Meeting Requirements Wherever Our Customers Are
Kira is built with an eye toward the data protection rules of the regions our customers actually operate in, not just the ones closest to our own headquarters. Privacy law isn't uniform across jurisdictions, what the GDPR requires in the EU differs in real, substantive ways from what the CCPA requires in California, and a product genuinely built for a global customer base has to account for those differences directly rather than applying a single, one-size-fits-all approach and hoping it holds up everywhere. We align with the major privacy laws relevant to where our customers operate and offer regional data residency options on eligible plans, so where your data physically lives can match what your business, and your own regulatory obligations, actually require.
Who Is the Controller, and Who Is the Processor
It's worth being precise about this relationship, since it determines who's actually responsible for what under most privacy frameworks. In the vast majority of cases, you, the customer, are the data controller, the party that determines why and how personal data is collected and used in the first place. Kira acts as the data processor, meaning we process personal data on your behalf and according to your documented instructions, as set out in our Privacy Policy and Data Processing Addendum, rather than deciding independently what to do with it.
This distinction matters practically, not just legally. As the controller, you remain responsible for things like ensuring you have a lawful basis to collect the data you're feeding into Kira in the first place, and for responding to certain categories of requests from the people whose data you control. As the processor, our responsibility is to handle that data securely, only for the purposes you've directed, and to support you in meeting your own obligations, for example by honoring data subject access and deletion requests you route to us. Neither role replaces the other, and a clear understanding of which party is responsible for what tends to prevent confusion later, particularly during an audit or regulatory inquiry.
Data Residency
| Region | Residency Option | Notes |
|---|---|---|
| United States | US (AWS) | Default for US customers |
| European Union | EU (AWS) | Available on eligible plans |
| United Kingdom | EU/UK safeguards | UK GDPR with SCCs/IDTA where needed |
| Other regions | US (AWS) | Contact us to discuss specific requirements |
What Data Residency Actually Covers, and What It Doesn't
It's important to be precise here rather than let "data residency" sound like a blanket guarantee that everything, every stage of processing, every downstream system, stays permanently confined to one region. That kind of vague assurance is easy to make and hard to actually verify, and we'd rather give you something specific enough to actually rely on.
Data residency, as we offer it, covers where your Customer Data is stored at rest, meaning your content, documents, and account data physically reside within the region you've selected. This is the piece most customers are actually asking about when they raise data residency as a requirement, and it's the piece we can commit to concretely.
It does not necessarily cover every stage of processing, however, and this distinction matters more than it might initially seem. AI features that generate responses on your behalf, drafting an email, summarizing a call, may route inference through underlying model providers whose infrastructure sits outside your selected residency region. This isn't a gap we're trying to obscure, it reflects a genuine technical reality of how modern AI systems work, the model doing the actual reasoning is often a specialized service operating under its own infrastructure footprint, distinct from where your data sits at rest.
If your organization has strict data sovereignty requirements, particularly if you're evaluating obligations under the EU AI Act or a sector-specific regulation like those governing healthcare or financial data specifically, we'd strongly encourage confirming the exact scope of AI processing with our team before relying on residency alone for AI-touching workflows. Reach out to support@kiraai.ai or support@kiraai.ai and we'll walk through exactly what does and doesn't stay within your selected region for your specific use case.
Beyond California: Other US State Privacy Laws
Since your customer base spans the United States broadly, not just California, it's worth noting that CCPA/CPRA isn't the only US state privacy law that may apply to you or your own customers. States including Virginia, Colorado, Connecticut, and a growing number of others have enacted their own comprehensive privacy laws in recent years, each with its own specific requirements around consumer rights, data minimization, and disclosure. While these laws share substantial overlap with the CCPA's general framework, access, deletion, correction, and opt-out rights, they aren't identical, and an organization operating across multiple states should confirm its own compliance posture under each applicable law rather than assuming CCPA compliance automatically satisfies every other state's requirements. Kira's practices, honoring access, deletion, and correction rights broadly, are designed to be consistent with this general direction across US state privacy law, but we'd encourage you to consult your own counsel on the specific requirements applicable to your organization's footprint.
Laws and Frameworks
Rather than maintain a separate certifications table on this page, and risk it quietly drifting out of sync with the same information maintained elsewhere, our current status against GDPR, UK GDPR, CCPA/CPRA, SOC 2, and ISO/IEC 27001 lives on our Security & Compliance page, which is the single source of truth for this information. If you're doing a compliance review and need our current status on any of these frameworks specifically, that's the page to check, rather than relying on a potentially outdated snapshot repeated here.
International Transfers
Where personal data leaves the EEA, UK, or Switzerland, we rely on appropriate safeguards, specifically the European Commission's Standard Contractual Clauses and the UK's International Data Transfer Addendum, consistent with the transfer restrictions set out in GDPR Article 44, which specifically governs how personal data may lawfully move outside the EU or EEA.
Beyond the standard safeguards themselves, eligible customers may request a Transfer Impact Assessment (TIA), a distinct document from our standard Data Processing Addendum that specifically evaluates the risk profile of a given international transfer in more depth. This matters for compliance teams doing their own due diligence, a TIA gives you the specific supplementary analysis regulators increasingly expect organizations to maintain on file, beyond simply having SCCs in place as a checkbox exercise. Request either the DPA or a TIA from support@kiraai.ai.
Migrating to a Different Region
If you request a migration to a different data residency region, whether that's moving from US to EU residency or another supported combination, your data is transferred to the new region, and the copy remaining in the original region is deleted within 30 days of the migration completing. This 30-day window is consistent with the general data retention practices described in our Privacy Policy, giving enough time to confirm the migration completed successfully and without data loss, while still ensuring the old copy doesn't linger indefinitely once it's no longer needed.
A migration itself doesn't happen instantaneously or silently, we'll coordinate with you directly on timing, particularly for larger accounts where a migration touches a meaningful volume of data, so you know exactly when to expect the transition to complete rather than discovering it retroactively.
How We Keep This Page Accurate Over Time
Regulatory requirements aren't static, new state privacy laws get enacted, existing frameworks get amended, and our own residency and processing architecture evolves as we add capabilities. Rather than treating this page as something written once and left untouched, we review it against actual regulatory developments and changes to our own infrastructure, updating it when something material changes rather than letting it quietly go stale while the underlying reality shifts around it. If you notice something here that seems inconsistent with a regulatory requirement you're tracking, we'd genuinely want to know, reach out to support@kiraai.ai directly.
Requesting Documentation
Eligible customers can request our DPA, Transfer Impact Assessment, sub-processor list, and current attestations from support@kiraai.ai or support@kiraai.ai. We're glad to walk through any of this in more depth for teams conducting formal vendor compliance review, whether that's part of an initial procurement decision or an ongoing periodic reassessment your organization runs on existing vendors.
References
Frequently asked questions
Quick answers to common questions.
Yes. EU data residency is available on eligible plans, contact us to enable it for your account.
Not necessarily. Residency covers where your Customer Data is stored at rest. AI inference may route through model providers outside your selected region. Confirm the exact scope with us directly if this matters for your specific compliance requirements.
You are the controller in the vast majority of cases, determining why and how personal data is collected and used. Kira is the processor, handling that data on your behalf according to your documented instructions.
Yes. We honor access, deletion, correction, and other rights under the GDPR and CCPA/CPRA. See our Privacy Policy for the complete breakdown.
Our practices are designed to align broadly with the direction of US state privacy law generally, but requirements do vary state to state. If your organization operates across multiple states, we'd recommend confirming your specific obligations with your own counsel rather than assuming CCPA compliance alone covers every applicable state law.
Yes, both. Request either from support@kiraai.ai.
It's deleted within 30 days of the migration completing, giving enough time to confirm the migration succeeded before the old copy is removed.
Because the model providers that power Kira's AI features operate their own infrastructure, distinct from where your data sits at rest. This is a genuine technical reality of how AI systems work, not a gap we're trying to minimize, which is why we recommend confirming the exact scope directly if AI processing location matters to your specific compliance needs.