EU Data Residency
All EU customer and Zoomer data is stored exclusively within the European Economic Area. No cross-border transfers without explicit safeguards.
Data Center Locations
quiXzoom operates primary and secondary data centers within the EU to ensure low latency, high availability, and full regulatory compliance:
🇩🇪 Frankfurt, Germany
Role: Primary production environment
Provider: AWS eu-central-1
Certifications: ISO 27001, SOC 2, PCI DSS
Primary🇸🇪 Stockholm, Sweden
Role: Secondary / DR site
Provider: AWS eu-north-1
Certifications: ISO 27001, SOC 2
SecondaryEncryption at Rest & In Transit
| Layer | Standard | Details |
|---|---|---|
| Database | AES-256 | All RDS and DynamoDB instances encrypted at rest |
| Object Storage | AES-256 | S3 buckets with server-side encryption (SSE-S3) |
| Backups | AES-256 | Automated daily backups, encrypted, 30-day retention |
| Network | TLS 1.3 | All API and web traffic encrypted in transit |
| Key Management | AWS KMS | Customer-managed keys with rotation every 365 days |
Redundancy & Availability
- Multi-AZ deployment: Production workloads span multiple availability zones within each region
- Cross-region replication: Critical data replicated asynchronously to the secondary region
- RPO: < 5 minutes (Recovery Point Objective)
- RTO: < 4 hours (Recovery Time Objective)
- Backups: Daily automated snapshots with 30-day retention; weekly snapshots retained for 90 days
Data Sovereignty Guarantees
What stays in the EU
✓ All personal data of EU-based Zoomers and customers
✓ Mission observation data (photos, GPS, metadata) for EU missions
✓ Payment and payout records for EU accounts
✓ KYC and identity verification documents
✓ Support tickets and communication history
Third-Country Transfers
Where EU data must be processed by non-EEA subprocessors (e.g., Stripe Inc. in the US), we implement the following safeguards:
- EU Commission Standard Contractual Clauses (SCCs) with Module Two (Controller to Processor)
- Transfer Impact Assessments (TIAs) documenting the law and practice of the destination country
- Technical measures: encryption, pseudonymization, and access logging
- Annual review of subprocessor jurisdictions and compliance posture
Our full subprocessor list is available at quixzoom.com/subprocessors.
Compliance & Audits
- Annual third-party penetration testing of all production environments
- Quarterly vulnerability scans and remediation tracking
- Continuous compliance monitoring via automated security tooling
- Access reviews every 90 days for all production systems