WHERE IS YOUR DATA · PRIVACY & DATA SECURITY
Where is your data actually stored — and why “in the cloud” is not an answer
Ask a business owner where their customer records are kept and you will almost always get the same reply: “in the cloud”. Ask where in the cloud, and you get silence. That is not carelessness — nobody ever asked them before, and the software vendor never volunteered it. Yet the answer to that question decides what happens the day the vendor disappears, who else can take a look, and what Israeli law expects of you. So let us answer it.
“The cloud” is not a place
The word was chosen precisely so that you would not think about it too hard. It is accurate — there is no server in your cupboard — but it blurs the plain fact behind it: your data is on a physical disk, inside a server, in a hall full of servers, in a building with a street address, in a country with laws. Somebody holds the key to that building, and somebody else holds the key to the disk. In most cases, neither of them is you.
And that is perfectly fine. Most businesses should not run a server and would be worse off if they did — we went into this in our piece on data security for small businesses. The question is not whether your data sits with someone else, but with whom, where, and on what terms. That much you are entitled to know, and it is easy to find out.
The four places your data really lives
1. On a computer at your premises. A spreadsheet, an old accounting package, a folder of scans. The advantage is obvious — you know exactly where it is. The drawback is just as obvious: one disk, no backup anyone has ever tested, in a room people can walk into. The risk here is not a hacker; it is spilled coffee, a burglary, or an employee taking the laptop home.
2. With a software vendor. The booking system, the CRM, the invoicing tool. You pay a subscription and the data sits with the vendor. But almost no vendor of that size owns its own servers — it rents them from Amazon, Google or Microsoft. So there are two layers: the vendor you know, and the cloud provider they chose, in the country they chose. Both layers are written down in the vendor's documents, usually the privacy policy or a list of “sub-processors”. Very few people read it.
3. Inside a big platform. Google Drive, Microsoft 365, WhatsApp. Here the line between “yours” and “theirs” is especially thin: the content is yours, but the location, the terms, what happens when the account is locked and what remains after deletion are not in your hands. A platform is an excellent working channel and a poor choice as the only place a client file exists.
4. In a system built for you. Here, and only here, the location is a choice. Whoever builds your system can place it in any region of any cloud provider — and at least two of the major providers now run a physical region in Israel. That choice is made once, at the start of the project, and anyone who does not ask about it gets the default of whoever did the building.
| Where | Who holds the key | Which country | When the vendor disappears |
|---|---|---|---|
| Computer at your premises | You — and whoever walks into the room | Israel | No vendor; one disk |
| Software vendor | The vendor, and beneath them their cloud provider | Whatever the vendor chose; it is in their documents | A short export window, if any |
| Big platform | The platform | Not decided by you | The platform does not disappear; the account can |
| System built for you | You, in an account in your name | Whatever you chose — Israel included | The system stays; you change the maintainer |
Why the country matters
Not because of speed. A server in Frankfurt or Dublin answers a customer in Tel Aviv fast enough that you will never notice. The country matters for three other reasons.
The law. Israel's privacy regulations allow personal data to be transferred outside the country only on conditions — for example when the receiving country guarantees a level of protection no lower than Israel's, when the person the data is about has consented, or when the recipient has undertaken in writing to meet the conditions of Israeli law. EU member states meet the first condition; other countries need paperwork. And since Amendment 13 to the Privacy Protection Law came into force, not being able to say where your data sits is a bigger problem than it used to be.
Access. The country a server stands in is a country whose authorities can, under certain conditions, demand access to it. For most businesses this is theoretical. For lawyers, therapists and anyone holding medical information, it is a consideration that should be said out loud rather than discovered afterwards.
Someone to call. When something goes wrong — a breach, a deletion, a dispute with a vendor — you want someone you can reach in your own language and a court you recognise. An Israeli vendor hosting abroad is still someone to call. A foreign vendor hosting abroad, less so.
Three questions every vendor must answer
You need no technical advice to ask them, and the answers should already be in the vendor's documents. If they are not there — that is an answer in itself.
Where, exactly. Which cloud provider and which country. “In the cloud” and “on secure servers” are not answers. “With Amazon, in the Ireland region” is.
Who else. The list of sub-processors: who sends the emails, who runs the backups, who provides support and sees screens. Each one is another pair of hands on your data, and each one belongs on the list. The duty to register the database itself is covered in our article on database registration.
How you leave. Whether everything can be exported — not merely viewed — in a format other software can read; how long the data is kept after the contract ends; and what is deleted, when, and how deletion is proved. A vendor who makes leaving hard at signing time will make it many times harder at parting time.
A backup in the same place is not a backup
“We have a backup” is the second sentence business owners say with confidence. Then it turns out the backup lives on the same disk, or in the same account, or with the same vendor — so whatever wipes the original wipes the backup too. A real backup meets three plain conditions: it is somewhere else, it happens without anyone having to remember, and someone has restored a file from it at least once and checked that it opens.
The third condition is the one that almost always fails. A backup that has never been restored is a hope, not a backup. In a system built for you, this is exactly one of the clauses that belongs in the maintenance agreement — we listed them in our article on what it costs to run a website or an app.
How to find out where your data is today
Twenty minutes and one sheet of paper. For each kind of data in the business — customers, invoices, correspondence, files, the diary — write four columns: which software it sits in, who the vendor is, which country the server is in according to their documents, and who in your business holds the password. The list almost always turns up the same two findings: data that sits in exactly one place with no backup, and data that sits in five places with nobody sure which version is right.
Those two findings are the starting point of every system that is built properly. Not a feature list, not a design — first where the data is, and only then what to do with it. That is the order we work in, and you can see the kind of result it produces on our client work page. It is also why the answer to “where is your data stored” should be a single sentence you can say from memory.
How we work with this. A system we build sits in a cloud account in the client's name, not ours, in a region chosen together at the start of the project — and, absent a reason otherwise, in Israel. Full export in an open format is part of the system from day one, not a request to be submitted. And if tomorrow you prefer another maintainer, the system stays with you and the keys go to them. That is how it is supposed to work, and it should not cost extra.
Done the twenty-minute list and not sure what to do with what you found? Send it to us — we will tell you what is urgent, what can wait, and what does not need us at all.
Frequently asked questions
What actually is “the cloud”?
The cloud is somebody else's computer. More precisely: a hall full of servers in a particular building in a particular country, run and rented out by a company such as Amazon, Google or Microsoft. When a software vendor says your data is “in the cloud”, they usually mean they rent a server from one of those companies. The word is accurate, but it does not answer the question that matters — which country the server stands in, and who holds the key.
Is an Israeli business allowed to keep customer data on a server abroad?
Yes, on conditions. Israel's privacy regulations allow personal data to be transferred outside the country only when one of several conditions is met — for example when the receiving country guarantees a level of protection no lower than Israel's, when the person the data is about has consented, or when the recipient has undertaken in writing to meet the conditions of Israeli law. Most large vendors have a document that covers this, but it is on you to check that it exists and that it refers to Israel.
My data is in Google Drive or WhatsApp — is it mine?
The content is yours; the control, less so. You can download the files and export the chats, but you do not decide where they are stored, what happens when the account is locked, or what the platform keeps after you delete. For a business that means a platform is fine as a working channel and a poor choice as the only place a client file lives. Whatever matters should also sit somewhere you control.
What happens to my data if the software vendor shuts down?
It depends on what you agreed in advance. A vendor that closes in an orderly way usually gives a window of a few weeks to export, then deletes. A vendor that simply vanishes gives you nothing. Hence three questions before signing: can everything be exported in an open format rather than only viewed, how long is data kept after the contract ends, and what is deleted and when. The fourth question is for yourself: when did you last actually export and check that the file opens?
How do I find out where my data is today?
Make a twenty-minute list. For each kind of data — customers, invoices, correspondence, files — write down which software it sits in, who the vendor is, which country the server is in according to the vendor's documents, and who in your business holds the password. In most businesses the list reveals two things: data that sits in exactly one place with no backup, and data that sits in five places with nobody sure which version is right. Those two findings are worth more than any consultant.
Sources
- Israeli Privacy Protection Authority — privacy protection regulations — the regulations that apply to anyone holding a database of personal data, including the security duties and the conditions for transferring data outside Israel.
- European Commission — adequacy decisions — the official list of countries whose level of personal-data protection the EU recognises, Israel among them.
- AWS — regions and availability zones — Amazon's map of physical regions, including the one in Israel; where you check where a server really stands.
- Google Cloud — locations — Google's equivalent map, with its Israel region.
Not sure where your data sits?
Send us the twenty-minute list — or just the part you managed to fill in. We will tell you what is urgent, what can wait, and if a system is needed you get a clear direction and a quote fixed in advance. First consultation free.
Email us