Trust & privacy

Where your data is processed, how we secure it, and who we work with — said plainly.

Terms, our privacy policy and a data processing agreement (DPA) are published on our legal pages. Read the DPA

Data processing in the EU

Everything we store ourselves — call logs, bookings and account information — sits in the EU. The database runs in Frankfurt, and the servers that handle call and booking traffic also run in Frankfurt.

The call itself is handled by the voice AI of a US-based subprocessor. Full EU data storage requires an extended agreement with the provider — which we have not enabled. So we do not claim the voice data is processed in the EU; how that data flow is governed is set out in the data processing agreement (DPA).

Everything is built for GDPR.

AI disclosure by default

Every single call opens with the receptionist stating that it is an AI. It never pretends to be a human.

This is both honest and required by law. The EU's Artificial Intelligence Act (Regulation (EU) 2024/1689) requires, in Article 50, that a provider of an AI system intended to interact directly with people informs them that they are interacting with an AI. The requirement applies from 2 August 2026 — we already do it today.

Consent and recording

Calls are transcribed so you can read what was said, follow up on messages and improve the receptionist. Audio recording can also be turned on.

We collect as little as possible. The receptionist does not ask for sensitive personal data, and a booking is created only when the caller asks for it themselves.

You are in control of the data from your own business. The exact rules for retention, deletion and access are set out in the privacy policy and the data processing agreement, coming before the first paying customer.

Security

Data is encrypted both in transit and at rest. The database encrypts all content with AES-256 at rest, and all traffic runs over encrypted connections (TLS).

Each account only sees its own data. Calls, bookings and settings are isolated per business.

We are not SOC 2 certified yet. It is on the roadmap — we don't use badges we haven't earned, and we'll update this page once the certification is in place.

Subprocessors

We use a small set of carefully chosen subprocessors to deliver the service. For competitive reasons we list them by category — what they do, and where the data is processed.

Subprocessors: category, role and processing location
CategoryRoleLocation
Voice-AI platformHandles the call itselfSee DPA
Telephony carrierPhone numbers and call routingSee DPA
Database providerStores call logs, bookings and account dataEU — Frankfurt
Cloud hostingApp hosting and computeEU — Frankfurt
Payments providerPayments and billingSee DPA
Authentication providerLogin and authenticationSee DPA
Email providerSending email notificationsSee DPA
AI provider (setup)Reads your website when the receptionist is set upSee DPA
Content crawler (setup)Fetches your website's content during setupSee DPA

“See DPA” means the exact processing location and terms are set out in the data processing agreement, coming before the first paying customer. The fully named subprocessor list is available to customers on request and in the data processing agreement.

Contact

Questions about privacy or security? Write to us and we'll answer. support@phoneless.io