Skip to main content

Your identity data stays in the EU

Every EU cluster runs in Frankfurt with backups in Ireland. You contract with Phase Two UK, Ltd under English law. Your users, credentials and events are never replicated outside the EU — and the administrative access that reaches them from outside the EU is described on this page rather than left out of it.

Who you are dealing with

Most pages like this one begin with certifications. We would rather begin with the company structure, because that is what decides which laws apply to your data, and because you can verify all of it.

  • Phase Two UK, Ltd is the contracting party for customers in the European Union and the United Kingdom. Registered in England and Wales, company number 16815578, registered office 2 Leman Street, London E1W 9US.
  • Phase Two, Inc. is the parent company, incorporated in the United States and based in Seattle. We are a remote team distributed across several countries.
  • Your clusters run in the EU — Frankfurt for everything, Ireland for backups — on infrastructure operated by AWS in Germany and Ireland.
  • EU to UK transfers need no extra safeguard. The European Commission renewed its adequacy decision for the United Kingdom on 19 December 2025, valid until 27 December 2031.

Where every class of data lives

Your end users’ identity data stays in the EU. Our own business systems — the dashboard you log into, support tickets, invoicing — run in the United States. Both halves are below, because a table that showed only the first half would be the more flattering document and the less useful one.

DataStored inInfrastructureWho can reach itLeaves the EU?
Keycloak database — users, credentials, groups, roles, client configFrankfurt (eu-central-1)AWS, GermanyPhase Two operations staff, including staff outside the EUNever replicated outside the EU
Sessions and cacheFrankfurt (eu-central-1)AWS, GermanyPhase Two operations staff, including staff outside the EUNever replicated outside the EU
Event store — login and admin eventsFrankfurt (eu-central-1)AWS, GermanyPhase Two operations staff, including staff outside the EUNever replicated outside the EU
BackupsIreland (eu-west-1)AWS, IrelandPhase Two operations staff, including staff outside the EUNever replicated outside the EU
Encryption keys for realm signingFrankfurt (eu-central-1)AWS KMS, GermanyPhase Two operations staffNever replicated outside the EU
Cluster logs and metricsFrankfurt (eu-central-1)AWS, GermanyPhase Two engineering, including staff outside the EUNever replicated outside the EU
Dashboard account metadata — your Phase Two login, org and cluster settingsUnited StatesSee the Trust Center subprocessor listPhase Two staffYes — this is not your end users' identity data
Support tickets and their attachmentsUnited StatesSee the Trust Center subprocessor listPhase Two support staffYes — send us no end-user personal data in a ticket
Billing and invoicingUnited StatesSee the Trust Center subprocessor listPhase Two finance staffYes — billing contact details only

The current list of subprocessors, with the service each one provides, is published in our Trust Center. We notify customers before adding one.

The CLOUD Act, and administrative access from outside the EU

Two things about the arrangement above are worth hearing from us rather than discovering during a procurement review.

Our parent company is incorporated in the United States. Under the US CLOUD Act a provider subject to United States jurisdiction can be compelled to disclose data in its “possession, custody, or control” wherever that data is stored. We therefore do not claim immunity from United States legal process, and we would encourage you to read any vendor who does claim it with some care — a European region does not by itself change where a parent company is incorporated.

Our control plane runs in the United States, and our engineers are distributed globally. Administering your cluster — provisioning it, upgrading it, restoring it, responding at three in the morning — means reaching it, and some of the people doing that are outside the EU. Under Chapter V of the GDPR that access is a restricted transfer, not a gap in one. It is limited to named roles, logged internally, and covered in the data processing agreement.

What we commit to in return: your identity data is never replicated outside the EU; encryption keys for EU clusters are held in the EU; we are not certified under the EU-US Data Privacy Framework and do not rely on it; and any request from any government is handled under our government requests policy. To date we have received none, and we publish that count every year.

Keys and access control

Realm signing keys for EU clusters are held in AWS KMS in the Frankfurt region and do not leave the EU. To be precise about something the industry is often vague about: these are our keys held in our key management service, not customer-held keys. We do not offer bring-your-own-key on hosted clusters today, and we would rather say that than imply otherwise.

Administrative access to clusters is restricted to named operations roles and logged internally. Those logs are part of what our SOC 2 Type II audit examines; they are not currently exposed to customers, which is a limitation we would like to remove.

What we sign, and what we do not hold

GDPR Article 28. A written data processing agreement covering processing on documented instructions, confidentiality, security, subprocessor authorisation and notification, assistance with data subject requests, deletion or return at the end of the service, and audit rights. The terms are published on the data processing page.

NIS2 and DORA. If you are in scope for either, you will need contractual terms from your identity provider covering incident notification, audit and access rights, subcontracting and an exit plan. We sign those. Our contractual incident notification window is 48 to 72 hours, which is worth knowing precisely: NIS2 gives you 24 hours for an early warning, so if your own clock depends on ours, tell us during contracting and we will discuss what is achievable for your deployment.

What we do not hold, stated plainly. We are not SecNumCloud qualified and will not be, because that qualification requires European ownership that a company with a United States parent cannot satisfy. We hold no BSI C5 attestation of our own; the AWS regions we run in are C5 attested, which is a statement about our infrastructure supplier and not about us. We are not certified under the EU-US Data Privacy Framework.

What we do hold. SOC 2 Type II and ISO/IEC 27001, both current, with reports available through the Trust Center, along with penetration test summaries.

Leaving

We run upstream Keycloak, not a fork and not a Keycloak-inspired product, which is what makes leaving a real option rather than a clause. You can export your realm configuration and users, and we will provide a database dump on request. Deletion of your data at the end of the service is a contractual commitment under Article 28(3)(g), carried out on request.

We do not yet publish a timed exit runbook or issue a deletion certificate. Both are in progress, and if either matters to your risk assessment, ask us and we will put the detail in writing for your contract.

Questions we get asked

Is hosting in the EU enough?
No, and we would rather say so than let you find out later. Where data is stored is one question; who can reach it, which company you contract with, and which laws that company is subject to are three more. This page answers all four, and the answer to the third and fourth involves a United States parent company. Any vendor telling you that an EU region settles the matter is selling you a simpler story than the one your data protection officer will ask for.
Are you subject to the US CLOUD Act?
Our parent company is incorporated in the United States, so we cannot claim immunity from United States legal process, and you should be sceptical of any vendor with a United States or United Kingdom parent that does. Under the CLOUD Act a provider subject to United States jurisdiction can be compelled to disclose data in its possession, custody, or control wherever that data is stored. What we can tell you is what we would do about it, which is on our government requests page, and that we have never received such a request.
Can staff outside the EU access my data?
Yes. Our control plane runs in the United States and our engineering team is distributed globally, so administrators outside the EU can reach your cluster in order to operate it. Access is limited to named roles and is logged internally. We disclose this because it is the part most vendors leave out.
Is remote administrative access a transfer under the GDPR?
Yes. Remote access to EU-stored data from outside the EU is a restricted transfer under Chapter V of the GDPR, not an exception to it. It is covered in our data processing agreement rather than left unsaid.
Why do I contract with a UK company?
Phase Two UK, Ltd is our European operating company and the contracting party for customers in the European Union and the United Kingdom. The European Commission renewed its adequacy decision for the United Kingdom on 19 December 2025, valid until 27 December 2031, so transfers from the EU to the United Kingdom need no additional safeguard.
Can I choose Ireland as my primary region?
Frankfurt is the primary region for EU clusters and Ireland holds the backups. If your requirement is specifically for an Irish primary, talk to us — it is a provisioning question, not a product limitation.
Do you rely on the EU-US Data Privacy Framework?
No. Phase Two is not certified under the Data Privacy Framework, so we do not rely on it. Transfers are handled through our data processing agreement.
Can my data protection officer get the DPA without signing an NDA?
Yes. The terms are published on our data processing page and the signature copy is available on request.

Related: managed Keycloak on dedicated clusters, available regions, data processing and government requests.

Last reviewed: 2026-09-21. The legal position described here changes; we review this page quarterly and on any material change.

Run Keycloak in Frankfurt
Or send this page to your data protection officer first.