Data sovereignty

Your customer data. EU & Swiss law. No exceptions.

Customer feedback is personal data. When you upload it to a CX platform hosted in the United States, you may be transferring personal data outside the European Economic Area — and exposing your organisation to legal risk you didn’t know existed.

InsightNarrator is hosted, processed, and operated entirely within the EU — with AI inference in Switzerland. No US cloud. No Cloud Act exposure. No ambiguity.

The problem you didn’t know you had

Most CX tools are American. Your data goes with them.

When your customers tell you what they think — in surveys, in reviews, in support tickets — they’re sharing personal data protected by GDPR. Names, email addresses, opinions, locations, behavioural patterns.

The platforms that process this data (Medallia, Qualtrics, SurveyMonkey, most AI analysis tools) are headquartered in the United States. Their servers are in the US. Their subprocessors are in the US. And under US law, US-based providers can be compelled to disclose data wherever their servers are — regardless of where the data subject lives.

The European Court of Justice invalidated the Privacy Shield framework in 2020 (the Schrems II ruling) precisely because US surveillance law does not provide adequate protection for European personal data. Standard Contractual Clauses help, but they require case-by-case assessment — and if you’re using a US-hosted CX platform, that assessment is your responsibility.

CLOUD Act exposure

Under the CLOUD Act, US-based cloud providers can be compelled to produce data stored on their servers — including data belonging to European citizens — without notifying the data subject or their government.

Articles 44–50

What GDPR actually requires for international transfers

GDPR Chapter V governs transfers of personal data to third countries. The key principle: personal data can only leave the EEA if the destination provides a level of data protection that is essentially equivalent to that within the EEA.

The 30-second version

  • Uploading customer feedback to a US-hosted platform is a GDPR cross-border transfer — Chapter V applies, whatever the vendor's privacy policy says.
  • There's no blanket adequacy for the US, and SCCs alone don't remove the risk: you must assess US surveillance law in practice (a TIA).
  • Derogations like explicit consent are narrow, and the core principles require you to know where your data is. If you can't answer that, you can't demonstrate compliance.

What this means for CX teams

Article 44

General principle for transfers

Any transfer of personal data to a third country must comply with Chapter V. Uploading customer feedback to a US-hosted platform is a transfer.

Article 45

Adequacy decisions

There is no blanket adequacy decision for the United States; the 2023 EU-US Data Privacy Framework covers only self-certified companies and remains contested.

Article 46

Appropriate safeguards

Standard Contractual Clauses (SCCs) are the most common mechanism, but post-Schrems II they require a Transfer Impact Assessment (TIA) to verify the destination country's surveillance laws don't undermine the safeguards.

Article 49

Derogations

Explicit consent or “compelling legitimate interests” — but these are narrow, specific, and hard to apply to ongoing data processing at scale.

Article 5

Principles

Lawfulness, purpose limitation, data minimisation. If you don't know where your data is, you can't demonstrate compliance with these principles.

Transfer Impact Assessment

If you use a US-hosted CX tool, you need a TIA. And it probably won’t pass.

A Transfer Impact Assessment evaluates whether the legal mechanisms protecting your data (like SCCs) are effective in practice — not just on paper. After Schrems II, the European Data Protection Board (EDPB) issued guidance requiring organisations to assess:

  • Whether the destination country's surveillance laws (like FISA 702 or EO 12333) could compel access to the data
  • Whether the data subject has effective legal remedies against surveillance
  • Whether the importer can resist access requests

For most US-hosted platforms, the honest answer to these questions is no — US surveillance law provides broad access powers with limited judicial redress for non-US persons.

“The assessment has to take into account the relevant aspects of the legal order of the third country, including those concerning access by public authorities to personal data.”

EDPB Recommendations 01/2020

This isn’t a theoretical risk. The Austrian DPA (DSB) ruled in 2023 that using Google Analytics constitutes an illegal data transfer because IP addresses and cookie identifiers could be accessed by US authorities.

How InsightNarrator solves this

Sovereignty by architecture, not by promise

European hosting

All data is stored and processed on infrastructure located in the European Union. No US servers, no US subprocessors for data storage, no US corporate parent.

Swiss-hosted LLMs

Analysis is performed by AI models served from Swiss data centres run by Infomaniak. Switzerland has its own robust data protection law (nFADP) and EU-recognised adequacy. Your DPO's due-diligence checklist shrinks to one adequacy decision.

No model training on your data

Your customer feedback is never used to train, fine-tune, or improve any AI model — ours or our providers'. Your data is your competitive advantage. We don't touch it.

Transparent subprocessors

Every subprocessor is disclosed and located in the EEA or Switzerland. No hidden AWS US East. No surprise data flows. Audit-ready answers in minutes, not weeks.

Data Processing Agreement

A GDPR-compliant DPA is available to all customers, with SCCs for any processing that touches third countries (Switzerland, for LLM inference — covered by the EU-Switzerland adequacy decision).

Right to deletion

Delete your workspace and all associated data is permanently removed within 30 days. No soft deletes, no “retention for improvement.”

The compliance checklist

Questions to ask any CX platform

Where are your servers physically located?

Determines jurisdiction

EU (primary), Switzerland (LLM inference only)

Are you subject to the US CLOUD Act?

Compelled disclosure risk

No. No US corporate presence.

Do you use US subprocessors for data storage?

Hidden transfer risk

No. All storage in the EU.

Is customer data used for model training?

Data leakage, IP risk

Never. Contractually prohibited.

Can you sign a DPA with SCCs?

Legal compliance

Yes. Standard for all customers.

Where does the AI model run?

Inference = data transfer

Switzerland (adequacy recognised by the EU)

What happens to our data if we leave?

Data portability & deletion

Full export, then permanent deletion

Do you have a Record of Processing Activities?

Article 30 compliance

Yes, available on request

Industry-specific concerns

Regulated industries, specific obligations

Stop wondering where your data is.

Book a 30-minute compliance briefing. We’ll walk you through our data flow diagram — and answer every question your DPO has.

Or skip the call for the essentials: Subprocessor list · Data Processing Agreement (DPA)

Curious how governance works inside the product? Read about governed agentic analytics.