Data Hosting & Sovereignty
Our Commitment
All client data across every Agend product is hosted and stored within Australia. This is a standing policy, not a per-client option, and is committed to contractually in our Data Processing Agreement (DPA).
Agend Pro (WordPress)
Agend Pro is hosted on Kinsta, running on Google Cloud Platform infrastructure. Client data — including backups — is stored in Australian data centres (Sydney/Melbourne). See Agend Pro Security Framework for hosting-environment detail.
Agend Product Suite
Agend Product Suite's database, authentication, and file storage run on Supabase, hosted in AWS Asia Pacific (Sydney). Application hosting (Vercel) and error/anomaly monitoring (Sentry) are also confirmed Australia-region. See Platform Security for architecture detail.
Email delivery residency is enforced at the infrastructure level: non-AU-capable email providers are not permitted for customer accounts, and Australia-capable providers are used for all transactional email.
Backup & Recovery
| Retention | Recovery Point Objective (RPO) | Recovery Time Objective (RTO) | |
|---|---|---|---|
| Agend Pro | 30-day rolling backups | Daily | ~3 hours (business hours) |
| Agend Product Suite | 30-day rolling backups | 24 hours | 8 business hours |
Availability
Agend Product Suite targets 99.9% monthly availability, with service credits available under our service level agreement if this is not met.
Data Export & Deletion
On termination or expiry of services, data is made available for export before deletion. Personal data is deleted or de-identified within 90 days. Financial records (e.g. invoices) are retained for 7 years in line with Australian tax obligations. Overseas disclosure of data occurs only as necessary to provide the service and only via providers disclosed in our sub-processor list below — consistent with Australian Privacy Principle 8 (APP 8).
Sub-processors
The table below lists the third parties who may process Agend Product Suite customer data on our behalf, current as of July 2026.
Core (all customers)
| Sub-processor | Purpose | Region | Certifications |
|---|---|---|---|
| Supabase | Database, authentication, file storage | AWS Asia Pacific (Sydney), Australia | SOC 2 Type II, ISO 27001 |
| Vercel | Application hosting | Australia | SOC 2 Type II |
| Sentry | Error & anomaly monitoring | Australia | SOC 2 |
| Cloudflare | Bot/CAPTCHA protection (Turnstile) | Global | SOC 2, ISO 27001 |
Payments (customers taking payments)
| Sub-processor | Purpose | Certifications |
|---|---|---|
| Stripe | Payment processing | PCI DSS Level 1, SOC 2 |
| eWay (Global Payments) | Payment processing | PCI DSS Level 1 |
| Xero | Accounting reconciliation | ISO 27001, SOC 2 |
Feature-dependent
| Sub-processor | Purpose | Status |
|---|---|---|
| SMTP2GO | Transactional email (Australian sub-accounts) | Active |
| Mailchimp | Email marketing (when connected by customer) | Active when connected |
| Inngest | Background job orchestration | Active |
Note
We do not currently use AI models (e.g. from Google or Anthropic) to process customer data in production. Should this change, the sub-processor list will be updated in advance, consistent with the notice and objection rights in our DPA. Customer-initiated integrations you configure yourself (e.g. syncing to your own WordPress site) move data to and from systems you control, and are not Agend sub-processors.
Questions about data hosting, sovereignty, or sub-processors can be directed to security@agend.com.au.