Where your customers' data lives is not a footnote. It determines which laws apply, which guarantees you can make, and how much friction stands between a merchant and their next market.
EU-native, not EU-compatible
CIQRA runs on Microsoft Azure in Germany — Frankfurt as primary, with disaster recovery in Germany North. Core personal data stays in the EEA. That's a deliberate choice: it means the GDPR baseline is the default, not an add-on, and merchants inherit a data-residency story they can hand to their own customers.
Compliance as architecture
Being EU-native pushes decisions upstream. VAT and OSS belong in the tax engine. Consent belongs in the analytics pipeline. Subprocessors are published, not buried. When these are structural, "being compliant" stops being a scramble and becomes the way the system already works.
What it means for merchants
You get a platform that was designed for cross-border selling — local currency, correct tax, and data handling that holds up to scrutiny — without stitching it together yourself.