Home / Insights / Operations and security
Which country will your customer data sit in?
All 4 vendors we checked put a sign-up from the United States in the United States, so on day one the answer to “where does our data sit?” is the same everywhere. What separates them is what happens the first time somebody asks for something else — a European client whose own policy names the EU, a health-care customer who wants a signed agreement, a state agency with its own approved-cloud list. HubSpot lets a paying customer move regions from the admin settings at no charge. Asana will move an existing organization, but only on the tiers that carry data residency. monday.com does not move an account at all once it has begun storing data. For Shopify we could not find a mechanism for the customer to choose a storage location stated on its own pages.
(Semrush and Squarespace are not covered here, because we could not find a mechanism for choosing a storage location stated on their own pages.)
Why does the storage location matter if you are buying from the United States?
One reason is the information-security questionnaire that clients send. A form of 100 to 200 questions will ask things like whether personal data is handled overseas and which countries are involved, and even 1 blank answer gets it sent back, delaying the start of trading by 2 to 4 weeks. As long as you can answer, an answer of “the United States” rarely stops a US deal. What stops it is being unable to answer.
The other is that the pressure on a US buyer almost never comes from a residency statute. The Department of Health and Human Services guidance on cloud computing states that the HIPAA Rules “do not include requirements specific to protection of electronic protected health information (ePHI) processed or stored by a CSP or any other business associate outside of the United States”, and answers the question of whether a covered entity may use a cloud provider that stores ePHI outside the country with “Yes, provided the covered entity (or business associate) enters into a business associate agreement (BAA) with the CSP”. What that rule asks for is a signed document, not a place. The requirements that do name a place come from contracts and procurement instead: a European client’s internal policy, a parent company’s standard, or a state government’s cloud authorization program.
Just 3 terms
SOC 2 / SOC 3 — an examination report by an external accounting auditor, and its summary version. What clients ask for is almost always SOC 2 Type 2 (an examination of whether the controls actually operated over a period of half a year to 1 year), released under a non-disclosure agreement. All 4 vendors can produce a Type 2, so product selection does not turn on this item.
Region / data residency — a region is the unit of geography in which data is placed; data residency is the name for the feature that lets the customer specify that geography.
BAA (business associate agreement) — the contract a HIPAA covered entity signs with a vendor that will handle protected health information on its behalf. It is a document, not a location, and a vendor either offers one or does not.
The 4 vendors split into those you can move and those you cannot
| Countries and regions where data is stored | Can you choose at sign-up? | Can you move it afterwards? | Signs a HIPAA BAA? | Own ISO 27001 | How to read this row | |
|---|---|---|---|---|---|---|
| HubSpot | US East (Virginia) / US West (Oregon) / EU (Germany) / Canada (Montreal) / Australia (Sydney). On AWS | No. “New customers purchasing a subscription service will be assigned a hosting location based on the geo-location of their IP address at sign up.” Accounts that use only the free version are placed in the United States wherever they signed up from | Yes, and at no charge. “Existing paid customers have the option to migrate their data to a new data center within your account settings. There is no charge for this” | Yes, on Enterprise. Storing health data means turning on the sensitive-data feature, which is an Enterprise-only subscription, and identifying as a covered entity or business associate so that HubSpot “can track the application of the Business Associate Agreement (BAA)”. HubSpot describes using its products in compliance with HIPAA as being in public beta | We could not confirm a certification in its own name (what appears on the vendor’s own pages is the certification of its infrastructure provider) | The cheapest route into the EU of the 4. You do not pick the region; you move it afterwards, free, once you are paying |
| monday.com | 3 regions: US / EU / APAC (Australia). On AWS | Only within limits. “Storing data in the EU Data Region is available for Enterprise plans, and for Standard and Pro plans created on or after January 23, 2023.” Accounts in North and South America are placed in the US region | No. “Since data is physically stored in a predetermined location, once an account begins storing data it cannot be moved.” The route the vendor states is to have a partner or account manager create a new account in the region you want, going forward | Listed on the Trust Center as available. The plan it requires is not stated there | ISO 27001:2022. Also the only 1 of the 4 carrying a US state cloud authorization on its own pages (TX-RAMP) | The one product where the door closes at the moment you first save data. The region has to be decided before the account exists |
| Asana | Virginia, US (default; backups in Ohio) / Frankfurt, Germany (Dublin) / Tokyo, Japan (Osaka) / Sydney, Australia (Melbourne) | No. “By default, data will continue to reside in the United States for new workspaces and existing customer data” | Yes, on the tiers that carry it. “Customers must contact our Sales team to opt-in for data residency to migrate their organization to their selected data region.” A paid add-on on Enterprise; included as standard on Enterprise+ | HIPAA is listed on the Trust page, alongside GLBA and the California, Colorado and Virginia state privacy laws. The plan it requires is not stated there | ISO 27001:2022 | An existing organization can be moved, but only by buying up and going through sales. Authentication data stays in the United States either way |
| Shopify | A Canadian company. Merchants and users in the United States contract with Shopify Inc. in Ottawa, Canada, and the privacy policy states that Shopify “may send your Personal Data outside of your state, province, or country, including to the United States” | We could not find this stated on the vendor’s own pages | We could not find this stated on the vendor’s own pages | We could not find this stated on the vendor’s own pages | We could not confirm a certification in its own name | This is not a product built around specifying where data is stored, and a US merchant’s counterparty is a Canadian entity |
Scroll sideways to see every column
Checked on each vendor’s own pages, rechecked 6 September 2026. SOC 2 Type 2 and SOC 3 are available from all 4 vendors. Sources are at the end of this article.
A note on the ISO 27001 column alone. monday.com and Asana hold ISO 27001:2022 in their own name, while HubSpot and Shopify state no certification of their own. What HubSpot’s own pages carry is “HubSpot products are hosted with cloud infrastructure providers with SOC 2 Type 2 and ISO 27001 certifications, among others.”, and that is the certification of AWS, the provider renting them the infrastructure. For these 2 vendors, a company asked to submit an ISO 27001 certificate can only answer “the infrastructure provider’s certification”.
As a basis for taking personal data out of the EU and the UK — the direction a US buyer with European customers actually travels — all 4 vendors have the standard contractual clauses and the UK addendum in place, so this item separates none of them.
What “you can move it afterwards” actually covers
HubSpot’s move is the genuinely cheap one: it happens in the account settings, it costs nothing, and the only condition is that you are a paying customer. That last condition is the catch for anyone starting free, because a free-only account sits in the United States regardless of where it signed up, and the migration option arrives with the first paid subscription.
Asana’s move is real but priced. Data residency is a paid add-on on Enterprise and standard on Enterprise+, and neither Enterprise pricing nor the price of the add-on is published on the vendor’s own pages — sales inquiry only. It also comes with an exclusion set out explicitly in Asana’s own help pages.
What moves to the region you chose is teams, projects, tasks, exports and attachments. What stays in the United States is authentication-related data such as email addresses, passwords, one-time keys, IP addresses and internal identifiers; measurement data on seat counts, usage and revenue; and data passed to external partners for AI features (customers in the EU excepted). For a US buyer moving to Frankfurt for a German client, that is the line to read carefully: business data in the region you chose, account data in the United States — so you cannot write “all of it sits in the EU” on a questionnaire.
monday.com states the position plainly.
The vendor’s stated route is to ask a partner or an account manager to create a new account in the region you want, going forward — which leaves the existing boards to be exported and imported back in. We could not confirm on the vendor’s own pages whether comments, update history, automation settings and connected apps carry over. If there is even a small chance you will need the EU region, telling the sales team before you create your first account is the only low-cost route.
Who should not choose these 4 vendors
monday.com — companies where there is even a small chance that the storage location becomes a requirement. A sign-up from the United States is placed in the US region, and once data has been stored the account cannot be moved. It is the only product here where the way back closes at the moment of signing.
Asana — companies that need the move to be cheap or quick. Moving an existing organization means an Enterprise add-on or Enterprise+, neither priced on the vendor’s own pages, plus a conversation with sales. And a company required to keep credentials in one region cannot meet that requirement at all, because authentication data remains in the United States whichever region you pick.
HubSpot — companies asked to submit an ISO 27001 certificate in the vendor’s own name; what appears on the vendor’s own pages is the certification of its infrastructure provider. Companies handling health data need care too: the sensitive-data feature that carries the BAA is Enterprise-only, and HubSpot describes HIPAA compliance support as being in public beta.
Shopify — companies that need to specify where data is stored, or that need a counterparty inside the United States. We could not find a mechanism for the customer to choose stated on the vendor’s own pages, and a US merchant’s contracting entity is Shopify Inc. in Canada.
Which of these applies to you?
Source: each vendor’s own pages (rechecked 6 September 2026)
If the personal data you handle is only your own staff roster and the business cards of your clients, if you hold no data entrusted to you by another company, and if you have no plans to work on public-sector, financial or health-care accounts, then buying up a tier to move the storage location should not be worth the cost. A DPA (data processing agreement) is built into the terms of service automatically at all 4 vendors, so a minimum contractual relationship is in place without you doing anything. How to produce the documents, and what to put in place before you are asked, are set out in a separate piece, “What do you show a client who asks how you manage information?”.
Buying from Japan? See the Japanese edition for the Act on the Protection of Personal Information, the Tokyo region and what a Japanese client’s questionnaire asks →
Sources (rechecked 6 September 2026)
- HubSpot: data center list (EU, Canada, Australia, US East and West / automatic assignment by IP / free users in the US / free migration for paid customers) / cloud infrastructure and data hosting FAQ (AWS, host cities) / storing sensitive data (Enterprise-only, the HIPAA-covered-entity checkbox, tracking the BAA) / HIPAA support announcement (public beta) / security program (SOC 2 Type 2, SOC 3, infrastructure provider certifications) / DPA (built in automatically, SCCs, UK Addendum, Swiss addendum, DPF) / Trust Center
- monday.com: data residency (US/EU/APAC, no move once storage has begun, the plan conditions for the EU, the new-account route) / Trust Center (ISO 27001:2022, TX-RAMP, HIPAA business associate agreement) / Compliance Hub / DPA (SCCs, IDTA B.1.0, EU-US DPF, Swiss addendum)
- Asana: data residency (4 regions and their backups, Enterprise add-on / standard on Enterprise+, the US default, migrating an existing organization through sales, the scope of data that remains in the US) / Trust (SOC 2 Type 2, ISO 27001:2022, HIPAA, GLBA, US state privacy laws) / DPA (the DPF-then-SCCs order of precedence, UK Addendum)
- Shopify: privacy policy (contracting entity by region, transfers outside your state, province or country) / international transfers of personal data / DPA (2021 SCCs, UK IDTA, BCRs) / security (PCI DSS Level 1, SOC 2 Type II, SOC 3) / how to view the compliance reports (including SOC 1 Type 2)
- US Department of Health and Human Services: guidance on HIPAA and cloud computing (the business associate agreement requirement, and ePHI stored outside the United States)
This article is not legal advice. For obligations under HIPAA, the GLBA, state privacy laws or a state authorization program, and for judgments about the standard required by a contract with a client, please consult a lawyer or another specialist. We could not find the following stated on the vendors’ own pages: whether the storage location can be chosen at Shopify and whether Shopify signs a BAA, how a SOC 2 Type 2 report is obtained from Asana and the pricing of its Enterprise tiers, which plans carry the HIPAA business associate agreement at monday.com and Asana, the scope of data that carries over if a monday.com account is recreated, and ISO 27001 certification in the names of HubSpot and Shopify. Vendor terms, certifications and data center configurations change. Please check the latest information on each vendor’s own pages before signing.
What changed on this page
- scope change6 September 2026 The English edition — currency and tax assumptions
yen prices, Japanese consumption tax and a card issuer’s foreign transaction fee → US published prices in US dollars; sales tax is described as determined by the billing address and no rate is assumed
Buying from Japan is covered in the Japanese edition, which keeps the yen figures.
Where: Processing rates do not decide the Shopify plan until monthly volume passes $25,000, Is the free trial actually free, No two vendors mean the same thing by “seat”, Budgeting from the list price times twelve leaves you short, On which plan does support stop being a help article?, monday.com or Asana: which should you choose?, How many months until that SaaS pays for itself?
Every recorded change to this site is in the change log.
More in Operations and security
All of operations and security →How many times a month will your automations run, before you sign?
With last month's actual volumes, 7 steps give you the monthly figure, but of the 4 vendors only monday.com lets you check afterwards whether that figure was right.
Read → Operations and security 23What do you hand over when a client asks how you manage information
SOC 3, the URL of the DPA and the storage-location display are the first 3 items of a client security questionnaire, and all 3 are free; the other 4 are listed in the piece.
Read → Operations and security 05What does SSO actually cost?
The cheapest published route is $90 per seat per month, but a mandatory $1,500 onboarding fee brings the first year to $2,580 for a single seat.
Read →