Data Residency
This page describes where qlane stores customer data, which sub-processors it shares data with, and how cross-border transfers are protected. It complements our Privacy Policy and is the canonical reference for prospects evaluating qlane on data-residency grounds.
- Available regions
- European Union, United States
- Region selection
- Pinned at sign-up; contact support to change residency
- Residency contact
- [email protected]
1. Where your data lives
Customer content (your organization, projects, chat sessions, PR diffs, screenshots, and credit ledger) is stored exclusively in the region you pick at sign-up and is never replicated cross-border. Authentication, error monitoring, product analytics, and billing metadata are handled by single-global vendors (listed below) and may transit US infrastructure. Active session prompts and test artefacts transit our LLM and browser-runtime sub-processors for the duration of the request only.
2. Sub-processors
We share personal data only with sub-processors acting under GDPR Art. 28 data-processing agreements. The current list:
- WorkOS, Inc. — Authentication and identity. USA. SCCs + EU–US Data Privacy Framework.
- Sentry (Functional Software, Inc.) — Error monitoring. USA, with EU-region ingestion. SCCs + EU–US DPF.
- PostHog, Inc. — Product analytics and feature flags. EU. Ingestion stays in the EU.
- Vercel Inc. — Application infrastructure (AI Gateway and PR-test sandboxes). USA. SCCs + EU–US DPF.
- Anthropic, PBC — LLM inference. USA. SCCs + EU–US DPF; no training on API data per Anthropic terms.
- OpenAI OpCo, LLC — LLM inference (fallback). USA. SCCs + EU–US DPF; no training on API data per OpenAI terms.
- Browserbase, Inc. — Managed browser automation. USA. SCCs + EU–US DPF.
- FoundryLabs, Inc. (E2B) — Ephemeral sandbox runtime for multi-service test environments. USA. SCCs.
- Stripe Payments Europe Ltd — Subscription billing and payment processing. Ireland. EU-resident processor.
- Railway Corp. — Application hosting and managed databases. USA, with EU-region and US-region application infrastructure. SCCs + EU–US DPF for control-plane US operations.
- Cloudflare, Inc. — DNS, CDN, and network security in front of all qlane.ai domains. USA, global edge network. SCCs + EU–US DPF.
- Resend, Inc. — Transactional email delivery. USA. SCCs.
- GitHub, Inc. — Source-code integration. USA. SCCs + EU–US DPF.
3. Cross-border transfers
Several sub-processors above are located outside the European Economic Area. Where we transfer personal data outside the EEA we rely on appropriate safeguards under GDPR Chapter V, in particular:
- The European Commission’s Standard Contractual Clauses (Decision 2021/914).
- Where applicable, certification under the EU–US Data Privacy Framework.
- Vendor-side technical measures (encryption in transit and at rest, least-privilege access controls, sub-processor restrictions in their own DPAs).
4. What we do not do
Some patterns are explicit non-features. If any of them are deal-blockers for your organization, contact us before signing.
- Cross-region administrative reads. qlane platform admins must sign in to whichever region they need to inspect. There is no single console that reads from both regional databases.
- No migration tool for moving an existing organization between regions. Your region is pinned at signup; a region change requires manual re-creation.
- Third regions (APAC, LATAM) are not on the roadmap. We’ll evaluate adding one when we have a customer signed to require it.
- Customers that prohibit any cross-border auth (some financial-services and government segments) are out of scope for the current offering. Authentication metadata transits a US-headquartered identity provider (WorkOS) by design. Contact sales if this is a blocker.
5. Data Processing Agreement
We sign a standard Data Processing Agreement (DPA) on request. To receive the current template, email [email protected] with your organization name and the regional context (EU customer / US customer) you need it for.
6. Sub-processor changes
We update this page when sub-processors are added, removed, or materially change their role. Our standard DPA provides at least ten (10) business days’ advance written notice before a new sub-processor processes your data, and a 30-day objection window. To receive these notices, email [email protected] and we’ll add you to the notification list.
Change log:
- 19 July 2026 — Removed Google LLC as an LLM sub-processor (fallback discontinued; Anthropic primary, OpenAI fallback). Added FoundryLabs, Inc. (E2B), Cloudflare, Inc., and Resend, Inc.
- 5 May 2026 — Initial publication.
7. Contact
Residency or sub-processor questions? Email [email protected] or use our contact form.