Knowledge base / regulation10.com product guide (EU AI Act)
Where your records are stored, and where a prompt is processed
Two different questions get asked as one here, and they have different answers. Where is your data held, and where is a prompt processed when the assistant answers you? This article answers both, in that order, and states the limits of each answer.
Storage. Your workspace records reside in Azure's Sweden Central region, inside the EU data boundary. That covers the system register, module runs, generated artefacts, the sealed evidence store and the audit trail. Records are encrypted in transit and at rest. A workspace's residency region is set when the workspace is created and stays as set for the life of the workspace, which is why it is the one onboarding choice worth pausing over.
Processing is a separate matter, and it is where loose wording usually creeps in. Model work on this lane routes to an Azure OpenAI deployment in Sweden Central. That deployment is provisioned on Microsoft's DataZoneStandard type. Microsoft documents DataZoneStandard as processing within the data zone, and the data zone here is the EU one: a set of EU and EEA regions, wider than any single region. So the accurate statement is that processing is bounded to the EU data zone. It is not a statement that every request is processed in Sweden Central specifically, and this article does not make that stronger claim.
Inference processes text in flight. No prompt content and no response content is retained at the inference endpoint. The record that is kept, the audit row, is written to your workspace's own region.
Why state it this carefully. A compliance platform that overstates its own residency posture has already failed the standard it sells. An absolute claim about egress is falsified the moment a processing lane is added, and an enumerated list of exceptions is falsified the same way. So the claim made here is the narrow one that stays true: records at rest in Sweden Central, processing bounded by its actual deployment type, and nothing asserted beyond what Microsoft's own documentation supports.
What this means in practice for a transfer assessment. The relevant fact for most reviewers is the deployment type, because that is what bounds the processing geography, and the relevant fact for storage is the region. Those two facts are stated above and the team will confirm them in writing, together with the current subprocessor list, on request. The platform does not assert an adequacy finding for any third country on your behalf; that determination belongs to your own assessment.