SupportCentral Enterprise

Data residency

Where your data physically lives, who can reach it, and what to put in the compliance questionnaire your own customer sent you.

Last updated: · Applies to SupportCentral Enterprise, operated by Support IT Ventures.

The short answer

All of it is in India, on infrastructure we control. Database, uploaded files, logs, search indexes and backups. None of it is replicated to another country.

Why this is a design decision, not a marketing line

Products like this hold employee names, personal email addresses, phone numbers, manager relationships and — in the enterprise product — a record of exactly which device a named person is holding. That is personal data about people who never chose the vendor.

Keeping it in India means your DPDP obligations are simpler to meet, your own customers' questionnaires are simpler to answer, and there is no cross-border transfer to justify.

The complete list of who else can touch it

Two companies: our payment processor, which sees billing identifiers when you pay, and our email provider, which delivers mail your desk sends. Both are on our sub-processors page with what they receive and where they are.

There is no analytics vendor, no advertising network, no CDN, no error-tracking service and no external AI provider in the default configuration.

AI, specifically

The AI features run on a model we host on our own hardware. Your tickets are not sent to a third-party model provider.

An administrator can point the AI at an external endpoint if they want to. If they do, the product names the destination host and requires a typed confirmation before it will save the setting, and the decision is written to the audit log. It is off by default and we do not recommend it for data you would not email.

What "in India" actually means here

It is worth being precise, because the phrase is used loosely. It means the primary database, the file storage holding every attachment your users upload, the application servers, the background workers, the log files and every copy of the backups are located in India and administered by us.

It does not mean data is merely "available" in an Indian region of a provider that may move it. There is no multi-region replication to switch on by accident, and no global edge cache holding fragments of your pages in another jurisdiction — because there is no edge cache at all.

Why there is no CDN, and what you get instead

A content delivery network would put copies of our pages, and the addresses of everyone who loads them, on servers around the world belonging to a company you never agreed to. So we do not use one — nor a web font service, an analytics script, an error-tracking service or a social pixel.

The trade is real and we think it is the right way round: we lose the ability to hand-wave about edge performance, and we gain a page that loads no third-party request at all, which is faster for most Indian visitors anyway and leaks nothing.

Backups, and where they are

Backups are encrypted and held on a daily, weekly and monthly retention schedule in a second location that is also in India. Restores are tested on a schedule and the result is written down, because an untested backup is a hope rather than a control.

If you need to leave

Residency is worth little without portability. You can export everything — every record type as CSV, every attachment under its original filename, your knowledge base as readable files — at any time, in any account state including a lapsed one, at no charge and without asking us. There is no export fee and no retention flow standing in the way.

For your compliance questionnaire

  • Data location: India.
  • Cross-border transfer: none in the default configuration.
  • Sub-processors: two, both listed publicly, 30 days' notice before any change.
  • Encryption: TLS in transit; secrets encrypted at rest; backups encrypted.
  • Data portability: full self-service export, all record types, any account state, no charge.
  • Deletion: on request, or automatically 90 days after termination, with prior email warnings.
  • Breach notification: to the Data Protection Board and affected principals as the DPDP Act requires, and to you with the detail you need for your own obligations.
  • DPA: available and signable by email.

Something here unclear or unfair? Tell us at support@supportcentral.in. We would rather fix the wording than argue about it later. See also Terms, Privacy and Grievance redressal.