Data Residency
How merchants can raise data-location, processing, backup, and transfer requirements before onboarding.
Gerai makes no universal public promise that customer data, backups, support access, or connected-service processing will remain in a particular country or region. Location requirements must be discussed and agreed before onboarding.
No public location promise
Gerai does not publish a default hosting region, country-specific storage guarantee, or regional failover promise on this page. A requirement is binding only if Gerai has confirmed it for the relevant service scope in a written agreement.
What data residency can cover
“Data residency” can refer to several different technical and legal questions. A country-only storage statement may be incomplete if it does not address processing, support, backups, and providers.
| Area | Question to resolve |
|---|---|
| Primary storage | Where is the live data for the agreed service configuration stored? |
| Processing and access | From which locations may systems, personnel, or providers process or access it? |
| Backups and recovery | Where may backup, replicated, archived, or recovery copies be held? |
| Transfers | Which cross-border transfers may occur and what written mechanism is required? |
| Deletion and migration | What happens to existing copies if a location changes or the service ends? |
Pre-onboarding discussion
A merchant with legal, regulatory, customer, or internal-policy location requirements should raise them before providing production data or relying on Gerai for a regulated workflow. The discussion should identify:
- the countries and laws relevant to the merchant and data subjects;
- the data categories, including any sensitive or regulated information;
- the Gerai features and connected services within scope;
- required and prohibited storage, processing, access, backup, and support locations;
- required transfer terms, notices, approvals, or audit information; and
- whether the requirement is mandatory or a preference.
Gerai can then assess feasibility for the proposed service scope. A discussion or request does not itself mean that a particular region, migration path, or configuration is available.
Connected and service providers
End-to-end data flows can include providers engaged by Gerai and services selected or contracted directly by a merchant. Their legal roles and data locations must be assessed separately.
Licensed payment gateways handle buyer payment credentials and settle funds directly to merchants; Gerai does not hold buyer funds. A gateway’s locations, transfer terms, and regulated obligations are governed by the merchant’s arrangement with that gateway and are not a Gerai data-residency promise.
See Subprocessors for Gerai’s process for verifying and disclosing relevant provider information without publishing unverified names or regions.
Written requirements
If Gerai confirms a location-specific arrangement, the written terms should define the relevant data and services, permitted locations, exceptions, provider dependencies, backup treatment, change process, and any transfer mechanism. The agreement should also explain what happens if the requested arrangement is not feasible or can no longer be provided.
Data-protection roles and processing instructions can be addressed through the Data Processing Addendum process. Gerai’s public Privacy Policy remains separate from any negotiated customer-specific residency terms.
Contact Gerai
Send data-residency and transfer requirements to hello@gerai.shop before onboarding. Include the proposed service scope, jurisdictions, data categories, required locations, prohibited locations, and any deadline for procurement review.
Legal review notice
This published document explains Gerai’s current approach and intended practices. It does not constitute legal advice to the reader. Gerai recommends obtaining advice from a qualified lawyer about the laws and contractual requirements that apply to your circumstances.