Data locations
Learn more about where your Camunda 8 SaaS data is located and how data is handled.
About Camunda 8 SaaS data locations
- Console and the Web Modeler are hosted in the EU.
- You can create Camunda Orchestration Clusters on AWS (Amazon Web Services) or GCP (Google Cloud Platform) in the region of your choice.
Unless specifically mentioned, Camunda does not process personal data on behalf of its customers. It is the responsibility of you as the customer to decide whether to use Camunda for processing personal data.
Some components are changing from GCP to AWS as part of planned improvements to Camunda 8 SaaS. For example, Console and connector secrets are planned to change to AWS hosting in December 2025.
Alerts
Camunda 8 Alerts can notify you when process instances stop with an error.
| Host location | Data handled | Personal data processing |
|---|---|---|
| Belgium, EU (GCP) | Route alerts containing administrative metadata only. | N/A |
Camunda 8 Alerts are optional. This information only applies if you use Alerts.
Connector secrets (credentials)
This only applies if you want to create connector secrets and are using the Camunda-hosted connector version. Connector secrets are configured and referenced via Console.
- If you want to control the location where the secrets are stored, you can also host your own connector runtime.
- If you want to use your own secret management solution, see Secrets (Self‑Managed).
| Host location | Data handled | Personal data processing |
|---|---|---|
GCP Secret Manager, replicated globally for high availability. From December 2025: Connector secrets for Camunda Orchestration Clusters >= 8.7 created in an AWS region will be stored inside AWS Secret Manager, in the same AWS region as the Camunda Orchestration Cluster only. | Stores credentials required by connectors (API keys, tokens, passwords), not business process data. | Not intended for personal data processing. If you embed personal data in connector secrets, note the global replication of data. You should review if your company has specific data residency requirements, and use connector secrets accordingly. |
Connector secrets are optional. This information only applies if you use connector secrets.
Console
The Camunda‑hosted Console admin UI is used for cluster and organization management.
| Host location | Data handled | Personal data processing |
|---|---|---|
Belgium, EU (GCP) From December 2025: Germany, EU (AWS) | Only stores administrative metadata and settings. | Limited to account/authentication data to access Camunda Platform SaaS. It does not include personal data in scope of Data Processing Agreements. |
Identity
Identity is managed by Camunda for SaaS. Single Sign-on (SSO) is supported.
| Host location | Data handled | Personal data processing |
|---|---|---|
| Germany, EU (Auth0 as part of Okta) | User accounts and authentication metadata. Separate from process payloads. | Limited to account/authentication data by design to access the Camunda Platform SaaS. It does not include personal data in scope of Data Processing Agreements. |
Orchestration Clusters and backups
You can choose a region in GCP or AWS. Each Orchestration Cluster uses a dedicated infrastructure.
| Host location | Data handled | Personal data processing |
|---|---|---|
Orchestration Clusters are created on AWS or GCP, in one of the available regions. Backups are single‑region by default, in the same region as the Orchestration Cluster. Optionally, you can replicate backups in a secondary region, depending on the chosen primary region. | All data uploaded to Camunda in Orchestration Clusters during customers’ process orchestration (used in Zeebe, Operate, Tasklist, Optimize and Connectors). | Dependent on the data you sent to Camunda in the Orchestration Clusters. Camunda does not process personal data by default. |
REST connector (traffic routing)
For security reasons, REST API requests made by the REST connector are all routed through a dedicated HTTPS proxy hosted by Camunda in the EU. The REST connector uses either an AWS or a GCP-hosted HTTPS proxy, depending on your chosen Orchestration Cluster cloud provider.
As a customer, you can either use the Camunda‑hosted REST connector, or host your own connector runtime (hybrid mode) to keep traffic in your chosen location.
| Host location | Data handled | Personal data processing |
|---|---|---|
| All data uploaded to Camunda in an Orchestration Cluster and processed specifically by the REST API Connector. Use of the REST API Connector is optional, and depends on the customers’ workflows. | Dependent on the data you send to Camunda in an Orchestration Cluster. Camunda does not process personal data by default. |
Use of the REST connector is optional. This information only applies if you use the REST connector.
Web Modeler
You can use the Camunda‑hosted Web Modeler in the EU, or Desktop Modeler with Camunda Self‑Managed if you want to control the hosting location.
| Host location | Data handled | Personal data processing |
|---|---|---|
| Belgium, EU (GCP) | Only stores process models (diagrams/designs). | Not intended for personal data processing. |