Trust & privacy

Where your data is processed, how we secure it, and who we work with — said plainly.

Terms, our privacy policy and a data processing agreement (DPA) are published on our legal pages. Read the DPA

Data processing in the EU

We store call logs, bookings and account information ourselves, in the EU. The database runs in Frankfurt, and the servers that handle call and booking traffic also run in Frankfurt.

The call itself is handled by a specialised voice-AI subprocessor. That processing, and the storage that goes with it, takes place within the EU under a data processing agreement (DPA). Recordings are kept for 30 days and then deleted.

Everything is built for GDPR.

AI disclosure by default

Every single call opens with the receptionist stating that it is an AI. It never pretends to be a human.

This is both honest and required by law. The EU's Artificial Intelligence Act (Regulation (EU) 2024/1689) sets the requirement in Article 50. A provider of an AI system intended to interact directly with people must inform them that they are interacting with an AI. The requirement applies from 2 August 2026, and we already do it today.

Consent and recording

Calls are transcribed so you can read what was said, follow up on messages and improve the receptionist. Audio recording can also be turned on.

We collect as little as possible. The receptionist does not ask for sensitive personal data, and a booking is created only when the caller asks for it themselves.

You are in control of the data from your own business. The exact rules for retention, deletion and access are set out in the privacy policy and the data processing agreement.

Security

Data is encrypted both in transit and at rest. The database encrypts all content with AES-256 at rest, and all traffic runs over encrypted connections (TLS).

Each account only sees its own data. Calls, bookings and settings are isolated per business.

We are not SOC 2 certified yet. Certification is on the roadmap. We don't use badges we haven't earned, and we'll update this page once the certification is in place.

Subprocessors

We use a small set of carefully chosen subprocessors to deliver the service. For competitive reasons we list them by category — what they do, and where the data is processed.

Subprocessors: category, role and processing location
CategoryRoleLocation
Voice-AI platformHandles the call itselfEU
Telephony carrierPhone numbers and call routingSee DPA
Cloud infrastructureApp hosting, and storage of call logs, bookings and account dataEU — Frankfurt
Payments providerPayments and billingSee DPA
Authentication providerLogin and authenticationSee DPA
Email providerSending email notificationsSee DPA
Content processing (setup)Fetches and reads your website when the receptionist is set upSee DPA

“See DPA” means the exact processing location and terms are set out in the data processing agreement. The fully named subprocessor list is available to customers on request and in the data processing agreement.

Contact

Questions about privacy or security? Write to us and we'll answer. support@phoneless.io