"Stored in Canada" — what that phrase does and does not promise
Data residency is the claim every Canadian health-software vendor makes and almost nobody breaks down. Here is what a practice is actually asking about, the five places patient data can quietly leave the country, and how to get a straight answer.
Every vendor selling software to a Canadian denture practice says the data stays in Canada. It is the easiest claim in the category to make and one of the harder ones to check, because "the data" is not one thing sitting in one place — it is five or six separate things that can each live somewhere different.
This is not an accusation that vendors are lying. Most are describing the part of the system they think about most, honestly, and have never been asked to break the rest down. The point of this piece is to give you the breakdown, so you can ask the question in the form that gets a real answer.
Does the law actually require it?
Mostly, no — and it is worth being clear about that before spending a purchasing decision on it. Ontario's Personal Health Information Protection Act does not contain a blanket prohibition on personal health information leaving the country. What it does is make your practice the health information custodian, and put the obligation on you to take reasonable steps to protect the information and to be able to account for what happens to it.
Residency is one of the strongest ways to discharge that obligation, which is why it has become shorthand for it. Data held in Canada sits under Canadian law, is reachable by Canadian regulators, and does not require you to reason about foreign disclosure regimes when a patient asks a pointed question. That is a real advantage. It is just not the same as a legal requirement, and a vendor who tells you it is has told you something you can check and found untrue.
Which parts of the system are we even talking about?
Five, and they are genuinely independent. A vendor can answer "Canada" to the question as asked and be describing only the first one:
- The application. The servers that run the software your staff log into. This is the one everyone means by "hosted in".
- The database. Where the clinical record itself lives — notes, health histories, appointments, ledgers. Frequently in the same region as the application, but not necessarily.
- File storage. Radiographs, scanned consent forms, photographs. These are usually kept in a different service from the database, and that service has its own region setting. It is a common place for a mismatch to hide.
- Backups. The most commonly missed one. A database in Toronto whose nightly backups replicate to a US region has your complete clinical record in the United States every night, and nothing about the phrase "our database is in Canada" is false.
- AI processing. The newest and now often the largest gap. An application in Montréal that sends each dictated note to an AI endpoint in Iowa has moved that note across the border, on every note.
How do I ask so a vague answer becomes obvious?
Ask for the cloud region identifier for each of the five, not the country. Cloud regions have public, unglamorous machine names — northamerica-northeast1 for Google Cloud in Montréal, ca-central-1 for AWS in Central Canada. A vendor whose engineers have configured this deliberately can produce those strings in a sentence. A vendor who has not will change the subject to encryption.
Encryption is a fine thing and an unrelated one. It protects data from someone who obtains the storage; it says nothing about which jurisdiction the storage is in. If you ask where and are answered with how securely, ask again.
Two follow-ups that cost nothing and are hard to fudge: do the backups stay in the same region, and which AI provider processes the notes, in which region, under what agreement. If you get five region names and those two answers in one reply, you are talking to someone who has actually made the decisions.
Where does DentureFlowPro hold it?
All five in Google Cloud's Montréal region, northamerica-northeast1: the application on Cloud Run, the clinical record in a managed Cloud SQL database, patient documents and radiographs in regional storage, the nightly encrypted database backups in that same region rather than a multi-region location outside Canada, and the AI processing on Google Cloud Vertex AI alongside the rest — under our signed Google Cloud agreement rather than through a consumer AI service. Data is encrypted in transit and at rest.
The backups line is the one worth dwelling on, because it is the one that takes a deliberate decision. Cloud platforms will happily default a database's backups to the nearest multi-region location, and for a database in Montréal that default is not in Canada. Nothing warns you. The instance is in the region you chose, the console says so, and a copy of everything lands elsewhere every night. Keeping backups in-region is a setting somebody has to go and change.
Which is why it is worth asking every vendor about specifically, in those words, and why our answer to it is written on the privacy and PHIPA page rather than only here — in the same order we said the question deserves: the region first, the component list second, the encryption last.
The short version
Residency is not a legal command, it is the cleanest way to answer a question you will be asked. It is a fact about five components rather than about a company. And the question that separates a considered answer from a comfortable one is simply: name the region, for each part, including backups and AI.
Quick answers
Does Canadian privacy law require patient data to stay in Canada?
Generally no. PHIPA does not impose a blanket ban on storing personal health information outside Canada. What it requires is that the custodian — your practice — take reasonable steps to protect it and be able to account for where it is and who can reach it. Residency is a way of meeting that, not the rule itself.
What does data residency mean in health software?
Data residency means the physical region where data is stored and processed. It is a per-component fact, not a per-company one: the application, the database, file storage, backups and AI processing can each sit in a different region, and a vendor can truthfully say "hosted in Canada" while only one of them is.
How can I verify a vendor's data residency claim?
Ask for the cloud provider's region identifier rather than a city — for example northamerica-northeast1 for Google Cloud Montréal. Region codes are public, specific and hard to say loosely, so the answer is either given or conspicuously not.
Where does DentureFlowPro store patient data?
Entirely in Google Cloud's Montréal region, northamerica-northeast1: the application on Cloud Run, the clinical record in a managed Cloud SQL database, patient documents and radiographs in regional storage, the nightly encrypted backups in that same region rather than a multi-region location outside Canada, and AI processing on Vertex AI alongside the rest.
Does AI processing send patient data outside Canada?
It can, and this is the component most often overlooked. An application hosted in Canada that calls an AI service in another region has moved the note across the border. DentureFlowPro runs its AI on Google Cloud Vertex AI in the same Montréal region as the rest of the data.
See how it actually works
Every claim on this page is set out in detail on our compliance page — or watch the software do the work in the demo videos.