Where your data lives
Storage location and legal jurisdiction are different questions. Both answered plainly: no Canadian residency claim today, United States processing named rather than implied, and a direct route for buyers with hard requirements.
Where your data is stored
Customer data is hosted on managed cloud platforms run by the providers on our subprocessor list. Parts of that infrastructure run in the United States, and several of our providers offer no Canadian region at all.
We do not claim Canadian data residency today, and we say that plainly rather than implying otherwise. A per-system region table will be published once each entry has been verified against the actual configuration.
Storage location is not the whole question
Where data physically sits and whose law can compel its disclosure are two different questions, and a reviewer who knows the difference will ask the second one. A provider incorporated in one country can generally be ordered to produce data it controls even when that data is stored in another.
Mercleo is a Canadian company subject to Canadian law. Our providers include companies incorporated in the United States, so customer data they process can be subject to United States legal process regardless of where the server sits.
What this means if you are a public body, or in Quebec
Requirements differ by province and by sector, and the ones that bite are usually flowed down through a funding agreement rather than chosen by the organization itself.
If your obligations require specific residency, a transfer assessment under Quebec's Law 25, or something narrower still, tell us what you need before you buy. We will answer directly against your requirement rather than leave you to infer a position from this page, and if the honest answer is that we cannot meet it yet, that is the answer you will get.
If our footprint changes
This page is updated when the hosting picture changes. If your organization needs contractual notice before customer data moves between regions, that commitment belongs in signed data-processing terms; ask us at legal@mercleo.com.
The rest of the trust centre. Everything else a reviewer asks for.
- SubprocessorsEvery third party that touches customer data, and what each one sees.
- SecurityTenant isolation, staff access, and the supply chain.
- Privacy and your rightsThe processing agreement, retention, export, deletion and breach notice.
- AI and your dataWhat uses a model, what gets sent, and whether it trains on anything.
- AccessibilityWhat has actually been checked, what has not been assessed, and how to report a barrier.
- ComplianceWhat we hold, what we are working towards, and what we do not have.
- Report a vulnerabilityHow to reach us, what is in scope, and what happens after you do.