
“Confirm all personal data is processed in the EU.” It reads like a yes-or-no question. For an agent that acts in other systems it is not, because the data takes a route: a user authorizes the agent, a provider hands over tokens, the agent calls a tool, a response comes back, something logs the call, and the result goes to a model. Each of those is a place data can land. Here is where each one lands in an EU workspace on Scalekit.

The user authorizes your agent on the provider's consent screen, and the integration layer exchanges the authorization code for an access token and a refresh token. In an EU workspace, environment URLs end in .eu.scalekit.com for production and .eu.scalekit.dev for development, and the tokens are written to the vault in Frankfurt.
Each token is encrypted with AES-256-GCM under a data encryption key that belongs to one environment. That key is itself encrypted by a master key in Google Cloud KMS, held apart from the database and the application. The trust center describes the regional clusters as having region-specific encryption. Tokens stay until the connected account is deleted. If you want the root of that key hierarchy in your own Google Cloud KMS, the bring-your-own-key post in this series covers it.
The gateway in Frankfurt looks up the user's credential, adds it to the request and calls the app's API. If the app only accepts traffic from known addresses, you allowlist Scalekit's outbound IP addresses for the EU region.
Say this plainly to your customers: the integration layer's region does not move the app's data. If their CRM tenant is hosted in the US, the CRM's data is in the US regardless of where the gateway runs. EU residency for the integration layer means the copy passing through it, and the credentials it holds, stay in the EU.
The response is the customer's data: a record, a thread, a file listing. On Scalekit, request and response payloads are processed in memory for the duration of the call and are not stored in Scalekit's database or logs. The response goes back to your agent and is not kept.
This hop carries the most personal data, so it is the one to press any vendor on. A platform that caches responses for retries or stores synced records has a second store of EU personal data with its own retention period.
Each tool call produces a log entry in the EU region holding the tool name, connection, connected account, user identifier, status, error code, duration and time. Successful responses are not logged.
Two settings decide how much personal data ends up there. Pass an internal user ID as the identifier, not an email address, or every log line carries personal data. And leave Store connector error details off outside debugging, because with it on the log keeps the error the app returned, which can include data from the app. Logs are kept for a fixed window, with longer, configurable retention on Enterprise.
After the agent receives the tool result, it usually sends it to an LLM. That hop is outside the integration layer. Check your model provider's regional processing options, retention terms and DPA on their own. An EU-hosted integration layer feeding a model endpoint outside the EU still transfers the data here.
The orchestrator, conversation state, memory and any vector store are yours. Their residency is your own infrastructure decision, and the DPO will ask about them next.
GDPR does not require EU residency. It allows transfers outside the EEA with safeguards such as Standard Contractual Clauses. EU buyers write residency into contracts because every transfer they avoid is one fewer to assess.
When a vendor processes EU personal data for you, it is your processor, or your sub-processor if you process on behalf of your own customer. Article 28 of the GDPR requires a written contract and says a processor may engage sub-processors only with the controller's authorization; with a general authorization, the processor has to give notice of changes and a chance to object. Those terms live in the DPA.
Scalekit's DPA, effective January 1, 2026, gives a general authorization from the subprocessor list in Schedule A, at least 30 days' notice of any new or replaced subprocessor with a right to object, EU Standard Contractual Clauses for EEA transfers (Module 2 or 3, governed by Irish law) with UK and Swiss transfer provisions, breach notification without undue delay, audit reports such as SOC 2 on written request, and deletion of customer data on termination.
For any vendor, check five things: whether the subprocessor list and locations are the same for EU and US workspaces; the notice period for changes; the transfer mechanism for any processing or support outside the EEA; whether tool-call payloads are in scope of the DPA's data categories; and breach and deletion terms.
If the layer is self-hosted, the question changes shape. In a self-hosted Scalekit deployment customer data stays in your deployment and Scalekit is not a sub-processor for it. Self-hosted agent integrations covers that path.
From each vendor's own pages as of October 2026. “Not found” means not on their public pages.
The full comparison, including key custody and compliance, is in Best self-hosted agent integration platforms.
Choose the region on the signup page, with Change Region, before you create your account. Your workspace and all its environments stay in that region; a workspace cannot move later, so a team serving both US and EU customers creates one workspace in each. The EU region runs on Google Cloud in europe-west3, Frankfurt, independent of the US region in Los Angeles, with no shared application state. EU residency is a $99 a month add-on on Growth and included on Enterprise, and the dashboard asks you to confirm it when you create an environment in an EU workspace.
Scalekit holds SOC 2 Type II and ISO 27001, is GDPR and CCPA compliant, and provides a standard DPA on every plan, with a custom DPA and a HIPAA BAA on Enterprise. The catalog of 500+ connectors and 20,000+ actions is the same in both regions.
Residency is one of three groups of questions a regulated buyer's review covers. The security questionnaire for AI agent vendors has all three, with Scalekit's answers.
The token vault, the compute that executes tool calls, any payload handling, and the logs. A vendor's region label covers some of these; ask about each one.
No. GDPR allows transfers outside the EEA with safeguards such as Standard Contractual Clauses. EU residency is usually a contractual requirement from the buyer.
In Frankfurt, in Google Cloud europe-west3. Each token is encrypted with AES-256-GCM under a per-environment key, which is itself encrypted by a Google Cloud KMS master key held apart from the database.
No. Tool-call inputs and responses are processed in memory for the duration of the call and are not stored. Logs hold call metadata only.
No. The region is chosen at signup and the workspace stays in it. To use both regions, create a workspace in each.