European Union
SOC platform with EU data residency and GDPR-native operations
All EU customer data stays in AWS EU-WEST-1 (Ireland) or EU-CENTRAL-1 (Frankfurt). ManySignal acts as a GDPR Article 28 Data Processor, provides NIS2 incident reporting support, and supports DORA ICT risk management requirements for financial entities operating in the EU.
EU data residency guarantees
Storage
All log data, entity graph data, case records, and analytics data is stored in AWS EU-WEST-1 (Dublin, Ireland) or EU-CENTRAL-1 (Frankfurt, Germany). You select the region at deployment. No data is replicated to non-EU regions without explicit customer consent.
Processing
All data processing — detection, analytics, AI inference, and report generation — occurs within the designated EU region. ManySignal's AI inference uses models deployed within EU infrastructure; no data is sent to US-based inference endpoints.
Support access
EU customer environments are accessible only by EU-based ManySignal staff under normal operations. US-based staff may access EU environments only with explicit customer approval and subject to the access logging and notification requirements in the DPA.
EU regulatory frameworks ManySignal supports
GDPR (2016/679)
General Data Protection Regulation — Article 28 DPA, 72-hour breach notification to DPC/CNIL/BfDI, data subject rights support
NIS2 (2022/2555)
Network and Information Security Directive 2 — 24-hour early warning, 72-hour incident notification, significant incident detection and reporting for essential and important entities
DORA (2022/2554)
Digital Operational Resilience Act — ICT risk management, ICT incident classification and reporting (4-hour major incident notification), TLPT evidence for financial entities
eIDAS 2.0
Electronic identification and trust services — monitoring for qualified trust service provider security requirements
EU AI Act
AI system monitoring requirements for high-risk AI — audit trail, transparency, and human oversight evidence for Article 13-14 compliance
Cyber Solidarity Act (2024)
European Cyber Shield and cybersecurity emergency mechanism — SOC capability requirements for cross-border incident coordination
EU sub-processors
Full sub-processor list with contractual mechanisms is maintained at /legal/subprocessors.
| Sub-processor | Role | Transfer mechanism |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure — EU-WEST-1 (Ireland), EU-CENTRAL-1 (Frankfurt) | Standard Contractual Clauses (SCCs) |
| Elastic | Search and log indexing | SCCs + EU-hosted deployment |
| Snowflake | Analytics data warehouse | SCCs + EU region (Frankfurt) |
| Twilio SendGrid | Transactional email (alert notifications) | SCCs |
| PagerDuty | Incident escalation and on-call routing | SCCs + EU data residency option |
Breach notification timelines — EU
24 hours
NIS2 — Early warning to national CSIRT or competent authority for significant incidents
72 hours
GDPR Art. 33 — Notification to lead supervisory authority (DPC for ManySignal's EU entity)
4 hours
DORA — Major ICT-related incident notification for financial entities to EBA/ESMA/EIOPA
EU sales and support contact
EU enterprise sales: eu-sales@manysignal.com
Data Protection Officer: privacy@manysignal.com
Security notifications: trust@manysignal.com
EU data residency — common questions
Where is EU customer data stored and processed?
EU customer data is stored and processed exclusively in AWS EU-WEST-1 (Dublin, Ireland) and AWS EU-CENTRAL-1 (Frankfurt, Germany). No EU customer data is transferred to AWS US regions. Data at rest is encrypted with AES-256; data in transit uses TLS 1.3. The specific AWS region used for your deployment is confirmed in your DPA.
Does ManySignal act as a Data Processor under GDPR Article 28?
Yes. When processing personal data on behalf of EU customers (employees, security telemetry containing personal data), ManySignal acts as a Data Processor under GDPR Article 28. ManySignal's Data Processing Agreement (DPA) — available at /legal/dpa — specifies the lawful basis, processing purposes, data categories, retention periods, and sub-processor list. It is executed as part of the standard customer agreement for EU deployments.
What is ManySignal's GDPR breach notification timeline?
Under GDPR Article 33, a personal data breach must be notified to the relevant supervisory authority within 72 hours of becoming aware. If ManySignal becomes aware of a breach affecting EU customer data, we notify the affected customer within 24 hours with the incident details required for the customer's supervisory authority notification. The relevant supervisory authorities by member state include: CNIL (France), BfDI (Germany), DPC (Ireland), GPDP (Italy), AEPD (Spain), ICO (UK — post-Brexit, separate from GDPR).
Is ManySignal certified under the EU-US Data Privacy Framework?
ManySignal participates in the EU-US Data Privacy Framework (DPF) for any residual cross-Atlantic data flows. For EU-deployed customers, the DPF certification is supplementary — primary data residency remains in EU AWS regions. The DPF certification covers ManySignal's US entity for any support access scenarios involving US-based staff, which is subject to the SCCs and our DPA's access control commitments.
Which EU supervisory authority oversees ManySignal as a data processor established in Ireland?
ManySignal's EU establishment is in Ireland. The Data Protection Commission (DPC) is ManySignal's lead supervisory authority under GDPR's One-Stop-Shop mechanism (Article 56). EU data subjects may file complaints with the DPC or with their local supervisory authority. ManySignal's DPO contact is privacy@manysignal.com.
Deploy ManySignal in the EU
Book a session with our EU team to discuss GDPR DPA execution, NIS2 monitoring configuration, and your preferred AWS EU region deployment.