Skip to main content
MaxInvent

Answer

Is there UK-hosted inventory software, and what does GDPR require?

Last updated By MaxInvent Editorial Team
Short answer

MaxInvent runs its application, databases and uploads in AWS London (eu-west-2). Encrypted disaster-recovery database snapshots are copied to AWS Ireland (eu-west-1), which is inside the EEA and covered by a UK adequacy decision. We do not claim to be 100% UK-only, because connected marketplaces, carriers and accounting providers process data under their own regional arrangements.

  • Primary region: AWS London eu-west-2 — app, databases and uploads
  • DR: encrypted database snapshots copied to AWS Ireland eu-west-1 (EEA)
  • Connected marketplaces and carriers use their own regions — ask them
  • UK GDPR needs a lawful basis and a transfer route, not a UK-only server
  • Ask any vendor for its subprocessor list and the DR region, in writing

Where our data actually sits

WhatWhereNotes
ApplicationAWS London, eu-west-2ECS rolling deployments with automated rollback
DatabasesAWS London, eu-west-2One database per tenant, selected from the sign-in hostname
Uploaded filesAWS London, eu-west-2Documents, labels and imported invoice files
Disaster-recovery snapshotsAWS Ireland, eu-west-1Encrypted database snapshots only, inside the EEA
Connected marketplaces, carriers, accountingTheir own regionsGoverned by their terms, not ours — ask each provider

We do not describe this as “100% UK hosted” or “UK-only”, because the DR copy leaves the UK by design and because any platform that connects Amazon, eBay, TikTok Shop, Temu or a carrier API sends order and address data to that provider. A vendor claiming end-to-end UK-only processing while offering those integrations is describing something that does not exist.

Why the backups are in Ireland

A backup in the same region as the primary is not disaster recovery; it is a second copy of the same risk. Ireland is the nearest AWS region outside the UK, it sits inside the EEA, and the UK has an adequacy decision covering transfers there, so no additional transfer mechanism is needed. The snapshots are encrypted at rest and contain database content only.

The alternative — keeping every copy in eu-west-2 — would let a single regional incident take your operational history with it. We consider that a worse outcome than a documented EEA transfer, and we would rather show you the reasoning than hide the region.

What UK GDPR actually requires

Not a UK server. UK GDPR requires a lawful basis for the processing, appropriate technical and organisational security, and — where personal data leaves the UK — a valid transfer route. Adequacy regulations, the International Data Transfer Agreement and the UK Addendum to the EU standard contractual clauses are all valid routes. “It must stay in the UK” is a procurement preference, and a reasonable one, but it is not the statutory test.

The requirement that does bite is knowing where the data goes. If a vendor cannot name its DR region and list its subprocessors, it cannot help you complete your own record of processing activities, and that is your obligation rather than theirs.

Five questions to ask any vendor

  1. Which region hosts the application and the production database?
  2. Which region holds backups and DR copies, and are they encrypted?
  3. Can I have the current subprocessor list with each entry's location, and the date it was last reviewed?
  4. Who at your company can access my data for support, under what controls, and is that access logged?
  5. How is one customer's data separated from another's — shared schema with a tenant column, or separate databases?

Our answers to all five are on the security page, and the processing detail is in the privacy notice. Question five matters more than people expect: we use a separate database per tenant, selected from the hostname you sign in on, so a query in one tenant's session cannot reach another tenant's records.

Deployment and change control

Releases go out as ECS rolling deployments with automated rollback on failed health checks. We do not call this blue-green, because it is not — there is no second idle environment holding a full copy of production. The practical effect for you is that a bad release is withdrawn automatically rather than manually, and that database migrations are applied as a controlled step rather than as a side effect of a deploy.

If your evaluation includes a data-protection review, see also how to choose inventory software for the operational half of the same decision.

Hosting architecture as reviewed on 23 August 2026. This page describes our arrangements and is not legal advice; consult your own adviser on your UK GDPR obligations.

FAQ

More questions, answered

Where does MaxInvent store our data?+

The application, the tenant databases and uploaded files run in AWS London, region eu-west-2. Encrypted disaster-recovery snapshots of the databases are copied to AWS Ireland, region eu-west-1, so that a London-region incident cannot take the backups with it.

Why not keep the backups in the UK too?+

Because a backup in the same region as the primary is not a disaster-recovery copy, it is a second copy of the same risk. Ireland is the nearest EEA region, it is covered by the UK adequacy decision, and the snapshots are encrypted at rest. We say this plainly rather than advertising UK-only hosting, which would not be true.

Does UK GDPR require a UK server?+

No. It requires a lawful basis for processing, appropriate security, and a valid transfer route for personal data leaving the UK. Adequacy regulations, the International Data Transfer Agreement and the UK Addendum are all valid routes. A UK-only server is a procurement preference, not a statutory requirement.

What about the marketplaces and carriers we connect?+

They process data in their own regions under their own terms, and no inventory vendor can change that. If you connect Amazon, eBay, TikTok Shop, Temu or a carrier API, order and address data flows to that provider. Any vendor claiming end-to-end UK-only processing while offering those integrations is describing something that does not exist.

What should we ask a vendor before signing?+

Four things in writing: the primary region, the backup and DR regions, the current subprocessor list with each one's location, and who can access your data for support. Then ask when that list was last reviewed. A vendor who cannot name the DR region has not thought about the question.

How are tenant boundaries handled?+

Each tenant's operational data lives in its own database, selected from the hostname you sign in on, so one tenant's queries cannot reach another's records. Deployments use ECS rolling releases with automated rollback. We do not describe this as blue-green, because it is not.

Evaluating MaxInvent?

We'll walk through the relevant workflows using suitable representative data for the channels you run.

Chat
MaxInvent
Talk to a real human.
UK-based team · typically reply within one business day.
Prefer a form?Book a demo·Contact form