Security Hub

Kissflow Data Residency

21.08.2026

Customers should have clear and transparent information about where their data is stored, where it is backed up, and how it may be processed.

Kissflow operates production environments across multiple geographies, allowing customers to select the region that best meets their business, regulatory, and data governance requirements.

What does data residency mean?

Data residency refers to the geographic location where customer data is primarily stored.

Data residency does not necessarily mean that every activity associated with the service occurs exclusively within that region. Where necessary, certain services, support activities, security operations, or subprocessors may process limited data outside the primary region to provide and secure the platform.

We disclose these processing activities through our Subprocessor List and Data Processing Addendum.

Where is my data stored?

Your production customer data is stored in the geographic region associated with your selected instance.

Current production regions:


Region

United States

European Union

India

Oceania

Primary

US

Europe

India

Australia

Backup

US

Europe

India

Australia


Where is my data processed?

Most customer data processing occurs within the selected production region. However, delivering a secure and reliable SaaS service may require certain data to be processed by infrastructure and service providers operating in other locations.

Examples may include:

  • Infrastructure and cloud services

  • Customer support

  • Security monitoring

  • Authentication and identity services

  • Communications

  • Service monitoring and observability

  • Customer-requested integrations

  • Other approved subprocessors

We maintain appropriate safeguards for international data transfers and disclose relevant subprocessors and processing locations.

International data transfers

Where customer data is transferred across borders, we apply appropriate safeguards in accordance with applicable data protection requirements.

Our Data Processing Addendum describes the contractual commitments governing the processing of personal data, including the applicable mechanisms for international data transfers.

Data retention and deletion

We retain customer data for as long as necessary to provide our services and meet applicable contractual, legal, security, and operational requirements.

When a customer relationship ends, customer data is deleted in accordance with our applicable contractual commitments and data retention policies.

This includes the deletion of production data and, subject to applicable backup lifecycles, data maintained in backup systems. Data is retained as long as the services are utilized and deleted within 30 days from production and 90 days from backup, post which it is permanently deleted.

Your data remains yours

We process customer data to provide and secure our services and in accordance with our agreements with customers.

We do not sell customer data.

Customers can access and export their data using the capabilities provided by the platform, subject to applicable product and contractual terms.

How do we protect your data?

Data residency is one part of our broader approach to protecting customer data.

We use technical and organizational safeguards designed to protect customer data against unauthorized access, loss, misuse, or disclosure.

These measures include:

  • Encryption in transit and at rest

  • Access controls and least-privilege principles

  • Authentication and authorization controls

  • Security monitoring and logging

  • Vulnerability management

  • Backup and disaster recovery

  • Secure development practices

  • Employee security and privacy controls

Learn more on our Security page.