Baseline · not an upsell

EU-isolated, single-tenant, NDA-bound.
That's the starting line — not the goal.

Before you sign the €8K+/month engagement, here's exactly where your data sits, who sees it, and what the contract says. Frame this as the operating standard — not the reason it's premium.

Apply — €8K+/month → Read the four pillars

Where your data lives, who signs what, and what the contract covers.

01

Data residency

EU-resident at all times. Your primary database sits in an EU region; there is no replication to US-region zones outside explicit contractual data flows.

02

Single-tenant infrastructure

Dedicated runtime, separate from any other client's queue, memory, or scheduled actions. No shared multi-tenant pools for your data, drafts, or jobs.

03

NDA template

Mutual NDA from the first keystroke. Signed before access is provisioned. Bound to your company's legal entity — not a blanket SaaS click-through.

04

GDPR Article 28 DPA

Data Processing Agreement provided as part of onboarding. Processor obligations explicit; sub-processor list available on request; DPO contact reachable.

Shared-tenant SaaS under EU residency requirements.

Most multi-tenant SaaS platforms weren't built for EU-residency-first engagements. The cheapest tier routes through US-region infrastructure by default. The EU-isolated tier is sold as premium. KlicaOS treats the EU-isolated configuration as the baseline.

Shared-tenant incumbents
KlicaOS Private Office
Data residency
Default US-hosted; EU region option requires a contract addendum at higher tier.
EU-isolated by default — primary database and compute in EU regions.
Tenant isolation
Multi-tenant pools for queues, memory, and storage; isolation by namespace, not physical.
Single-tenant runtime; dedicated queue, memory, and storage per engagement.
NDA availability
Standard click-through online terms; bespoke NDA requires legal review and procurement.
Mutual NDA template provided pre-engagement; bound to legal entity before access.
Sub-processor transparency
Sub-processor list published generically; updates via terms-of-service amendments.
Sub-processor list disclosed on request per client; DPO contact reachable for changes.
Regulator audit posture
Audit cooperation routed through support tickets; lag measured in weeks.
Direct DPO escalation path; audit cooperation handled within the engagement team.

Common questions before you sign.

Direct answers about residency, NDA scope, the Article 28 DPA, and what happens when a regulator asks. For pricing and engagement structure, see the Private Office FAQ.

Which region does my data live in?
EU-resident. The primary database, the compute layer, and the queue infrastructure all sit in EU regions. There is no replication to non-EU zones outside of explicit contractual data flows that we document in the Article 28 DPA. Apply →
Who signs the mutual NDA, and when?
The NDA is signed before any access is provisioned — including the intake interview itself. It is bound to your company's legal entity, not to a blanket SaaS click-through that leaves your specific data flows uncovered. Apply →
What does the Article 28 DPA cover?
It sets out processor obligations, the categories of data processed, the lawful sub-processors in scope, the security measures, the breach-notification window, and the audit rights your data controller retains. The template is provided at onboarding and adapted to your entity. See the Private Office FAQ →
How are sub-processors disclosed?
The full sub-processor list is provided as part of the Article 28 DPA. Changes to that list are disclosed before they take effect, with a defined notice window your DPO can act on. We do not amend the list via generic terms-of-service updates.
What happens when an EU regulator asks for an audit?
Your DPO contacts ours directly through a documented escalation path — not a generic support ticket. Audit requests are handled by the engagement team within the contracted response window, and the relevant processor-side logs are produced under the Article 28 DPA's audit clause.
Does the EU posture survive a US subpoena?
Your data sits in EU regions under EU jurisdiction. We do not exfiltrate EU-resident data to US-region systems, and we contractually notify you of any lawful-access request that touches your tenant. The single-tenant configuration means there is no neighboring tenant data in scope. Apply →
04 — Apply

The €8,000+/month engagement starts here.

EU-isolated, single-tenant, NDA-bound, and covered by an Article 28 DPA from the first keystroke. The trust baseline isn’t a premium on this tier — it’s the starting line.

Apply — €8,000+/month