Trust centre
How ParlioTec handles your callers' data. Updated 21 Sept 2026, 18:11 · live service status at /status.
Data residency
Call records, transcripts, recordings and the database are hosted in the UK (DigitalOcean London). Speech, language and voice vendors are listed below with their processing region; UK-region and self-hosted profiles are available for customers who require no data to leave the UK.
Data processing agreement
ParlioTec acts as processor for our customers (controllers). Our DPA incorporates the UK GDPR Article 28 terms and the UK Addendum to the EU SCCs for any transfer to sub-processors outside the UK. Request a signed copy from support.
Call recording & consent
Assistants announce recording at the start of every call where recording is enabled. Recording, transcription and retention are configurable per assistant; default retention is 90 days with automatic purge and PII redaction options.
Security
TLS everywhere, encrypted credential vault for PBX/SIP secrets, per-tenant row-level isolation in PostgreSQL, TOTP two-factor authentication with per-tenant enforcement, SSO/SCIM for Enterprise, audit log of every staff and admin action, dependency and container scanning in CI.
Incident response & breach notification
24x7 on-call for P1 incidents with a 15-minute acknowledgement target, public status page updates within 30 minutes, root-cause analysis within 48 hours for Enterprise customers. Personal-data breaches are notified to affected customers without undue delay and within 72 hours as required by UK GDPR.
Telephony demarcation
ParlioTec is responsible for the SIP edge, media and AI platform. Customers remain responsible for their own phone line, call forwarding and PBX configuration; our Health page classifies faults as customer, carrier or ParlioTec with an evidence pack to share with your provider.
Data subject rights
Export and erasure of a caller's data is available in-product (Compliance → GDPR) and honoured across recordings, transcripts, contacts and tickets.
Certifications
Cyber Essentials in progress; ISO 27001 and SOC 2 Type II on the roadmap. Sub-processors hold SOC 2 / ISO 27001 as noted in their DPAs.
Sub-processors
| name | purpose | region | dpa |
|---|---|---|---|
| Deepgram | speech-to-text | US (EU endpoint available) | yes |
| OpenAI | conversation / summaries / QA | US (zero data retention API) | yes |
| Cartesia | text-to-speech | US | yes |
| Telnyx | UK numbers, SIP, SMS | UK/EU PoPs | yes |
| DigitalOcean (London) | API, database, media, LiveKit | UK | yes |
| Cloudflare | dashboard hosting / TLS | global edge | yes |
| Supabase | dashboard sign-in | EU (London) | yes |