Security

Built in Europe. Written into the contract.

Security you can read in the contract.

Your calls are processed in the EU and your core data is stored in Germany. Encryption, access, providers and deletion are written into our Data Processing Addendum, not only promised on a page.

Data kept in Europe

  • Stored in Germany

    Core application data is stored in Germany, with a partner certified to ISO 27001 and audited to SOC 2 Type 2. Recordings are stored only in Germany or Switzerland.

  • Processed in the EU

    The models behind your calls run on EU infrastructure, and call audio is processed in the EU.

  • Not training data

    Neither Cirel nor its providers may train general-purpose AI models on your data unless a separate written agreement first sets out the purpose and the safeguards.

Security in the contract

  • Encrypted in transit and at rest

    Connections run over TLS 1.2 or higher, and data at rest is encrypted with AES-256, recordings and backups included.

  • Least-privilege access

    Access to customer data is limited to what the work needs, and every workspace is kept separate from every other.

  • Providers disclosed before processing

    The provider annex and the processing register for your workspace come with your agreement. A new provider needs 15 days' written notice, and you can object.

  • Breach notice

    If a personal data breach affects your data, you are told without undue delay.

Full ownership and flexibility

Export and delete your data with the dashboard controls, with our help where they do not cover a request. When the service ends you can take an export for 30 days, and the rest is deleted within 90. Enterprise customers can run with zero data retention, or send call transcripts, artifacts and recordings to their own private bucket on AWS S3, Google Cloud Storage or Cloudflare R2, so the record lives in their tenancy and under their keys.

Compliance & certifications

The rules we work under, and the certifications behind the infrastructure we build on.

GDPR

Cirel processes personal data under the EU GDPR, the UK GDPR and the Swiss FADP, and our Data Processing Addendum puts that in writing.

ISO 27001, data storage

The database that holds your core application data is run by an infrastructure partner certified to ISO 27001. The certificate is the partner's, not Cirel's.

SOC 2 Type 2, data storage

The same partner is audited to SOC 2 Type 2 every year by an independent auditor. The report covers the partner's platform, not Cirel as a company.

PCI DSS, payments

Card payments go through our payment processor's hosted checkout, certified to PCI DSS Level 1, so no full card number is stored on our side.

“We had specific requirements around data security, EU data handling and access for different team members. Cirel took the time to understand those requirements and worked closely with us to tailor a solution. We can manage access by role and keep data separate between team members, which gives us peace of mind when using the platform on a day to day basis.”

Jamie Hueg

Green Tech Logistics

A loaded container ship under way at sea, seen from above

Your data. Your decisions.

You decide what is kept, where it lives and who sees it.

Data retention

Run with zero data retention on an enterprise agreement: recordings, transcripts and artifacts are processed for the call and not kept afterwards.

Export and deletion

Export and delete data from the dashboard. When the service ends, you have 30 days to take an export before the rest is deleted.

Your own storage

Send transcripts, artifacts and recordings to your own private bucket, so the record lives in your tenancy and under your keys.

Access and roles

Invite your team and decide what each person sees, down to an appointments-only role for field reps.

FAQ

Connections run over TLS 1.2 or higher, and data at rest is encrypted with AES-256, recordings and backups included. Ordinary phone networks are not end-to-end encrypted, and we do not claim they are.

Core application data is stored in Germany, and recordings only in Germany or Switzerland. The models behind your calls run on EU infrastructure, and call audio is processed in the EU.

Not as a company. The database that holds your core application data is run by an infrastructure partner that is certified to ISO 27001 and audited to SOC 2 Type 2, and those certifications are the partner's. What Cirel commits to is written into the Data Processing Addendum. Questions from a security review can go to la@cirel.ai.

No. Neither Cirel nor its providers may train general-purpose AI models on your data unless a separate written agreement first sets out the purpose, roles, legal basis and safeguards.

When the service ends you can take an export for 30 days, and the rest is deleted within 90. Deleted data leaves the encrypted backups within 35 days.

The provider annex and the processing register for your workspace come with your agreement, before your data is processed. A new provider needs 15 days' written notice, and you can object.

Have a security review coming up?

Book a demo, and bring your questionnaire.