§ Answer · Data protection
Is an AI phone assistant GDPR and revDSG compliant?
Yes, provided data location, encryption and processing responsibilities are settled. Auralinx stores calls, transcripts and appointment data exclusively on certified servers inside the EU, encrypts them with AES-256, and puts a data processing agreement in place automatically on signup. Customer data is never used to train AI models.
Key facts
- Data resides in the EU only. Call data does not leave the EU.
- AES-256 encryption, both during the call and at rest.
- A data processing agreement (DPA) applies automatically on use.
- Configurable retention: automatic deletion after 30, 60 or 90 days.
- Customer data is never used to train AI models.
Where is my callers' data stored?
Calls, transcripts and appointment data sit on certified servers inside the European Union and do not leave the EU. Data is encrypted with AES-256 both during the call and at rest, making it unreadable to anyone without explicit access.
Who is answerable to the supervisory authority?
You remain the controller under GDPR and the revised Swiss Data Protection Act. Auralinx is the processor. The data processing agreement sets out that split and applies automatically on use — you do not need to request it separately.
The full agreement is on the DPA page; processing purposes and retention periods are set out in the privacy policy.
What happens with an access or deletion request?
Callers can request access to their data or its deletion at any time. You pass the request to us and we action it within a few days. Independently of that, you set an automatic retention period for your business — 30, 60 or 90 days.
Do I have to tell callers?
Yes. Transparency is a core obligation under both GDPR and the revDSG: callers must learn that they are speaking to an AI assistant and that the call is being processed. Auralinx states this in the greeting; you set the exact wording during setup.
Data protection at a glance
| Aspect | Auralinx |
|---|---|
| Data location | EU only |
| Encryption | AES-256, in transit and at rest |
| Platform certification | ISO 27001 and ISO 9001 |
| Data processing agreement | Automatic on use |
| Training on customer data | No, under no circumstances |
| Sharing with third parties | No sale, no rental, no sharing |
| Retention period | Configurable: 30, 60 or 90 days |
| Role under GDPR | Your business is controller, Auralinx is processor |
Related questions
Does anyone at Auralinx listen to my calls?
No, unless you explicitly grant permission — for example to investigate a fault.
Is my data used to train the AI?
No. Customer data is never fed into model training under any circumstances.
Does this also cover health data in a medical practice?
Health data is a special category of personal data and carries stricter requirements. EU data residency, AES-256 encryption, the DPA and the configurable retention period all apply unchanged. You decide during setup what your assistant records at all — we recommend limiting capture to what booking an appointment actually requires.
Try it free for 14 days.
Fully configured, live on your number. No setup fee, cancel monthly.