Skip to main content

Where your data is hosted (data residency)

All ReFresh customer data is hosted in Australia, in the AWS ap-southeast-2 (Sydney) region. No customer data leaves Australian jurisdiction.

Written by Harrison Kennedy

All ReFresh customer data is hosted in Australia, in the AWS ap-southeast-2 (Sydney) region. No customer data leaves Australian jurisdiction.

  • Hosting region: AWS ap-southeast-2 (Sydney)

  • All customer data stays in Australian jurisdiction

  • A small number of operational sub-processors handle infrastructure functions

  • Data Processing Agreements (DPAs) are available under contract


Hosting location

ReFresh runs entirely in AWS ap-southeast-2 (Sydney). Customer data, including risks, controls, evidence, incidents, surveys, and reports, is stored exclusively in this region.

The architecture uses Cloudflare Workers (edge-deployed globally) for the application layer and AWS Lambda for background processing. Customer data does not leave AWS Sydney for application processing; the edge layer carries only routing and protection traffic.


Sub-processors

ReFresh uses a small number of operational sub-processors:

Sub-processor

Role

AWS

Hosting (Sydney region)

Cloudflare

Edge layer, web application firewall, DDoS protection

Neon

Managed PostgreSQL

FusionAuth

Authentication

PostHog

Product analytics

Stripe

Billing

Customer data is stored in Australia; some operational metadata may be processed by these sub-processors under contract.

A full, current sub-processor list is available under NDA. Contact your ReFresh account contact to request it. (Confirm internally: current sub-processor inventory and data flow map for any with non-AU processing.)


Data Processing Agreement (DPA)

DPAs are available under contract. To request a DPA, contact your ReFresh account contact.


What this means for procurement

For organisations with strict data residency requirements:

  • Customer data does not leave Australia

  • Sub-processors are limited to those listed

  • A DPA can be put in place

  • SOC 2 reports and audit information are available under NDA

For tender responses, refer to your ReFresh account contact for the current sub-processor list and DPA template.


Related articles

  • ReFresh security overview (8.1)

  • Browser and device compatibility (8.3)

Did this answer your question?