North America
SAP Business One cloud hosting in the United States and Canada.
- United States
- Canada
Support: 24/7 support in English, French and Spanish across North American hours.
Overview
Our New York presence covers a market with no single federal privacy law and a growing patchwork of state ones, where buyers substitute contractual and audit assurance for a national regime. That makes SOC 2 expectations, breach notification terms and clear subprocessor disclosure the practical currency. Canada is a separate regime again, with Quebec stricter still.
Markets served
- United States
- Canada
US workloads sit in the US region you select, with backup and disaster recovery copies kept in country by default. Canadian customers can be kept entirely within Canada Central and Canada East, or Canada (Central), which is what Quebec's Law 25 and public sector procurement usually require.
Microsoft Azure
United States & Canada
AWS
United States & Canada
CCPA / CPRA (California)
What it governs
California's consumer privacy regime: consumer rights, service provider obligations and required contractual terms.
How we support it
Service provider contractual terms, security controls proportionate to the data, deletion and access request support, and no use of your data beyond providing the service.
US state privacy laws (Virginia, Colorado, Connecticut, Texas and others)
What it governs
A growing set of state level comprehensive privacy laws with broadly similar controller and processor duties.
How we support it
Processor side terms, security measures and rights handling support that satisfy the common core of these regimes rather than only one of them.
SOC 2 expectations
What it governs
The assurance framework North American buyers most often use in vendor due diligence, covering security, availability and confidentiality.
How we support it
Control documentation, access and change management evidence, monitoring records and incident response artefacts to support your vendor assessment and your own SOC 2 programme.
HIPAA (where applicable)
What it governs
US health information privacy and security rules, applying where protected health information is processed.
How we support it
Where PHI is in scope, a Business Associate Agreement, encryption, access control, audit logging and breach notification aligned to the Security and Breach Notification Rules.
Canada PIPEDA
What it governs
Canada's federal private sector privacy law, including breach reporting to the Privacy Commissioner.
How we support it
Canadian region deployment, safeguards proportionate to sensitivity, and breach assessment and reporting support.
Quebec Law 25
What it governs
Quebec's modernised privacy regime, stricter than the federal baseline, with privacy impact assessments and specific rules on transfers outside Quebec.
How we support it
Canada East (Quebec City) deployment so data need not leave the province, and our input to the privacy impact assessment the law requires for a transfer.
| Regulation | What it governs | How we support it |
|---|---|---|
| CCPA / CPRA (California) | California's consumer privacy regime: consumer rights, service provider obligations and required contractual terms. | Service provider contractual terms, security controls proportionate to the data, deletion and access request support, and no use of your data beyond providing the service. |
| US state privacy laws (Virginia, Colorado, Connecticut, Texas and others) | A growing set of state level comprehensive privacy laws with broadly similar controller and processor duties. | Processor side terms, security measures and rights handling support that satisfy the common core of these regimes rather than only one of them. |
| SOC 2 expectations | The assurance framework North American buyers most often use in vendor due diligence, covering security, availability and confidentiality. | Control documentation, access and change management evidence, monitoring records and incident response artefacts to support your vendor assessment and your own SOC 2 programme. |
| HIPAA (where applicable) | US health information privacy and security rules, applying where protected health information is processed. | Where PHI is in scope, a Business Associate Agreement, encryption, access control, audit logging and breach notification aligned to the Security and Breach Notification Rules. |
| Canada PIPEDA | Canada's federal private sector privacy law, including breach reporting to the Privacy Commissioner. | Canadian region deployment, safeguards proportionate to sensitivity, and breach assessment and reporting support. |
| Quebec Law 25 | Quebec's modernised privacy regime, stricter than the federal baseline, with privacy impact assessments and specific rules on transfers outside Quebec. | Canada East (Quebec City) deployment so data need not leave the province, and our input to the privacy impact assessment the law requires for a transfer. |
Compliance is shared between provider and customer. We provide the infrastructure controls, evidence and documentation on our side of that line: residency, encryption, access control, backup, monitoring and incident response. Your obligations as data controller remain yours. This page is general information, not legal advice; confirm your specific obligations with your own counsel.
Services available here
Move to the cloud, the right way.
Let's talk about your SAP environment, your security and your growth plan. Migration with minimal disruption is what we do.
Common questions
Which US region will our data be in?
Whichever you select: East US, Central US or West US on Azure, or US East (N. Virginia) and US West (Oregon) on AWS. Backup and disaster recovery copies stay in the United States by default.
Are you SOC 2 certified?
We operate the controls SOC 2 covers (access management, change management, monitoring, incident response) and provide the documentation and evidence your vendor assessment needs. We do not claim an attestation we do not hold, and we will tell you plainly what we can and cannot supply for your audit.
Can Canadian data stay in Canada?
Yes. Azure Canada Central and Canada East, or AWS Canada (Central), keep everything within Canada. For Quebec entities under Law 25, Canada East keeps data within the province.
Can you sign a Business Associate Agreement for HIPAA?
Where protected health information is genuinely in scope, yes, together with the encryption, access control, audit logging and breach notification the Security and Breach Notification Rules require. Tell us early, because it changes the environment design.