Data processing in the EU
Everything we store ourselves — call logs, bookings and account information — sits in the EU. The database runs in Frankfurt, and the servers that handle call and booking traffic also run in Frankfurt.
The call itself is handled by the voice AI of a US-based subprocessor. Full EU data storage requires an extended agreement with the provider — which we have not enabled. So we do not claim the voice data is processed in the EU; how that data flow is governed is set out in the data processing agreement (DPA).
Everything is built for GDPR.
AI disclosure by default
Every single call opens with the receptionist stating that it is an AI. It never pretends to be a human.
This is both honest and required by law. The EU's Artificial Intelligence Act (Regulation (EU) 2024/1689) requires, in Article 50, that a provider of an AI system intended to interact directly with people informs them that they are interacting with an AI. The requirement applies from 2 August 2026 — we already do it today.
Consent and recording
Calls are transcribed so you can read what was said, follow up on messages and improve the receptionist. Audio recording can also be turned on.
We collect as little as possible. The receptionist does not ask for sensitive personal data, and a booking is created only when the caller asks for it themselves.
You are in control of the data from your own business. The exact rules for retention, deletion and access are set out in the privacy policy and the data processing agreement, coming before the first paying customer.
Security
Data is encrypted both in transit and at rest. The database encrypts all content with AES-256 at rest, and all traffic runs over encrypted connections (TLS).
Each account only sees its own data. Calls, bookings and settings are isolated per business.
We are not SOC 2 certified yet. It is on the roadmap — we don't use badges we haven't earned, and we'll update this page once the certification is in place.
Subprocessors
We use a small set of carefully chosen subprocessors to deliver the service. For competitive reasons we list them by category — what they do, and where the data is processed.
| Category | Role | Location |
|---|---|---|
| Voice-AI platform | Handles the call itself | See DPA |
| Telephony carrier | Phone numbers and call routing | See DPA |
| Database provider | Stores call logs, bookings and account data | EU — Frankfurt |
| Cloud hosting | App hosting and compute | EU — Frankfurt |
| Payments provider | Payments and billing | See DPA |
| Authentication provider | Login and authentication | See DPA |
| Email provider | Sending email notifications | See DPA |
| AI provider (setup) | Reads your website when the receptionist is set up | See DPA |
| Content crawler (setup) | Fetches your website's content during setup | See DPA |
“See DPA” means the exact processing location and terms are set out in the data processing agreement, coming before the first paying customer. The fully named subprocessor list is available to customers on request and in the data processing agreement.
Contact
Questions about privacy or security? Write to us and we'll answer. support@phoneless.io