We understand that on-premise deployment is not currently offered, and that all PII is stored and processed in the US under your HIPAA-compliant setup. That helps clarify the US side.
To help us evaluate this properly for our client, could you please share a bit more detail on the points below?
Do you offer regional data center options, even if on-premise is not available?
Do you currently have data centers in the GCC, Australia, the UK, or Europe/Turkey?
If yes, can customers select a specific data center region, or is that not configurable?
If regional selection is not available, how do you support clients in jurisdictions where data is not allowed to leave a specific region, particularly in the GCC?
What security and compliance certifications do you maintain for such regional or cross-border data scenarios, and are these backed by formal documentation or contractual commitments?
Would your team be able to sign a contract or provide written commitments around data residency, security, and compliance requirements if needed?
On the enterprise side, what is the starting package or minimum level for the Enterprise Plan?
For context, our client is based in the GCC, and due to local legal and regulatory considerations, they are particularly sensitive about whether data can leave GCC-hosted infrastructure. We are also reviewing suitability for clients in the UK, Australia, and Turkey/Europe, so clarity on your regional hosting model would be very helpful.
Your team has been quite slow in responding. I submitted the request earlier, but received a response after 20 days, even though I mentioned it was urgent. Could you please look into this and provide a response as soon as possible?
Here are the answers to your questions. Please take a look
We currently have only 1 region for data residency (AWS US-West-2 Oregon). More regions in the EU will be added in 2026.
No
Currently not configurable
Data can be kept in-region via configurable storage policies, webhook streaming, and PII scrubbing. Vendor-side retention can be disabled entirely. Where cross-border transfer is unavoidable, DPA transfer mechanisms and encryption controls apply. https://docs.retellai.com/accounts/privacy-disable
Processing is limited to US with very strict data security and privacy laws compliant with GDPR and HIPAA.