Skip to content

Security & data

Designed to comply with Saudi Arabia's Personal Data Protection Law (PDPL) — your data stored in the Gulf region, with full disclosure of where processing happens.

Deliberately precise: where your data is stored, where it is processed, and who can reach it.

Is the platform aligned with the Saudi PDPL?

It is built on the law's principles: defined lawful purposes, data minimisation, clear retention limits, rights of access, correction and deletion, and full disclosure of where processing happens.

The detail buyers ask for is in the data and compliance FAQ.

Where is your data stored?

Permanent storage runs on managed PostgreSQL in the Gulf region (Doha), reachable over private IP only, with backups and point-in-time restore.

Is recording customer calls PDPL compliant?

Recordings sit in the same region; recording retention follows the plan terms confirmed at activation: 90 days for Essential, 180 for Growth, 365 for Expansion, and by contract for Enterprise. They open only through short-lived signed links, and every access is written to the audit log. Notifying the caller and establishing a lawful basis remain the operating organisation's responsibility — and the agent's opening line can carry a recording notice.

Is customer data stored and processed inside Saudi Arabia?

We do not claim everything sits inside Saudi Arabia, because that is not accurate today. Permanent storage is in the Gulf region (Doha), while realtime speech and AI processing transits global providers, and knowledge-base document processing (OCR) runs on a European endpoint. Disclosing cross-border transfer is what the law requires.

Can the audit log be edited or deleted?

No. Every sensitive action is written to an append-only log enforced by the database itself: no row can be edited or deleted, not even by an administrator. Enterprise customers can export it for review.

Every escalation to a human employee lands in it too — read how your employee inherits the call with its full context.

Who can reach your data?

Your employees, under roles and permissions you define, with hard tenant isolation enforced at the database level. Support access is automatically audit-logged, and any temporary access to your account is recorded, visible and revocable.

Security questions

Where exactly is my call data stored?

Permanent storage is in the Gulf region (Doha) over private networking, and recording retention follows the plan terms confirmed at activation: 90 days for Essential, 180 for Growth, 365 for Expansion, and by contract for Enterprise.

Is data processed inside Saudi Arabia?

Permanent storage is in the Gulf region, while realtime speech and AI processing transits global providers. We disclose that fully, because disclosing cross-border transfer is what the PDPL requires.

Who can see my organisation's calls?

Your employees under the permissions you define, and platform support only when needed — every support view is written to an append-only audit log.

Is there a data processing agreement?

Yes. A summary DPA is published on its own page, and the full version is signed as part of contracting.

Also read: Privacy policy · Terms of service · DPA

Ready to see it answer your customers?

A 30-minute intro demo — we show you the platform live and answer your questions.

Book a demo