Regional Compliance
Syntic, in your jurisdiction, under your rules.
Syntic operates across six continents. Wherever your business runs, your data stays there — under the privacy, security, and operational frameworks of the jurisdiction you operate in. Regional data residency. Region-specific compliance scoping. Contracting through local entities where required. No cross-border data movement without your explicit configuration. No assumptions about which rules apply to your business. We scope to your jurisdiction, not the other way around.
How it works
Three layers. All configured to your jurisdiction.
Every Syntic deployment is scoped across three dimensions: where your data lives, which regulatory frameworks your deployment meets, and which Syntic entity holds your contract. Each is set independently to match your jurisdiction — not defaulted to whatever is easiest for us.
Data residency
Where your data is stored and processed — and where it stays. Configurable at the Project level on Business and Enterprise plans. Customer content — conversations, voice transcripts, uploaded documents, knowledge sources, and Agent Execution traces — is pinned to the region you select at configuration. No cross-region replication without your explicit instruction. No movement for operational convenience. The default is always: data stays where you put it.
Regulatory framework alignment
Which laws and frameworks your deployment meets. HIPAA for US healthcare, GDPR for the EU, UK GDPR and DPA 2018, PIPEDA in Canada, DPDP Act in India, Privacy Act in Australia, and LGPD in Brazil, plus industry-specific frameworks like FDCPA, GLBA, FERPA, PCI DSS, and SR 11-7, and public sector frameworks like FedRAMP, IL2 to IL5, IRAP, ISMAP, C5, and SecNumCloud.
Contracting entity
Which Syntic legal entity holds your contract and processes your data under it. Different jurisdictions require different contracting structures — local data processor, local controller, joint-controller arrangements, intra-group data transfer agreements, and local incorporation requirements. We adapt the contracting structure to your jurisdiction's requirements, not the other way around. Where we don't yet have a local entity, we partner with established local entities for contracting, billing, and data handling. The current entity structure is in the Contracting section below.
Compliance by region
Every jurisdiction we operate in, with the frameworks, residency options, public sector authorizations, and procurement vehicles that apply.
If your jurisdiction isn't listed, contact compliance@syntic.ai — we scope to new jurisdictions regularly through our regional partner network.
United States and Canada
Data residency
Primary US-East and US-West regions. Canadian residency available on Business and Enterprise.
Federal frameworks
HIPAA (healthcare), BAA available on Business and Enterprise
GLBA (financial services), supporting controls scoped per engagement
FERPA (education), supporting controls available
FDCPA (collections), built into the Vertical AI Collections Employee
TCPA (telecommunications), built into AI Call Center voice and SMS
CAN-SPAM (email marketing), built into outbound email workflows
COPPA (children's privacy), supporting controls for K-12 education
State frameworks
CCPA and CPRA (California)
CDPA (Virginia), CPA (Colorado), UCPA (Utah), CTDPA (Connecticut), and equivalent emerging state privacy laws
State telemedicine and telehealth regulations supported
Federal government
FedRAMP Moderate authorization in progress, target 2027
FedRAMP High roadmap defined
DoD Impact Levels IL2 today, IL4 and IL5 on roadmap
CJIS-aligned deployments available
StateRAMP alignment for state and local government
Procurement vehicles
GSA Multiple Award Schedule (in progress)
SEWP, ITES, CIO-SP3, OASIS+ partnership paths
State and local NASPO ValuePoint, GovBuy, regional cooperatives
Subcontracting and teaming with established primes available
Canada
PIPEDA federal compliance
Provincial frameworks PHIPA (Ontario), Act respecting Health Services (Quebec), HIA (Alberta)
Canadian data residency available
Bilingual English and French deployments standard
European Union and United Kingdom
Data residency
EU regions Frankfurt, Dublin, Paris and UK region London. Customer content pinned to the selected region by default.
EU framework
GDPR, DPA available on all paid plans
Standard Contractual Clauses (SCC 2021 module 2) for cross-border transfers
EU representative designated under Article 27
Schrems II analysis documented per customer engagement
ePrivacy Directive alignment for electronic communications
AI Act compliance scoping in progress, with enforcement timelines aligned to phase-in dates
UK framework
UK GDPR and Data Protection Act 2018
UK representative designated
International Data Transfer Agreement (IDTA) for non-UK transfers
ICO registration current
Member state frameworks
Germany C5 (Cloud Computing Compliance Criteria Catalogue) alignment in progress
France SecNumCloud roadmap and ANSSI guidance alignment
Netherlands NEN 7510 for healthcare
Spain ENS (Esquema Nacional de Seguridad) for public sector
Italy AgID Cloud Marketplace alignment
Public sector
UK G-Cloud framework in progress, NCSC Cloud Security Principles alignment, OFFICIAL classification deployments available
EU NEGOMETRO and member state procurement frameworks
ENISA framework alignment
Industry-specific
DORA (Digital Operational Resilience Act) for financial services
NIS2 Directive for essential and important entities
MDR (Medical Device Regulation), noting Syntic is not a medical device and maintains clinician-in-the-loop framing
Asia-Pacific
Data residency
Singapore, Tokyo, and Sydney regions in production. Mumbai and Seoul on roadmap.
Australia
Privacy Act 1988 and Australian Privacy Principles
My Health Records Act for healthcare
IRAP assessment scoped for 2027 government engagements
ISM (Information Security Manual) alignment
Australian data residency in Sydney
Japan
APPI (Act on the Protection of Personal Information)
ISMAP scoped for 2027 government engagements
Healthcare data handling under MHLW guidance
Japanese data residency in Tokyo
Singapore
PDPA (Personal Data Protection Act)
MTCS SS 584 scoped for government engagements
Banking Cybersecurity Guidelines (MAS TRM)
Healthcare data under the PDPA Healthcare Sector Advisory
Singapore data residency
South Korea
PIPA (Personal Information Protection Act)
K-ISMS scoped for government engagements
Korean data residency on roadmap
India
DPDP Act 2023
IT Act 2000 and SPDI Rules
MeitY framework alignment for government
RBI data localization for regulated financial services
HIS (Health Information Standards) for healthcare engagements
Indian data residency in Mumbai on roadmap
Hong Kong
PDPO (Personal Data Privacy Ordinance)
HKMA cybersecurity guidelines for financial services
China (Mainland)
Syntic does not currently offer direct commercial services in mainland China. Customers with operations in China who need to process data locally are supported through partner-led deployments with established local entities — covering PIPL compliance, local data residency, and Cyberspace Administration of China requirements. Contact compliance@syntic.ai for current partner engagement structures and timelines.
Middle East and Africa
United Arab Emirates
UAE Federal Data Protection Law (PDPL)
ADGM Data Protection Regulations
DIFC Data Protection Law
TEJARI procurement vehicle for government engagements
Arabic-language deployments standard
UAE data residency through regional partner cloud
Saudi Arabia
PDPL (Personal Data Protection Law)
SDAIA framework alignment
NCA Essential Cybersecurity Controls
Saudi data residency through regional partner cloud
Arabic-language deployments standard
Israel
Privacy Protection Law and Regulations
Israeli data residency through regional partner infrastructure
South Africa
POPIA (Protection of Personal Information Act)
South African data residency on roadmap
Egypt, Kenya, Nigeria, Morocco
Local privacy framework alignment per engagement
Partner-led deployments through regional cloud providers
Latin America
Brazil
LGPD
ANPD registration
Brazilian healthcare data under CFM guidance
Brazilian data residency on roadmap
Portuguese-language deployments standard
Mexico
LFPDPPP
LGPDPPSO for public sector
Mexican data residency on roadmap
Spanish-language deployments standard
Argentina, Colombia, Chile, Peru
Local privacy framework alignment per engagement
EU adequacy decisions recognized where applicable
Honduras and Central America
Local privacy framework alignment per engagement
Partner support through regional infrastructure
Spanish-language deployments standard
Industry-specific frameworks
The regulatory requirements that follow your industry across every jurisdiction you operate in.
These frameworks apply regardless of region — we scope them per engagement based on your industry and the jurisdictions you serve.
Healthcare
HIPAA US, GDPR special category data EU, PHIPA Ontario, DPDP healthcare India, MHLW guidance Japan, Privacy Act health Australia, POPIA health South Africa
BAA, DPA, and equivalent agreements available
42 CFR Part 2 for substance use disorder treatment data in the US
Clinician-in-the-loop framing enforced, Syntic not marketed as a medical device
Financial services
SR 11-7 US Federal Reserve
PRA SS1/23 UK
BaFin MaRisk Germany
MAS Technology Risk Management Singapore
APRA CPS 234 Australia
OSFI guideline E-23 Canada
RBI master directions India
DORA EU
Collections and recovery
FDCPA US federal
State-level fair debt collection acts
FCA CONC UK
Australian Consumer Law Schedule 2
EU Consumer Credit Directive
All built into the Vertical AI Collections Employee
Public sector cross-region
FedRAMP, DoD IL, CJIS, StateRAMP US
NCSC, G-Cloud, OFFICIAL UK
C5, SecNumCloud, ENS EU member states
IRAP, ISMAP, MTCS, K-ISMS, MeitY APAC
Sovereign cloud and air-gapped deployment options
Education
FERPA US
GDPR education sector guidance EU
UK GDPR education provisions
DPDP educational data India
Provincial education privacy frameworks Canada
Payment processing
PCI DSS scoped per engagement
PSD2 EU and Open Banking
RBI payment system guidelines India
MAS PSN02 Singapore
Data transfer and cross-border
When your data needs to cross a jurisdiction boundary.
The default is no movement. When transfers happen, the legal mechanisms are already in place, and there are lines we do not cross.
Default behavior
- By default, customer content stays in the region you select. We don't move customer data across regions for product operations.
When transfers happen
- Customer explicitly enables multi-region deployment
- Support requests requiring access to data in a different region
- Cross-region failover configured per Enterprise customer
- Legal compliance requirements
Legal mechanisms in place
- Standard Contractual Clauses 2021 modules
- UK International Data Transfer Agreement
- Binding Corporate Rules in development for intra-Syntic transfers
- Adequacy decisions where available
- Customer-specific data transfer agreements on Enterprise
What we don't do
- We don't transfer customer data to jurisdictions without a documented legal basis — no informal transfers, no operational convenience exceptions.
- We don't respond to law enforcement or government data requests without proper legal process. Where legally permitted, we notify customers before complying. Where we cannot notify, we log the request and report aggregate counts in our annual transparency report.
- We don't comply with requests we believe are unlawful. We will challenge requests through available legal mechanisms where we have grounds to do so.
- We publish our government request transparency report annually at syntic.ai/transparency, including request counts by jurisdiction, how we responded, and how many we challenged or refused.
Contracting and entity structure
Which Syntic entity contracts with you depends on your jurisdiction.
Different jurisdictions require different contracting structures. We adapt to yours.
Syntic AI, Inc. (Delaware, USA)
US customers and international customers without local entity requirements.
Syntic AI Limited (United Kingdom)
UK customers and EU customers, transitional, pending EU entity.
Syntic AI BV (Netherlands)
EU customers requiring an EU contracting entity. In setup.
Syntic AI Pte Ltd (Singapore)
APAC customers requiring a regional contracting entity. In setup.
Local partners
For jurisdictions requiring local incorporation, we partner with established local entities for contracting, billing, and data handling. Contact compliance for current partner relationships in your region.
Sovereign deployment
For governments and regulated industries that cannot depend on shared infrastructure.
Some workloads — classified government data, sensitive regulated industry data, air-gapped operational environments — cannot run on shared commercial cloud infrastructure regardless of the contractual protections around it. Syntic supports full sovereign deployment for these workloads: on-premise inside your data centre, in government-controlled sovereign cloud, or air-gapped with no external dependencies. The same frontier AI capability, entirely inside your perimeter.
On-premise deployment
Syntic deployed inside your data centre on your own infrastructure. Air-gapped operation supported — no external network calls required after initial deployment. Customer-managed updates, security patching, and model versioning. No dependency on Syntic's cloud infrastructure remaining operational. Available on Enterprise; contact compliance to scope the engagement.
Sovereign cloud
Deployment in customer-controlled or government-controlled cloud infrastructure. No foreign commercial cloud dependency. Available for government and regulated industry engagements.
Customer-managed keys (BYOK)
Customer holds and rotates encryption keys. Syntic cannot decrypt data without customer cooperation. Available on Enterprise.
Dedicated runtime
Single-tenant infrastructure for the customer. No shared inference. Customer-controlled regional pinning. Standard on Business and Enterprise plans for AI Call Center, available on request for other workloads.
For procurement and legal teams
What we provide to make your jurisdictional diligence easier.
Standard documentation, materials under NDA, and dedicated support on Business and Enterprise.
Standard documentation
Region-specific Data Processing Agreement
Standard Contractual Clauses and UK IDTA
Business Associate Agreement for US healthcare
Country-specific privacy law addendums
Subprocessor list with regional breakdown
Data flow diagrams per region
Schrems II transfer impact assessment template
Under NDA
Region-specific security pack
Penetration testing reports per region
Compliance gap analysis versus local frameworks
Customer-specific compliance scoping documents
Regional incident response procedures
On Business and Enterprise
Live calls with our compliance team
Custom regional compliance scoping
Validation evidence packages per jurisdiction
Region-specific service level agreements
Frequently asked questions
The questions procurement, legal, and security teams ask.
Region selection, multi-region deployment, regulator requests, and emerging AI frameworks.
How do I select my deployment region?
Region selection is configured at the Project level in your Syntic account settings on Business and Enterprise plans. When you create a Project, you select the deployment region — US-East, US-West, EU-Frankfurt, EU-Dublin, UK-London, Canada, Singapore, Tokyo, or Sydney. All customer content associated with that Project is stored and processed in that region. Pro plan customers are on US-East by default; contact us if you need a different region on Pro.
Can I deploy in multiple regions?
Yes. Business and Enterprise customers can deploy Projects in different regions. Each Project's data stays in its selected region by default.
What happens if a regulator requests my data?
We require proper legal process — a court order, subpoena, or equivalent legal instrument in the relevant jurisdiction — before complying with any government or law enforcement request for customer data. We do not voluntarily disclose customer data to any authority. Where the law permits us to notify the customer before complying, we do so. Where we cannot notify, we log the request. We publish aggregate government request counts in our annual transparency report. If you receive notice of a legal process requiring your data from Syntic, contact legal@syntic.ai immediately.
What if my region isn't listed?
Contact compliance@syntic.ai with your jurisdiction. We scope to new regions regularly through our regional partner network and have engagement structures for most jurisdictions not explicitly listed on this page. If we can support your jurisdiction today through a partner, we'll tell you that and introduce you to the right partner. If we can't yet, we'll tell you that honestly and give you a realistic timeline.
How do you handle the AI Act in the EU?
Syntic AI is scoping compliance with the EU AI Act aligned to its phase-in timeline. The AI Act classifies AI systems by risk category — the majority of Syntic's use cases fall in the limited or minimal risk categories. Where Syntic deployments touch higher-risk categories — certain HR use cases, some public sector deployments, and some healthcare applications — we are documenting conformity requirements and will publish our approach as the relevant provisions enter force. Our clinician-in-the-loop framing for healthcare and our human-in-the-loop platform controls for high-stakes decisions are designed to be consistent with the Act's requirements for human oversight. Contact compliance@syntic.ai for EU AI Act scoping on your specific deployment.
Do you support sovereign AI for non-US governments?
Yes. Sovereign cloud and on-premise deployments are available for government and regulated industry engagements. Custom models can be trained and deployed inside customer-controlled infrastructure.
What about emerging frameworks like Canada AIDA, the EU AI Act, and the US AI Executive Order?
We monitor regulatory developments in all production regions and update our compliance posture as frameworks finalize. Customer-facing changes are communicated 30 days in advance for Business and Enterprise.
How does data residency work for voice calls?
Voice processing runs regionally for low latency. Call recordings are stored in the region of the calling party by default, configurable per customer.
What if I have a custom regulatory requirement?
Most regulatory requirements are scopable into our existing framework. Contact compliance@syntic.ai with your specific framework and we'll assess fit and propose a path.
Get in touch
Bring us your jurisdiction. We will scope the rest.
Every compliance engagement starts with a conversation. Tell us where you operate, what industry you're in, and what frameworks your procurement or legal team requires. We will scope what we have today, what's in progress, and what we'd need to build for your specific deployment.
Compliance questions
compliance@syntic.ai · trust.syntic.ai
Regional procurement
Americas — americas-compliance@syntic.ai · EMEA — emea-compliance@syntic.ai · APAC — apac-compliance@syntic.ai
Data subject rights
privacy@syntic.ai · DSAR portal at trust.syntic.ai/dsar
Government and public sector
publicsector@syntic.ai
Legal and contract questions
legal@syntic.ai
Response time
Compliance inquiries acknowledged within one business day and substantively responded to within three. For urgent procurement timelines, note that in your email and we'll prioritise accordingly.