Skip to main content

Privacy and security

Swiftner listens to your customer calls and analyses them.

The rule is simple, and privacy is the reason for it: we store the transcript, not the audio. The call is written down while it happens, and the recording never reaches our storage. Audio sits with us in only two cases, when you upload a file yourself, or when a recording is pulled in from LeadDesk. If you use Nextcom or Aircall, the recording stays in your own system.

Everything is processed in the EU. The rest of it is settings you control yourself.

You set the standard

The privacy standard is set in your own settings. Every change is logged with what it was, what it became, and who made it.

The EU is the default

AI analysis runs in the EU. Analysis and coaching go through Google Vertex AI's EU endpoint. Moving it out takes an active confirmation, and your data protection summary shows the change.

Whether the customer is recorded

Turn on seller-only capture and we never take the customer's audio (you'll lose the interest score and talk ratio). Consent from the person you're calling is yours to manage, as the controller.

What gets filtered out

Turn on PII filtering and names, email addresses and street addresses are left out of the transcript and the analysis. Then they aren't in what we store either.

Set your retention

Set the window yourself. A nightly job deletes calls older than it, along with the transcript, the analysis and any recordings. Set no window and we keep your calls until you do, or until the contract ends.

Delete whenever you want

Individual calls and user accounts can be deleted without waiting for the window. At contract end we erase everything we hold on you, and give you written confirmation of the erasure.

Everything is stored and processed in the EU

Every customer gets their own isolated database schema, and data is never mixed between customers.

  • Application servers and database: Hetzner, Falkenstein in Germany, two data centres
  • Uploaded recordings: Google Cloud, europe-north1 in Finland
  • Transcription: Speechmatics, EU endpoints
  • AI analysis and coaching: Google Vertex AI, the EU multi-region endpoint
  • Error monitoring: our own Sentry on our own infrastructure, no third party
  • Encrypted in transit over TLS

One exception is voice practice, which runs in the US. There the rep practises against a synthetic buyer, and only the rep's own practice audio is sent. No customer calls leave the EU. Customers who can't accept the exception get the feature switched off.

Everything is stored and processed in the EU

What we guarantee, and what we don't offer

This we guarantee

  • Calls aren't recorded. We store the transcript, not the audio
  • No emotion analysis and no voice recognition. Interest is read from what the customer said
  • We measure behaviour, not the person: talk speed, filler words, question technique, checklist and closing attempts
  • Your calls never train AI models
  • Every assessment is advice to a human, never a decision about an employee
  • The transcript sits beside every assessment, so all of it can be checked

This you get from us

  • Data processing agreement under Article 28
  • Breach notification without undue delay, so you make your own 72-hour deadline
  • Sub-processor list with processing locations
  • DPIA template for your own assessment
  • Pre-filled security questionnaire
  • AI transparency statement
  • Dated data protection summary as a PDF

This we don't have

  • Hetzner, Google Cloud and Speechmatics are ISO 27001 certified for the services we use. Their certifications aren't ours, and we don't pretend otherwise.
  • No ISO 27001
  • No SOC 2
  • No third-party penetration test

More questions about security and privacy at Swiftner?