Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Ironclad Work in China? Contract Data, PIPL & Data Residency

Ironclad runs its contract-lifecycle platform on US-hosted Google Cloud Platform, with an EU datacenter option and no mainland-China region — so the contracts, counterparty and signatory PII and e-signature records it holds come to rest offshore, a PIPL cross-border transfer. A compliance-first look at the data-residency and PIPL questions that decide whether you can use it in China.

Does Ironclad work in China?

Ironclad's dashboard opens from China, but the contracts, counterparty and signatory PII and e-signature records it holds rest on US-hosted Google Cloud Platform — or Ironclad's EU datacenter — never in mainland China, so each one is a cross-border transfer of personal information under PIPL.

Ironclad runs production on US-hosted Google Cloud Platform, with an EU datacenter as the only alternative region and no mainland-China option. Your agreements, the counterparty and signatory names, emails and e-signature identity records on them, and the negotiation and approval trail are all personal information — and where a contract carries a signatory's ID number or financial-account details, that subset is sensitive personal information under PIPL Article 28. Because those records leave the mainland, the handler (you, not Ironclad) owes notice, separate consent and a transfer mechanism (PIPL Articles 38–43), and a CIIO or large-volume handler owes in-country storage the platform's US and EU regions cannot provide. This is a risk map, not a verdict — settle specifics with counsel.

What Ironclad's own documentation says about China

FactPrimary source
Ironclad hosts production on US-based Google Cloud, with no mainland-China region. On its own Security page Ironclad states it "uses the US-hosted Google Cloud Platform for production servers and operates in multiple zones to protect against outages," and that it leverages "multiple data center regions from our providers ... while providing the necessary data residency requirements." None of those regions is in mainland China — the page does not mention China at all — so contracts and signer records collected in China come to rest offshore, a cross-border transfer of personal information under PIPL (Articles 38–43). Ironclad Security page, retrieved 2026-10-10
Ironclad's subprocessor list names Google Cloud Platform in the USA, plus an EU datacenter — not China. Ironclad's approved-subprocessors page lists "Google Cloud Platform" as its "Cloud & AI Infrastructure" provider located in the "USA," with a parallel entry under a "CLM Subprocessors — EU Datacenter" section; Amazon Web Services appears only as the host for Ironclad's separate Clickwrap product. No listed location is in mainland China, so there is no in-country region to store contract data on or to attach an ICP filing to. Ironclad approved subprocessors, retrieved 2026-10-10
Personal data leaving China is a regulated cross-border transfer, and some contract data is sensitive. Under the Personal Information Protection Law, moving personal information collected in China to Ironclad's US or EU region is a cross-border transfer: the handler must give notice, obtain separate consent and clear one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–43). Where a contract carries a signatory's government ID or financial-account details, that is sensitive personal information under PIPL Article 28, which raises the bar further. Personal Information Protection Law of the PRC, Articles 28 and 38–43
For some handlers the data must stay in China, and a China-facing surface triggers an ICP filing. A critical information infrastructure operator or large-volume handler must store personal information collected in China inside the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty Ironclad's US and EU regions cannot meet. Any China-facing signing or intake surface actually served from inside the mainland must also carry an ICP filing (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource Ironclad does not provide. Cybersecurity Law Article 39 (formerly Article 37); PIPL Article 40; State Council Order No. 292; MIIT Order No. 33

Sources verified by the 21YunBox compliance team on 2026-10-10.

For teams in mainland China, the question about Ironclad is not whether the contracting dashboard opens — it does — but where the records it keeps are allowed to come to rest. Ironclad is a contract-lifecycle platform: it holds your third-party agreements along with the counterparty and signatory names, email addresses and e-signature identity records attached to them, and the negotiation and approval trail around each contract. All of that is personal information, and where a contract carries a signatory’s government ID or financial-account details, that subset is the sensitive kind. Ironclad states on its own security page that production runs on US-hosted Google Cloud Platform, with an EU datacenter the only alternative and no mainland-China region. So the dashboard is reachable, yet every contract and signer record tied to China comes to rest offshore — a cross-border transfer of personal information China’s law governs. The load time is a symptom; the residency is the exposure.

Ironclad's own Security page stating that Ironclad uses the US-hosted Google Cloud Platform for production servers and operates in multiple zones to protect against outages, with no mainland-China region named
Ironclad's own Security page: it “uses the US-hosted Google Cloud Platform for production servers and operates in multiple zones,” none of them in mainland China — the page names no China region at all. Source: ironcladapp.com/security

Ironclad in China at a glance

What decides it In Ironclad's own terms — and China's law
Where the records live Ironclad “uses the US-hosted Google Cloud Platform for production servers,” and its subprocessor list names Google Cloud Platform as its “Cloud & AI Infrastructure” provider in the “USA,” with an EU datacenter as the only alternative. Neither region is inside mainland China.
What it holds, and why it's PI Your contracts plus the counterparty and signatory names, emails and e-signature identity records on them, and the negotiation, approval and audit trail — all personal information. Where a contract carries a signatory's government ID or financial-account details, that subset is sensitive personal information (PIPL Article 28).
Your China data = cross-border A contract signed, uploaded or negotiated from China whose records rest on Google Cloud in the US or EU is a cross-border transfer of personal information. The handler — you, not Ironclad — owes notice, separate consent and one transfer mechanism (PIPL Articles 38–43).
In-country storage duty A critical information infrastructure operator or large-volume handler must store personal information collected in China inside the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). Ironclad's US and EU regions cannot satisfy it.
Reachability is not the axis The dashboard loads from China; that changes neither where the contracts rest nor whether the transfer is lawful. A China-facing signing or intake surface actually served from inside the mainland also needs an ICP filing bound to in-country hosting.

No mainland region, so your contracts leave the country

Ironclad is explicit about where it runs. Its security page states that it “uses the US-hosted Google Cloud Platform for production servers and operates in multiple zones to protect against outages,” and that it leverages “multiple data center regions from our providers … while providing the necessary data residency requirements.” Its approved-subprocessors page names Google Cloud Platform as its “Cloud & AI Infrastructure” provider in the “USA,” with a second, EU datacenter option for the contract-lifecycle product. Neither page mentions mainland China, and neither region sits inside it.

The EU datacenter matters for European residency, but it does nothing for China: it is simply a second offshore location. So when a contract is signed, uploaded or negotiated from China, the agreement and the personal information attached to it are written to storage in the United States or Europe. Under China’s Personal Information Protection Law, that is a cross-border transfer, and the obligation falls on the personal-information handler — you, not Ironclad. You must give notice, obtain separate consent for the overseas transfer, and clear one transfer mechanism (PIPL Articles 38–43).

For a critical information infrastructure operator or a large-volume handler there is a harder floor: personal information collected in China must be stored inside the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty two offshore regions cannot meet no matter which one you pick.

What Ironclad holds is personal information

Strip away the workflow and Ironclad is a store of personal information. Every agreement carries the names, titles, email addresses and signatures of the people on both sides; the e-signature layer records who signed, from where, and the identity evidence behind it; and the repository keeps the negotiation history, approvals and audit trail around each contract. That is personal information in PIPL’s terms, and the handler’s duties attach to it the moment it crosses the border.

Some of it is the sensitive kind. Where a contract carries a signatory’s government ID number, passport number or financial-account details — routine in cross-border deals, financing and employment agreements — that subset is sensitive personal information under PIPL Article 28, which demands a stricter necessity test and specific consent. And the volume adds up fast: a busy legal team moves thousands of counterparties’ details offshore in a year. Under the CAC’s March 2024 cross-border rules, a non-CIIO transferring fewer than 100,000 individuals’ non-sensitive personal information in a calendar year is exempt from the heavier mechanisms; cross that line, act as a CIIO, or handle sensitive data, and a security assessment, the standard contract, or certification come back into play.

There is an irony worth naming. Ironclad is the system a company runs to keep its contracting orderly and defensible — yet used as-is for China, it can quietly create the very cross-border exposure your legal team exists to manage.

Narrowing the exposure doesn’t close the door

The levers a SaaS contracting platform gives you — choosing the EU datacenter over the US region, redacting fields, limiting what syncs to analytics subprocessors, tightening retention — are all real, and all worth using. But they change what crosses the border and how much, not that it crosses. Picking Ironclad’s EU datacenter moves the data from one offshore region to another; it does not place it in mainland China, and it does not create the in-country storage footing a CIIO or large-volume handler owes. Residency is unaffected.

The same distinction governs any China-facing surface. A signing page, a counterparty intake form or an approval portal actually served to users inside the mainland turns on an ICP filing (ICP 备案) under State Council Order No. 292 and MIIT Order No. 33, bound to a hosting resource physically in China — something Ironclad’s US and EU regions give you nothing to file against.

This is a risk map, not a verdict. Whether you owe separate consent, a transfer mechanism, in-country storage, an ICP filing, or some combination turns on your entity, your data volumes, how sensitive the contract data is, and who your users are — worth settling with counsel before you rely on it.

The lawful path — map, localize, deliver

You keep running Ironclad. 21YunBox adds the piece a US- and EU-hosted contracting platform structurally cannot, as a compliant overlay rather than a migration — and as a partner to the stack you already run, not a competitor to it.

  • Map. Our China compliance team reads your PIPL cross-border, data-residency and sensitive-personal-information obligations against your entity, your contract volumes, and who your signers and counterparties are.
  • Localize. We stand up consented, in-country processing and storage for the records that must stay on mainland soil — and, where the platform supports it, a self-managed deployment — so the data with a residency duty rests where the law requires.
  • Deliver. Any China-facing surface — a signing page, an intake form, an approval portal — is delivered over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), set in front of the Ironclad you already use, with no rebuild and no second codebase.

The result runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Where does Ironclad store our contracts and signers' data — is any of it in mainland China?
No. On its own Security page Ironclad says it "uses the US-hosted Google Cloud Platform for production servers," and its subprocessor list offers only a USA region and an EU datacenter — no mainland-China region. Contracts, counterparty and signatory PII and e-signature records tied to China therefore come to rest offshore, which makes them a cross-border transfer of personal information under PIPL: the handler (you, not Ironclad) owes notice, separate consent and a transfer mechanism.
Ironclad is the tool we use to manage contracts — how can it be a compliance risk in China?
Because compliance in China turns on where the data lives, not on what the tool is for. A contract-lifecycle platform exists to keep your agreements and approvals in order, but if those records — and the counterparty and signatory personal information in them — rest on Google Cloud in the US or EU, you have created the exact cross-border transfer PIPL regulates, plus a data-residency duty an offshore store cannot meet for a CIIO or large-volume handler. The tool that runs your contracting can create a PIPL exposure of its own. Treat it as a risk to work through with counsel.
Can 21YunBox make our Ironclad setup compliant for mainland China?
Yes — as a compliant overlay, not a migration. Our China team maps the PIPL cross-border and data-residency obligations that attach to the contracts and signer data Ironclad holds, for your entity, data volumes and users; stands up consented, in-country storage for the records that must stay on mainland soil; and delivers any China-facing signing or intake surface over ICP-filed, in-country infrastructure, in front of the Ironclad you already run. 21YunBox never uses or suggests circumvention of any kind.

ARTICLES RELATED TO IRONCLAD

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.