Application hosting
This is where the software itself runs: the servers that handle every request from your agents. It is the layer most vendors mean by EU-hosted. Ask for the country and the hosting provider by name.
This page takes the phrase "EU-hosted" apart into the three things it covers, then gives you ten questions to put to any support tool vendor. It is written for whoever has to answer for the choice later: an operations lead, a support manager, or whoever owns the shortlist.
The first question about a support tool used to be what it can do. In Europe it has shifted to where the conversations end up and who can read them. The question usually arrives late, from security or from a customer filling in a supplier form, when a shortlist already exists.
Most buying teams have no framework for judging the answer. A vendor page says the platform is hosted in Europe. That sounds like the whole story, so the conversation stops there. What follows takes that phrase apart into the three things it covers, gives you ten questions for a vendor call, and ends with what to say when your own customer asks.
"Hosted in the EU" is one phrase covering three separate decisions. A vendor can make one of them in Europe and the other two elsewhere, and still use those words honestly.
This is where the software itself runs: the servers that handle every request from your agents. It is the layer most vendors mean by EU-hosted. Ask for the country and the hosting provider by name.
Conversation content, attachments, backups and system logs are four different stores that rarely sit in the same place. Backups get replicated to a second region, and logs flow to a monitoring service nobody thinks of as storage. "Our database is in Frankfurt" answers a smaller question than the one you asked.
If the tool uses AI, the text of every conversation is sent to a model provider. That provider can be a different company, under a different jurisdiction than the one hosting the application. Ask who it is, where the processing happens, and whether the routing can change without anyone telling you.
Your office is in Brussels. Every letter you send is collected, driven to a sorting centre across the border, opened for scanning, and driven back the next morning. The plate on your front door is accurate, and it says nothing about the route your post takes.
A vendor can say "hosted in the EU" in good faith while every customer message passes through a model provider outside Europe. The answer is accurate and still incomplete, because the question was asked at a level too coarse to separate the three layers.
Take this into your next vendor conversation and work through it one question at a time, declining the summary answer that covers all ten at once.
Ticks stay in this browser and nothing is sent anywhere.
The answer should be a country and a company name, given without hesitation. Vendors who build on someone else's platform sometimes cannot say, having never asked.
Warning signA vendor who cannot name the country and the provider is describing an arrangement they have never inspected themselves.
#1These are four systems and each can land in its own place. Ask about each by name, because one answer for the whole platform skips three.
Warning signAn answer that covers only the main database means the other three were never mapped.
#2The AI layer is a separate supplier with its own location and terms, and some products route to more than one. Ask which one, which region, and whether either is fixed by contract.
Warning signVagueness here usually means the routing is treated as an implementation detail the vendor reserves the right to change.
#3Training use is decided in two places: the vendor's terms and the provider's terms underneath. A vendor can promise no training while a provider default says otherwise.
Warning signAn answer that describes intentions and never points at a setting means nobody has read the layer underneath.
#4Retention is a setting somewhere, and it has a default. Find out what it is, and whether deleting a conversation also clears it from backups and logs.
Warning signIf deletion only happens through a support ticket, your retention policy is really theirs.
#5Every tool your vendor uses is a party that can touch your data. Notification matters as much as the list, because the version you approved at signing ages.
Warning signA list available only on request tends to be assembled on request.
#6Ask for the agreement before the contract stage and read what it says about transfers. Then ask which safeguard covers each one, and the AI layer in particular.
Warning signA vendor who hands over the agreement but cannot explain the transfer part has signed a template they never read.
#7Support engineers can usually reach customer data, and that is workable while it is bounded. Ask how access is granted, whether it expires, and who sees the audit trail.
Warning sign"Nobody can see your data" is either inaccurate or describes a door that exists and goes unwatched.
#8Where this obligation lands depends on how the tool is supplied and branded, so settle which of you carries it before you sign. Then check whether you can word the notice yourself.
Warning signA vendor who treats disclosure as a styling option has not thought about who carries the obligation.
#9Exit is the moment you discover whose data it was. Ask for the format, whether attachments and internal notes are included, and whether you can run it yourself.
Warning signAn export that needs a support request and a waiting period is a lock-in you agreed to without noticing.
#10Small teams tend to approach the AI Act expecting a wall. The obligations that cause the worry apply to a different category of system: uses with serious consequences for people, such as decisions about employment, credit or safety. A support assistant that answers questions from your own documentation is generally not the kind of system those rules are aimed at. That is worth confirming for your own case with someone qualified.
The obligation most teams need to look at is transparency. A person interacting with an AI system should be able to tell that this is what is happening. Where does the notice appear? Is it visible before the customer types anything? What does the handover to a human look like? These are product decisions you can inspect today.
Timing depends on which obligation you are looking at, so check the current position with your own counsel. Your team already knows how to ask the GDPR questions: purpose, retention, processors. Those questions do most of the practical work here, which is why the ten above come first.
This page is general information and it is not legal advice.
A customer who asks this wants two things: a sign that you understand the question, and a sign that you are not improvising. The usable answer has three parts: where the software runs, where the conversation is kept, and which AI provider reads the text. Say what you know for each, in plain words.
Then say what you do not know. An agent who names the edge of their knowledge and hands the rest over cleanly sounds reliable. Give the customer a person and a day. Log it so the follow-up actually happens. Keep a short internal note, so the next agent does not start from zero.
"That is fully GDPR compliant." It answers a question about routing with a claim about status, and the customer who asked carefully will hear that the question was avoided.
"The application runs in Europe and your conversation is stored there. I am not certain which AI provider handles the text or in which region, and I want to check before I answer. I will ask our team today and come back tomorrow morning with the specifics."
A guessed answer costs you the moment somebody checks it, and the customer who cared enough to ask is the one who checks. The honest version turns a hard question into a follow-up you control.
Three layers hide behind one phrase, and ten questions pull them apart. Ask them one at a time, because the pattern of hesitation across the ten tells you more than any single answer.
Sarrai is a European helpdesk assistant, and the same ten questions apply to it as to every other tool on your shortlist.
https://sarrai.io/resources/eu-data-residency-checklist