AInora
The data path

Compliant is a word. The data path is a fact

Ask any voice AI vendor whether they are GDPR compliant and expect a yes every time, because the word costs nothing to print on a homepage. Ask them to trace one call instead, hop by hop, naming the company and the country at each one, and the answers separate immediately.

You think you are choosing a vendor. You are choosing a data path. A customer speaks. That audio leaves the phone network and enters something. It is transcribed by something, somewhere. The text goes to a model that runs somewhere, possibly on a different continent from the audio. A summary lands in a diary or a CRM. A recording sits in storage under someone else's retention policy.

Every one of those hops is a country, a company, a contract and a retention period. You are answerable for all of them: to the person who called you, to your regulator, and increasingly to the procurement team of whichever enterprise client is currently sending you a supplier assurance questionnaire. Your name is on the answer, not your vendor's.

This page is about the path the data takes. It is a separate question from what the agent must disclose on the call and which numbers it may present, which is the telephony layer and lives on our page on multi-country voice AI compliance. The long version of the argument below, with the statute references and the case law, is in the essay on where AI call data actually goes.

Six hops, six questions

Trace one call. At each hop, a different company holds a copy of your customer, on a clock you did not necessarily choose.

The line

Before anything is transcribed, the audio has already left the public phone network and entered a carrier or platform that terminates the media. That company sees the number, the timing and the call itself, and it keeps call detail records on a clock of its own.

Which legal entity terminates the media, and in which country?

The audio

Speech becomes text somewhere. This is the hop most buyers never ask about separately, and it is the one that matters most, because raw audio carries everything the words carry plus the voice that said them. A transcript is a reduction. The audio is not.

Where is the audio itself processed, and is it retained anywhere after the transcript exists?

The reasoning

The text goes to a model that runs on hardware in a specific region, quite possibly a different continent from the audio. Some inference providers retain inputs for abuse monitoring, on their own retention schedule, under their own contract with your vendor rather than with you. Whether yours does is a question with a real answer.

Which region does inference run in, and are inputs retained for monitoring? For how long, and by whom?

The write-back

A summary, a booking, a contact record lands in your CRM or your diary. That is a second copy of the same personal data, living under a different retention policy, in a different processor, often in a different jurisdiction from the call it came from. It is the copy people forget exists.

Which system of record receives the summary, and whose retention policy governs it once it arrives?

The recording

If a recording is kept, it sits in object storage under a retention period somebody chose. The question is who chose it. A retention period the vendor cannot change, because it is set by their storage supplier, is not a retention period you control.

Who sets the deletion clock on the recording: you, the vendor, or a supplier of the vendor?

The exhaust

Logs, backups, error traces, monitoring and analytics. Every hop above produces some of it, and it is where personal data quietly outlives the retention policy printed on the main system. It is also the part almost no sub-processor list mentions.

Which of these hops writes personal data into logs or backups, and on what schedule do those expire?

Why nobody can answer

The reason most vendors cannot trace the path is structural rather than evasive. Much of this category is assembled on top of a handful of specialist suppliers, and a supplier chosen for latency and unit price is not necessarily a supplier chosen for jurisdiction. Where one is swapped out for a cheaper one, the map goes stale without anyone updating it. The honest version of their answer is a list they have never written down, and writing it down would require asking their own suppliers questions they have never asked.

So the word compliant does the work instead. It is unfalsifiable, it is free, and until somebody asks the mechanical question it holds up perfectly. The mechanical question is not a legal question and it does not need a lawyer to ask. It is a routing question that happens to have legal consequences.

The single most useful distinction, and the one that catches the most vendors, is between where a company is registered and where the audio is processed. Those are different facts. A company incorporated inside the EU can, and often does, send audio to a transcription service in one country and text to an inference region in another, under contracts you have never seen, without any of it appearing on a website that says GDPR compliant in the footer.

The check you can run on anyone

Two sentences, sent by email, no legal budget required. Send them to us as well.

1. Please send your current list of sub-processors, with the country each one processes in.

2. Of those, which ones touch the raw audio, as distinct from the text derived from it?

The second sentence is the one that does the work. Plenty of vendors will produce a page of supplier logos, because that artefact is cheap and increasingly standard. Very few can tell you which of those suppliers hears the customer rather than reads a transcript of them, and that is the distinction that changes what a breach four hops down actually exposes.

Read the reply, not the tone of it. A vendor who has done the work sends a list, with countries, and often a few entries you had not thought to ask about. A vendor who has not sends the word compliant again, in a longer paragraph.

What we settle before anything is signed

01

The list, with countries

Every sub-processor in the path, named, with the country it processes in, in writing and before a contract exists. If we would be embarrassed to send it, that is a design problem on our side, not a disclosure problem on yours.

02

Audio separated from text

Which hops receive the recording itself and which receive only derived text. These carry different exposure and they get answered separately rather than folded into one sentence about hosting.

03

One clock per copy

The recording, the transcript, the summary in your system of record and the operational logs each get a retention period that you set and that is written down, rather than inherited silently from a supplier default.

Where the data sits by default is on our EU data residency page, the controls around it are on the security page, and what we do with data about you rather than your callers is set out separately. None of those pages is a substitute for the list, which is why we send the list.

Frequently Asked Questions

Is an AI receptionist GDPR compliant?

That question cannot be answered by a vendor, only claimed by one, which is why every vendor answers yes. Compliance is a property of a specific deployment: a specific chain of companies, in specific countries, under specific contracts, with specific retention periods. The answerable version is: send me the list of sub-processors in the path and the country each one processes in. A vendor who has done the work sends a list. A vendor who has not sends the word compliant again.

Where is patient call data stored?

There is no single storage location, and that is the point of the question. A clinic call produces audio, a transcript, model inputs, a summary in the practice system and a call detail record at the carrier. Those are five copies, potentially in five places, on five clocks. A vendor answering with one country and one sentence is describing where their company is registered, not where the data is processed.

Why does the country a vendor is registered in not answer the question?

Because a company can be registered in one country and process audio in another, through a supplier it did not name. Registration is a fact about the company. Processing location is a fact about each hop in the path, and the path set out on this page has six of them. The two are not the same fact and they are frequently not the same country.

Are we entitled to the sub-processor list, or is it a favour?

It is closer to an entitlement. Under Article 28 of the GDPR a processor may not engage another processor without the written authorisation of the controller, must impose the same obligations down the chain, and must make available to the controller all the information necessary to demonstrate compliance with its Article 28 obligations. The European Data Protection Board went further in its Opinion 22/2024, taking the view that controllers should have the identity of all processors and sub-processors readily available at all times, and that the processor should provide that information proactively and keep it current.

Why is deleting the recording not enough to honour an erasure request?

Because the recording is one copy. Article 19 requires the controller to communicate an erasure to each recipient to whom the data was disclosed, unless that proves impossible or takes disproportionate effort, and you cannot communicate anything to a recipient you cannot name. If the transcript, the model inputs, the CRM summary and the carrier record each sit with a different company on a different clock, deleting the audio completes one fifth of the job and leaves the rest quietly in place.

What does Ainora do about this?

We will name every sub-processor in the path and the country each one processes in, in writing, before anything is signed. Contact data and call records are processed on EU-hosted infrastructure with no US-default routing, we sign a Data Processing Agreement per client and act as your processor, and retention is configured by you and written down rather than assumed. What we will not do is give you a one-word answer, because a one-word answer is exactly what this page argues you should refuse.

This is general information about how to evaluate a supplier, not legal advice. Verify the current rules for your own use case and jurisdiction.

JB
Justas Butkus

Founder & CEO, AInora

Building AI digital administrators that replace front-desk overhead for service businesses across Europe. Previously built voice AI systems for dental clinics, hotels, and restaurants.

View all articles

A working session, not a demo

Forty-five minutes on your actual call flow. We take the policies your front desk already follows, draw the path a real call would take through them, and find the edge cases that break it. You keep the written data-path map and the vendor question sheet at the end, whether or not anything else happens. When something else does happen, it is one workflow first, usually missed calls and after hours, roughly two weeks, before anything else moves.

Send us your call flow