Security

Data residency and GDPR

Where StageReady stores your data, and how it handles personal data under GDPR.

1 min readUpdated Jul 31, 2026

Where your data lives

StageReady runs on Microsoft Azure in the European Union, specifically the Azure West Europe region in Amsterdam. The application, the database, and the vault all stay within the EU; your data isn't moved outside it.

Every tier, one region
ApplicationAzure West Europe

The portal and API your technicians use.

DatabaseAzure West Europe

Jobs, devices, templates, and the audit trail.

Azure Key VaultAzure West Europe

Client credentials, held nowhere else.

Client credentials

Credentials for each client's Microsoft environment are held only in Azure Key Vault, never in our database, in configuration, on the USB, or on the device. The application can read them only for the moment a job needs them. See the security model for the full picture.

Personal data

A device's hardware hash is the fingerprint needed to register it into Autopilot.

The hardware hash is treated as personal data

It identifies a specific physical machine, so StageReady handles it as personal data under GDPR: it is never written to logs, and it lives only on the device record it belongs to.

Your audit trail

Every code, step, and device is recorded so you can show any client exactly what was done, when, and by whom. Provisioning records are retained for a limited period and then removed, and you stay in control of your data throughout.