Your data
stays in the EU.
Hosting in the European Union, end-to-end encryption, strict per-customer isolation. Security, treated as a product, not a checkbox.
Secure by default.
Hosting in the EU
Database and application hosted in the European Union. Our sub-processors established outside the EU are covered by standard contractual clauses.
End-to-end encryption
TLS 1.3 in transit, AES-256 at rest. Data isolated per customer.
Per-customer isolation (RLS)
PostgreSQL Row-Level Security enabled on every table. No customer can access another's data.
No training on your data
Your calls, transcriptions and customer records never feed an AI model. Contractual OpenAI Zero Data Retention.
Full GDPR
DPA available, records of processing, documented legal bases, DPO reachable. Self-service right to erasure.
Immutable audit logs
Every sensitive action is logged (timestamp, user, IP). Logs kept 12 months, cryptographically signed.
Nothing stays longer than necessary.
Every data category has a duration justified by a GDPR legal basis. Deletions are automatic, verified by a daily cron.
| Data | Detail |
|---|---|
| Audio recordings | None —Calls are not recorded |
| Text transcriptions | 365 days —Automatic anonymization |
| Call metadata | 24 months —Aggregated statistics |
| Billing data | 10 years —French Commercial Code obligation |
| Admin access logs | 12 months —Signed, tamper-proof |
| Inactive accounts | 36 months —Permanent deletion |
Standards & sub-processors.
GDPR
Compliant — Regulation (EU) 2016/679
CNIL
2021 cookie recommendations applied
OpenAI ZDR
Zero Data Retention on all models
Stripe
PCI-DSS Level 1 (payment sub-processor)
Security incident or GDPR question?
Write to security@softcallia.com — response within 24 business hours. To exercise your GDPR rights (access, rectification, erasure), use the dedicated form.
Official documents.
For a full contractual review, see our documents: