Data processing & locations

A factual overview of CRM Software Pro's standard production architecture and the choices customers must make before processing personal data.

Last updated: 23 September 2026.

The standard CRM Software Pro service is not EU-only. The primary production database and authentication project is currently hosted in AWS US East (North Virginia) through Supabase. The production file bucket is currently in Cloudflare R2's Asia-Pacific location. Cloudflare's location hint is not a jurisdiction guarantee. Optional providers can process data in additional countries.

Core data flows

Account and workspace data

Supabase provides the primary database, authentication, realtime services, and Edge Functions. Records can include users, workspaces, permissions, contacts, messages, configuration, and operational metadata.

Files

Uploaded chat and workspace files can be stored in Cloudflare R2 or Supabase storage. File names, MIME types, ownership, and access metadata are stored with the service.

AI text and knowledge

When AI features are enabled, relevant instructions, customer messages, conversation context, website/help content, and embeddings may be sent to OpenAI to generate answers, translations, summaries, or indexes.

Voice and avatars

When enabled, Vapi coordinates voice calls; ElevenLabs may process text or voice samples; Simli may process avatar inputs. Call metadata, transcripts, audio, and provider identifiers can be generated depending on configuration.

Email and connected channels

Resend handles selected transactional email. Google/Gmail/Calendar, Meta/WhatsApp, Telegram, and Slack process data only when the customer connects or uses those channels.

Payments and delivery

Stripe processes billing and payment data. Cloudflare serves application and website traffic. GitLab stores source code and CI artifacts; it is not the primary customer-content database.

Customer responsibilities

EU-only requirements

Customers that require all in-scope personal data to remain in the EEA should not assume the standard service meets that requirement. Contact dpo@sem.chat before deployment. An EU-only architecture would require separate EU-region infrastructure and eligible provider configurations, migration and validation; it is not activated merely by selecting a language or adding GDPR wording.

Retention and deletion

Workspace data remains available while needed by the active account unless an authorized user deletes it or a contractual closure workflow applies. Security logs, billing records, provider logs, and backups may follow separate schedules. Verified deletion requests are handled according to the applicable controller instructions, contract, technical dependencies, and legal obligations.