“Where does our data live?” is the first question in this market, and it deserves a precise answer rather than a reassuring one. The honest answer differs per configuration, so this page states it per configuration.
Nothing here is legal advice, and nothing here is a compliance claim about a specific obligation. Whether a configuration satisfies a rule that applies to you depends on your contract, your sector and your jurisdiction. Get the commitments that matter to you in writing.

Where data sits, per configuration

Licensing is checked against a signed file held on the deployment, so no configuration depends on a live connection to keep answering calls. See Licensing and egress.
Residency selection between Saudi Arabia and the EU, private deployment, and a self-hosted control plane are enterprise-tier options. They are scoped per engagement rather than switched on in a console.

Sovereignty is more than location

A deployment can sit physically in Riyadh and still fail a sovereignty review. The questions that actually get asked:
Not who is contractually permitted to, but who holds credentials that would work. In a self-hosted deployment, that is your directory and nobody else’s.
A security review will scan for it rather than take the answer on trust. In a self-hosted deployment the answer is the periodic usage sync for billing, and nothing else. See Licensing and egress.
Update media, how it is delivered, and who can trigger an update in your environment.
Ask it explicitly, ask whether it can be switched off, and get the answer in the contract rather than in a slide.
In a self-hosted deployment the data is already yours and stays where it is. Confirm what happens to the software.

PDPL and the Gulf

Saudi Arabia’s Personal Data Protection Law places specific requirements on processing personal data, including rules on transfers outside the Kingdom. Comparable regimes apply across the Gulf. Call audio is personal data in its own right in most jurisdictions, and biometric data in some. Where an obligation restricts transfers outside the country, a deployment that processes calls inside your own environment removes the transfer from the picture rather than justifying it. That is the argument on-premise is usually bought for, but it is your legal team’s argument to make, against your obligations.

Evidence your reviewers will ask for

Have these ready before the security review rather than during it:
  • A network diagram showing the boundary and every path that crosses it. See Architecture.
  • The egress answer for your mode, and how it is enforced.
  • Retention periods per data type: audio, transcripts, summaries, action logs.
  • The access model: who can read transcripts, under which role, through which identity provider.
  • The audit trail and where it is streamed.
  • The deletion procedure, tested.
  • The caller notification your line plays, and when in the call it plays.

Security and data handling

What a voice line collects, and what to settle before launch.

Architecture

The boundary, drawn.