Regional hosting
Formspring runs in one region: the EU. Application servers, the primary database, background workers, object storage for uploaded files, and backups are all EU-resident. This is the same for every team, on every plan, and it is not a setting.
There is no US region, no per-project region picker, and no plan tier that unlocks a different location. If you have read otherwise anywhere in this documentation, this page is the correct version.
What runs where
| Component | Location |
|---|---|
| Application servers | EU data centre, Falkenstein (Germany) |
| Primary database | EU data centre, same location as the application |
| Object storage (file uploads) | EU object storage, Falkenstein (Germany) |
| Background workers | EU data centre, same location as the database |
| Backups | EU data centre, same location as the database, encrypted |
| Content delivery network | Global, marketing pages only - never submission traffic |
Submissions, uploaded files, and submission metadata do not leave the EU in the normal course of processing.
The data that does travel
Some third parties process a narrow slice of data outside the EU. This is the complete list, and each one is a sub-processor with its own agreement:
- Payment processing for your own subscription billing. Required to take a card. Submission data is never sent.
- Transactional email delivery, which carries the notification or autoresponder message itself.
- Spam classification, only when you have enabled it on the form, and only for the fields that have not been marked as personal data.
- Human-verification challenges, only on forms where you have switched a challenge on. The submission payload is not sent.
- Optional AI features, only on plans that include them and only on forms where you have switched the specific feature on.
Every one of these is opt-in except payment processing and transactional email, both of which are required to run the service at all. The vendor names, purposes, and countries are in the sub-processors disclosure, which is the authoritative list.
Confirming where your data is
Each project page shows the residency statement under Project → Settings → Data region:
Project -> Settings -> Data region: EU - Falkenstein, Germany
It reads the same on every project because there is only one answer. When project metadata is exported or inspected by support, the stored machine-readable key is eu-falkenstein.
Projects created before September 2026
Between May 2026 and September 2026 the project settings panel offered a second option labelled "US - Ashburn, Virginia". That picker recorded a preference and nothing else: no code path ever read it to choose a database, a disk, a queue, or a backup target, and no customer data was ever stored outside the EU as a result of selecting it.
If you selected it, your project's data has been EU-resident the entire time, exactly like every other project. The picker has been removed, the stored value is normalised to the EU key the next time the project is saved, and the project page now reports the EU location it always had. If you chose that option because you needed US residency, the honest answer is that we never provided it - please write to info@pixelandprocess.de so we can work out what you need.
Can I pin a specific country or data centre?
No. There is a single EU location and no mechanism to select a different one. We would rather say that plainly than offer a control that does not reach the storage layer.
If a contract requires residency in a specific EU country, write to info@pixelandprocess.de before you sign it so we can tell you honestly whether we can meet it.
Cross-region replication
There is none, because there is no second region to replicate to. Backups stay in the EU with the data they were taken from.
What's next
- Sub-processors → - third parties and where they operate
- GDPR → - the formal compliance posture
- Encryption → - what's encrypted in transit and at rest
- Data retention → - how long things stick around