GDPR · EU AI Act · SOC 2

Security & Compliance

Your customers trust you with their data. We take that responsibility seriously. AINORA is built from the ground up with privacy, security, and regulatory compliance at its core.

GDPR

Compliant

EU AI Act

Ready

AES-256

Encryption

99.9%

Uptime SLA

GDPR Compliance

All data processed within the EU. Transparent data handling, strict retention policies, and full support for data subject rights including erasure.

EU AI Act Ready

Transparent AI usage — every caller is informed they are speaking with AI. Human oversight built in. No manipulation or deceptive practices.

Fully Encrypted

All data encrypted in transit (TLS 1.3) and at rest (AES-256). Secure API connections to your CRM. Zero plaintext storage of sensitive information.

Consent-Based Recordings

Call recordings only with explicit consent. Callers are informed at the start of every call. No recordings stored without authorization.

EU Infrastructure

All servers hosted in the European Union. SOC 2 Type II certified infrastructure providers. 99.9% uptime SLA for enterprise clients.

No AI Training on Your Data

Caller data and conversation content are never used to train AI models. Your customers' information stays private and is used solely for service delivery.

GDPR Compliance

AINORA processes all personal data in full compliance with the General Data Protection Regulation (GDPR). As a Lithuanian company operating within the EU, data protection is not an afterthought — it is a foundational requirement.

  • EU Data Residency: All customer data is processed and stored on servers located within the European Union. No data is transferred outside the EU/EEA.
  • No Third-Party Data Sharing: Customer conversation data is never sold, shared, or made available to third parties for marketing or any other purpose.
  • Data Retention Policies: We retain data only for as long as necessary to deliver the service. Retention periods are configurable by the business owner and clearly documented.
  • Right to Deletion: Any individual can request complete erasure of their personal data. We honor all GDPR data subject requests within 30 days.
  • Data Processing Agreements: We maintain DPAs with all sub-processors and infrastructure providers to ensure end-to-end compliance.

EU AI Act Compliance

The EU AI Act establishes the world's first comprehensive regulatory framework for artificial intelligence. AINORA is designed to meet these requirements from the outset.

  • Transparent AI: Every caller is informed at the beginning of the conversation that they are speaking with an AI assistant. There is no attempt to disguise AI as a human.
  • Human Oversight: Calls can be transferred to a real person at any point. Business owners maintain full control over what the AI can and cannot do.
  • No Manipulation: AINORA does not use subliminal techniques, exploit psychological vulnerabilities, or engage in deceptive practices to influence caller behavior.
  • Risk Classification: Our voice AI assistant is classified as limited-risk under the EU AI Act, requiring transparency obligations which we fully meet.

Data Security

We implement multiple layers of security to protect your business data and your customers' information at every stage.

  • Encryption in Transit: All data transmitted between your systems and AINORA is protected with TLS 1.3 encryption.
  • Encryption at Rest: Stored data is encrypted using AES-256, the same standard used by banks and government agencies.
  • Secure CRM Connections: API integrations with your CRM use OAuth 2.0 authentication and encrypted channels. We access only the minimum data required.
  • Access Controls: Strict role-based access controls ensure only authorized personnel can access system components. All access is logged and auditable.
  • Regular Security Audits: We conduct regular security assessments and vulnerability testing to identify and address potential risks proactively.

Voice AI Data Handling

Voice data requires special care. Here is exactly how we handle it.

  • Consent-Based Recording: Call recordings are only created when the business owner has enabled recording and the caller has been informed. Every call begins with a clear disclosure.
  • Real-Time Processing: Voice data is processed in real time to deliver the AI conversation. We minimize data retention — once the call ends, only the agreed-upon data (summary, booking details) is stored.
  • No AI Training: Your customers' voice data and conversation content are never used to train AI models. This is a firm policy, not a toggle.
  • Configurable Retention: Business owners can configure how long call recordings and transcripts are retained — from immediate deletion to custom retention periods.

Infrastructure

AINORA's infrastructure is designed for reliability, performance, and security.

  • EU-Based Servers: All production infrastructure runs on servers located within the European Union, ensuring compliance with EU data sovereignty requirements.
  • SOC 2 Type II Providers: Our cloud infrastructure providers maintain SOC 2 Type II certification, demonstrating rigorous security controls verified by independent auditors.
  • 99.9% Uptime SLA: Enterprise clients receive a 99.9% uptime guarantee, backed by redundant systems, automatic failover, and 24/7 infrastructure monitoring.
  • Disaster Recovery: Automated backups, geographic redundancy, and tested recovery procedures ensure your service remains available even during infrastructure incidents.

Frequently Asked Questions

Does AINORA store my customers' phone conversations?

Call recordings are only stored when explicitly enabled by the business owner and with caller consent. Every call begins with a disclosure that the conversation may be recorded. Recordings are stored encrypted within EU data centers and can be deleted at any time upon request.

Is my CRM data safe when connected to AINORA?

Yes. All CRM connections use encrypted API channels (TLS 1.3). We access only the minimum data required to deliver the service — typically calendar availability and customer contact details. We never export or replicate your full CRM database.

Can I request deletion of all my data?

Absolutely. Under GDPR, you have the right to erasure. Contact us at info@ainora.lt and we will delete all your data within 30 days. This includes call recordings, conversation logs, and any CRM-synced information.

How does AINORA comply with the EU AI Act?

AINORA ensures full transparency: every caller is informed they are speaking with an AI assistant. Human oversight is always available — calls can be transferred to a real person at any time. We do not use subliminal techniques, exploit vulnerabilities, or engage in social scoring.

Where are AINORA's servers located?

All infrastructure is hosted within the European Union. Our infrastructure providers maintain SOC 2 Type II certification, ISO 27001 compliance, and undergo regular third-party security audits.

Questions about security?

We are happy to discuss our security practices, provide additional documentation, or walk you through our compliance measures. Your trust matters to us.