Compliance
Written for your data protection officer, not to reassure you.
This page exists to be forwarded as it is to the person in your organisation who will have to approve Konvoice. It contains tables, retention periods and names, and not one sentence along the lines of “security is our priority”.
Roles
Who is responsible for what.
The distinction is not legal pedantry: it determines who answers a subject access request from your employees or your customers.
You are the controller
You decide why you record calls, who has access, how long you keep them, and you inform your employees and the people they speak to. Konvoice gives you the settings to apply those decisions, not the decisions themselves.
We are the processor
We process your data on your instructions, within the limits of the data-processing agreement. We do not use it for our own purposes, we do not sell it, and we train no model with it.
Hosting
Where your data physically sits.
You choose the region when your company is created. It does not change afterwards without your written agreement, and no data is replicated outside the chosen region.
| Region | Location | Available to |
|---|---|---|
| European Union | France and Germany, two availability zones | The default for every customer |
| Canada | Montréal and Toronto | On request |
| West Africa | Abidjan, with regional fallback | On request |
| Private cloud | The host and the country you name | On quotation |
| Your own servers | At your premises, with no egress to the internet | Sovereign mode |
The data-processing agreement
The commitments on this page are in the contract, not only on it.
A compliance page promising what the contract does not say is a communications page. Every statement here has a signed counterpart — the list of sub-processors, the hosting location, the retention periods and the right to leave are annexes, not intentions.
- Sub-processor annex — by name, with prior notification of any addition.
- Guaranteed location — the European Union, at a named host.
- Configurable retention — yours, with a contractual maximum and a verifiable purge.
- The right to leave — full export of your data and your recordings, in a documented format.
Retention periods
How long each piece of data is kept.
The values below are the defaults. All of them can be changed by your administrator, up or down, company by company and queue by queue.
| Data | Default | Adjustable | Deletion |
|---|---|---|---|
| Call log and metadata | 24 months | 3 to 120 months | Automatic at expiry |
| Audio recordings | 6 months | 1 to 60 months | Automatic, audio and derivatives |
| Transcripts and summaries | The associated recording’s period | Can be independent | Follow the recording |
| Voicemails | 3 months after being played | Yes | Automatic |
| Audit log | 36 months | Minimum 12 months | Not modifiable before expiry |
| Billing data | 10 years | Legal obligation | At the statutory expiry |
| User accounts | The term of the contract | Yes | 30 days after deletion |
| Backups | 35 days rolling | 7 to 90 days | Automatic rotation |
A requested deletion propagates to backups as they rotate, within a maximum equal to the backup retention period. We write this down because most suppliers omit it.
Sub-processors
The named list, kept up to date.
Every addition is notified to customers thirty days before it goes live, with a right of objection written into the contract.
| Sub-processor | Role | Processing region | Data concerned |
|---|---|---|---|
| Certified European host | Compute and storage infrastructure | France, Germany | All platform data |
| Telecommunications carriers | Routing calls and SMS | Depending on the destination called | Calling and called numbers, duration |
| Transcription supplier | Transcription and summaries (Naya) | European Union | Audio of recorded calls, if Naya is enabled |
| Transactional email service | Notifications, voicemail by email | European Union | Email addresses, notification content |
| Support and monitoring | Technical logs and alerts | European Union | Technical logs, with no conversation content |
The contractual version of this register names each company, with its registered name, its country of establishment and the legal basis for any transfer. Ask for it
Keeping a recording longer than necessary is not caution. It is a breach.
The period is yours, and the purge is verifiable
Your obligations, our tools
What Konvoice gives you in order to comply.
Recording a call is processing personal data. Doing it properly requires four things, and they are in the product.
Informing people
An announcement played automatically to the caller, configurable by country and by language, with proof it was played in the log.
Right of access
A complete export of the data relating to a person — calls, recordings, transcripts — in a readable format, from the console.
Right to erasure
Deletion of a person and everything attached to them, with a report of what was deleted and what is retained under a legal obligation.
Record of processing
We supply the standard “business telephony” processing record your DPO can take and adapt, rather than drafting it from nothing.
Exit
What you take with you the day you leave.
An exit clause that does not say what is returned, in what format and within what time protects nobody.
- Your numbers — outbound porting to the carrier of your choice, at no charge and with no extended notice condition.
- Your recordings — a full export in standard audio files, with the index file linking each file to its call.
- Your history — call logs, transcripts, notes and labels in open formats.
- Your contacts and your configuration — directory, queues, hours and routing rules, in a readable format that documents what you will have to rebuild elsewhere.
- Your devices — a full inventory with MAC addresses, so your next supplier takes over the estate without rediscovering it.
- Timing — the export supplied within fifteen working days of the request, and the data deleted from our systems thirty days after the end of the contract, unless a legal obligation says otherwise.
Compliance questions
Do you have a standard data-processing agreement?
Are we obliged to record calls?
Does the GDPR oblige us to inform the caller?
How do you respond to a judicial order?
What happens in the event of a data breach?
Your DPO has questions? They will get written answers.
We answer compliance questionnaires with dated commitments and an identifiable person behind every answer.
This page is a summary for information. The contractual commitments are in the service agreement and its data-processing annex.