Data Security and Data Protection at Voicery

Data Security and Data Protection at Voicery

Data Security and Data Protection at Voicery

Unified standards. Reliable structures. Transparent processes.

Unified standards. Reliable structures. Transparent processes.

Security and data protection as a core commitment

Security and data protection as a core commitment

As a provider of data protection–relevant software solutions, Voicery places particular emphasis on the security of personal data and on compliance with legal and regulatory requirements.

The data protection and information security design of the Voicery platform follows a structured and documented approach – from technical, organizational, and contractual perspectives.

The platform is designed for professional use in corporate environments and is operated accordingly in compliance with recognized international security and quality standards.

Certified security and quality standards

Certified security and quality standards

Voicery is operated on a technical infrastructure whose operation is certified in accordance with ISO/IEC 27001:2022 (information security management) and ISO 9001:2015 (quality management).

These certifications confirm that defined processes and controls are in place for the operation of the underlying technical infrastructure to ensure the confidentiality, integrity, and availability of sensitive data. At the same time, procedures for continuous improvement are implemented to regularly review and further develop technical and organizational measures.

Data Protection Management and Audit Processes

Data Protection Management and Audit Processes

To maintain a high level of data protection, our company works with an independent external Data Protection Officer and undergoes regular GDPR data protection audits.
As part of these audits, the implementation of technical and organizational measures in accordance with Art. 32 GDPR is reviewed, as well as compliance with requirements for data protection management, transparency, and accountability (Art. 5(2) GDPR).

This includes, among others:

  • Access restrictions and role-based authorization concepts

  • Measures to ensure data integrity and availability

  • Documented procedures for the regular review of security measures

  • Measures to ensure data minimization and purpose limitation

The processing of personal data is carried out in full compliance with the General Data Protection Regulation (GDPR).

Data processing within Europe

Data processing within Europe

Data processing in the standard configuration from the Pro plan onwards takes place exclusively in our providers' European processing regions.

Our platform offers flexible EU-based processing for Large Language Models (LLMs), Speech-to-Text (STT), and Text-to-Speech (TTS), depending on the selected model or provider. This allows customers to choose the setup that best fits their compliance and data protection requirements.

Our infrastructure includes, among others:

  • Amazon Web Services (AWS) – Hosting and Storage of Recordings and Transcripts (Frankfurt, Germany)

  • OpenAI via Microsoft Azure – LLM (Sweden; processed within the EU data zone)

  • ElevenLabs – TTS (EU region: Belgium, Brussels)

  • Gladia – STT (EU region: France)

  • Twilio – Telephony (EU-Region: Irland)

  • LiveKit – Real-Time Media Path for SIP and WebRTC (EU Endpoint)

We exclusively use Azure OpenAI deployments that keep data processing within Europe. Global deployments, which allow Microsoft to process requests in any region, are not used.

The following applies to all configured providers: No silent fallback is performed. If a configured provider or region is temporarily unavailable, requests are not automatically redirected to another region or provider.

In addition, we support providers that are integrated outside Europe.

  • Google Gemini – LLM

  • Anthropic Claude – LLM

  • Deepgram – STT

  • Cartesia – TTS

  • LLaMA via Groq – LLM

All subprocessors are selected and integrated based on documented data protection agreements, transparent data flow analyses, and appropriate safeguards in accordance with Chapter V GDPR. Where necessary, internationally recognized protection mechanisms such as Standard Contractual Clauses are applied to ensure a compliant and secure data processing framework.

Summary

Summary

Voicery stands for a responsible and transparent approach to data.

  • Technical foundation based on certified security and quality standards (ISO/IEC 27001:2022, ISO 9001:2015).

  • Processing of core AI components in Europe in the standard configuration, including LLMs, STT, and TTS.

  • GDPR-compliant data processing with documented technical and organizational measures (TOMs).

  • Audited operational processes and GDPR-complient data protection management.

The combination of GDPR-compliant data protection, internationally recognized security standards and, upon request, a fully European infrastructure (when selecting corresponding models and providers) makes Voicery a suitable platform for data protection–compliant communication in enterprise environments.