Where is customer data stored in cloud customer service solutions?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

When you move to a cloud customer service solution, one of the first questions that comes up is: where does all that customer data actually go? It’s a fair question, because you’re dealing with customer personal data, call recordings, chat history and potentially sensitive case information. With cloud solutions for customer contact, transparency about data storage is not a luxury, but a necessity. In this article, we explain where customer data is stored in cloud solutions, what rules apply and how you as an organization keep control of your data.

Where exactly is customer data stored in cloud customer service?

With a cloud customer service solution, customer data is stored on servers managed by the cloud provider. Those servers are physically located somewhere in a data center, and the location of that data center determines which laws apply to your data. That sounds technical, but it directly impacts your privacy obligations.

In practice, there are three variants:

  • Storage in the Netherlands: Data is on Dutch servers, under Dutch and European law. This offers the most control and compliance assurance.
  • Storage in the EU: Data is in an EU member state, which means the AVG applies. This is allowed in principle, but always check in which country exactly.
  • Storage outside the EU: This is the riskiest situation. Consider servers in the United States or Asia, where different privacy laws apply and access by foreign governments is possible.

Cloud vendors often use multiple data centers simultaneously, including for redundancy and backups. So it is possible that your customer data is in multiple locations simultaneously, even if the primary storage is in the Netherlands or the EU. Always ask about this explicitly.

What are the AVG rules for customer data in cloud solutions?

The General Data Protection Regulation (AVG) sets clear requirements for how organizations handle customer personal data. This also applies if you store that data in a cloud solution. As a data controller, you as an organization are responsible for compliance, even if the actual storage is with an external provider.

The main AVG obligations in cloud storage are:

  • You must enter into a processing agreement with your cloud provider. In this you lay down what the supplier is allowed to do with your data.
  • Data should be stored only as long as necessary for the purpose for which it was collected.
  • Customers have the right to access, correct and delete their data. Your cloud solution should technically enable this.
  • In the event of a data breach, you are required to report it to the Personal Data Authority within 72 hours.
  • Transfer of data outside the EU is allowed only under strict conditions, such as an adequacy decision or standard contract clauses (SCCs).

Many organizations think the cloud vendor takes over this responsibility. This is a misconception. The vendor is a processor; you remain responsible.

What is the difference between storage in the Netherlands, the EU and outside the EU?

The location of data storage has practical and legal implications. Here is a concrete explanation of the distinction:

Storage in the Netherlands offers the most security. Dutch legislation is fully in line with the AVG, and you know exactly which agencies may request access. Moreover, latency is low, which benefits the performance of your customer service platform. For organizations in sectors such as government, healthcare or education, Dutch storage is often a requirement.

Storage in the EU is also acceptable in most cases. The AVG applies in all EU member states. Do note that some EU countries have parent companies outside the EU, which may pose indirect risks. Always check your supplier’s corporate structure.

Storage outside the EU carries the most risk. For example, the U.S. CLOUD Act allows U.S. authorities to request access to data managed by U.S. companies, even if that data is physically located in Europe. This can conflict with the AVG. If you want to avoid this, choose a vendor with a fully European or Dutch infrastructure.

How do you know if a cloud provider is managing customer data securely?

Certifications are a reliable indicator of how serious a vendor is about information security and data quality. In your assessment, pay attention to the following points:

  • ISO 27001 is the international standard for information security. This is the most relevant certification when it comes to data storage and security. A supplier with ISO 27001 has demonstrably established processes to secure information.
  • ISO 9001 says something about the quality of processes and services in general.
  • ISO 26000 focuses on corporate social responsibility.
  • Question about penetration tests and audits: are they performed regularly by independent parties?
  • Verify that the vendor has a clear incident response process for data breaches.

In addition to certifications, transparency is an important signal. A reliable vendor is open about where data resides, who has access to it and how backups are managed. If a vendor remains vague on these questions, it is a warning signal.

What questions should you ask a cloud customer service provider?

Before implementing a customer service cloud solution, it is wise to have a structured conversation about data and security. At a minimum, ask the following questions:

  1. In which country or countries is our customer data stored?
  2. Are backups also stored in the same region?
  3. What information security certifications does your organization have?
  4. How is the processor agreement set up and what are our rights in it?
  5. Who in your organization has access to our customer data?
  6. How is data deleted if we end the partnership?
  7. What is your procedure in the event of a data breach and how are we informed?
  8. Does your platform use AI models trained on customer data?

The latter question is increasingly relevant as AI plays a larger role in customer service platforms. Some vendors are using customer interactions to improve their AI models. This can have implications for your customers’ privacy if not transparently managed.

How do you protect customer data when moving to a cloud solution?

A migration to a cloud solution is a critical time for data security. With the right preparation, you significantly reduce the risks:

  • Before you begin, map your current data streams. What customer data is stored where and processed by whom?
  • Draft a processor agreement before the migration starts, not after.
  • Delete unnecessary data prior to migration. This is a good time to sanitize data you no longer need.
  • Test the security of the new environment before going live with real customer data.
  • Inform employees about the new way of working and its privacy rules.
  • Document everything: what data is where, who has access and on what basis is data being processed.

A switch is also an opportunity to improve processes. Organizations that centralize customer contact in a single platform typically have better visibility into their data flows than those working with multiple separate systems.

How Pegamento helps with secure cloud storage for customer service

We understand that questions about data storage, AVG compliance and security are barriers for many organizations when moving to a cloud solution. That’s why we build our solutions on a foundation of transparency and security.

  • Dutch infrastructure: Our own cloud infrastructure runs entirely on Dutch servers, so customer data stays within the Netherlands and is processed in full AVG compliance.
  • ISO 27001 certified: Information security is not an afterthought with us. In addition to ISO 27001, we are also ISO 9001 and ISO 26000 certified.
  • Privacy-first AI: Our AI applications, including the Expert Engine, do not use public AI models and process data only within their own secure environment.
  • Everything under one roof: From telephony via our Phone System to omnichannel customer contact, we are a single point of contact for your entire technology stack. No complex supplier structures, no ambiguity about who is responsible for what data.
  • Processor agreement and guidance: We help you properly set up the legal and organizational side of the migration, not just the technology.

Want to know how your organization can securely store and manage customer data in a modern cloud solution? Contact us and we will be happy to work with you on an approach that fits your situation and industry.

Frequently Asked Questions

Wat moet ik doen als mijn huidige cloudleverancier data buiten de EU opslaat?

Controleer eerst je bestaande verwerkersovereenkomst om te zien of er aanvullende mechanismen zijn vastgelegd, zoals standaardcontractbepalingen (SCC’s) of een adequaatheidsbesluit van de Europese Commissie. Als die ontbreken, ben je mogelijk niet AVG-compliant en loop je risico op boetes van de Autoriteit Persoonsgegevens. Het verstandigste is om op korte termijn contact op te nemen met je leverancier en te onderzoeken of er een Europese opslagoptie beschikbaar is — of te overwegen over te stappen naar een leverancier met een volledig Europese of Nederlandse infrastructuur.

Hoe lang mag klantdata in een cloudoplossing voor klantenservice worden bewaard?

Onder de AVG geldt het principe van opslagbeperking: data mag niet langer worden bewaard dan noodzakelijk voor het doel waarvoor het is verzameld. Voor klantenservice betekent dit in de praktijk dat je per datatype een bewaartermijn vaststelt — bijvoorbeeld 6 maanden voor chathistorie en 1 jaar voor gespreksopnames — en dat je cloudoplossing automatische verwijdering of archivering ondersteunt. Leg deze bewaartermijnen schriftelijk vast in je privacybeleid en verwerkersovereenkomst, zodat je altijd kunt aantonen dat je je hier actief aan houdt.

Mogen medewerkers van de cloudleverancier toegang hebben tot onze klantdata?

In principe zo min mogelijk: een betrouwbare leverancier hanteert het ‘need-to-know’-principe, waarbij alleen medewerkers met een aantoonbare functionele reden toegang hebben tot klantdata. Vraag de leverancier expliciet wie er toegang heeft, op welke basis en of die toegang wordt gelogd en gecontroleerd. Dit moet ook worden vastgelegd in de verwerkersovereenkomst, inclusief een geheimhoudingsplicht voor betrokken medewerkers van de leverancier.

Wat gebeurt er met onze klantdata als we besluiten van cloudleverancier te wisselen?

Dit is een cruciaal punt dat je vóór contractondertekening moet regelen. Zorg dat de verwerkersovereenkomst een expliciete exitprocedure bevat: binnen welke termijn wordt data teruggegeven, in welk formaat, en wanneer wordt alle data definitief en aantoonbaar verwijderd van de servers van de leverancier — inclusief back-ups. Leveranciers die hier vaag over zijn of geen gestructureerde data-export aanbieden, creëren een ongewenste afhankelijkheid die je onderhandelingspositie bij een overstap sterk verzwakt.

Is een verwerkersovereenkomst verplicht, ook als de cloudleverancier al een standaard privacybeleid heeft?

Ja, een verwerkersovereenkomst is wettelijk verplicht op grond van artikel 28 van de AVG en vervangt niet het algemene privacybeleid van de leverancier. Een privacybeleid is een publiek document dat beschrijft hoe een leverancier omgaat met data in het algemeen; een verwerkersovereenkomst is een bindend contract tussen jou als verwerkingsverantwoordelijke en de leverancier als verwerker, specifiek voor jóuw klantdata. Zonder een geldige verwerkersovereenkomst ben jij als organisatie in overtreding, ongeacht wat het privacybeleid van de leverancier zegt.

Hoe gaan cloudoplossingen voor klantenservice om met AI en de privacy van klantdata?

Dit verschilt sterk per leverancier en is een van de snelst veranderende aspecten in de sector. Sommige leveranciers gebruiken klantinteracties als trainingsdata voor hun AI-modellen, wat privacyrisico’s met zich meebrengt als dit niet transparant is geregeld. Vraag altijd expliciet of klantdata wordt gebruikt voor AI-training, of dit opt-in of opt-out is, en of de AI-verwerking plaatsvindt binnen een afgeschermde omgeving of via externe modellen zoals publieke API’s van derde partijen. Kies bij voorkeur voor een leverancier die AI-toepassingen volledig binnen de eigen beveiligde infrastructuur verwerkt.

Welke sectoren hebben extra strenge eisen aan cloudopslag van klantdata?

Organisaties in de zorg, het onderwijs, de overheid en de financiële sector hebben naast de AVG te maken met aanvullende wet- en regelgeving. Zo gelden in de zorg de NEN 7510-norm en de Wet op de geneeskundige behandelingsovereenkomst (WGBO), en stelt de overheid via BIO (Baseline Informatiebeveiliging Overheid) extra eisen aan cloudopslag. Voor deze sectoren is opslag op Nederlandse servers doorgaans niet alleen een voorkeur, maar een harde eis — en is het verstandig een leverancier te kiezen die aantoonbare ervaring heeft met jouw specifieke sector en de bijbehorende compliance-vereisten.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.

Ernst Vegter-Business consultant Pegamento

Ernst Vegter

Business Consultant

Hospitality is one of my deepest motivations.
Not surprisingly, of course, customer service is a common thread in my career. Aspects of hospitality is being able to connect, to facilitate but mainly to make someone feel genuinely welcome. My intuition is my greatest asset to be able to put myself in the shoes of a guest. A customer is my guest.

Fed by various senses, an image forms around the client. I listen to what is being said, watch facial expressions, taste the underlying tone and get a feel for the challenge to be addressed. An image literally forms on my retina. I have to be able to see it. If I can see it, I can create it.

In this, the trick is to pursue simplicity, give the client a warm feeling that the problem is understood, receive good advice, facilitated and carefully guided to the solution. Trust, connect and unburden.

The feeling when a guest arrives at your hotel after a long tiring journey, can sit in front of the fireplace, be handed a good glass of wine and stare carefree at the fire. My guest knows it will be okay.

This piece was written by Ernst Vegter, working as a Business Consultant at Pegamento.

Ger Koedam-Communication & Marketing Pegamento

Ger Koedam

Marketing & Communications

How can I help you? That’s pretty much the first question I ask when talking to people who are curious about our services. In such a conversation, the use of senses is very important. Because not everyone is the same. One person thinks in images, while for another words are important or how something feels. For me, sight and hearing are the most beautiful senses, because both eyes and ears absorb information and can convey or process emotions.

Why hearing? Because listening is essential in contact. And it’s the key to unlocking valuable insights.

I developed this skill early on. As a child, I enjoyed radio plays on the radio, bringing the stories to life in my head.

Rob Roode-Research Development

Rob Roode

Research & Development

Recognizing and automating patterns. Tasks we are constantly working on when implementing our robots at Pegamento. My 2 Drentsche Patrijshonden are hunting dogs and certainly not robots. The hunting instinct and intuition is basically in their genes. Continuing to offer new forms of training has taught them to recognize and act independently in hunting situations. Even “unsupervised,” even if I’m not around.

But when you try to teach a brain something, it also starts to see things you don’t expect. Dogs pick up on the slightest deviation in your voice or directions. To start recognizing that and correcting it again is perhaps the most complex challenge. But in our work, for the wonderful clients for whom we get to work, it often yields the most beautiful new insights!

This piece was written by Rob, founder of Pegamento and in charge of Marketing and R&D.

Serge Poppes-CEO Pegamento

Serge Poppes

CEO

Feeling. That’s the best thing Pegamento stands for. Feeling for technology in the broadest sense of the word. Not only feeling for the exciting stuff like AI, but also for the basics of communication.

The very best part of my job is selling, listening, translating and thinking about what really matters. We bring the digital transformation with a great team!
The diversity of our team, how sharp we are, but especially the wonderful things we get to make makes me feel extremely good. Hence, I intuitively chose the sense of “feeling.

Feeling gives life and differentiation!