Zanda Health

Zanda Knowledge Base

Data Location and Separation

Your practice's data lives in the region you choose, and stays there for as long as you're with Zanda.

Your practice’s data lives in one region, chosen when your account was created, so you always know exactly where it’s stored and can meet your own jurisdiction’s data residency requirements with confidence.


Where is my data stored?

Zanda operates in three regions: Australia, the United Kingdom, and the United States. Each region runs its own complete infrastructure, entirely separate from the others, including servers, storage, and data processing, so a practice’s data never leaves the region it’s stored in. That region is set when the account is created, including during a trial, and stays fixed for the life of the account.

What does “kept within my region” cover?

Your practice’s data stays in your selected region, including the primary databases, uploaded files and attachments, backups, system logs, and the servers that process it. See Data Protection, Backups, and Disaster Recovery for how that data is replicated and protected within the region.

What happens with email, SMS, AI, and third-party integrations?

Built-in email and SMS processing happens entirely within the infrastructure in a practice’s selected region. Email processing stays HIPAA compliant throughout.

AI features stay within secure, isolated systems in AWS and are never sent to an external AI provider. Most AI processing happens in the selected region too, though AI features are evolving quickly, and an advanced capability not yet available in a particular region may occasionally draw on processing capacity in another region instead. That is limited strictly to processing: no data is stored or retained as part of it, and none of it is used to train AI models.

Third-party integrations are different, simply because they are not Zanda. We choose reliable partners to integrate with, but once your data reaches one of them, such as a payment processor or an email delivery provider, the region commitment no longer applies - that service’s own data location and handling practices take over from there.

How is my practice’s data separated from other practices?

Your practice’s data is protected by key layers of security working together. First, it is encrypted at rest using an encryption key unique to your practice, so your data is distinct from every other practice’s even at the storage level. Second, the application itself enforces access: once a user signs in, Zanda only reads and decrypts the data tied to their own account.

Together, these keep your practice’s information private and secure.

See Security and Operational Maturity for more on how encryption and access controls are managed and audited.


Frequently Asked Questions

Does my data ever move to a different region after my account is set up?

No. The region is set when the account is created and stays fixed for the life of the account. Moving to a different region is a migration Zanda carries out on request - see Australian Data Residency and Access for the full detail on relocating a practice.

Can I choose or change my data region myself?

Not directly - the region is fixed at account creation. Only Zanda can move it, as a manual migration, so contact Zanda Support if a move is genuinely needed.

Does my selected region affect where email and SMS are processed?

Yes. Built-in email and SMS processing stays within the infrastructure in the selected region. Email processing remains HIPAA compliant throughout.

Can I use my own email provider instead of the built-in one?

Yes, but that connection runs as a separate, third-party integration. Zanda has no control over where a third-party email provider processes or stores data, so the region guarantee described in this article doesn’t extend to it. Zanda doesn’t support third-party SMS providers, so built-in SMS always stays within your selected region.

Is AI processing always done in my region?

Mostly, yes. AI features are evolving quickly, though, and an advanced capability that is not yet available in a particular region may occasionally draw on processing capacity in another region instead. That is limited strictly to processing: no data is stored or retained as part of it, and none of it is used to train AI models. What stays consistent across every AI feature is that processing stays inside secure, isolated AWS systems and is never sent to an external AI provider.

If I use a third-party integration, does the region commitment still apply to that data?

No, not once the data reaches that service. The region commitment covers data processed directly by Zanda. After data is sent to an external integrated service, that service’s own data location and handling practices apply instead.

How is my practice’s data kept separate from other practices?

Through encryption and access control together. Each practice has its own unique encryption key, and once a user signs in, the application allows access only to their own practice’s data. See Security and Operational Maturity for more on how that is managed and tested.

Related articles

Was this article helpful?