Data & Security

Your calls are your most sensitive data. We built like it.

A call recording contains your customers' voices, their personal details and your business playbook — all at once. That's why we made a decision most AI companies don't: we run the entire pipeline ourselves, in Europe.

Why we rebuilt everything

The easy way to build an AI call analysis product is to chain together American AI APIs: one vendor for transcription, another for analysis, another for search. It's fast to ship — and it means your customers' voices travel through a chain of sub-processors on another continent, each one a line item in your GDPR risk assessment.

We started there, like everyone. Then we did the harder thing: we rebuilt the entire pipeline — transcription, speaker separation, voice intelligence, AI analysis, embeddings and storage — to run on European infrastructure under our own operational control, using models we run ourselves.

The result is simple to explain to any DPO: your audio enters our EU infrastructure, is processed there, stays there, and leaves only if you export or delete it.

European data residency

Call audio, transcripts, analysis results and search indexes are stored and processed exclusively within the European Union. Nothing crosses the Atlantic — not for transcription, not for AI analysis, not for anything.

Infrastructure we operate ourselves

We deliberately rebuilt our platform to run the entire pipeline — transcription, voice intelligence, analysis and storage — on infrastructure under our own operational control. There is no third-party AI service in your data path, which means no surprise sub-processors in your vendor review.

PII redaction before storage

Optionally strip emails, phone numbers, national ID numbers, IBANs, card numbers, names and addresses from transcripts before they are stored or analyzed. Configure it once per account, override it per campaign when different clients need different rules.

Strict tenant isolation

Every query, every search, every analysis is scoped to your account at the data layer. Your calls, scorecards and knowledge bases are never visible to — or mixed with — any other customer, in any feature.

Short-lived working data

Files created while processing a call are transient by design and cleaned up automatically within a day. What persists is what you see in the product — and it stays within your storage quota, under your control.

GDPR self-service

Export all of your data as JSON or delete your account entirely — directly from Settings, no support ticket, no waiting period. Deleting a call removes it; deleting your account removes everything.

The questions your DPO will ask

Straight answers, no legalese.

Who processes our call data?

Sumgrey operates the processing pipeline end to end on European infrastructure. There are no third-party AI providers in the data path — which keeps your Data Processing Agreement short and your sub-processor list shorter.

Is our data used to train AI models?

No. Your recordings, transcripts and analysis results are used to deliver the service to you — nothing else. They are never used to train or fine-tune models.

Can we limit what personal data is stored?

Yes. Enable PII redaction and identifiers like emails, phone numbers, national IDs, IBANs, card numbers, names and addresses are removed from transcripts before storage and analysis. You can also delete individual calls or your entire account at any time.

Where exactly is the data located?

All storage and processing happens in the European Union. If your compliance review needs more architectural detail, we're happy to walk your team through it directly — during the beta you'll be talking to the people who built it.

Do you hold security certifications?

We are an early-stage product and we won't claim badges we haven't earned yet. What we offer today is an honest, verifiable architecture: EU-only processing, operator-controlled infrastructure, PII redaction, tenant isolation and self-service data rights. Formal certifications are on our roadmap as we grow.

Bring your compliance team. We like those conversations.

Try the platform free with PII redaction enabled, or book a call and we'll walk your team through exactly how your data is handled.

Full data & privacy details in our Privacy Policy