Data Sovereignty & Residency
1. Data Storage Locations
Section titled “1. Data Storage Locations”All XBert customer data is stored within Microsoft Azure data centres located in Australia. Data is replicated across multiple availability zones within the Australian region to ensure high availability and resilience.
| Purpose | Azure Region |
|---|---|
| Primary | Australia Southeast (Melbourne) |
| Disaster Recovery | Australia East (Sydney) |
All database backups are encrypted and stored exclusively within Australian Azure regions. No customer data is stored outside Australia except as noted under Cross-Border Data Flows below.
2. Cross-Border Data Flows
Section titled “2. Cross-Border Data Flows”XBert’s architecture is designed to keep customer data within Australia. There is one controlled exception:
| Flow | Destination | Data Handling | Retention |
|---|---|---|---|
| AI processing (OpenAI, Anthropic) | US-based API endpoints | Data is ephemeral and processed in-memory only | Not stored by providers per Data Processing Agreement (DPA) |
| AI memory service (Mem0) | Azure Container Apps, Australia | Stored within Australian infrastructure | Subject to standard data retention policy |
AI processing requests may flow to US-based API endpoints for inference. Under the terms of our Data Processing Agreements with these providers, customer data is not stored, logged, or used for model training. Data returns to Australian-hosted systems after processing.
3. Data Sovereignty Controls
Section titled “3. Data Sovereignty Controls”XBert implements the following controls to maintain data sovereignty:
- All primary and backup data stores reside in Australian Azure regions
- Azure resource policies enforce data residency at the subscription level
- Any change to data residency must be approved by the CTO and communicated to affected customers
- AI memory and context services are hosted on Azure Container Apps within Australia
- Database geo-replication is restricted to Australian regions (Australia Southeast (Melbourne) and Australia East (Sydney))
4. Multi-Tenancy Isolation
Section titled “4. Multi-Tenancy Isolation”XBert operates a multi-tenant architecture with strong logical separation between customers.
| Control | Detail |
|---|---|
| Database-level segmentation | Customer data is logically separated using tenancy identifiers |
| Access control policies | Application-layer access controls enforce tenant boundaries |
| Tenancy identifiers | Every data record is associated with a specific tenant, preventing cross-tenant data access |
| No shared storage | Customer data is not co-mingled in unscoped storage; all queries are tenant-scoped |
5. Privacy & Regulatory Compliance
Section titled “5. Privacy & Regulatory Compliance”XBert’s data sovereignty practices comply with the following regulatory frameworks:
| Regulation | Applicability | Detail |
|---|---|---|
| Privacy Act 1988 (Cth) | All operations | Compliance with Australian Privacy Principles (APPs) |
| GDPR | EU/UK customers | General Data Protection Regulation compliance where applicable |
| PCI-DSS | Not applicable | XBert does not store PCI-regulated payment card data |
| HIPAA | Not applicable | XBert does not store HIPAA-regulated health data |
6. Customer Data Ownership
Section titled “6. Customer Data Ownership”Customers retain full ownership of their data at all times. XBert provides the following data rights:
| Right | Detail |
|---|---|
| Data export | Self-service export tools available to all customers |
| Data deletion | Self-service deletion tools available; data purged within 30 days of account deletion |
| Data portability | Customers can export their data in standard formats at any time |
| No vendor lock-in | Customer data is accessible and exportable throughout the subscription |
7. International Data Transfers
Section titled “7. International Data Transfers”For customers in the United Kingdom and European Union, XBert maintains appropriate safeguards for any international data transfer:
| Mechanism | Detail |
|---|---|
| International Data Transfer Agreement (IDTA) | Executed for UK clients where required, ensuring transfers comply with UK GDPR |
| Data Processing Agreements | In place with all sub-processors that handle customer data |
| AI provider DPAs | OpenAI and Anthropic DPAs confirm data is ephemeral and not retained |
All international data transfer arrangements are reviewed as part of XBert’s annual vendor management process. For further details, refer to the Third-Party Vendor Management Policy.
8. Change History
Section titled “8. Change History”| Version | Date | Changes |
|---|---|---|
| 1.0 | April 2026 | Initial creation |