Pushwoosh operates hosting regions in more than one jurisdiction, so the answer depends on which region your account is provisioned in.
- EU region: primary hosting is in Germany, with a secondary location also in the EU. This is the default for most accounts and supports GDPR-based data residency requirements.
- US region: Pushwoosh also runs a production region in the United States (US East). Pushwoosh, Inc. is certified under the EU-U.S. Data Privacy Framework, including the UK extension and the Swiss-U.S. DPF, which is the transfer mechanism covering EU personal data processed in the US.
Confirm your own region. Because this determines your data-residency position, do not assume it — ask Pushwoosh Support or your Customer Success Manager to confirm in writing which region hosts your account, and have it recorded in your Data Processing Agreement (DPA).
Compliance posture: Pushwoosh is certified to ISO 27001:2022, holds a SOC 2 Type 1 report, is HIPAA compliant, follows OWASP security-by-design principles, and is GDPR compliant. See Security certifications and compliance.
Regarding data access:
- Support and technical teams are globally distributed to provide 24/7 service.
- It is technically possible to restrict access to your data to personnel in a specific region on request, but be aware of the trade-off:
- Support service levels: restricting access can lengthen response times, since availability depends on a smaller regional team rather than 24/7 coverage.
- Platform availability: this restriction does not affect the availability or performance of the platform itself.
- Pushwoosh acts as a data processor for the data you provide. Any data you send (including custom data via tags or events) is stored in the region assigned to your account.
Comments
0 comments
Please sign in to leave a comment.