Skip to content

Data Sovereignty & Residency

All XBert customer data is stored within Microsoft Azure data centres located in Australia. Data is replicated across multiple availability zones within the Australian region to ensure high availability and resilience.

PurposeAzure Region
PrimaryAustralia Southeast (Melbourne)
Disaster RecoveryAustralia East (Sydney)

All database backups are encrypted and stored exclusively within Australian Azure regions. No customer data is stored outside Australia except as noted under Cross-Border Data Flows below.

XBert’s architecture is designed to keep customer data within Australia. There is one controlled exception:

FlowDestinationData HandlingRetention
AI processing (OpenAI, Anthropic)US-based API endpointsData is ephemeral and processed in-memory onlyNot stored by providers per Data Processing Agreement (DPA)
AI memory service (Mem0)Azure Container Apps, AustraliaStored within Australian infrastructureSubject to standard data retention policy

AI processing requests may flow to US-based API endpoints for inference. Under the terms of our Data Processing Agreements with these providers, customer data is not stored, logged, or used for model training. Data returns to Australian-hosted systems after processing.

XBert implements the following controls to maintain data sovereignty:

  • All primary and backup data stores reside in Australian Azure regions
  • Azure resource policies enforce data residency at the subscription level
  • Any change to data residency must be approved by the CTO and communicated to affected customers
  • AI memory and context services are hosted on Azure Container Apps within Australia
  • Database geo-replication is restricted to Australian regions (Australia Southeast (Melbourne) and Australia East (Sydney))

XBert operates a multi-tenant architecture with strong logical separation between customers.

ControlDetail
Database-level segmentationCustomer data is logically separated using tenancy identifiers
Access control policiesApplication-layer access controls enforce tenant boundaries
Tenancy identifiersEvery data record is associated with a specific tenant, preventing cross-tenant data access
No shared storageCustomer data is not co-mingled in unscoped storage; all queries are tenant-scoped

XBert’s data sovereignty practices comply with the following regulatory frameworks:

RegulationApplicabilityDetail
Privacy Act 1988 (Cth)All operationsCompliance with Australian Privacy Principles (APPs)
GDPREU/UK customersGeneral Data Protection Regulation compliance where applicable
PCI-DSSNot applicableXBert does not store PCI-regulated payment card data
HIPAANot applicableXBert does not store HIPAA-regulated health data

Customers retain full ownership of their data at all times. XBert provides the following data rights:

RightDetail
Data exportSelf-service export tools available to all customers
Data deletionSelf-service deletion tools available; data purged within 30 days of account deletion
Data portabilityCustomers can export their data in standard formats at any time
No vendor lock-inCustomer data is accessible and exportable throughout the subscription

For customers in the United Kingdom and European Union, XBert maintains appropriate safeguards for any international data transfer:

MechanismDetail
International Data Transfer Agreement (IDTA)Executed for UK clients where required, ensuring transfers comply with UK GDPR
Data Processing AgreementsIn place with all sub-processors that handle customer data
AI provider DPAsOpenAI and Anthropic DPAs confirm data is ephemeral and not retained

All international data transfer arrangements are reviewed as part of XBert’s annual vendor management process. For further details, refer to the Third-Party Vendor Management Policy.

VersionDateChanges
1.0April 2026Initial creation