New Skip the empty dashboard — get pre-loaded cascading OKRs tailored to your team. Start free

OKR Software with EU Data Residency (GDPR)

OKR software that stores all data in the EU (AWS Ireland), is GDPR compliant, and encrypts every byte. What EU teams need for data sovereignty.

Steven Macdonald
5 Mins read
August 14, 2026
OKR Software with EU Data Residency (GDPR)

OKRs Tool is OKR software that stores 100% of customer data inside the EU — in AWS Ireland (eu-west-1), where data never leaves the region. It is GDPR compliant, encrypts every byte with AES-256 at rest and TLS 1.3 in transit, and inherits SOC 2, ISO 27001, and PCI DSS from its infrastructure providers. For European companies that need goal-setting software without sending data to US servers, it is built to pass a security review.

Nearly every OKR platform is US-hosted, which means a European company adopting one ships its strategic data — objectives, performance signals, sometimes personal data about employees — to servers outside the EU. For teams bound by GDPR, public-sector procurement rules, or an internal data-sovereignty policy, that is often a dealbreaker before the software is even evaluated on features.

This page answers the questions those teams ask, with the specifics a security reviewer needs — and it sits alongside the broader case for why teams choose OKRs Tool.

OKR software your security team will approve

EU data residency, GDPR compliance, and a signed DPA on request. Free for up to 5 users.

Start Free →

Where Is the Data Stored?

All customer data in OKRs Tool is stored in AWS Ireland (eu-west-1), and it never leaves the EU. There is no replication to US regions and no fallback to non-EU infrastructure. For a European organization, that means the objectives, key results, check-ins, and user records your teams create stay within EU jurisdiction for their entire lifecycle.

This matters because data residency and data sovereignty are not the same as a vendor simply "being GDPR compliant" on paper. Residency is about where the bytes physically sit. A US-hosted tool with a GDPR policy still stores your data in the US; OKRs Tool stores it in Ireland, under EU law, full stop. The full picture lives on the Trust and Compliance page, with deeper detail on security controls and GDPR specifics.

Is It GDPR Compliant?

Yes. OKRs Tool is fully GDPR compliant, and the compliance is operational, not just a policy document. It covers lawful basis for processing, retention controls, and full sub-processor disclosure. Two data-subject rights matter most in practice:

Right to erasure is a hard delete. When an organization requests deletion, its data is removed entirely — including audit logs — with no soft-delete window where the data lingers on disk. Right to portability is covered by a personal JSON export, an org-level Excel export of OKRs, check-ins, and users, an audit-log CSV, and a full REST API.

A signed Data Processing Agreement (DPA), on the standard GDPR template, is available on request for procurement teams, and the full list of sub-processors that touch your data is published for review.

The Compliance Facts, in One Table

For a security questionnaire or a vendor review, here is the full picture in one place.

AreaWhat OKRs Tool provides
Data residencyAll data in AWS Ireland (eu-west-1); never leaves the EU
Encryption at restAES-256 on every byte of customer data
Encryption in transitTLS 1.2 / 1.3; older protocols disabled
GDPRFull compliance: lawful basis, retention controls, sub-processor disclosure
Right to erasureHard delete of all org data, audit logs included — no soft-delete window
Data portabilityJSON export, org Excel export, audit-log CSV, full REST API
Inherited certificationsSOC 2, ISO 27001, PCI DSS (via Cloudflare, AWS, Supabase, Stripe)
AuthenticationSAML 2.0 SSO (Entra, Okta, Google Workspace), TOTP 2FA, org-enforced MFA
Access controlRole-based access (Admin, Manager, Member, Viewer), row-level data isolation
Audit logEvery action logged with actor and timestamp; indefinite retention; CSV export
BackupsDaily automated backups, 7-day retention
DPASigned Data Processing Agreement available on request

What Certifications Does It Have?

OKRs Tool inherits SOC 2, ISO 27001, and PCI DSS from its infrastructure providers, and runs every layer of its stack on certified infrastructure. Cloudflare provides the network edge, DDoS protection, and WAF (SOC 2 Type II, ISO 27001). AWS provides compute, storage, and EU regional hosting (SOC 1, SOC 2, SOC 3, ISO 27001, PCI DSS). Supabase runs the database, auth, and real-time sync (SOC 2 Type II). Stripe handles payments (PCI DSS Level 1).

Copies of the SOC 2 and ISO 27001 reports from these providers are available under NDA for a vendor review. This is the honest framing worth stating plainly: the certifications are inherited from the infrastructure, not held directly by OKRs Tool as an independent SOC 2 audit — which is the appropriate and common posture for a focused product built on certified cloud infrastructure.

Is It Secure Enough for a Large or Regulated Team?

The controls are built for exactly that review. Data is isolated per organization at the database layer through row-level security, so no organization's data can be reached from another's.

SAML 2.0 SSO on the Expand plan supports Entra/AAD, Okta, Google Workspace, and any SAML 2.0 identity provider, and admins can enforce MFA across the whole organization. Sessions use short-lived tokens that rotate on use and revoke on sign-out, with admin-configurable idle and absolute timeouts. These are the access controls a large team running OKRs at scale needs before rollout.

Every meaningful action — each objective, key result, check-in, review, member change, and role change — is captured in an audit log with actor and timestamp, retained for the life of the account, and exportable to CSV with a date-range picker for security questionnaires or board reviews.

OKR Software Built for European Teams

For a European company running OKRs, the choice usually comes down to a US-hosted platform with a GDPR policy bolted on, or a tool that keeps data in the EU by design. OKRs Tool is the second. It is a full OKR platform — company-to-team goal alignment, weekly check-ins, owner accountability, and progress tracking — built for team OKRs across a whole company, that happens to store every byte in Ireland and pass a data-sovereignty review without exceptions. If you are weighing it against other platforms, the independent OKR software comparison covers the wider field.

If you are comparing options, the questions worth asking any vendor are simple: where is the data physically stored, does it ever leave the EU, is erasure a hard delete, and can you get a signed DPA. OKRs Tool answers EU, no, yes, and yes. You can start free for up to five users, run a full security review in parallel, and see how it works while your team evaluates the platform.

OKR software that keeps your data in the EU

AWS Ireland hosting, GDPR compliance, AES-256 encryption. Set up in an afternoon, free for up to 5 users.

Start Free →


Compliance details sourced from the OKRs Tool Trust & Compliance page. Available on request for vendor review: signed DPA, completed security questionnaire (SIG Lite, CAIQ), and infrastructure SOC 2 / ISO 27001 reports under NDA.

CEO Photo

Founder

Steven Macdonald│LinkedInX

Steven is the founder of OKRs Tool, OKR software built for senior operators inside growing companies. Trusted by 350+ teams to run OKRs that survive beyond the first cycle — with weekly check-ins, required KR ownership and a visual alignment map that shows how every goal connects.