Syntic

Regional Compliance

Syntic, in your jurisdiction, under your rules.

Syntic operates across six continents. Wherever your business runs, your data stays there — under the privacy, security, and operational frameworks of the jurisdiction you operate in. Regional data residency. Region-specific compliance scoping. Contracting through local entities where required. No cross-border data movement without your explicit configuration. No assumptions about which rules apply to your business. We scope to your jurisdiction, not the other way around.

5 deployment regions
US, EU, UK, Canada, and APAC in production today
40+ jurisdictions
supported through regional partners and local contracting entities
0
customer data crossing region boundaries without your explicit configuration
Per-jurisdiction
data residency, regulatory framework alignment, and contracting entity, all scoped to you

How it works

Three layers. All configured to your jurisdiction.

Every Syntic deployment is scoped across three dimensions: where your data lives, which regulatory frameworks your deployment meets, and which Syntic entity holds your contract. Each is set independently to match your jurisdiction — not defaulted to whatever is easiest for us.

Data residency

Where your data is stored and processed — and where it stays. Configurable at the Project level on Business and Enterprise plans. Customer content — conversations, voice transcripts, uploaded documents, knowledge sources, and Agent Execution traces — is pinned to the region you select at configuration. No cross-region replication without your explicit instruction. No movement for operational convenience. The default is always: data stays where you put it.

Regulatory framework alignment

Which laws and frameworks your deployment meets. HIPAA for US healthcare, GDPR for the EU, UK GDPR and DPA 2018, PIPEDA in Canada, DPDP Act in India, Privacy Act in Australia, and LGPD in Brazil, plus industry-specific frameworks like FDCPA, GLBA, FERPA, PCI DSS, and SR 11-7, and public sector frameworks like FedRAMP, IL2 to IL5, IRAP, ISMAP, C5, and SecNumCloud.

Contracting entity

Which Syntic legal entity holds your contract and processes your data under it. Different jurisdictions require different contracting structures — local data processor, local controller, joint-controller arrangements, intra-group data transfer agreements, and local incorporation requirements. We adapt the contracting structure to your jurisdiction's requirements, not the other way around. Where we don't yet have a local entity, we partner with established local entities for contracting, billing, and data handling. The current entity structure is in the Contracting section below.

Compliance by region

Every jurisdiction we operate in, with the frameworks, residency options, public sector authorizations, and procurement vehicles that apply.

If your jurisdiction isn't listed, contact compliance@syntic.ai — we scope to new jurisdictions regularly through our regional partner network.

United States and Canada

Data residency

Primary US-East and US-West regions. Canadian residency available on Business and Enterprise.

Federal frameworks

HIPAA (healthcare), BAA available on Business and Enterprise

GLBA (financial services), supporting controls scoped per engagement

FERPA (education), supporting controls available

FDCPA (collections), built into the Vertical AI Collections Employee

TCPA (telecommunications), built into AI Call Center voice and SMS

CAN-SPAM (email marketing), built into outbound email workflows

COPPA (children's privacy), supporting controls for K-12 education

State frameworks

CCPA and CPRA (California)

CDPA (Virginia), CPA (Colorado), UCPA (Utah), CTDPA (Connecticut), and equivalent emerging state privacy laws

State telemedicine and telehealth regulations supported

Federal government

FedRAMP Moderate authorization in progress, target 2027

FedRAMP High roadmap defined

DoD Impact Levels IL2 today, IL4 and IL5 on roadmap

CJIS-aligned deployments available

StateRAMP alignment for state and local government

Procurement vehicles

GSA Multiple Award Schedule (in progress)

SEWP, ITES, CIO-SP3, OASIS+ partnership paths

State and local NASPO ValuePoint, GovBuy, regional cooperatives

Subcontracting and teaming with established primes available

Canada

PIPEDA federal compliance

Provincial frameworks PHIPA (Ontario), Act respecting Health Services (Quebec), HIA (Alberta)

Canadian data residency available

Bilingual English and French deployments standard

European Union and United Kingdom

Data residency

EU regions Frankfurt, Dublin, Paris and UK region London. Customer content pinned to the selected region by default.

EU framework

GDPR, DPA available on all paid plans

Standard Contractual Clauses (SCC 2021 module 2) for cross-border transfers

EU representative designated under Article 27

Schrems II analysis documented per customer engagement

ePrivacy Directive alignment for electronic communications

AI Act compliance scoping in progress, with enforcement timelines aligned to phase-in dates

UK framework

UK GDPR and Data Protection Act 2018

UK representative designated

International Data Transfer Agreement (IDTA) for non-UK transfers

ICO registration current

Member state frameworks

Germany C5 (Cloud Computing Compliance Criteria Catalogue) alignment in progress

France SecNumCloud roadmap and ANSSI guidance alignment

Netherlands NEN 7510 for healthcare

Spain ENS (Esquema Nacional de Seguridad) for public sector

Italy AgID Cloud Marketplace alignment

Public sector

UK G-Cloud framework in progress, NCSC Cloud Security Principles alignment, OFFICIAL classification deployments available

EU NEGOMETRO and member state procurement frameworks

ENISA framework alignment

Industry-specific

DORA (Digital Operational Resilience Act) for financial services

NIS2 Directive for essential and important entities

MDR (Medical Device Regulation), noting Syntic is not a medical device and maintains clinician-in-the-loop framing

Asia-Pacific

Data residency

Singapore, Tokyo, and Sydney regions in production. Mumbai and Seoul on roadmap.

Australia

Privacy Act 1988 and Australian Privacy Principles

My Health Records Act for healthcare

IRAP assessment scoped for 2027 government engagements

ISM (Information Security Manual) alignment

Australian data residency in Sydney

Japan

APPI (Act on the Protection of Personal Information)

ISMAP scoped for 2027 government engagements

Healthcare data handling under MHLW guidance

Japanese data residency in Tokyo

Singapore

PDPA (Personal Data Protection Act)

MTCS SS 584 scoped for government engagements

Banking Cybersecurity Guidelines (MAS TRM)

Healthcare data under the PDPA Healthcare Sector Advisory

Singapore data residency

South Korea

PIPA (Personal Information Protection Act)

K-ISMS scoped for government engagements

Korean data residency on roadmap

India

DPDP Act 2023

IT Act 2000 and SPDI Rules

MeitY framework alignment for government

RBI data localization for regulated financial services

HIS (Health Information Standards) for healthcare engagements

Indian data residency in Mumbai on roadmap

Hong Kong

PDPO (Personal Data Privacy Ordinance)

HKMA cybersecurity guidelines for financial services

China (Mainland)

Syntic does not currently offer direct commercial services in mainland China. Customers with operations in China who need to process data locally are supported through partner-led deployments with established local entities — covering PIPL compliance, local data residency, and Cyberspace Administration of China requirements. Contact compliance@syntic.ai for current partner engagement structures and timelines.

Middle East and Africa

United Arab Emirates

UAE Federal Data Protection Law (PDPL)

ADGM Data Protection Regulations

DIFC Data Protection Law

TEJARI procurement vehicle for government engagements

Arabic-language deployments standard

UAE data residency through regional partner cloud

Saudi Arabia

PDPL (Personal Data Protection Law)

SDAIA framework alignment

NCA Essential Cybersecurity Controls

Saudi data residency through regional partner cloud

Arabic-language deployments standard

Israel

Privacy Protection Law and Regulations

Israeli data residency through regional partner infrastructure

South Africa

POPIA (Protection of Personal Information Act)

South African data residency on roadmap

Egypt, Kenya, Nigeria, Morocco

Local privacy framework alignment per engagement

Partner-led deployments through regional cloud providers

Latin America

Brazil

LGPD

ANPD registration

Brazilian healthcare data under CFM guidance

Brazilian data residency on roadmap

Portuguese-language deployments standard

Mexico

LFPDPPP

LGPDPPSO for public sector

Mexican data residency on roadmap

Spanish-language deployments standard

Argentina, Colombia, Chile, Peru

Local privacy framework alignment per engagement

EU adequacy decisions recognized where applicable

Honduras and Central America

Local privacy framework alignment per engagement

Partner support through regional infrastructure

Spanish-language deployments standard

Industry-specific frameworks

The regulatory requirements that follow your industry across every jurisdiction you operate in.

These frameworks apply regardless of region — we scope them per engagement based on your industry and the jurisdictions you serve.

Healthcare

HIPAA US, GDPR special category data EU, PHIPA Ontario, DPDP healthcare India, MHLW guidance Japan, Privacy Act health Australia, POPIA health South Africa

BAA, DPA, and equivalent agreements available

42 CFR Part 2 for substance use disorder treatment data in the US

Clinician-in-the-loop framing enforced, Syntic not marketed as a medical device

Financial services

SR 11-7 US Federal Reserve

PRA SS1/23 UK

BaFin MaRisk Germany

MAS Technology Risk Management Singapore

APRA CPS 234 Australia

OSFI guideline E-23 Canada

RBI master directions India

DORA EU

Collections and recovery

FDCPA US federal

State-level fair debt collection acts

FCA CONC UK

Australian Consumer Law Schedule 2

EU Consumer Credit Directive

All built into the Vertical AI Collections Employee

Public sector cross-region

FedRAMP, DoD IL, CJIS, StateRAMP US

NCSC, G-Cloud, OFFICIAL UK

C5, SecNumCloud, ENS EU member states

IRAP, ISMAP, MTCS, K-ISMS, MeitY APAC

Sovereign cloud and air-gapped deployment options

Education

FERPA US

GDPR education sector guidance EU

UK GDPR education provisions

DPDP educational data India

Provincial education privacy frameworks Canada

Payment processing

PCI DSS scoped per engagement

PSD2 EU and Open Banking

RBI payment system guidelines India

MAS PSN02 Singapore

Data transfer and cross-border

When your data needs to cross a jurisdiction boundary.

The default is no movement. When transfers happen, the legal mechanisms are already in place, and there are lines we do not cross.

Default behavior

  • By default, customer content stays in the region you select. We don't move customer data across regions for product operations.

When transfers happen

  • Customer explicitly enables multi-region deployment
  • Support requests requiring access to data in a different region
  • Cross-region failover configured per Enterprise customer
  • Legal compliance requirements

Legal mechanisms in place

  • Standard Contractual Clauses 2021 modules
  • UK International Data Transfer Agreement
  • Binding Corporate Rules in development for intra-Syntic transfers
  • Adequacy decisions where available
  • Customer-specific data transfer agreements on Enterprise

What we don't do

  • We don't transfer customer data to jurisdictions without a documented legal basis — no informal transfers, no operational convenience exceptions.
  • We don't respond to law enforcement or government data requests without proper legal process. Where legally permitted, we notify customers before complying. Where we cannot notify, we log the request and report aggregate counts in our annual transparency report.
  • We don't comply with requests we believe are unlawful. We will challenge requests through available legal mechanisms where we have grounds to do so.
  • We publish our government request transparency report annually at syntic.ai/transparency, including request counts by jurisdiction, how we responded, and how many we challenged or refused.

Contracting and entity structure

Which Syntic entity contracts with you depends on your jurisdiction.

Different jurisdictions require different contracting structures. We adapt to yours.

Syntic AI, Inc. (Delaware, USA)

US customers and international customers without local entity requirements.

Syntic AI Limited (United Kingdom)

UK customers and EU customers, transitional, pending EU entity.

Syntic AI BV (Netherlands)

EU customers requiring an EU contracting entity. In setup.

Syntic AI Pte Ltd (Singapore)

APAC customers requiring a regional contracting entity. In setup.

Local partners

For jurisdictions requiring local incorporation, we partner with established local entities for contracting, billing, and data handling. Contact compliance for current partner relationships in your region.

Sovereign deployment

For governments and regulated industries that cannot depend on shared infrastructure.

Some workloads — classified government data, sensitive regulated industry data, air-gapped operational environments — cannot run on shared commercial cloud infrastructure regardless of the contractual protections around it. Syntic supports full sovereign deployment for these workloads: on-premise inside your data centre, in government-controlled sovereign cloud, or air-gapped with no external dependencies. The same frontier AI capability, entirely inside your perimeter.

On-premise deployment

Syntic deployed inside your data centre on your own infrastructure. Air-gapped operation supported — no external network calls required after initial deployment. Customer-managed updates, security patching, and model versioning. No dependency on Syntic's cloud infrastructure remaining operational. Available on Enterprise; contact compliance to scope the engagement.

Sovereign cloud

Deployment in customer-controlled or government-controlled cloud infrastructure. No foreign commercial cloud dependency. Available for government and regulated industry engagements.

Customer-managed keys (BYOK)

Customer holds and rotates encryption keys. Syntic cannot decrypt data without customer cooperation. Available on Enterprise.

Dedicated runtime

Single-tenant infrastructure for the customer. No shared inference. Customer-controlled regional pinning. Standard on Business and Enterprise plans for AI Call Center, available on request for other workloads.

For procurement and legal teams

What we provide to make your jurisdictional diligence easier.

Standard documentation, materials under NDA, and dedicated support on Business and Enterprise.

Standard documentation

Region-specific Data Processing Agreement

Standard Contractual Clauses and UK IDTA

Business Associate Agreement for US healthcare

Country-specific privacy law addendums

Subprocessor list with regional breakdown

Data flow diagrams per region

Schrems II transfer impact assessment template

Under NDA

Region-specific security pack

Penetration testing reports per region

Compliance gap analysis versus local frameworks

Customer-specific compliance scoping documents

Regional incident response procedures

On Business and Enterprise

Live calls with our compliance team

Custom regional compliance scoping

Validation evidence packages per jurisdiction

Region-specific service level agreements

Frequently asked questions

The questions procurement, legal, and security teams ask.

Region selection, multi-region deployment, regulator requests, and emerging AI frameworks.

How do I select my deployment region?

Region selection is configured at the Project level in your Syntic account settings on Business and Enterprise plans. When you create a Project, you select the deployment region — US-East, US-West, EU-Frankfurt, EU-Dublin, UK-London, Canada, Singapore, Tokyo, or Sydney. All customer content associated with that Project is stored and processed in that region. Pro plan customers are on US-East by default; contact us if you need a different region on Pro.

Can I deploy in multiple regions?

Yes. Business and Enterprise customers can deploy Projects in different regions. Each Project's data stays in its selected region by default.

What happens if a regulator requests my data?

We require proper legal process — a court order, subpoena, or equivalent legal instrument in the relevant jurisdiction — before complying with any government or law enforcement request for customer data. We do not voluntarily disclose customer data to any authority. Where the law permits us to notify the customer before complying, we do so. Where we cannot notify, we log the request. We publish aggregate government request counts in our annual transparency report. If you receive notice of a legal process requiring your data from Syntic, contact legal@syntic.ai immediately.

What if my region isn't listed?

Contact compliance@syntic.ai with your jurisdiction. We scope to new regions regularly through our regional partner network and have engagement structures for most jurisdictions not explicitly listed on this page. If we can support your jurisdiction today through a partner, we'll tell you that and introduce you to the right partner. If we can't yet, we'll tell you that honestly and give you a realistic timeline.

How do you handle the AI Act in the EU?

Syntic AI is scoping compliance with the EU AI Act aligned to its phase-in timeline. The AI Act classifies AI systems by risk category — the majority of Syntic's use cases fall in the limited or minimal risk categories. Where Syntic deployments touch higher-risk categories — certain HR use cases, some public sector deployments, and some healthcare applications — we are documenting conformity requirements and will publish our approach as the relevant provisions enter force. Our clinician-in-the-loop framing for healthcare and our human-in-the-loop platform controls for high-stakes decisions are designed to be consistent with the Act's requirements for human oversight. Contact compliance@syntic.ai for EU AI Act scoping on your specific deployment.

Do you support sovereign AI for non-US governments?

Yes. Sovereign cloud and on-premise deployments are available for government and regulated industry engagements. Custom models can be trained and deployed inside customer-controlled infrastructure.

What about emerging frameworks like Canada AIDA, the EU AI Act, and the US AI Executive Order?

We monitor regulatory developments in all production regions and update our compliance posture as frameworks finalize. Customer-facing changes are communicated 30 days in advance for Business and Enterprise.

How does data residency work for voice calls?

Voice processing runs regionally for low latency. Call recordings are stored in the region of the calling party by default, configurable per customer.

What if I have a custom regulatory requirement?

Most regulatory requirements are scopable into our existing framework. Contact compliance@syntic.ai with your specific framework and we'll assess fit and propose a path.

Get in touch

Bring us your jurisdiction. We will scope the rest.

Every compliance engagement starts with a conversation. Tell us where you operate, what industry you're in, and what frameworks your procurement or legal team requires. We will scope what we have today, what's in progress, and what we'd need to build for your specific deployment.

Compliance questions

compliance@syntic.ai · trust.syntic.ai

Regional procurement

Americas — americas-compliance@syntic.ai · EMEA — emea-compliance@syntic.ai · APAC — apac-compliance@syntic.ai

Data subject rights

privacy@syntic.ai · DSAR portal at trust.syntic.ai/dsar

Government and public sector

publicsector@syntic.ai

Legal and contract questions

legal@syntic.ai

Response time

Compliance inquiries acknowledged within one business day and substantively responded to within three. For urgent procurement timelines, note that in your email and we'll prioritise accordingly.