Keeping Voice AI Data Inside the EU
Text data gets treated carefully. Voice data often does not, which is odd, because a recorded call is usually the more revealing of the two. It carries the words, and it also carries who was speaking, what they sounded like, what they let slip while thinking out loud, and whatever a colleague said in the background.
Audio is personal data
Under the GDPR a recorded call is personal data, and a voice is capable of identifying the person it came from. That puts the whole pipeline in scope: the live stream while the call is running, whatever is buffered mid-processing, the transcript, the summary, and anything derived from them afterwards.
Which makes the honest question about a voice AI vendor a geographic one rather than a policy one. Not "are you GDPR compliant", because everyone says yes. The question is where the audio physically goes between the caller speaking and your dashboard showing a transcript.
Questions worth asking
- Where is the speech model hosted, and is it yours or an API call to somebody else's region?
- Where is audio buffered while the call is in flight, as opposed to where the recording is eventually stored?
- Where do the transcript, the summary and the embeddings live, and for how long?
- Who are the sub-processors, and does the list change without notice?
- What happens to all of it when a customer asks for deletion?
A vendor whose answer to the first two is "our provider handles that" has told you the answer is somewhere else. That is not automatically disqualifying, but it is a fact about your compliance posture, not theirs, and it should be written down rather than assumed.
Cirel is built in Europe and runs on EU infrastructure, with call recordings stored in Switzerland under its adequacy finding. That was an architectural decision rather than a certificate collected afterwards, which is the part that matters: GDPR-native means the data path was drawn that way from the start, not routed back after somebody asked.
It has a practical upside beyond compliance. The same choice that keeps audio inside the EU is what lets Memory hold one shared customer record with recall under 200ms, close to where the calls are actually happening. Handling more than 40 languages with native voices does not require shipping the audio out of the region either.
If you want the data path drawn out properly for your own setup, book a demo and ask.