Data sovereignty
Your customer data. EU & Swiss law. No exceptions.
Customer feedback is personal data. When you upload it to a CX platform hosted in the United States, you may be transferring personal data outside the European Economic Area — and exposing your organisation to legal risk you didn’t know existed.
InsightNarrator is hosted, processed, and operated entirely within the EU — with AI inference in Switzerland. No US cloud. No Cloud Act exposure. No ambiguity.
The problem you didn’t know you had
Most CX tools are American. Your data goes with them.
When your customers tell you what they think — in surveys, in reviews, in support tickets — they’re sharing personal data protected by GDPR. Names, email addresses, opinions, locations, behavioural patterns.
The platforms that process this data (Medallia, Qualtrics, SurveyMonkey, most AI analysis tools) are headquartered in the United States. Their servers are in the US. Their subprocessors are in the US. And under US law, US-based providers can be compelled to disclose data wherever their servers are — regardless of where the data subject lives.
The European Court of Justice invalidated the Privacy Shield framework in 2020 (the Schrems II ruling) precisely because US surveillance law does not provide adequate protection for European personal data. Standard Contractual Clauses help, but they require case-by-case assessment — and if you’re using a US-hosted CX platform, that assessment is your responsibility.
Under the CLOUD Act, US-based cloud providers can be compelled to produce data stored on their servers — including data belonging to European citizens — without notifying the data subject or their government.
Articles 44–50
What GDPR actually requires for international transfers
GDPR Chapter V governs transfers of personal data to third countries. The key principle: personal data can only leave the EEA if the destination provides a level of data protection that is essentially equivalent to that within the EEA.
The 30-second version
- Uploading customer feedback to a US-hosted platform is a GDPR cross-border transfer — Chapter V applies, whatever the vendor's privacy policy says.
- There's no blanket adequacy for the US, and SCCs alone don't remove the risk: you must assess US surveillance law in practice (a TIA).
- Derogations like explicit consent are narrow, and the core principles require you to know where your data is. If you can't answer that, you can't demonstrate compliance.
What this means for CX teams
General principle for transfers
Any transfer of personal data to a third country must comply with Chapter V. Uploading customer feedback to a US-hosted platform is a transfer.
Adequacy decisions
There is no blanket adequacy decision for the United States; the 2023 EU-US Data Privacy Framework covers only self-certified companies and remains contested.
Appropriate safeguards
Standard Contractual Clauses (SCCs) are the most common mechanism, but post-Schrems II they require a Transfer Impact Assessment (TIA) to verify the destination country's surveillance laws don't undermine the safeguards.
Derogations
Explicit consent or “compelling legitimate interests” — but these are narrow, specific, and hard to apply to ongoing data processing at scale.
Principles
Lawfulness, purpose limitation, data minimisation. If you don't know where your data is, you can't demonstrate compliance with these principles.
Transfer Impact Assessment
If you use a US-hosted CX tool, you need a TIA. And it probably won’t pass.
A Transfer Impact Assessment evaluates whether the legal mechanisms protecting your data (like SCCs) are effective in practice — not just on paper. After Schrems II, the European Data Protection Board (EDPB) issued guidance requiring organisations to assess:
- Whether the destination country's surveillance laws (like FISA 702 or EO 12333) could compel access to the data
- Whether the data subject has effective legal remedies against surveillance
- Whether the importer can resist access requests
For most US-hosted platforms, the honest answer to these questions is no — US surveillance law provides broad access powers with limited judicial redress for non-US persons.
“The assessment has to take into account the relevant aspects of the legal order of the third country, including those concerning access by public authorities to personal data.”
This isn’t a theoretical risk. The Austrian DPA (DSB) ruled in 2023 that using Google Analytics constitutes an illegal data transfer because IP addresses and cookie identifiers could be accessed by US authorities.
How InsightNarrator solves this
Sovereignty by architecture, not by promise
European hosting
All data is stored and processed on infrastructure located in the European Union. No US servers, no US subprocessors for data storage, no US corporate parent.
Swiss-hosted LLMs
Analysis is performed by AI models served from Swiss data centres run by Infomaniak. Switzerland has its own robust data protection law (nFADP) and EU-recognised adequacy. Your DPO's due-diligence checklist shrinks to one adequacy decision.
No model training on your data
Your customer feedback is never used to train, fine-tune, or improve any AI model — ours or our providers'. Your data is your competitive advantage. We don't touch it.
Transparent subprocessors
Every subprocessor is disclosed and located in the EEA or Switzerland. No hidden AWS US East. No surprise data flows. Audit-ready answers in minutes, not weeks.
Data Processing Agreement
A GDPR-compliant DPA is available to all customers, with SCCs for any processing that touches third countries (Switzerland, for LLM inference — covered by the EU-Switzerland adequacy decision).
Right to deletion
Delete your workspace and all associated data is permanently removed within 30 days. No soft deletes, no “retention for improvement.”
The compliance checklist
Questions to ask any CX platform
| Question | Why it matters | InsightNarrator |
|---|---|---|
| Where are your servers physically located? | Determines jurisdiction | EU (primary), Switzerland (LLM inference only) |
| Are you subject to the US CLOUD Act? | Compelled disclosure risk | No. No US corporate presence. |
| Do you use US subprocessors for data storage? | Hidden transfer risk | No. All storage in the EU. |
| Is customer data used for model training? | Data leakage, IP risk | Never. Contractually prohibited. |
| Can you sign a DPA with SCCs? | Legal compliance | Yes. Standard for all customers. |
| Where does the AI model run? | Inference = data transfer | Switzerland (adequacy recognised by the EU) |
| What happens to our data if we leave? | Data portability & deletion | Full export, then permanent deletion |
| Do you have a Record of Processing Activities? | Article 30 compliance | Yes, available on request |
Where are your servers physically located?
Determines jurisdiction
EU (primary), Switzerland (LLM inference only)
Are you subject to the US CLOUD Act?
Compelled disclosure risk
No. No US corporate presence.
Do you use US subprocessors for data storage?
Hidden transfer risk
No. All storage in the EU.
Is customer data used for model training?
Data leakage, IP risk
Never. Contractually prohibited.
Can you sign a DPA with SCCs?
Legal compliance
Yes. Standard for all customers.
Where does the AI model run?
Inference = data transfer
Switzerland (adequacy recognised by the EU)
What happens to our data if we leave?
Data portability & deletion
Full export, then permanent deletion
Do you have a Record of Processing Activities?
Article 30 compliance
Yes, available on request
Industry-specific concerns
Regulated industries, specific obligations
Stop wondering where your data is.
Book a 30-minute compliance briefing. We’ll walk you through our data flow diagram — and answer every question your DPO has.
Or skip the call for the essentials: Subprocessor list · Data Processing Agreement (DPA)
Curious how governance works inside the product? Read about governed agentic analytics.