Skip to content

Get straight answers on CRM data residency in Australia

Australian buyers usually ask two things of a CRM vendor: where the data is stored, and whether the law requires it to be here. This page answers both honestly. HelloGrowthCRM is built by Soor LLC, and where we can state a fact about the platform we do. Where the answer depends on your account, hosting region being the main one, we say so and tell you to get it confirmed in writing. Written for procurement and privacy reviewers, and not legal advice.

What Australian law actually requires about location

There is no general rule in Australian federal privacy law that personal information must be stored in Australia. The Privacy Act 1988 and the Australian Privacy Principles regulate how personal information is handled, not where the servers sit. Buyers often start a CRM evaluation assuming an onshore mandate exists, then find the real obligations are about accountability, security and disclosure. Narrower residency rules do exist in specific places, including the My Health Records framework, some government procurement arrangements that rely on hosting certification, and state-level health and justice requirements. The answer depends on who you are and what data you hold.

What applies to almost every commercial buyer is APP 8 on cross-border disclosure, APP 11 on security, and the Notifiable Data Breaches scheme. Together they mean you stay responsible for personal information you send offshore, you must protect it with reasonable steps, and you must assess and report qualifying breaches to the OAIC and to affected individuals. Penalties for serious or repeated interference with privacy have risen substantially, and further reform of the Privacy Act has been progressing in stages. A control framework built to today's bare minimum tends to age badly and gets re-examined at the worst moment.

So the practical goal is not to find a vendor with an Australian flag on its pricing page. It is to know where the data goes, to hold contract terms that survive scrutiny, and to be able to show your working when a regulator or a large enterprise customer asks. That is a documentation exercise as much as a technical one, and it is far cheaper to complete during evaluation than to reconstruct two years into a contract with a tender deadline running. Ask the questions while you still have the leverage of an unsigned order form, because vendors answer more precisely before the deal closes.

APP 8, section 16C and the use-versus-disclosure question

APP 8 requires an entity to take steps that are reasonable in the circumstances to ensure an overseas recipient does not breach the APPs, before disclosing personal information to that recipient. In practice, reasonable steps usually means enforceable contract terms covering handling, subcontracting, complaint processes and breach notification. The expected effort scales with the sensitivity of the information and the risk involved, and cost or inconvenience alone is not accepted as a reason to skip it. Exceptions exist, including where the recipient is subject to a substantially similar law with an accessible enforcement mechanism, or where the individual gives informed consent.

Section 16C is the part procurement teams should read closely. If an overseas recipient does something that would breach the APPs, that act is treated as having been done by the Australian entity. Taking reasonable steps does not move the liability across. This is why contract quality matters more than a badge on a vendor website. Your agreement should state what the vendor may do with the data, bind subprocessors to equivalent terms, require assistance with access and correction requests, and set breach notification timing that leaves you room to meet your own obligations.

There is also a long-standing distinction between use and disclosure for cloud services. OAIC guidance accepts that giving personal information to an overseas cloud provider may be a use rather than a disclosure where a binding contract limits the provider to handling the data for your purposes, binds its subcontractors equally, and leaves you in effective control, able to access, retrieve, correct and require deletion. If that is your arrangement, APP 8 disclosure duties may not be triggered. You still hold the information, and every other APP, including APP 11, continues to apply in full.

APP 11 security and notifiable data breaches

APP 11 requires reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed. What counts as reasonable depends on the volume and sensitivity of the information and the harm that would follow a compromise. A CRM holding thousands of named contacts, mobile numbers, deal notes and email history sits squarely in the range where encryption, access control, logging and a defined deletion path are expected rather than treated as optional extras.

HelloGrowthCRM protects data in transit with TLS and encrypts data at rest. Customer data sits in Supabase-managed Postgres on AWS, with row-level security enforcing tenant isolation. Role-based access control governs which of your users can see which records. Production access on our side is least-privilege, multi-factor gated, logged and reviewed periodically. Automated backups run with point-in-time recovery. Soor LLC completed a SOC 2 Type II examination covering a February to June 2025 observation window, and the report is available under NDA from sales@hellogrowthcrm.com. We make no claim to ISO 27001 or PCI DSS.

Under the Notifiable Data Breaches scheme, an eligible data breach, meaning unauthorised access, disclosure or loss likely to result in serious harm, must be assessed promptly and notified to the OAIC and to affected individuals. If a vendor is slow to tell you, your own assessment window is already consuming itself. Soor LLC maintains a documented incident-response workflow that includes customer notification, and publishes a vulnerability disclosure process at /legal/vulnerability-disclosure so researchers have a defined route to report problems rather than posting them publicly. Check that your contract with any vendor sets notification timing you can actually work with, not timing that consumes your entire assessment window before you hear anything.

Hosting, region and what to confirm at onboarding

HelloGrowthCRM runs on Supabase-managed Postgres hosted on AWS. The region that applies to a given account is confirmed during onboarding or a security review rather than assumed from a marketing page. If Australian hosting is a requirement for your organisation, because of a government contract, a health-sector rule, an internal policy or a commitment you made to your own customers, raise it before you sign. Ask us to confirm in writing which region your account will use and whether the region you need is available for your deployment, then keep that confirmation with your assessment.

Do not treat an Australian sales presence, a local phone number or an .au domain as evidence of local hosting, from us or from any vendor. Ask the same question of every shortlisted supplier and ask it precisely. Which region holds the primary database? Where do backups and read replicas live? From where does support access customer data? Are logs, product analytics, email content and file attachments in the same region as the database, or somewhere else? Which subprocessors touch the data and where do they operate? Our subprocessor list at /subprocessors answers the last one publicly.

If offshore processing turns out to be acceptable for your use case, which it often is, document why. Record the reasonable steps you took, the contract terms you relied on, whether you treated the arrangement as a use or a disclosure, and who signed it off. An assessment written at purchase time takes an afternoon. The same assessment reconstructed under pressure during a tender response or a regulator enquiry takes far longer and reads as considerably weaker. A Data Processing Agreement is available from us to sit behind that record.

A procurement checklist that works for any CRM

Start with documents. Ask for the data processing agreement, the subprocessor list, the security overview and the most recent independent assurance report. For Soor LLC that is a SOC 2 Type II report covering a February to June 2025 observation window, available under NDA. Read the scope section rather than the cover page, because the value of a report lies in which systems and criteria it covers and which exceptions were noted. If a vendor offers only a completed self-assessment questionnaire and nothing independent, that is an answer in itself.

Then test the operational claims in a trial account rather than in a sales call. Can an administrator export all account data without vendor help? Ours can, at any time. Can you delete a contact and have it stay deleted, understanding that backups hold data for a recovery window? Can you restrict a user to a subset of records through roles? Is there a documented process for data rights requests, and is it published? Ours is at /legal/data-rights. Answers you can verify yourself are worth considerably more than answers you are given.

Finally, watch how a vendor behaves when it does not have a good answer. Precise statements about what is and is not offered are a better signal than an unbroken run of yes responses. We do not hold ISO 27001 certification. We do not hold PCI DSS certification. We do not publish uptime figures on this page. The hosting region for your account is confirmed with you directly rather than promised in advertising. If those answers rule us out for a particular tender, it is better to establish that during evaluation than after migration.

Controls and capabilities at a glance

  • Data is protected with TLS in transit and encrypted at rest, supporting the reasonable steps expected under Australian Privacy Principle 11.
  • Customer data sits in Supabase-managed Postgres on AWS, with row-level security enforcing tenant isolation between separate accounts.
  • The hosting region for your account is confirmed during onboarding or a security review; ask for it in writing before you sign anything.
  • Role-based access control lets you limit which users see which contacts, deals and notes, so access matches actual business need.
  • Production access at Soor LLC is least-privilege, multi-factor gated, logged and reviewed periodically rather than permanently granted.
  • Soor LLC completed a SOC 2 Type II examination covering a February to June 2025 observation window, available under NDA on request.
  • A published subprocessor list at /subprocessors and an available Data Processing Agreement support your APP 8 reasonable steps record.
  • Administrators can export account data at any time, which supports access requests, tender evidence and a clean exit from the platform.
  • Automated backups with point-in-time recovery allow restoration to a chosen moment, supporting availability and integrity commitments.
  • A documented incident-response workflow includes customer notification, so your Notifiable Data Breaches assessment can begin promptly.

Questions reviewers ask

Does Australian law require CRM data to be stored in Australia?
Not as a general rule. The Privacy Act 1988 and the Australian Privacy Principles govern how personal information is handled rather than where it is stored. Specific residency requirements do exist in narrower contexts, including the My Health Records framework, certain government procurement arrangements and some state health and justice rules. The honest answer is that it depends on your sector and your contracts. If a residency obligation applies to you, treat it as a hard requirement and confirm it before signing.
Is an Australian hosting region available for my account?
The hosting region that applies to a given account is confirmed during onboarding or a security review, so ask us directly and get the answer in writing before you commit. We will not assert a region on a marketing page that we have not confirmed for your deployment. If a specific region is a hard requirement for your organisation, raise it at the start of the evaluation so it can be resolved while you still have alternatives rather than after migration has begun.
What does APP 8 mean for using an overseas CRM?
Before disclosing personal information to an overseas recipient, you must take steps that are reasonable in the circumstances to ensure they do not breach the APPs, which usually means enforceable contract terms covering handling, subcontracting, complaints and breach notification. Section 16C then treats an overseas recipient's breach as your breach, so the liability stays with you. That is why the data processing agreement, rather than the vendor's marketing material, is the document your privacy team should be reading closely.
Is sending data to a cloud provider a use or a disclosure?
OAIC guidance accepts that providing personal information to an overseas cloud provider may be a use rather than a disclosure where a binding contract limits the provider to handling the data for your purposes, binds subcontractors equally, and leaves you in effective control, including the ability to access, retrieve, correct and require deletion. If that describes your arrangement, APP 8 disclosure obligations may not apply. You still hold the information, and APP 11 and the other principles continue to apply.
Do you hold ISO 27001 or an IRAP assessment?
We do not hold ISO 27001 certification, we do not hold PCI DSS certification, and we do not hold an IRAP assessment. What Soor LLC does hold is a completed SOC 2 Type II examination covering a February to June 2025 observation window, with the report available under NDA from sales@hellogrowthcrm.com. If your tender requires a certification we do not have, that is a genuine constraint, and we would rather you know it during evaluation than discover it at contract review.
How would we hear about a data breach?
Soor LLC maintains a documented incident-response workflow covering detection, containment, remediation and customer notification. Because the Notifiable Data Breaches scheme requires you to assess an eligible breach promptly and notify the OAIC and affected individuals, decide internally who receives our notification and what they do in the first hour. Also check that your data processing agreement sets notification timing that leaves you room to complete your own assessment rather than consuming all of it.
Can we get all our data out if we leave?
Yes. Administrators can export account data at any time without raising a support request, so an exit does not depend on vendor goodwill or a professional services quote. Deletion requests are honoured and the documented process is at /legal/data-rights. Bear in mind that automated backups with point-in-time recovery mean deleted data persists for a recovery window before ageing out, which is normal for managed databases and worth reflecting in your own retention documentation.
What should we ask every CRM vendor about residency?
Ask which region holds the primary database, where backups and replicas sit, from where support staff access customer data, whether logs, analytics, email content and attachments live in the same region as the database, and which subprocessors are involved and where they operate. Then ask for those answers in writing. Vendors that answer precisely, including where the answer is no, are usually easier to work with than vendors who answer yes to everything.

Confirm the details before you shortlist

Ask sales@hellogrowthcrm.com for written confirmation of the hosting region for your account, the Data Processing Agreement and the SOC 2 Type II report under NDA. The subprocessor list is at /subprocessors, data rights are at /legal/data-rights, and security issues can be reported at /legal/vulnerability-disclosure. Bring your privacy team's questions to the security review.