Skip to main content
01Security & GDPR

Your data
stays in the EU.

Hosting in the European Union, end-to-end encryption, strict per-customer isolation. Security, treated as a product, not a checkbox.

02Six pillars

Secure by default.

Hosting in the EU

Database and application hosted in the European Union. Our sub-processors established outside the EU are covered by standard contractual clauses.

End-to-end encryption

TLS 1.3 in transit, AES-256 at rest. Data isolated per customer.

Per-customer isolation (RLS)

PostgreSQL Row-Level Security enabled on every table. No customer can access another's data.

No training on your data

Your calls, transcriptions and customer records never feed an AI model. Contractual OpenAI Zero Data Retention.

Full GDPR

DPA available, records of processing, documented legal bases, DPO reachable. Self-service right to erasure.

Immutable audit logs

Every sensitive action is logged (timestamp, user, IP). Logs kept 12 months, cryptographically signed.

03Data retention

Nothing stays longer than necessary.

Every data category has a duration justified by a GDPR legal basis. Deletions are automatic, verified by a daily cron.

DataDetail
Audio recordingsNoneCalls are not recorded
Text transcriptions365 daysAutomatic anonymization
Call metadata24 monthsAggregated statistics
Billing data10 yearsFrench Commercial Code obligation
Admin access logs12 monthsSigned, tamper-proof
Inactive accounts36 monthsPermanent deletion
04Compliance

Standards & sub-processors.

GDPR

Compliant — Regulation (EU) 2016/679

CNIL

2021 cookie recommendations applied

OpenAI ZDR

Zero Data Retention on all models

Stripe

PCI-DSS Level 1 (payment sub-processor)

Security incident or GDPR question?

Write to security@softcallia.com — response within 24 business hours. To exercise your GDPR rights (access, rectification, erasure), use the dedicated form.

05Documentation

Official documents.

For a full contractual review, see our documents: