IT and legal reviewers checking where health data is hosted
Data residency
Where a record is hosted is a configuration, checked against the data-protection law of the market it serves.
Regions and the law they align with
| Region | Alignment |
|---|---|
| European Union | GDPR, and HDS for health-data hosting in France |
| United States | HIPAA / HITECH-aligned safeguards |
| ASEAN markets | Local data-protection laws (e.g. PDPA) |
| Other markets | Assessed case by case against the applicable law |
Sub-processors
Infrastructure and platform sub-processors — including Supabase and OVHcloud — are listed in the privacy policy along with what each one handles.
The six questions
- What is it?
- The hosting regions available and the rule that decides which one a customer's data uses.
- Who is it for?
- IT reviewers and legal teams confirming a deployment meets a local data-protection law.
- Which problem does it solve?
- Health data hosted in the wrong jurisdiction can put a customer in breach of its own local law, regardless of what the vendor promises elsewhere.
- How does it work?
- Hosting regions cover the EU, the US and ASEAN markets. A customer's processing region is set at onboarding to match the data-protection law that applies to it, and international transfers are governed by the data processing agreement.
- How is it different?
- Residency is stated as a configuration with a governing rule, not as a blanket 'your data stays local' claim.
- What is the proof?
- The sub-processor list and transfer mechanism are published in the privacy policy and the DPA.
This page is part of a platform of 2,156 clinical and operational capabilities across 8 business domains.
Explore the catalogueContinue
Security contact
Coordinated disclosure and documentation requests: security@on-kare.org.
security@on-kare.orgLegal review: 2026-08-24