DPA & Compliance

Certifications

Data retention

CategoryDefaultConfigurableDeletion mechanism
Call recordings and transcriptions (AI and human legs)30 daysPer customer and per AI agent, 0–180 days; stricter policies additionally anonymize the caller phone number and clear conversation contentAutomated daily retention job; permanent deletion from object storage
Call summaries and call analysisDuration of the subscriptionStricter per-agent policies delete or anonymize them; after termination kept at least 30 days, deleted within 60 daysAutomated daily retention job; deletion after account termination per the DPA
Security and call logs (audit, call, SIP, activity changes)30 daysExtended retention available by specific agreementAutomatic deletion via database TTL indexes
Technical logs (system, activity reads)7 daysExtended retention available by specific agreementAutomatic deletion via database TTL indexes
Database backups (MongoDB platform data)30 daysExtended retention available by specific agreementAutomatic deletion from AWS S3 after 30 days (daily backup job cleanup)
All customer data after contract terminationReturn and/or destruction within 60 days (reversibility window); minimum 30 days post-termination retentionPer the Data Processing AgreementCompany purge — permanent deletion of all stored objects and records

Technical & organizational measures

AreaMeasure
Encryption in transitHTTPS/TLS for web, API and WebSocket interfaces. SIP over TLS and SRTP for voice where supported by the interconnected carrier/PBX; otherwise UDP/RTP restricted at network level (IP allowlisting, firewall).
Encryption at restFiles (recordings, transcriptions, attachments) stored in AWS S3 eu-north-1 with AES-256 server-side encryption. Sensitive credentials and integration tokens encrypted at application level with AES-256-GCM. User passwords stored as bcrypt hashes only.
HostingPrimary infrastructure (application servers, self-hosted MongoDB/Redis, voice stack) on Hetzner dedicated servers in Frankfurt (Germany) and Finland — EU/EEA, ISO/IEC 27001 certified data centers. Speech-to-text and text-to-speech default to third-party EU providers; self-hosted AI models on EU dedicated machines are used only on customer selection. Databases are not internet-exposed.
Access controlNamed per-user accounts, company-scoped data isolation, MFA for privileged remote access and source-code platforms, formal privileged-account lifecycle. Access revoked within 1 month of departure (immediately for privileged access).
Incident responseCustomer notification without undue delay (service-level alert at 48 hours of detection). Where NIS2 applies: early warning within 24 hours and a detailed notification within 72 hours. For personal-data breaches the customer as controller notifies the competent supervisory authority within 72 hours (GDPR) and Voice Logica provides the necessary assistance. Root Cause Analysis within 2 weeks. Incident subject prefix: [Voice Logica Security Incident].
Database backupsDaily automated full MongoDB backup, compressed and streamed directly to AWS S3 eu-north-1 with AES-256 server-side encryption; retained 30 days then auto-deleted, with no backup files kept on the production server. Large operational log collections (call, activity, SIP, audit and system logs, emails) are excluded from backups and instead expire via database TTL (30 days for security and call logs, 7 days for technical logs).
Business continuityRTO 4 hours, RPO 24 hours (daily offsite database backups); a 3-node database replica set protects against the loss of a single server; disaster recovery plan reviewed at least annually.
Vulnerability managementDaily monitoring of vendor advisories. Remediation: critical 4 hours, high 48 hours, medium 2 months, low next release.
AuditsAnnual third-party security audits including ISO/IEC 27001 and 27701 surveillance audits. Customer audit right with 10 business days notice (72 hours in emergencies).
PaymentsPCI-DSS not applicable — payments processed exclusively by Stripe (PCI DSS Level 1); cardholder data never touches Voice Logica systems.

Sub-processor register

NameRoleData categoriesLocationTransfer mechanismDefault
Hetzner Online GmbHInfrastructure (dedicated servers: applications, self-hosted databases, voice stack; self-hosted AI models only on customer selection)All hosted service dataFrankfurt (Germany) + Finland, EU/EEAn/a (EEA)yes
Amazon Web Services EMEA SARLObject storage S3 (recordings, transcriptions, attachments) + email SESCall recordings, transcriptions, attachments, email contenteu-north-1 (Stockholm), EU/EEAn/a in-region; AWS DPA SCCs + DPF for any non-EEA accessyes
Yuboto TelephonyTelecom interconnection (call routing, numbering, SMS) only for numbers or SMS arranged through Voice Logica; otherwise calls use the customer's own telephony provider, contracted by the customerPhone numbers, call/traffic metadata, voice content in transitGreece, EU/EEAn/a (EEA)on request
OpenAI (OpenAI Ireland Ltd)LLM — default dialogue/analysis provider (signed DPA); optionally Whisper STT / TTS / embeddingsConversation text, transcriptions, prompts, call metadataEU contracting entity; processing may occur in the USDPA with SCCs; EU-US Data Privacy Frameworkyes
Soniox Inc.Speech-to-text — default provider; optionally TTSReal-time call audio stream, transcriptionsEU data residency (default); US/JP selectablen/a for EU residency; otherwise SCCs/DPFyes
Google (Google Ireland Ltd / Google Cloud)Speech-to-text fallback (EU region); optionally Cloud TTS, Search API, Maps/Places for in-call location tools (location text only)Real-time call audio stream, transcriptions; location text from location toolsGoogle Cloud EU regions (Maps/Places: Google global infrastructure)Google Cloud DPA; SCCs/DPF where applicableyes
Google (Gemini API)Image analysis — default provider; optionally Gemini LLM on customer selection; not used on agents where the customer enables core-providers modeImages and attachments submitted for analysis, promptsGoogle global infrastructure (processing may occur outside the EEA)Google DPA; SCCs/DPF where applicableyes
ElevenLabs Inc.Text-to-speech — default provider (EU data residency); optionally STTAgent response text to be spoken (transient)EU data residency (default)n/a for EU residency; otherwise SCCs/DPFyes
Microsoft Ireland Operations Ltd (Azure Speech)Text-to-speech fallback (EU region); optionally STTAgent response text to be spoken (transient)Azure EU regionsMicrosoft DPA (EU Data Boundary); SCCs/DPF where applicableyes
Stripe Payments Europe LtdBilling/subscriptions (largely independent controller; card data never touches Voice Logica)Customer billing detailsEU/USSCCs in Stripe DPA + DPFyes
Anthropic PBCLLM (on customer selection only)Conversation text, promptsUSDPF and/or SCCson request
xAI Corp. (Grok)LLM (on customer selection only)Conversation text, promptsUSDPF and/or SCCson request
Groq Inc.LLM — default for auxiliary in-call processing (knowledge lookup and distillation, in-call assistant, unanswered-question capture, analytics enrichment); not used on agents where the customer enables core-providers modeConversation excerpts, knowledge and tool results, promptsUSDPF and/or SCCsyes
Together AI Inc.LLM (on customer selection only)Conversation text, promptsUSDPF and/or SCCson request
MiniMaxLLM/TTS (on customer selection only; SCCs/TIA review required before activation for EU data)Conversation textNon-EEASCCs + Transfer Impact Assessmenton request
Deepgram Inc.Speech-to-text (on customer selection only; no data retention configuration)Real-time call audio streamUSDPF and/or SCCson request
Speechmatics LtdSpeech-to-text (on customer selection only)Real-time call audio streamUnited KingdomEU adequacy decision for the UKon request
Fireworks AI Inc.Speech-to-text (on customer selection only)Real-time call audio streamUS (us-virginia-1)DPF and/or SCCson request
Murf AI Inc.Text-to-speech (on customer selection only)Agent response text (transient)USDPF and/or SCCson request