Knowledge base / regulation10.ae product guide (DIFC Reg 10)
Where your records are stored, and where a prompt is processed
Two different questions get asked as one here, and they have different answers. Where is your data held, and where is a prompt processed when the assistant answers you? This article answers both, in that order, and states the limits of each answer.
Storage. Your workspace records reside in Azure's UAE North region. That covers the system register, module runs, generated artefacts, the sealed evidence store and the audit trail. Records are encrypted in transit and at rest. A workspace's residency region is set when the workspace is created and stays as set for the life of the workspace, which is why it is the one onboarding choice worth pausing over.
Processing is a separate matter, and it is where loose wording usually creeps in. The platform routes model work down two lanes. The classification and redaction check, which screens a prompt before any response is returned, runs on an Azure OpenAI deployment in Sweden Central, an EU and EEA region. The judgement and explanation lane runs on a deployment provisioned in UAE North. That second deployment is provisioned on Microsoft's GlobalStandard type, and Microsoft documents GlobalStandard as processable in any Azure region. Provisioning location and processing location are therefore not the same statement, and this platform makes no in-country-only processing claim on the strength of one.
Both inference lanes process text in flight. No prompt content and no response content is retained at either inference endpoint. The record that is kept, the audit row, is written to your workspace's own region.
Why state it this carefully. A compliance platform that overstates its own residency posture has already failed the standard it sells. An absolute claim about egress is falsified the moment a processing lane is added, and an enumerated list of exceptions is falsified the same way. So the claim made here is the narrow one that stays true: records at rest in UAE North, processing described by its actual deployment type, and nothing asserted about a region that Microsoft's own documentation does not support.
One thing this article deliberately does not resolve. It does not assert an adequacy finding for any region involved; that is a legal determination and an open question, not something a product page settles. It is also worth being clear that the Sweden Central step is not an exceptional or emergency route. It is a routine step on every prompt, which is precisely why it has to be stated rather than glossed.
Where personal data is transferred outside the DIFC, transfers are made under DIFC standard contractual clauses. If your own assessment needs the subprocessor list, the deployment types and the transfer basis in one document, ask for it and the team will provide the current version rather than a summary of it.