Data processing in the EU
We store call logs, bookings and account information ourselves, in the EU. The database runs in Frankfurt, and the servers that handle call and booking traffic also run in Frankfurt.
The call itself is handled by a specialised voice-AI subprocessor. That processing, and the storage that goes with it, takes place within the EU under a data processing agreement (DPA). Recordings are kept for 30 days and then deleted.
Everything is built for GDPR.
AI disclosure by default
Every single call opens with the receptionist stating that it is an AI. It never pretends to be a human.
This is both honest and required by law. The EU's Artificial Intelligence Act (Regulation (EU) 2024/1689) sets the requirement in Article 50. A provider of an AI system intended to interact directly with people must inform them that they are interacting with an AI. The requirement applies from 2 August 2026, and we already do it today.
Consent and recording
Calls are transcribed so you can read what was said, follow up on messages and improve the receptionist. Audio recording can also be turned on.
We collect as little as possible. The receptionist does not ask for sensitive personal data, and a booking is created only when the caller asks for it themselves.
You are in control of the data from your own business. The exact rules for retention, deletion and access are set out in the privacy policy and the data processing agreement.
Security
Data is encrypted both in transit and at rest. The database encrypts all content with AES-256 at rest, and all traffic runs over encrypted connections (TLS).
Each account only sees its own data. Calls, bookings and settings are isolated per business.
We are not SOC 2 certified yet. Certification is on the roadmap. We don't use badges we haven't earned, and we'll update this page once the certification is in place.
Subprocessors
We use a small set of carefully chosen subprocessors to deliver the service. For competitive reasons we list them by category — what they do, and where the data is processed.
| Category | Role | Location |
|---|---|---|
| Voice-AI platform | Handles the call itself | EU |
| Telephony carrier | Phone numbers and call routing | See DPA |
| Cloud infrastructure | App hosting, and storage of call logs, bookings and account data | EU — Frankfurt |
| Payments provider | Payments and billing | See DPA |
| Authentication provider | Login and authentication | See DPA |
| Email provider | Sending email notifications | See DPA |
| Content processing (setup) | Fetches and reads your website when the receptionist is set up | See DPA |
“See DPA” means the exact processing location and terms are set out in the data processing agreement. The fully named subprocessor list is available to customers on request and in the data processing agreement.
Contact
Questions about privacy or security? Write to us and we'll answer. support@phoneless.io