Where your Solace Care data lives | Solace Care

Compliance

Where your Solace Care data lives

Your Solace Care data stays inside the European Union by default. Here is where it lives, who hosts it, and why that matters for your privacy.

Solace Care - Data

Your Solace Care data is stored in AWS data centres in Frankfurt, Germany — inside the European Union, under full GDPR protection. We do not move personal data outside the EU by default.

Where your data lives matters. Two identical services can treat your information very differently depending on which country their servers are in, which laws apply, and who the government can compel them to share it with. This article explains where Solace Care stores your data, and why we made that choice.

Where exactly is your data stored?

All personal data you share with Solace Care is stored in Amazon Web Services (AWS) data centres located in the eu-central-1 region — Frankfurt, Germany. These facilities are operated by AWS, the largest cloud provider in the world, and they meet the highest available standards for physical and operational security.

Frankfurt is one of the most heavily regulated and best-protected data centre hubs in Europe. AWS publishes its compliance certifications publicly, including ISO 27001, SOC 2, and the EU Cloud Code of Conduct.

Why does EU-based hosting matter?

When data sits inside the EU, three things change in your favour.

First, GDPR applies in full. You get the strongest data protection rights in the world, and we are legally accountable to an EU supervisory authority if we fail to uphold them.

Second, data access by governments is tightly constrained. EU member states cannot demand access to your data on a whim — they need a specific legal basis and, usually, judicial oversight.

Third, the 2020 Schrems II ruling by the Court of Justice of the European Union made transfers of EU personal data to the United States far more restricted. Keeping data in the EU by default avoids those legal complications entirely.

What about the software suppliers you use?

Running a modern service means working with suppliers. We are careful about which ones we work with, and we follow a simple rule: EU-first, and never without safeguards.

Where a supplier offers an EU-hosted instance, we use it. Where a supplier is headquartered outside the EU (a handful of AI providers, for example), we apply four layers of protection:

  1. Data redaction and tokenisation — Personal information is removed or replaced with tokens before it leaves our systems.

  2. EU-hosted instances where the supplier offers them, even if their head office is elsewhere.

  3. No training on your data — contractually enforced through Data Processing Agreements, and technically enforced through API settings.

  4. Standard Contractual Clauses and Transfer Impact Assessments — the legal instruments required under Schrems II to transfer data responsibly.

Who physically protects the data centres?

AWS operates the Frankfurt facilities to world-class physical security standards: biometric access controls, 24/7 monitoring, environmental protection against power failure, fire, and flooding, and strict staff vetting. Our own staff never enter the data centre — we operate the servers remotely through secure, audited access.

You can read AWS's physical security documentation in their compliance portal.

What about backups? Where do they live?

Backups live in the same EU region as the primary data, with redundancy across separate availability zones for resilience. We test our ability to restore from backup at least once a year to make sure the recovery process actually works.

This is one of the reasons the ISO 27001 certification matters in practice: it requires us to demonstrate that our backup and disaster recovery processes are tested, not just written down.

Can you request to know where your specific data is?

Yes. Under GDPR Article 15, you have the right to be told how and where your data is processed. Email privacy@solace.care and we will walk you through it. For enterprise partners and investors doing due diligence, we share a full technical architecture document under NDA.

What if you need data deleted?

Deletion applies everywhere your data is stored. When you or we delete personal data from Solace Care, it is removed from the primary database and from backups within the retention windows required for disaster recovery — typically within 90 days. We document this process and can show it to you on request.

A short summary

Your data lives inside the EU, protected by GDPR, inside a Frankfurt data centre operated by AWS. It is encrypted at rest and in transit. We keep it there by default, and when we need to work with suppliers elsewhere, we apply layered safeguards so your information stays private.

If you want to understand more, or you are an insurance partner doing due diligence, email privacy@solace.care. We are happy to walk you through the architecture.

Related reading