Skip to main content

Where we are based and where your data lives

Registered office, operations and data residency

Customers sometimes ask where MyDocSafe is “based”, where their data is stored, and whether those are the same thing. They are not.

Registered office vs operational location

DocSafe Limited, the company behind MyDocSafe, is a UK company registered in England and Wales. Its registered office is the company's formal legal address and is used for corporate and statutory purposes.

A registered office should not be confused with:

  • where the MyDocSafe application is hosted;

  • where customer files are stored;

  • where cloud infrastructure is located; or

  • where particular suppliers or sub-processors operate.

For data-protection and procurement purposes, the more relevant questions are usually where customer data is stored and processed, rather than the company's registered-office address.

Where is MyDocSafe customer data stored?

When creating a MyDocSafe account, customers can select a preferred data-storage location.

The standard options currently include:

  • United Kingdom

  • European Union (Ireland)

  • United States

MyDocSafe recommends choosing the region that best matches your regulatory and operational requirements. For example, UK organisations would normally select the UK, while EU organisations would normally select the European Union. Enterprise customers with specific requirements can contact MyDocSafe to discuss other arrangements.

MyDocSafe uses Amazon Web Services (AWS) for its core hosting infrastructure. Files uploaded to MyDocSafe are encrypted using AES-256 and stored using AWS regional infrastructure. (MyDocSafe)

What does “data residency” mean?

Data residency generally refers to the geographic region in which your customer data is stored. For example, if your organisation has selected UK data residency, the intention is that the relevant customer data is stored in the UK hosting region configured for your account.

This is different from the location of MyDocSafe's registered office and can also be different from the locations from which particular support, infrastructure or sub-processing activities are performed.

UK and EU processing

MyDocSafe's published GDPR information states that customers can select UK, EU or US data centres and that its core data processing is carried out in Dublin, Ireland.

This means it is useful to distinguish between:

Storage location — the region selected for your account, such as the UK or EU.

Processing location — locations from which systems or authorised service providers may process data in order to provide the service.

For organisations with particularly strict residency requirements, such as financial services firms, public-sector bodies or organisations subject to contractual localisation requirements, these distinctions can be important.

What about third-party suppliers?

Like most SaaS providers, MyDocSafe uses specialist third-party service providers to deliver parts of the service. Its published Data Processing Agreement identifies sub-processors including AWS for hosting and specialist providers for functions such as email delivery, payments and identity verification.

The fact that your core MyDocSafe data is stored in a particular region does not necessarily mean that every piece of data associated with every optional service is processed exclusively within that region.

For example, using:

  • identity verification;

  • payment processing;

  • email delivery;

  • integrations; or

  • other third-party services

may involve additional processors and locations.

Where this matters to your organisation, we recommend requesting a data-residency statement covering the specific MyDocSafe services you intend to use.

Can I choose my data-storage region?

Yes.

When setting up a MyDocSafe account, choose the data-storage location appropriate to your organisation.

Our general guidance is:

Organisation

Typical choice

UK organisation

UK

EU organisation

European Union (Dublin, Ireland)

US organisation

USA

Organisation with bespoke residency requirements

Contact MyDocSafe

If your organisation has specific contractual or regulatory requirements, do not rely solely on this general guidance. Ask us to confirm your proposed configuration.

How to request a data-residency statement

If your compliance, information-security or procurement team needs written confirmation, contact MyDocSafe and ask for a data-residency statement.

The easiest route is through in-app support while logged into MyDocSafe, or by contacting our support team.

Please include:

  • your organisation name;

  • your MyDocSafe account name or ID;

  • the data-storage region you require;

  • whether your question relates to storage only or also to processing;

  • which MyDocSafe services you use or intend to use, particularly any optional integrations, payments or identity-verification services;

  • whether you require the statement for a particular regulatory, procurement or contractual purpose.

We can then provide a statement appropriate to your account and, where necessary, identify relevant sub-processors.

What should I ask for?

For most procurement exercises, the following wording is sufficient:

“Please provide a current data-residency statement for our MyDocSafe account confirming the location of core customer-data storage, relevant processing locations and material sub-processors applicable to the services we use.”

For more detailed due diligence, you may also want to request:

  • MyDocSafe's Data Processing Agreement;

  • current sub-processor information;

  • security information;

  • ISO 27001 certification details; and

  • information regarding international transfers.

MyDocSafe is ISO 27001:2022 certified; current certification information is available on our Security Overview page. (MyDocSafe)

Further information

Important: If your organisation has a strict requirement that data must not leave a particular country or region under any circumstances, please tell us before implementation so that we can confirm whether the required MyDocSafe configuration and any optional third-party services are compatible with that requirement.

Did this answer your question?