Your practice’s data lives in one region, chosen when your account was created, so you always know exactly where it’s stored and can meet your own jurisdiction’s data residency requirements with confidence.
Where is my data stored?
Zanda supports practices around the world, and every account, wherever the practice is based, is hosted in one of three regions: Australia, the United Kingdom, or the United States. Each region runs its own complete infrastructure, entirely separate from the others, including servers, storage, and data processing, so a practice’s data never leaves the region it’s stored in. That region is set when the account is created, including during a trial, and stays fixed for the life of the account.
- Australian accounts are hosted in AWS data centers located within Australia.
- UK accounts are hosted in AWS data centers located within the United Kingdom.
- US accounts are hosted in AWS data centers located within the United States.
Data is encrypted both at rest and in transit in every region.
What if my practice is outside Australia, the UK, or the US?
Zanda supports practices in many countries beyond these three, including New Zealand and Canada - your account is simply hosted in whichever of the three regions best fits your local requirements, rather than in a dedicated data center for your own country:
- New Zealand accounts are hosted in the Australia region (AWS Sydney), managed in line with New Zealand’s Privacy Act 2020 and, for health information, the Health Information Privacy Code (HIPC) 2020.
- Canadian accounts are hosted in the Australia, UK, or US region based on local requirements, in line with Canadian privacy standards - the Personal Information Protection and Electronic Documents Act (PIPEDA) and, in Ontario, the Personal Health Information Protection Act (PHIPA).
- For any other country, contact Zanda Support to confirm which region your account uses.
The Zanda privacy program (ISO 27001 certified, externally audited, overseen by a dedicated Data Protection Officer) applies regardless of which region hosts your account; it isn’t limited to Australian Privacy Principles compliance. See Security and Operational Maturity for that detail. For a formal, account-specific response, such as a signed attestation or a completed compliance questionnaire naming your own country’s requirements, contact Zanda Support with the exact wording you need. Australian accounts additionally have Medicare integration and an Australian Privacy Principles (APP)-specific audited program; see Australian Compliance: Medicare, APPs, and Audited Standards for that detail.
When is my data accessed from outside my region?
Your data is stored and processed inside your account’s region by default, and Zanda doesn’t access it without authorization from the account holder, and only for the purpose of providing support or resolving an issue. A small number of situations can still involve data being accessed or processed from outside your region:
- After-hours or urgent support. Zanda provides 24/7 customer support. Each region is primarily supported by its own local team, but during urgent or after-hours events, a team member based in another region may assist. Every Zanda team member follows the same training, compliance obligations, and background screening regardless of the region they support. For Australian accounts specifically, Zanda also confirms compliance with Australian Privacy Principle (APP) 8 before granting this kind of access.
- Third-party integrations. See “What happens with email, SMS, AI, and third-party integrations?” below: once your data reaches a third-party service such as a payment processor or email provider, that service’s own data handling practices apply.
- Logging in while travelling. If you log in to Zanda from outside your account’s region, for example while travelling, data is transmitted securely over the internet. This doesn’t change where your data is stored, though it may count as international access under some definitions.
What does “kept within my region” cover?
Your practice’s data stays in your selected region, including the primary databases, uploaded files and attachments, backups, system logs, and the servers that process it. See Data Protection, Backups, and Disaster Recovery for how that data is replicated and protected within the region.
What happens with email, SMS, AI, and third-party integrations?
Built-in email and SMS processing happens entirely within the infrastructure in a practice’s selected region. Email processing stays HIPAA compliant throughout.
AI features stay within secure, isolated systems in AWS and are never sent to an external AI provider. Most AI processing happens in the selected region too, though AI features are evolving quickly, and an advanced capability not yet available in a particular region may occasionally draw on processing capacity in another region instead. That is limited strictly to processing: no data is stored or retained as part of it, and none of it is used to train AI models.
Third-party integrations are different, simply because they are not Zanda. We choose reliable partners to integrate with, but once your data reaches one of them, the region commitment no longer applies; that service’s own data location and handling practices take over from there.
How is my practice’s data separated from other practices?
Your practice’s data is protected by key layers of security working together. First, it is encrypted at rest using an encryption key unique to your practice, so your data is distinct from every other practice’s even at the storage level. Second, the application itself enforces access: once a user signs in, Zanda only reads and decrypts the data tied to their own account.
Together, these keep your practice’s information private and secure.
See Security and Operational Maturity for more on how encryption and access controls are managed and audited.
Frequently Asked Questions
Does my data ever move to a different region after my account is set up?
No, not on its own. The region is set when the account is created and stays fixed for the life of the account. Moving your practice overseas, updating your address, changing the Country in your Business Information, or logging in from another country does not move where your data is stored.
To actually move your data to a different region, contact Zanda Support with the region you need and the reason for the request. Moving your data is a migration our team carries out for you, and it’s the only thing that changes your account’s data region.
Can I choose or change my data region myself?
Not directly - the region is fixed at account creation. Only Zanda can move it, as a manual migration, so contact Zanda Support if a move is genuinely needed.
Does my selected region affect where email and SMS are processed?
Yes. Built-in email and SMS processing stays within the infrastructure in the selected region. Email processing remains HIPAA compliant throughout.
Can I use my own email provider instead of the built-in one?
Yes, but that connection runs as a separate, third-party integration. Zanda has no control over where a third-party email provider processes or stores data, so the region guarantee described in this article doesn’t extend to it. Zanda doesn’t support third-party SMS providers, so built-in SMS always stays within your selected region.
Is AI processing always done in my region?
Mostly, yes. AI features are evolving quickly, though, and an advanced capability that is not yet available in a particular region may occasionally draw on processing capacity in another region instead. That is limited strictly to processing: no data is stored or retained as part of it, and none of it is used to train AI models. What stays consistent across every AI feature is that processing stays inside secure, isolated AWS systems and is never sent to an external AI provider.
If I use a third-party integration, does the region commitment still apply to that data?
No, not once the data reaches that service. The region commitment covers data processed directly by Zanda. After data is sent to an external integrated service, that service’s own data location and handling practices apply instead.
How is my practice’s data kept separate from other practices?
Through encryption and access control together. Each practice has its own unique encryption key, and once a user signs in, the application allows access only to their own practice’s data. See Security and Operational Maturity for more on how that is managed and tested.
Where is data hosted for accounts outside Australia, the UK, or the US?
Zanda stores customer data in Amazon Web Services (AWS) data centers, encrypted at rest and in transit, in whichever of the three regions best fits local requirements. For a New Zealand account, that’s the Australia region (AWS Sydney). For a Canadian account, it’s one of London, Northern Virginia, or Sydney, depending on local requirements. For written confirmation of the region tied to your own account, contact Zanda Support and include the reason you need it (for example, a service purchaser, insurer, oversight body, audit, or internal policy).
Does Zanda support New Zealand practices, and address the NZ Privacy Act 2020 and the Health Information Privacy Code (HIPC)?
Yes. Zanda does not operate a dedicated New Zealand data center; data for New Zealand accounts is hosted in AWS data centers in the Sydney (Australia) region, encrypted at rest and in transit, and managed in line with New Zealand’s Privacy Act 2020 and, for health information, the Health Information Privacy Code (HIPC) 2020. The broader Zanda privacy program is ISO 27001 certified, externally audited, and overseen by a dedicated Data Protection Officer, so the compliance framework isn’t limited to the Australian Privacy Principles. For a formal, account-specific response - a signed attestation, specific region wording, or a completed compliance questionnaire naming the Privacy Act 2020 or HIPC - contact Zanda Support with the exact wording you need.
Where is data hosted for Canadian accounts?
Zanda does not publish a Canada-specific data center city. Data for Canadian accounts is hosted in London, Northern Virginia, or Sydney based on local requirements, in line with Canadian privacy standards - the Personal Information Protection and Electronic Documents Act (PIPEDA) and, in Ontario, the Personal Health Information Protection Act (PHIPA). For account-specific confirmation, contact Zanda Support.
Is data for UK accounts kept within the UK, and does UK data protection law apply?
Yes. UK accounts are hosted in AWS data centers within the United Kingdom, the same as the Australia and US regions, so data for a UK account never leaves the UK. The Zanda privacy program (ISO 27001 certified, externally audited, overseen by a dedicated Data Protection Officer) applies to UK accounts the same as every other region. The Global Data Processing Agreement that covers every Zanda subscription also includes the EU Standard Contractual Clauses, required under (EU) GDPR, and the UK Addendum, required under UK GDPR; see EU Standard Contractual Clause and UK Addendum for that detail.
Does Zanda support practices in the European Union (EU)?
Yes. EU-based practice data is hosted in the UK. The Global Data Processing Agreement that covers every Zanda subscription includes the EU Standard Contractual Clauses, required under (EU) GDPR, and the UK Addendum, required under UK GDPR; see EU Standard Contractual Clause and UK Addendum for that detail.