VoiceDock · Flireo B.V.

Your data stays in the EU.
You choose the models.

The proof behind VoiceDock's security posture, in one place. EU hosting, a plainly-named sub-processor list, a GDPR-compliant DPA, and the sovereignty story of a stack we own end to end.

Data residency

EU only

Frankfurt (data) · Nuremberg (real-time media)

Infrastructure

ISO 27001 · SOC 2

Certified EU cloud regions and hosting

Standard DPA

GDPR Art. 28

Ready to sign, at no additional cost

Sub-processors

7 listed

Every one named, with transfer basis

Compliance & certifications

Certified where it counts, honest about the rest

Certifications are attributed to the layer that actually holds them. We never claim a certification Flireo does not itself hold.

Certified EU infrastructure

Our platform runs on ISO 27001 and SOC 2 Type II certified EU cloud regions and hosting. These certifications are held by our infrastructure providers, not by Flireo.

GDPR & EU transfers

GDPR-aligned by design. Where a sub-processor has a US parent, all transfers run under EU Standard Contractual Clauses. Hosting is EU-only: EU (Germany: Frankfurt for platform data, Nuremberg for real-time media).

Data Processing Agreement

A ready-to-sign, GDPR Article 28-compliant Standard DPA is included at no additional cost for the recommended EU configuration. See the document hub below.

What Flireo B.V. holds itself: ISO 27001 — Not held by Flireo itself. SOC 2 — Not held by Flireo itself. We inherit these standards from our certified infrastructure and are deliberately transparent about the distinction rather than implying a company-level certificate we do not hold.

Document hub

Everything a reviewer needs, self-serve

Public documents are readable inline and can be saved as a PDF. Documents marked confidential are released through the reviewer document room once access is approved. Every document is version-controlled, so what you read is always the current version.

Agreements & policies

Data Processing Agreement

v1.0

Confidential · effective 2026-08-01

Data Processing Agreement — full text

v1.0

Confidential · effective 2026-08-01

Terms and Conditions

v1.0

Signed PDF · effective 2026-01-01

Privacy Policy

v1.0

Readable · effective 2026-08-01

Fair Use Policy

v1.0

Readable · effective 2026-08-01

Cookie Policy

v1.0

Readable · effective 2026-08-01

Data & residency

EU Data Sovereignty

v1.0

Confidential · effective 2026-08-01

Data Retention & Deletion

v1.0

Confidential · effective 2026-08-01

Sub-processors

v1.0

Confidential · effective 2026-08-01

Security & resilience

Security Overview

v1.0

Confidential · effective 2026-08-01

Incident Response & Breach Notification

v1.0

Confidential · effective 2026-08-01

Business Continuity & Disaster Recovery

v1.0

Confidential · effective 2026-08-01

Vulnerability Disclosure Policy

v1.0

Readable · effective 2026-08-01

Knowledge base

Security Questionnaire

v1.0

Confidential · effective 2026-08-01

Sub-processors

Every sub-processor, named plainly

No hidden parties. Where a processor has a US parent operating in an EU region, we say so and state the transfer basis. Last reviewed 2026-07-27.

Sub-processorPurposeData residencyTransfer basisCertifications
Hetzner Online GmbHcall audio, orchestration, on-premise STT and TTSVoice infrastructure hosting (real-time media and orchestration)Germany (Nuremberg). Gunzenhausen is the registered office, not the data centreEU entity (Germany). No transfer mechanism required
ISO 27001ISO 27018ISO 27701
Supabase, Inc.account data, call records, transcripts, recordingsManaged database and storage hostingGermany (Frankfurt, eu-central-1)EU SCCs 2021/914, completed in Schedule 2 of the executed DPA: Module Two where Flireo is controller (account data), Module Three where Flireo is processor on a customer's behalf (call data). Docking clause (Clause 7) excluded; Clause 9(a) Option 2 with a 30-day sub-processor notice period; Clause 17 Option 1, Irish law; Clause 18, courts of Ireland. UK and Swiss addenda included.
SOC 2 Type IIISO 27001
Telnyx LLCcall audio (telephony leg), CDRs, phone numbersTelephony (SIP inbound/outbound, numbers)EU points of presenceHQ USA, EU SCCs in place
SOC 2ISO 27001
Vercel Inc.dashboard traffic, site trafficDashboard and site hostingEU region functionsHQ USA, EU SCCs in place
SOC 2 Type 2
Stripebilling dataPayment processingEU / IrelandEU contracting entity; onward transfer to Stripe, Inc. under EU SCCs
PCI DSS Level 1SOC 1/2
Sentry (Functional Software, Inc.)error events, stack traces, request metadataServer-side application error monitoring (crash reports and stack traces)EU (Frankfurt, Germany) — organisation data-storage region set to European UnionHQ USA. Their DPA relies primarily on the EU-US Data Privacy Framework, with the 2021/914 SCCs as the stated fallback should the Framework be invalidated. Verified against their published DPA on 2026-07-28. No separate EU entity; their SCC schedule names the Irish Data Protection Commissioner as the competent supervisory authority.
SOC 2 Type IIISO 27001
Resendemail addressesTransactional emailEU (eu-west-1, Ireland)HQ USA. Their DPA relies on the EU-US Data Privacy Framework (and its UK extension) alongside the 2021/914 SCCs for transfers out of the EEA. Incorporated automatically on entering their agreement; no separate signature. Verified against their published DPA and terms on 2026-07-28.
SOC 2

AI providers

Engaged only when an agent is configured to use them

Which of these apply differs per agent. Two columns matter most to reviewers and are stated plainly: whether the provider trains on call data, and how long they keep it.

ProviderPurposeData residencyTrainingRetention
Google (Gemini Developer API, via Google AI Studio)Platform defaultRealtime speech-to-speech and post-call analysisNo EU data residency on any tier. Google's terms state that data may be stored transiently or cached in any country where Google or its agents maintain facilities, and Google's data-residency product list does not include the Gemini Developer API. Vertex AI is the only EU-resident route. Not used for model improvement on the paid tier. On the unpaid tier Google does use submitted content to develop its products and human reviewers may read it. The boundary is whether an active Cloud Billing account is attached, not whether the interface is called AI Studio or the API. Not published. Google's terms state prompts and responses are logged "for a limited period of time" for policy enforcement, without a number. The widely cited 55 days is a different thing: it is the developer-owned logging feature, which is opt-in and separate from abuse-monitoring logs. Zero data retention is available for paid projects on approval.
Google (Vertex AI)Realtime speech-to-speech and post-call analysis, when the agent sets vertexai=trueeurope-west4 (Netherlands), selected at the Google Cloud project and Vertex API levelNot used to train or fine-tune Google modelsNo persistent storage after the call; implicit caching is disabled at project level. Google may retain prompts up to 90 days in the region of origin where automated safety classifiers flag content for abuse review.
Mistral AILanguage model inference and speech-to-text (Voxtral)European Union by default. A US endpoint exists but is an explicit opt-in that VoiceDock does not use. Core inference runs on Microsoft (Sweden, Norway) and CoreWeave (EEA) infrastructure. Excluded by default on the Scale plan; enabled by default on the free tier. Opt-out is available in the admin console for API traffic. Thirty rolling days for abuse monitoring. Zero retention exists but is Scale-plan only, stateless endpoints only, and granted on application
GladiaSpeech-to-textVoiceDock selects their EU-West region by default, but the contract's own Annex I states data localization as **"Europe, USA"**, and Annex III lists Gladia Inc. (Delaware) as a sub-processor performing storage and processing of "Voice, transcripts". Their US entity handles the call audio itself. Further names in that annex, including OpenAI, Meta, Together, DeepL, Private AI and Mistral, also carry the USA in scope. Treat as EU-default with a materially non-EU chain, not EU-only. Excluded. Their privacy notice §1.3 states that the datasets used to test and improve their models are publicly available CC-BY corpora and that "the Datasets do not contain any voice recordings from the use of the AI Service". Separately, their security page confirms paid plans are excluded from model training; only free-plan data is used. Both statements point the same way. Twelve months. Annex I of the contract defines the data retention period as "the length of time Gladia, as a vendor, stores customer data after it has been processed or received" and sets it at "Standard (12 months)". This matches their trust centre. Zero retention is available as an enterprise feature and Flireo has deliberately not taken it, so twelve months applies to call audio and transcripts routed through this provider. CORRECTION 2026-07-28: this entry previously claimed their documentation contradicted itself, citing "duration of the agreement plus five years" against the twelve months. That was a misreading on our side. Both figures appear in the same annex and mean different things: "Duration of processing" is how long the processing relationship runs, "Data retention period" is how long they keep the data. There is no contradiction, and this was wrongly flagged as the highest-priority open question. Customers who need call audio not to sit at a third party for a year should use on-premise speech-to-text instead.
Deepgram, Inc.Speech-to-textUnited States, because VoiceDock has not yet switched to their EU endpoint. That endpoint (api.eu.deepgram.com) reached general availability in December 2025 and, per Deepgram's own announcement, keeps processing "fully inside the EU legal boundary". It uses the same API keys and SDKs, has no waitlist, no activation step and no price difference, and requires only replacing the base URL. It covers speech-to-text, text-to-speech, the voice agent and text intelligence endpoints; the sole exclusion is their hosted Whisper models, which VoiceDock does not use because it runs Whisper on its own hardware. So the gap between this entry and EU residency is one configuration line, not a migration. Scheduled for v1.1 (ClickUp 869e9v97x). Until it ships, this entry states where the data actually goes rather than where it could go. Note their privacy policy still says data is stored on US servers. That policy dates from October 2021 and predates the EU endpoint; it is stale rather than contradictory. ENABLED by default. Deepgram's own pricing page states that the published rates opt in to their Model Improvement Program. Exclusion requires sending mip_opt_out=true on each request. Their sub-processor page also notes that data may be shared with third-party speech recognition providers, "including industry peers", for benchmarking unless opted out. Not published. Their documentation says only that they store "fractional increments of data". Opted-out requests are retained only for the duration needed to process them.
ElevenLabs (Eleven Labs Inc.)Text-to-speech and speech-to-text (Scribe)Hosting in the United States, the Netherlands and Singapore. EU data residency is an Enterprise feature. Note that residency limits storage only: their documentation states processing may still occur outside the selected location, including by affiliates and sub-processors. Only the combination of EU residency, Zero Retention Mode and API use restricts processing to the EU. DISABLED on Flireo's account. ElevenLabs enables training by default on non-Enterprise accounts, including paid self-serve API use; the "Improve the models for everyone" setting under Terms and privacy, Data use has been switched off on our account, confirmed 2026-07-28. Customers using their own ElevenLabs key control this setting themselves and should check it. Two years by default for agent conversation data (transcripts and audio recordings held separately), configurable per agent down to scheduled deletion. Zero Retention Mode is Enterprise-only.
OpenAI Ireland LtdLanguage model inferenceOutside the EEA by default, primarily the United States. A Europe region (eu.api.openai.com) keeps both storage and processing in the EEA and Switzerland, but it can only be selected when a project is created, cannot be applied to existing projects, and is subject to eligibility via sales. Not used to train or improve models unless explicitly opted inThirty days for abuse-monitoring logs. The audio transcription and translation endpoints are listed with no retention. Zero retention is available for eligible customers on prior approval.
xAI (X.AI LLC)Realtime speech-to-speech and language model inferenceUnited States. Their EU privacy addendum states all personal information is processed in the US, and every entry on their sub-processor list is US-based except one UK subsidiary. Marketing pages mention "EU data residency options" but no EU endpoint is documented and the previously indexed regional endpoint now returns not-found. Not used to train on API inputs or outputs without explicit permissionThirty days, encrypted at rest, for abuse auditing. Zero data retention is available and, uniquely among these providers, self-serve from the console
Inworld (Theai, Inc.)Text-to-speechUnited States. All ten of their published sub-processors are US-located. EU data residency is listed as an Enterprise feature on their pricing page and an EU portal exists, but no technical documentation describes what stays in the EU. Their terms state they do not train generally available models on non-public materials, except for feedback and content flagged for trust and safety review. Their speech-to-text documentation states audio is never used for training by Inworld or any upstream provider. Note the tension with the broad licence in their terms to use materials to "operate, maintain, and improve the Services". Not published. Zero data retention exists but is configured per workspace via their sales team

On your own API keys. Supplying your own provider key changes who pays, not who processes. We still route the audio and make the call from our infrastructure, so the provider remains our sub-processor and stays on this list. What your key does change is the account settings, which are then yours to control: retention and training defaults differ per provider, and the table above states them.

Security practices

How the platform protects call data

Encryption in transit and at rest

Traffic is encrypted in transit; call records, transcripts and recordings are encrypted at rest in the EU region.

Per-tenant isolation

Each organisation's data is isolated with row-level security. One customer can never read another customer's calls or configuration.

Vault-managed secrets

Provider keys and credentials are held as managed secrets, never in plaintext config, and scoped to the organisation that owns them.

Bring your own keys (BYOK)

Route model traffic through your own provider accounts and DPAs. You keep control of where your call content is processed.

GDPR mode

A configuration that keeps processing on the EU-compliant path (Vertex EU) and is the scope under which the Standard DPA applies.

Recording consent

Recording and retention are configurable per assistant, so you can meet the consent and data-minimisation rules your use case requires.

Live platform statusCurrent uptime and incident history, updated automatically.

Data residency

Sovereign by architecture, not by promise

Customer data is processed and stored in the EU. US-parent sub-processors operating in EU regions are named plainly and run under EU Standard Contractual Clauses. For workloads that need absolute CLOUD Act immunity, we offer on-premise deployment.

Request the EU data sovereignty explainer
Platform data (DB, storage)
Frankfurt, eu-central-1
Real-time media & orchestration
Nuremberg, Germany
Generative AI (Vertex path)
europe-west4, Netherlands
Transfer basis for US parents
EU Standard Contractual Clauses
CLOUD Act immunity option
On-premise deployment

Not sure which configuration you need?

Answer a few questions and get an indicative view of the VoiceDock configuration that fits your requirements and your likely compliance posture. It is an estimate, not legal advice, and takes about a minute.

Start the self-assessment

Request a security review

Need something for your vendor assessment?

Tell us what your due diligence needs, whether that is the signed DPA, a filled security questionnaire, or a conversation with the people who run the infrastructure. We answer these ourselves.

Or email us directly at support@flireo.com.