Choose where your customer content is hosted. Gleap supports European Union (EU) and United States (US) data residency, with GDPR (DSGVO) obligations and contractual safeguards applying in either region.
Hosting locations
- EU: DigitalOcean, Frankfurt, Germany.
- US: DigitalOcean, NYC3 data center, New York, United States.
Choose your region
Select your data region when creating your account. Check the project’s region next to its API token in the dashboard, then configure your SDKs and server integrations for that region. EU is the default in the SDKs. US projects require the US endpoints.
See the data regions documentation for SDK examples, API hosts and supported versions. Changing an SDK region or API URL routes requests; it does not migrate existing customer data. Contact privacy@gleap.io to discuss an existing account’s residency requirements before making changes.
What residency covers
Customer databases, uploaded files and backups stay in the selected region: EU for EU accounts and US for US accounts. Each region has separate API, streaming and file hosts. EU accounts use EU AI endpoints; US accounts use US AI endpoints. The agreed DPA and account configuration govern your processing scope.
The region selection is not a promise that all data, all access and every service provider stay within that region. Review the following processing separately:
- AI features: model serving, embeddings, reranking, document conversion, web retrieval and coding sandboxes may involve providers outside your region. A model selection alone does not guarantee where every supporting operation runs.
- Email and integrations: email delivery and customer-connected services use their own providers and processing locations.
- Account and service operations: account administration, billing, support and monitoring are distinct from regional customer-content hosting.
- Global delivery: shared apps and static assets use global delivery infrastructure. Connection metadata and video-call processing are distinct from where customer content is stored.
Our sub-processor schedule identifies providers, purposes and disclosed locations. Contact us to review feature-specific restrictions for your account. Regional AI endpoints do not establish that every provider operation, supporting service or onward transfer stays within that region.
GDPR and DSGVO
GDPR and DSGVO refer to the same EU data protection regulation. Gleap’s GDPR obligations do not disappear when a customer chooses US hosting. Our DPA covers processing instructions, confidentiality, security, sub-processors, breach notification and assistance with data protection rights.
Transfers outside the EEA require an applicable legal transfer mechanism. Depending on the recipient and processing, this may be an adequacy decision or Standard Contractual Clauses with supplementary measures where required. The EU-US Data Privacy Framework applies to eligible transfers to participating, certified recipients, not to every US provider. See the European Commission’s adequacy decisions.
Customers remain responsible for their own lawful basis, notices, product configuration and use of the service. Region selection alone does not establish compliance for a customer’s entire workflow.
SOC 2 Type II assurance
Gleap is SOC 2 Type II audited for the Security trust services category. The report issued on August 27, 2026 covers April 1 to June 30, 2026. Request the report under NDA via privacy@gleap.io to assess the systems and period covered. The report should not be read as confirmation that a subsequently introduced region was included in that audit.
See our security practices for encryption, access controls and incident response, and our privacy policy for personal-data processing information.