as its default.

Every cell below was read on the vendor's own page on **6 September 2026** and is quoted rather than summarised. Where a vendor holds more than we do, this page says so, because a comparison a reader can catch out is worth nothing.

## Does EU data residency cover the AI part?

Usually not, and the vendors are not hiding it so much as answering a narrower question than the one buyers think they asked. “Data residency” in this market almost always means *storage at rest*. The model that reads your documents and writes the answer is a separate service, often a separate company, and it frequently runs somewhere else.

- **0 of 9** - vendors that promise AI inference happens inside the customer’s chosen EU region (Source: Google Workspace, data covered by data regions - https://knowledge.workspace.google.com/admin/compliance/data-covered-by-data-regions)
- **1 of 9** - with any documented processing-region control at all, and it is gated to Enterprise Plus (Source: Google Workspace, data region features by edition - https://knowledge.workspace.google.com/admin/compliance/compare-data-region-features-across-google-workspace-editions)
- **25 Mar 2026** - the date Microsoft made routing EU Copilot inference to the US, Canada or Australia the default for new tenants (Source: Microsoft Learn, Copilot flex routing - https://learn.microsoft.com/en-us/microsoft-365/copilot/copilot-flex-routing)

## Storage residency and inference residency are two different products

Hold the two apart and the whole field becomes readable.

**Storage residency** is where the index, the documents, the chat history and the embeddings sit when nothing is happening. It is a well-understood, well-documented feature and most of these vendors sell it. It is also the one a compliance questionnaire usually asks about.

**Inference residency** is where the model runs at the moment it reads your content and produces an answer. It is harder to provide, because the model may belong to a third party with its own footprint, and because capacity is scarce and moves. Almost nobody sells it, and most vendors do not have a page about it at all.

There is a third thing that gets mistaken for both, and it is worth naming because two vendors here lean on it: a **trust-boundary claim**. “Our models run inside our own cloud account” and “the model provider never sees your data” are statements about *who* can reach the content, not about *where* it is. They can be entirely true and still tell you nothing about geography. Slack and Atlassian both make claims of this shape, and both are worth having, but neither answers a residency question.

## Nine vendors, three questions each

Read column two and column three as separate answers. In six of the nine rows they differ.

| Vendor | EU region for storage | Does residency cover inference | Which tier it takes |
| --- | --- | --- | --- |
| Glean[Source: Glean docs, supported GCP regions](https://docs.glean.com/get-started/prepare/self-hosted-deployment/gcp/supported-gcp-regions) | Yes, europe-west4, but it must be requested. “The default region for tenants hosted by Glean is us-central1, which is located in North America.” | No. Its sub-processor list places all seven dedicated LLM providers in the United States with no customer-discretion footnote, and open models are US-hosted regardless of the tenant region. | Enterprise deployment choice |
| Dust[Source: Dust, security page](https://dust.tt/home/security) | Yes, on the self-serve tier. “Host in the EU or US to meet your regulatory needs.” The EU instance answers on its own hostname. | Not separately documented. No page describing data residency exists in the docs sitemap. | Business, the self-serve plan |
| Guru[Source: Guru, privacy policy](https://www.getguru.com/privacy) | No. “Personal Data that you provide while in the EU or an EAA member state will be transferred to the United States.” (Guru’s own spelling of EEA.) | No. There is no EU region to place it in. | Not offered at any tier |
| Sana (Workday)[Source: Sana, sub-processor list PDF (last updated 27 May 2026)](https://sanalabs.com/download/legal/subprocessors.pdf) | Yes, and the EU is the default for hosting. The sub-processor list gives Google Cloud Ireland as “EEA/EU (default) USA (option for US customers)”. | No, and the vendor says so: “If no specific agreement has been entered into, default worldwide routing will apply.” | Enterprise, now attached to Workday HCM or Financial Management |
| Microsoft 365 Copilot[Source: Microsoft Learn, Copilot flex routing](https://learn.microsoft.com/en-us/microsoft-365/copilot/copilot-flex-routing) | Yes, the EU Data Boundary, by tenant sign-up country. Multi-Geo customers “are not in scope for the EU Data Boundary”. | No, and the default changed. Flex routing sends inferencing to “the United States, Canada, and Australia” at peak, and is on by default for tenants created after 25 March 2026. An admin can switch it off. | By tenant sign-up country, not by licence tier |
| Gemini for Google Workspace[Source: Google Workspace, data covered by data regions](https://knowledge.workspace.google.com/admin/compliance/data-covered-by-data-regions) | Yes. “With data regions, you can choose to store your covered data in a specific geographic location (the United States or Europe).” | Yes, uniquely, but gated. Google’s table ticks Gemini prompts and responses for processing as well as at rest, then footnotes “Data covered during processing varies by Google Workspace edition.” | At rest: Business Standard and up. Processing: Enterprise Plus, Frontline Plus, or the Data Regions add-on |
| Notion AI[Source: Notion, data residency help page](https://www.notion.com/help/data-residency) | Yes, Frankfurt and Ireland, but sales-gated. “Until you contact Notion and receive confirmation that migration is complete, your workspace data will remain hosted in the United States.” | No, and Notion states it plainly: processing outside the region “can include: Customer Data processed by Notion subprocessors, including LLM providers.” | Enterprise only |
| Slack AI[Source: Slack, data residency for Slack](https://slack.com/help/articles/360035633934-Data-residency-for-Slack) | Yes, Frankfurt, Paris and Stockholm. “If you’re not using data residency, your data will be stored in the US.” | Not documented. AI does not appear in the exhaustive list of covered categories. Slack’s nearest statement is that its models run inside its own AWS virtual private cloud, which is a claim about the trust boundary rather than about geography. | Business+ and Enterprise, sales-gated |
| Atlassian Rovo[Source: Atlassian, understand data residency](https://support.atlassian.com/security-and-access-policies/docs/understand-data-residency/) | Yes, Frankfurt and Dublin, and available from the Standard plan, which is the broadest tier availability in this set. “By default, all Atlassian apps are hosted in the Global location.” | Split. Rovo’s own chat logs, agent configuration and ingested third-party content can be pinned; the “AI data” generated inside Jira, Confluence and the rest cannot. Routing is dynamic by default, and Atlassian-hosted-only models are “available by request for Cloud Enterprise organizations”. | Standard and up, self-serve |
| Ainora | Customer data is processed and stored on servers inside the European Union. Where a sub-processor is involved in delivering the service, any transfer outside the EU or EEA takes place under the safeguards the GDPR requires, and the sub-processors are named in our privacy policy. | EU-only processing is available on request for deployments that require it. We do not claim it as an unconditional default, because on the evidence standard this page applies to everyone else, that claim would not survive our own sub-processor list. | Individual pricing |

## Microsoft: the default changed on 25 March 2026

This is the most consequential item in the field this year and most published comparisons have not caught up with it, including, until this week, our own.

Microsoft's Copilot privacy documentation still opens with a reassuring sentence: “EU traffic stays within the EU Data Boundary while worldwide traffic can be sent to the EU and other countries or regions for LLM processing.” Microsoft's own [EU Data Boundary exception register](https://learn.microsoft.com/en-us/privacy/eudb/eu-data-boundary-ongoing-partial-transfers), a page whose title is literally about services that transfer customer data out of the boundary on an ongoing basis, then records the exception:

> “To help maintain a consistent Copilot experience during periods of peak demand, Copilot prompts, responses, and grounding data may be processed outside the EU Data Boundary for AI inferencing, including in the United States, Canada, and Australia. Pseudonymous user IDs may be stored in those locations for security and operational purposes. This applies to tenants that allow flex routing as described in Flex routing (EU and EFTA).”

And the default, from the flex routing page itself: “Flex routing is on by default for eligible tenants that were created after March 25, 2026.” Tenants that existed before that date are told to check the Message Center for their own setting, which means an EU organisation cannot know its own answer without looking.

> **The fair reading, because the switch is real**
>
> This is a default, not a lock-in. Microsoft states that “EU and EFTA customers can disable flex routing in the Microsoft 365 admin center at any time,” and that if you do, “LLM inferencing will occur inside the EU Data Boundary, even during periods of peak demand.” So Microsoft is one of the few vendors here that *can* keep inference in the EU on request. The problem is that it does not do so unless somebody goes and says so, and the organisations most likely to care are exactly the ones whose policy documents already assume it. Two further carve-outs belong in the same admin session: Anthropic models inside Copilot are excluded from the boundary, though Microsoft records that EU Data Boundary and UK customers “have Anthropic models disabled by default”; and tenants that purchased Multi-Geo Capabilities “are not in scope for the EU Data Boundary even if their tenant is listed as being in a country or region in the EU or EFTA.”
>
> [Source: Microsoft Learn, Copilot flex routing](https://learn.microsoft.com/en-us/microsoft-365/copilot/copilot-flex-routing)

## Google: the only documented processing-region control, and it is edition-gated

Google is the exception in this comparison and it deserves the credit, including because the claim most often made about it is now wrong.

It has been widely repeated, on other people's pages and previously on ours, that Google Workspace data regions do not cover AI. That is no longer true. Google's data-regions table lists “Gemini App” and “Google Workspace with Gemini” with “Prompts and responses” as covered data, and ticks both the “Data covered at rest” and the “Data covered during processing” columns. On the same page Google explains what “data regions” buys: “With data regions, you can choose to store your covered data in a specific geographic location (the United States or Europe).”

The catch is the entitlement, not the data type, and Google footnotes it on the same page: **“Data covered during processing varies by Google Workspace edition.”** Reading the edition matrix cell by cell: Business Starter gets no data-regions control at all. Business Standard and Business Plus can set a single data-at-rest region policy but the row for setting data-region *processing* policies is unavailable to them. The processing-region policy arrives with Enterprise Plus, and with Frontline Plus or the Data Regions add-on.

One exclusion survives regardless of edition, and it is the surface most likely to be handed a folder of internal documents: “When users upload sources from Drive, Gemini Notebook creates a new copy of each file. This new file is stored with the user's Gemini Notebook data, not in their Drive. Your organization's file sharing and data region settings do not apply to data in Gemini Notebook.”

## Notion and Slack: one says the quiet part, the other says nothing

**Notion** is the most quotable vendor in the set precisely because it writes down the thing everyone else leaves implicit. Under the heading “When is Customer Data processed outside the data region?” it answers: processing outside the region “can include: Customer Data processed by Notion subprocessors, including LLM providers.”

Read Notion's own AI answer next to it, because it answers a different question from the one it asks. Asked whether customer data is stored in the data region when using Notion AI, Notion says the covered categories are stored in the data region, and then: “The large language model (LLM) providers we use to provide Notion AI utilize zero data retention for Enterprise Plan workspaces, so no data is stored with LLM providers.” The claim is that nothing is *stored* at the provider. It is not a claim that inference happens in the EU. Combined with the sub-processor sentence, the honest reading is storage in Frankfurt or Ireland, inference wherever the sub-processor runs. Notion's residency is also Enterprise-only and sales-gated, and until you ask for it, “your workspace data will remain hosted in the United States.”

**Slack** is the opposite case: it is not that Slack says something unfavourable, it is that Slack says nothing. Its data-residency article gives an exhaustive list of the categories stored in your selected region, and the list is messages, canvases and snippets, files, the search index, app and bot messages, and app data. There is no AI category in it. No summaries, no recaps, no prompts, no AI outputs. Searching the body of that article for “AI” or “artificial” returns nothing at all.

> **State the absence, and state it precisely**
>
> The accurate sentence is: *Slack's data-residency documentation lists the categories it covers and AI is not among them. Slack states elsewhere only that its models run inside its own AWS virtual private cloud, which is a claim about the trust boundary rather than about geography.* The inaccurate sentence, which we are not making, is “Slack says AI leaves your region.” Slack says no such thing. Not documenting a thing and documenting the opposite are different findings, and treating them the same is how comparison tables become wrong.
>
> [Source: Slack, data residency for Slack](https://slack.com/help/articles/360035633934-Data-residency-for-Slack)

## Glean and Sana: where the sub-processor list settles it

Both of these vendors offer EU hosting, and in both cases the interesting answer is one document deeper than the marketing page.

**Glean** documents an EU region, `europe-west4`, as one of three preferred regions. It also documents the default, and the default is not Europe: “The default region for tenants hosted by Glean is us-central1, which is located in North America. Please advise Glean if you would like your tenant deployed in an different region.” (The typo is Glean's.) So “Glean offers EU hosting” is true and “Glean is EU-hosted” is not.

Then read the asterisks on its sub-processor list. Three cloud providers are listed in the United States with a footnote saying “Customers have discretion to select a different Cloud Service Provider and location.” The seven dedicated LLM providers carry no such footnote and are listed, flatly, as United States. Glean also documents that open models are US-hosted regardless of the customer's region. The checkable sentence is therefore sharper than a residency badge: Glean lets an EU customer choose where the tenant sits, and its own sub-processor list places every dedicated LLM provider in the United States with no stated customer discretion.

**Sana**, now owned by Workday, is the vendor whose own compliance document contains the single most citable sentence in this whole comparison. Its sub-processor list gives Google Cloud Ireland for hosting infrastructure as “EEA/EU (default) USA (option for US customers)”, so the EU is genuinely the default for hosting, which corrects a claim we have seen repeated in the other direction. But on the row for its LLM provider, the same document says:

> “Routing is dependent on configurations as agreed between the Subscriber and Sana. **If no specific agreement has been entered into, default worldwide routing will apply.**”

That is a vendor stating, in its own compliance artefact, that customer content is routed worldwide to a model by default unless the customer negotiates otherwise. It is not a scandal and it is not unusual. It is simply the field, written down. Several of Sana's core sub-processors are also US-only regardless of the hosting region, including its primary data store.

## Dust, Guru and Atlassian: the two ends of the range

**Dust** is the vendor against whom EU hosting is not a differentiator for anyone, us included. It is a French company, its security page says “Host in the EU or US to meet your regulatory needs,” its feature matrix marks data residency as available on both the Business and Enterprise plans, and its EU instance answers on its own hostname. That is EU residency on a self-serve tier at a published price, which is more than most of this field offers. The honest and narrow difference is contractual: the same matrix marks “Custom legal terms (MSA, DPA)” as Enterprise-only, so a smaller EU buyer on the Business plan cannot get a signed data-processing agreement on standard terms. For a controller with GDPR Article 28 obligations that is a genuine problem, and it has nothing to do with geography.

**Guru** is the other end. There is no EU region on any published page. Its privacy policy says: “Personal Data that you provide while in the EU or an EAA member state will be transferred to the United States.” (“EAA” is Guru's own spelling.) It relies on the EU-U.S. Data Privacy Framework for the transfer and on standard contractual clauses or consent as safeguards. For a buyer whose policy requires in-region storage, that is disqualifying regardless of everything else on the product. It is worth saying in the same breath that Guru holds a SOC 2 Type II report, which we do not.

**Atlassian Rovo** has the broadest tier availability in the set, and a genuinely split answer. Residency covers Jira, Jira Service Management, Jira Product Discovery, Loom and Confluence on Enterprise, Premium *and Standard* plans, which is materially broader than Slack's Business+ or Notion's Enterprise-only. Rovo's own data can be pinned: chat session logs, agent configuration, Rovo bookmarks and ingested third-party content. What cannot be pinned is the “AI data” generated inside Jira, JSM, JPD, Confluence and Focus. Do not flatten that into “Rovo ignores data residency”, which is inaccurate. On the model itself, Atlassian says routing is dynamic by default across Atlassian-hosted and third-party providers, and that customers can elect Atlassian-hosted models only, “available by request for Cloud Enterprise organizations” and with “slight variations in performance and latency”. Note the shape of that promise: it is a boundary claim, not a geography claim.

## Does the GDPR even require EU data to stay in the EU?

No, and the cleanest statement of it comes from one of the vendors in this comparison. Slack's own trust page asks and answers: *“Does the GDPR require EU personal data to stay in the EU? The GDPR does not require EU data to reside in the European Union.”*

That is correct, and it is worth being the page that says so. The GDPR regulates international transfers rather than prohibiting them, which is why several vendors here rely on transfer mechanisms instead of on regions. In-region storage is a policy choice, a customer requirement, a sector rule or a sovereignty preference, and any of those can be a completely sound reason to insist on it. What it is not is a blanket legal obligation, and a vendor page that implies otherwise is selling a requirement rather than answering one.

Two practical consequences follow. If your requirement is contractual, coming from your own customers or your own policy, then write it as a region name and hold the vendor to it. If your requirement is legal, the questions that actually matter are about the transfer mechanism, the sub-processor list and the data-processing agreement, and at least one vendor here gates the last of those behind an enterprise contract.

## The six questions to put to a vendor in writing

Each of these is answerable in one sentence by a vendor who has thought about it, and each has at least one vendor in this comparison who answers it in the customer's disfavour, which is what makes them worth asking.

| Ask this | Why, with the vendor that makes the point |
| --- | --- |
| 1. Where is customer content stored at rest, and is that the default or an option I have to ask for?[Source: Glean docs, supported GCP regions](https://docs.glean.com/get-started/prepare/self-hosted-deployment/gcp/supported-gcp-regions) | Glean’s default is us-central1 even though europe-west4 exists. Notion stays in the United States until you contact them and the migration completes. |
| 2. Where does inference run, and can I pin it? Name the region.[Source: Google Workspace, data region features by edition](https://knowledge.workspace.google.com/admin/compliance/compare-data-region-features-across-google-workspace-editions) | This is the question that separates the field. Only one vendor in this set documents a processing-region control, and it comes with the top edition. |
| 3. Is there a routing default that overrides my region under load, and how would I know it had fired?[Source: Microsoft Learn, Copilot flex routing](https://learn.microsoft.com/en-us/microsoft-365/copilot/copilot-flex-routing) | Microsoft documents exactly this, calls it flex routing, and turns it on by default for tenants created after 25 March 2026. |
| 4. Which sub-processors touch prompt content, and in which country is each one located?[Source: Glean, sub-processor list (last updated 28 July 2026)](https://www.glean.com/legal/subprocessors) | Glean’s and Sana’s published lists answer this and the answers are more specific than either marketing page. |
| 5. Does a data-processing agreement come with my plan, or only with Enterprise?[Source: Dust, pricing page](https://dust.tt/home/pricing) | Dust gates its DPA to Enterprise. A smaller EU buyer on the self-serve plan cannot sign one on standard terms. |
| 6. Which product surfaces are excluded from the residency policy entirely?[Source: Google Workspace, generative AI privacy hub](https://knowledge.workspace.google.com/admin/generative-ai/generative-ai-in-google-workspace-privacy-hub) | Google documents that Gemini Notebook is outside it. Atlassian excludes in-product “AI data”. Notion excludes Calendar, Mail and Beta services. |

Put them in writing rather than on a call. The written answer is the one that survives into the data-processing agreement, and it is the one you can put in front of a data protection officer. Our longer [vendor security assessment template](/blog/ai-voice-agent-vendor-security-assessment-template) covers the same discipline for a different class of vendor, and [the questions that actually get answers about where data goes](/blog/where-does-ai-call-data-go-vendor-questions) covers the sub-processor question in more depth.

## Where we sit, including what we do not have

We build EU-native, and the accurate version of that sentence is narrower than the marketing version, so here is the accurate version. Customer data is processed and stored on servers inside the European Union. Where a sub-processor is involved in delivering the service, any transfer outside the EU or EEA takes place under the safeguards the GDPR requires, and those sub-processors are named in our [privacy policy](/privacy) rather than on a marketing page. **EU-only processing is available on request** for deployments that require it. What we are not saying, because it would fail the test this page applies to everybody else, is that no data ever leaves the EU under any circumstances. We corrected that absolute claim across our own site rather than leave it standing.

What we do not have matters just as much on a page like this, so here it is plainly. **Ainora holds no SOC 2 report, of any type, and no ISO certification.** Glean, Sana, Notion, Slack, Atlassian, Microsoft and Google all hold SOC 2 and ISO 27001; several hold ISO 42001 as well; Dust claims SOC 2 Type II. Those are their credentials, not ours, and an infrastructure provider's certificate is theirs too and does not transfer to us by hosting. If your procurement process requires a SOC 2 report from the vendor, we do not have one to give you, and you should know that from a comparison page rather than from week three of an evaluation. Uptime we do state, because it is true: 99.9%.

On pricing, ours is individual and quoted per engagement rather than published, which puts us in the same category as Glean and Guru on transparency and behind Dust, Notion, Slack, Microsoft and Google. That is not a boast. It is the accurate cell in the table.

If you want to see the rest of this cluster: [what an AI teammate does inside a company](/ai-teammate) is the hub, [the provider directory](/ai-teammate/providers) compares the field one vendor at a time, [permission leakage](/blog/internal-ai-assistant-permission-leakage) covers the failure mode buyers meet after purchase, [retrieval versus agentic](/blog/rag-vs-agentic-internal-ai-assistant) gives you the three questions that separate a search box from something that can write into your systems, [training defaults by account tier](/blog/does-your-ai-vendor-train-on-your-data) covers the four consumer assistants your staff already use, and [the hours-wasted-searching statistic](/blog/hours-wasted-searching-for-information-studies) traces the number your business case is probably resting on.

> **Method and re-verification**
>
> Every quotation on this page was read on the vendor's own page or in the vendor's own PDF on **6 September 2026**. Two of the underlying artefacts are compliance documents with their own last-updated dates: Glean's sub-processor list, 28 July 2026, and Sana's sub-processor list, 27 May 2026. Where a page is a client-rendered shell that returns no text to a fetch, that is noted rather than worked around, and nothing is quoted from it. This page is re-checked quarterly and the next scheduled re-verification is December 2026. Residency terms in this market change without changelogs, which is exactly what happened at Microsoft on 25 March 2026, so treat any comparison table older than a quarter, including this one, as a starting point for your own check rather than as an answer.

## Frequently Asked Questions

**Does EU data residency cover AI processing?**

On the published evidence, almost never. We checked nine internal AI assistant vendors on 6 September 2026 and not one of them promises that AI inference happens inside the customer’s chosen EU region. Google comes closest and is the only vendor in the set with a documented processing-region control, and that control is gated to Enterprise Plus, Frontline Plus or a paid add-on. Microsoft documents the opposite as its default for tenants created after 25 March 2026. Sana documents worldwide routing as its default absent a negotiated agreement. Notion states plainly that processing outside the region can include customer data processed by its LLM providers. Slack says nothing about AI in its residency documentation at all. Residency of data at rest and residency of inference are two different products, and most vendors only sell the first. (Source: Google Workspace, data covered by data regions - https://knowledge.workspace.google.com/admin/compliance/data-covered-by-data-regions)

**Is Microsoft 365 Copilot still inside the EU Data Boundary?**

Partly, and less completely than before 25 March 2026. Microsoft’s privacy page still says “EU traffic stays within the EU Data Boundary while worldwide traffic can be sent to the EU and other countries or regions for LLM processing.” Its own EU Data Boundary exception register then records that “Copilot prompts, responses, and grounding data may be processed outside the EU Data Boundary for AI inferencing, including in the United States, Canada, and Australia.” Microsoft calls this flex routing and states it is “on by default for eligible tenants that were created after March 25, 2026.” EU and EFTA admins can switch it off at any time, after which “LLM inferencing will occur inside the EU Data Boundary, even during periods of peak demand.” Two further carve-outs: Anthropic models inside Copilot sit outside the boundary but are “disabled by default” for EU Data Boundary and UK customers, and tenants that bought Multi-Geo Capabilities “are not in scope for the EU Data Boundary” at all. (Source: Microsoft Learn, Copilot flex routing - https://learn.microsoft.com/en-us/microsoft-365/copilot/copilot-flex-routing)

**Which vendor has the best EU data residency for an internal AI assistant?**

It depends which of two questions you are asking, and they have different answers. If you need the processing region pinned, Google Workspace is the only vendor in this set with a documented control, and you need Enterprise Plus, Frontline Plus or the Data Regions add-on to get it. If you need residency available without an enterprise negotiation, Atlassian offers it from the Standard plan and Dust offers it on its self-serve Business plan, which are the two broadest tier availabilities here. If your policy simply forbids storage outside the EU, Guru is disqualified outright because it has no EU region and transfers EU and EEA data to the United States. (Source: Atlassian, understand data residency - https://support.atlassian.com/security-and-access-policies/docs/understand-data-residency/)

**Does the GDPR require EU personal data to stay in the EU?**

No, and one of the vendors in this comparison says so on its own trust page: “The GDPR does not require EU data to reside in the European Union.” The GDPR regulates international transfers rather than banning them, which is why several vendors here rely on transfer mechanisms instead of regions. In-region storage is a policy choice, a procurement requirement or a sector rule, and it is often a perfectly good one. It is just not the same thing as a legal obligation, and a vendor comparison that conflates the two is easy to catch out. (Source: Slack, trust and compliance - https://slack.com/trust/compliance)

**Is EU hosting a differentiator against Dust?**

No, and we would rather say that than let a reader catch us at it. Dust is a French company offering EU data residency on its self-serve Business plan at a published price, with a live EU instance. Against Dust, EU hosting is not a differentiator for anyone. The genuine and narrow difference is contractual rather than geographic: Dust’s feature matrix marks “Custom legal terms (MSA, DPA)” as Enterprise-only, so a smaller EU buyer on the Business plan cannot get a signed data-processing agreement on standard terms. For a controller with GDPR Article 28 obligations, that is a real problem, and it is a different problem from where the servers are. (Source: Dust, pricing page - https://dust.tt/home/pricing)

**What is the single question that separates the vendors?**

Ask where inference runs, and ask for the answer in writing with a region name in it. Every vendor in this set can answer where data is stored. The answers diverge sharply the moment you ask where the model runs, and three of the nine answer it in the customer’s disfavour in their own documentation: Microsoft with flex routing, Sana with default worldwide routing, and Notion by listing LLM providers among the sub-processors that process outside the region. A vendor that answers the storage question and changes the subject has answered a different question from the one you asked. (Source: Sana, sub-processor list PDF (last updated 27 May 2026) - https://sanalabs.com/download/legal/subprocessors.pdf)

Related on Ainora

Explore the platform and industry pages relevant to this article.

- [AINORA AI voice agentPlatform overview and capabilities](/ai-voice-agent)
- [AI debt collectionCompliant voice for recoveries](/ai-debt-collection)
- [PricingHow we quote per project](/pricing)
- [How it worksSetup, integrations, and go-live](/how-it-works)
