Where is the data hosted?
The application and PostgreSQL database are hosted in the European Union. Voice AI and generation providers process the data needed for their services, sometimes outside the EU with contractual safeguards (standard contractual clauses, Data Privacy Framework).
Each provider, its country, and its safeguards are listed on the subprocessors page. We do not claim complete data sovereignty.
Is audio stored?
No. Conversations are processed live and transcribed. The application does not archive audio files. Voicemail is held in memory until transcription is complete, then deleted.
Transcripts, call reports, and documents are data that need protection. By default, transcripts are deleted after 180 days. Call reports are deleted after 365 days and then become anonymous statistics. With Business, these periods can be set from 30 days to 3 years.
Who can access what?
Organizations are isolated: one organization can never see another’s data. Permissions depend on the user’s role. Two-factor authentication is available to everyone and can be required across the organization with Business. Connections use HTTPS.
Encryption at rest depends on the storage services selected and will be confirmed for your rollout. No external audit or certification is claimed as completed.
What does the audit log track?
Administrative and security actions: accounts, roles, settings, exports, and consents. The audit log can be exported as a CSV with Business.
Each person can export their data or request its deletion. The owner can export the entire organization or delete it, in which case a deletion certificate is sent.
How is AI disclosed?
Before each call, users are told they’re speaking with an AI-simulated customer and that their words will be transcribed. Call reports indicate that they’re AI-generated.
Scoring analyzes the text using an explicit scoring grid. It does not analyze emotions or personality. A score should not be used on its own to make an HR decision. This page is not an AI Act certification.
How do you report a problem?
Contact us through the contact page, describing the problem and the steps to reproduce it. Don’t send passwords, session tokens, or bulk copies of data.
You can also write to us at NOZZL SAS. We don’t specify a response time or on-call coverage.
