ORBIS Cloud runs in two regions: eu-nl-1 (Amsterdam) and eu-de-1 (Frankfurt). Your tenancy is pinned to one primary region, chosen at provisioning.
Backups from eu-nl-1 are replicated to eu-de-1 and vice versa. Both are in the EU. Data does not leave the EU in the course of normal operation.
Support access is role-based, logged, and requires a ticket reference. Support staff in Singapore and Denver can access tenancy metadata and, with your consent recorded on the ticket, your data. You can disable out-of-region support access under Tenancy Settings → Support Access, at the cost of slower out-of-hours response.