Security and compliance

Customer contact is your most sensitive data

A voice agent listens in on your most customer-sensitive processes. That is why privacy is not an afterthought for us but a design principle from the start: for each agent we define which data it sees, what it may record and how you check that afterwards.

The safeguards

How we handle your data

EU hosting

Conversations and conversation data are hosted and processed within the European Union. You know where your data is and which law it falls under.

GDPR as the starting point

A data processing agreement is a standard part of working together, including the sub-processors in the chain. Privacy by design is built into the design of every agent.

Transparent under the EU AI Act

Every caller hears at the start of the conversation that they are speaking with an AI agent, as the EU AI Act requires. That is not small print, that is the opening line.

Fully verifiable

Every conversation can be read back: transcript, actions performed and handovers in a single audit trail. What the agent did and why can be demonstrated afterwards.

As little data as possible

The agent gets access to exactly the fields it needs to do its job, not to your entire customer database. Per integration we define what it may read and write.

Resistant to misuse

The platform recognises attempts to talk the agent outside its remit and keeps it within the boundaries you have set.

Within your own walls too

Strict requirements on data location? For larger organisations the environment can run in a private cloud (VPC) or on-premise. Discuss it during the intake.

Analysis within the limits

What we do and do not analyse

Analysing conversations helps you steer, but not everything that is technically possible is also sensible or permitted. We deliberately keep our distance from the sharp edges of the law.

Yes: what was said

Topics, outcomes, handling times, how many conversations the agent resolved itself and where it handed over. The tone of a conversation is assessed from the transcript, not from someone's voice.

No: emotions from voice characteristics

We do not infer emotions or personal characteristics from the sound of someone's voice, and we do not run analysis on your own staff. The EU AI Act sets hard limits there and we respect them in the design.

Frequently asked questions

What security and privacy teams usually ask

Are conversations recorded, and for how long are they kept?

What is recorded and how long it is kept is agreed with you per agent and laid down in the data processing agreement. You can opt for transcripts only, or for a shorter retention period than the standard.

Where is the data stored?

Within the European Union. The full chain of processors, including the parties behind speech recognition and language models, is laid down in the data processing agreement.

Does the caller know they are speaking with AI?

Yes, always. The agent says so at the start of every conversation. That is a requirement of the EU AI Act and simply good manners: people speak differently when they do not know and find out afterwards.

Can we carry out a DPIA on this deployment?

Certainly, and in practice that is what happens. We supply the technical description, the processing activities and the measures you need for it, and we join the assessment.

What happens if we stop?

Then processing stops and we agree how the data is returned or deleted. You are not tied to an annual contract; the notice period is set out in your agreement.

Want to go through this with your privacy or security team?

We include the full overview of measures, processing activities and agreements with every proposal, and we are happy to sit down with your data protection officer.