You asked
Norvext’s primary database is configured in Stockholm and the application deployments are configured in Frankfurt. That does not mean every support, security, payment, email, edge-network or AI processing operation is confined to the EEA. The complete answer is the current Subprocessor Register, including provider operations and transfer safeguards.
Three different location questions
Database location describes where customer records are stored at rest. Application location describes where the servers handling requests run. Subprocessor location covers the other providers needed for delivery, such as email, payments, edge protection and, when enabled, a platform AI model.
A statement about the first layer does not answer the second or third. That is why a single ‘EU hosted’ badge cannot replace an infrastructure and transfer review.
The current Norvext arrangement
The managed database is configured in the Stockholm project region. The main application deployments are configured in Frankfurt. The provider register also records material global operations: Cloudflare operates a global edge network; Resend uses an Ireland sending region with United States provider operations; Stripe operates a global payment network; and model-provider processing depends on the AI mode in use.
An EU deployment region is an important control, but it is not proof that provider support, security or other processing can never occur elsewhere. We publish both the selected region and the wider provider-operations context.
AI is not one data path
When the built-in assistant uses the platform’s own key, the provider marked ‘in use’ in the Subprocessor Register acts as our subprocessor. If an organization configures its own provider and key, that provider works under the customer’s agreement. If a customer drives Norvext from its own AI client through the API or MCP connector, Norvext does not send the request to a platform model provider.
‘Mixed’ therefore does not mean every record is sent to every provider. It means the transfer analysis must follow the feature actually used, the provider’s role, its operating locations and the safeguard stated in the register.
What to verify
Check which providers are marked ‘in use’ rather than merely approved, what activity and data category each provider supports, the configured service region, any material global operations and the Chapter V safeguard for restricted transfers.
The register is the current public statement. If the architecture changes, it is updated and material new subprocessors follow the notice process in the DPA. A sales slogan should never be treated as a frozen map of a live service.
Read a residency claim in layers
- Database region and data at rest
- Application and request-processing region
- Current subprocessors and the features that use them
- Global provider operations and transfer safeguards
