Questions before prod

  1. Where are recordings stored?
  2. Where are transcripts stored?
  3. Can storage region be selected?
  4. What is the default retention period?
  5. Are recordings used for model training?
  6. What subprocessors are involved?
  7. Is a DPA available?
  8. Are UK/EU transfer safeguards available?

Hello @powerautomate

1/2. Call recordings and transcripts are stored indefinitely in session history. Customers can disable storage, in which case data is not retained.

  1. All data processing and storage happens in the US (AWS US regions).

  2. By default, call recordings and transcripts are stored indefinitely in session history. Customers can disable storage, in which case data is not retained. Webhook-delivered recording URLs will expire after processing. Retention settings can also be customized.

  3. We do not use customer call data for training or fine-tuning AI models. We rely on pre-trained third-party models. We enforce provider-level training opt-outs.

  4. Our DPA restricts data usage strictly to service-related purposes.6. You can review our current sub processor list here: https://trust.retellai.com/subprocessors Clients must approve all sub processors under GDPR Article 28.

  5. Our self-sign DPA does not include Standard Contractual Clauses (SCCs). If SCCs are required, you can request a separate DPA.

  6. What we do offer for GDPR:

  • GDPR compliance via legal transfer mechanisms — we offer a self-serve Data Processing Addendum (DPA) with Standard Contractual Clauses (SCCs) available at https://click-agreements.retellai.com

  • SOC 2 Type I & II certification and HIPAA compliance — details at our Trust Center https://trust.retellai.com

  • Data encryption in transit and at rest

However, as you correctly identified, SCCs address the legal basis for cross-border data transfers under GDPR — they do not satisfy a physical EU data residency requirement, which is what NIS2-regulated entities typically demand.

Thank You