Data protection and security, for your review
Trust center
Review how SonicR1 handles your data: storage, AI processing, subprocessors, deletion and security assurance.
- Customer records
- Frankfurt
- SonicR1-hosted records; provider setting checked 22 July 2026
- AI inference
- EU endpoints
- Vertex AI (EU) and AssemblyAI (Dublin)
- Limited data outside the EU
- 3 of 8 providers
- Supporting services: Vercel, Inngest, Resend. Subprocessors
- Own SOC 2 / ISO 27001
- None
- Review route: DPA, Annex 3 measures, questionnaire
Quick answers for your review
- Storage
- SonicR1-hosted customer records are stored in Frankfurt. Supporting providers also hold limited data outside the EU.
- See the subprocessors
- AI providers
- Language-model processing uses Google Cloud Vertex AI. Speech-to-text uses AssemblyAI. The DPA lists model scope and processing locations.
- DPA Annex 2
- Model training
- SonicR1 does not train shared or general-purpose models on customer data without a separate express written customer instruction. Provider restrictions are described in DPA section 6.4 and Annex 2.
- DPA section 6
- Deletion
- Individual calls, personal accounts and workspaces have different deletion scopes. Some evidence, billing records and provider copies have separate retention rules.
- Deletion FAQ
- DPA
- The Standard DPA applies to every plan from first use. A separate signature is optional; a signable PDF is available.
- Read the DPA
- Audits
- SonicR1 has no SOC 2 attestation or ISO 27001 certification of its own. Review our DPA and technical measures, or request responses to your security questionnaire.
- Assurance status
Who processes your data
These providers process customer data on SonicR1’s behalf. The table shows their purpose, the data they receive, processing locations and transfer safeguards. Full contractual details are in DPA Annex 2.
EU storage and AI endpoints, with limited data outside the EU. The customer records SonicR1 hosts are stored in Frankfurt. AI inference uses EU endpoints. Supporting services also handle workflow state, email content and hosting metadata outside the EU, as shown below.
Outside EU (limited) marks a provider that holds limited customer data outside the EU; its region cell says which data.
AI and speech processing
2 providers| Provider | Purpose | Data handled | Region / processing | Transfer basis |
|---|---|---|---|---|
| Google Cloud EMEA LimitedEntity: Ireland | Language-model processing through Vertex AI; synthetic voices for simulations | Transcript and prompt text, model outputs. Call transcripts pass through redaction. Knowledge-base documents, imported URL text, briefing and pre-call inputs, and knowledge-base questions are sent without that call-context redaction. Text-to-speech receives AI persona text. | EU endpointsEU multi-region and dedicated EU endpoints; EU-only model failover. Text-to-speech uses an EU endpoint. | Google Cloud Data Processing Addendum; EU Standard Contractual Clauses, Module 3, for third-country support or ancillary access |
| AssemblyAI, Inc.Entity: US | Live and uploaded-audio transcription | Call audio, transcripts, timing, language and speaker metadata | Dublin, IrelandEU API and streaming endpoints in Dublin, Ireland. Annex 2 records a model-improvement opt-out and one-day audio/transcript TTL, checked 22 July 2026. | Provider DPA; EU Standard Contractual Clauses, Module 3, for third-country access |
Google Cloud EMEA LimitedEntity: IrelandEU endpointsLanguage-model processing through Vertex AI; synthetic voices for simulations
- Data handled
- Transcript and prompt text, model outputs. Call transcripts pass through redaction. Knowledge-base documents, imported URL text, briefing and pre-call inputs, and knowledge-base questions are sent without that call-context redaction. Text-to-speech receives AI persona text.
- Region / processing
- EU multi-region and dedicated EU endpoints; EU-only model failover. Text-to-speech uses an EU endpoint.
- Transfer basis
- Google Cloud Data Processing Addendum; EU Standard Contractual Clauses, Module 3, for third-country support or ancillary access
AssemblyAI, Inc.Entity: USDublin, IrelandLive and uploaded-audio transcription
- Data handled
- Call audio, transcripts, timing, language and speaker metadata
- Region / processing
- EU API and streaming endpoints in Dublin, Ireland. Annex 2 records a model-improvement opt-out and one-day audio/transcript TTL, checked 22 July 2026.
- Transfer basis
- Provider DPA; EU Standard Contractual Clauses, Module 3, for third-country access
Hosting and data storage
3 providers| Provider | Purpose | Data handled | Region / processing | Transfer basis |
|---|---|---|---|---|
| Supabase, Inc.Entity: US | Database, authentication, file storage and authentication email | Account and workspace records, call files, transcripts, AI outputs, CRM snapshots, knowledge content and logs | FrankfurtProduction project: Frankfurt, Germany; provider setting checked 22 July 2026 | Provider DPA; EU Standard Contractual Clauses, Module 3, for third-country support access |
| Vercel Inc.Entity: US | Application hosting, compute, deployment, edge delivery and logs | Request content where needed, IP/device/request metadata, application logs and transient customer content | Frankfurt + global edgeOutside EU (limited)Application compute: Frankfurt (fra1). Global edge and control-plane infrastructure; this is not a promise of complete account or log residency. | Provider DPA; EU Standard Contractual Clauses, Module 3 |
| Fly.io, Inc.Entity: US | Hosting simulation agents and self-hosted speech services | Practice/simulation audio or text and transient service metadata, depending on the feature | FrankfurtWorkloads configured for Frankfurt (fra). Annex 2 states that the provider retains platform data for 90 days after termination. | Executed provider DPA with EU Standard Contractual Clauses; Annex 2 also identifies EU–US Data Privacy Framework participation |
Supabase, Inc.Entity: USFrankfurtDatabase, authentication, file storage and authentication email
- Data handled
- Account and workspace records, call files, transcripts, AI outputs, CRM snapshots, knowledge content and logs
- Region / processing
- Production project: Frankfurt, Germany; provider setting checked 22 July 2026
- Transfer basis
- Provider DPA; EU Standard Contractual Clauses, Module 3, for third-country support access
Vercel Inc.Entity: USFrankfurt + global edgeOutside EU (limited)Application hosting, compute, deployment, edge delivery and logs
- Data handled
- Request content where needed, IP/device/request metadata, application logs and transient customer content
- Region / processing
- Application compute: Frankfurt (fra1). Global edge and control-plane infrastructure; this is not a promise of complete account or log residency.
- Transfer basis
- Provider DPA; EU Standard Contractual Clauses, Module 3
Fly.io, Inc.Entity: USFrankfurtHosting simulation agents and self-hosted speech services
- Data handled
- Practice/simulation audio or text and transient service metadata, depending on the feature
- Region / processing
- Workloads configured for Frankfurt (fra). Annex 2 states that the provider retains platform data for 90 days after termination.
- Transfer basis
- Executed provider DPA with EU Standard Contractual Clauses; Annex 2 also identifies EU–US Data Privacy Framework participation
Background jobs, rate limiting and email
3 providers| Provider | Purpose | Data handled | Region / processing | Transfer basis |
|---|---|---|---|---|
| Inngest, Inc.Entity: US | Background jobs and workflow orchestration | Job IDs, execution metadata and persisted step outputs, including pseudonymised transcript text and derived call metrics. Email jobs also carry recipient addresses and rendering variables, potentially including another member’s name or email. CRM write jobs carry record IDs and status, rather than generated CRM content. No call audio. | United StatesOutside EU (limited)US-hosted data stores on AWS. | Executed provider DPA; EU Standard Contractual Clauses, Module 3; UK addendum where applicable |
| Upstash, Inc.Entity: US | Rate limiting and related serverless data functions | Pseudonymous keys/IDs, counters, timestamps and rate-limit metadata; no call content by design | FrankfurtDeployed database: Frankfurt, Germany (eu-central-1); provider setting checked 22 July 2026 | Provider DPA; EU Standard Contractual Clauses, Module 3 |
| Plus Five Five, Inc., trading as ResendEntity: US | Transactional email delivery | Recipient addresses, message content, delivery events, email metadata, logs and API records | Ireland send · US storeOutside EU (limited)Sending through Ireland; account data, message content, metadata, logs and API records stored in the US regardless of sending region. Sending setting checked 22 July 2026. | Provider DPA; EU Standard Contractual Clauses, Module 3; Annex 2 also identifies EU–US Data Privacy Framework certification |
Inngest, Inc.Entity: USUnited StatesOutside EU (limited)Background jobs and workflow orchestration
- Data handled
- Job IDs, execution metadata and persisted step outputs, including pseudonymised transcript text and derived call metrics. Email jobs also carry recipient addresses and rendering variables, potentially including another member’s name or email. CRM write jobs carry record IDs and status, rather than generated CRM content. No call audio.
- Region / processing
- US-hosted data stores on AWS.
- Transfer basis
- Executed provider DPA; EU Standard Contractual Clauses, Module 3; UK addendum where applicable
Upstash, Inc.Entity: USFrankfurtRate limiting and related serverless data functions
- Data handled
- Pseudonymous keys/IDs, counters, timestamps and rate-limit metadata; no call content by design
- Region / processing
- Deployed database: Frankfurt, Germany (eu-central-1); provider setting checked 22 July 2026
- Transfer basis
- Provider DPA; EU Standard Contractual Clauses, Module 3
Plus Five Five, Inc., trading as ResendEntity: USIreland send · US storeOutside EU (limited)Transactional email delivery
- Data handled
- Recipient addresses, message content, delivery events, email metadata, logs and API records
- Region / processing
- Sending through Ireland; account data, message content, metadata, logs and API records stored in the US regardless of sending region. Sending setting checked 22 July 2026.
- Transfer basis
- Provider DPA; EU Standard Contractual Clauses, Module 3; Annex 2 also identifies EU–US Data Privacy Framework certification
Provider account settings were last checked on the dates stated in Annex 2. A regional endpoint does not establish the location of all provider logs, support access or account data.
Model scope: Google Gemini is the code’s default language-model family. DPA Annex 2 also authorises standard Google-hosted Claude Sonnet and Haiku inference, subject to verified EU availability before activation. Authorisation does not mean a model is currently enabled. Anthropic is the model publisher; direct Anthropic APIs are excluded from this authorisation.
Your connected services: CRM, calendar and conferencing tools you connect are not automatically SonicR1 subprocessors. You remain responsible for their contracts, settings and lawful use. Stripe processes account-holder billing data under our Privacy Policy and does not receive customer call content.
Changes to this list: We give at least 30 days’ advance notice by email to your account owner or administrator before adding or replacing a subprocessor. A replacement needed to protect security or service continuity may require shorter notice; we then explain the reason and notify you as soon as reasonably possible. Objection rights are described in DPA section 10.
How we protect call data
Redaction, encryption, retention and who can see what.
The live coaching path tokenises structured data such as email addresses and phone numbers before the AI sees the line. Names are not tokenised live; post-call analysis adds name detection.
What we redact
Before your conversation reaches our coaching AI, we automatically detect and tokenize structured personal data: email addresses, phone numbers, payment-card numbers, IBANs, BICs, postal codes, and URLs.
This runs wherever SonicR1's coaching AI processes your conversation — live coaching in real time and post-call debriefs.
How it works
Detected values are replaced with neutral tokens in memory before the request leaves our systems, so the coaching AI receives tokens in place of raw structured personal data.
Your team sees the real values in the product; the coaching model works from tokens.
Personal names in post-call analysis
When we generate your post-call debrief, personal names are automatically detected and removed from the transcript — in addition to the structured data above — before it is sent to our AI provider.
This applies to your post-call analysis and works across English and German conversations. As with all redaction, your team still sees the real names in the product.
Encryption
Identifying values are encrypted at rest with AES-256-GCM. The encryption key is held in an isolated secrets vault, separate from application credentials.
All data is encrypted in transit with TLS.
Model training restrictions
SonicR1 does not itself use your conversations to train shared or general-purpose AI models without your separate express written instruction. Using the service alone is not that instruction (DPA sections 3.1 and 6.4). We use production AI endpoints under the model-improvement opt-outs and contractual restrictions the providers make available to us — an account-level opt-out at our speech-to-text provider, contractual terms at the model provider; the commitment is in section 6.4 of our DPA.
Your data rights
You can delete your account yourself in Settings. The request is held for 24 hours and can be cancelled at any point in that window; after that, deletion runs automatically.
Workspace owners and admins can also delete individual calls from the library, singly or in bulk.
Some things still need a person: a copy of your data, a correction, or winding down a workspace you share with others. Write to legal@sonicr1.com.
Retention & anonymization
Retention is configurable per workspace. Automatic call retention removes stored call content once the retention window set for your workspace has passed, within your plan's limits; you can see the active policy in Settings. After the retention window, the tokens generated during analysis can no longer be re-linked to their original values, while aggregate analytics remain available.
Audit integrity
Every redaction event is written to an audit trail that cannot be altered or overwritten while the call exists; it is removed together with the call when you delete it. More than the consent and erasure logs survives the deletion of an account. The identifying records deliberately retained are: the consent attestations and the erasure log (described in Annex 1, Part D of our DPA), the acceptance evidence for our Terms and DPA including the e-mail address that accepted them, the deletion request record itself, the workspace wind-down record, and billing and monthly usage aggregates. Also kept — the one people are most often surprised by — is the e-mail address of anyone on our do-not-send list, precisely so that the suppression keeps working once the account behind it is gone. Separately from those records, deleting an account does not remove the calls made from it: the account is unlinked from them — the reference goes, the content stays in the workspace — so a transcript may still name the person. That is account unlinking, not anonymisation.
EU data residency by default
Your calls, transcripts and AI coaching are stored in the EU (Frankfurt), and all AI processing runs on EU endpoints — no Customer data is routed to an AI endpoint outside the EEA. The AI endpoints are operated by Google Cloud EMEA Limited (Dublin, Ireland) and by AssemblyAI, Inc., a US-established provider serving EU endpoints; both are engaged under the EU Standard Contractual Clauses (2021/914, Module 3). Three supporting providers hold limited data outside the EU: background-job step state, which can include pseudonymised transcript text and derived call metrics; transactional e-mail content and metadata; and hosting logs and control-plane data. All are named in section 11.5 and Annex 2 of our DPA. Your data is isolated per organization and never shared across tenants.
Questions about your data
Does all my data stay in the EU?
SonicR1-hosted customer records are stored in Frankfurt, and AI inference uses EU endpoints. This does not cover every supporting service: Inngest stores workflow state in the US, including pseudonymised transcript text and call metrics; Resend stores email content and metadata in the US; Vercel operates global edge and control-plane infrastructure. See the subprocessor table for the data and safeguards involved.
Which companies process data for AI features?
Language-model requests use Google Cloud Vertex AI; speech-to-text uses AssemblyAI’s EU endpoints. Gemini is the code’s default language-model family. The DPA also authorises certain Google-hosted Claude models after verification of EU availability; that authorisation does not establish which models are enabled.
Is my data used to train shared AI models?
SonicR1 does not use customer data to train shared or general-purpose models without a separate express written customer instruction. We use provider contractual restrictions and available account controls to restrict shared-model improvement. Annex 2 records AssemblyAI’s opt-out, checked on 22 July 2026. This training restriction does not mean providers retain no data.
What does the coaching AI see?
Detected email addresses, phone numbers, payment-card numbers, IBANs, BICs, postal codes and URLs are replaced with tokens on the live coaching path. Personal names are not tokenised on that live path. Post-call analysis additionally uses name detection. Uploaded knowledge-base documents, imported URL text, briefing and pre-call inputs, and knowledge-base questions are sent without call-context redaction. Tokenisation is pseudonymisation, not a guarantee that text contains no personal data.
Does SonicR1 save my live calls?
Ephemeral live mode is the default: SonicR1 does not retain reusable call audio, transcripts, notes or debriefs from that mode. Limited operational, security and consent metadata may remain. AI notes mode saves a transcript and summary with consent, without saving live-call audio. Uploaded recordings are a separate case and are stored for playback. AssemblyAI’s provider-side retention is separate; Annex 2 records a one-day audio/transcript TTL.
What happens when I delete a call or my account?
Deleting a call removes its stored conversation content and covered derived records. Deleting your personal account removes your attribution from workspace calls; those calls remain in the workspace and may still name you in the transcript. Workspace deletion is a separate process. Certain consent, erasure, acceptance, suppression and billing records remain under separate retention rules. Backups and workflow-provider copies also have their own retention rules.
Is a DPA available for my plan?
Yes. The Standard DPA applies to every plan from first use; a separate signature is optional. You can read it online or download the signable PDF. The English version is binding; the German version is a non-binding reading translation.
Does SonicR1 have its own SOC 2 or ISO 27001 assurance?
No. SonicR1 has no SOC 2 attestation or ISO 27001 certification of its own. Some infrastructure providers publish their own reports and certifications. Those apply to the providers’ stated scope, not to SonicR1 as a whole. For a review, start with our DPA and technical measures, then contact us with your security questionnaire.
How will I hear about a new subprocessor?
We email your account owner or administrator at least 30 days before an intended addition or replacement. Security or service-continuity replacements may require shorter notice, with an explanation as soon as reasonably possible. The DPA describes your objection rights. This page’s update log supplements contractual email notices.
Security assurance: current status
SonicR1 has no SOC 2 attestation or ISO 27001 certification of its own.
Our providers’ reports and certifications describe their own controls and service scope. They do not certify SonicR1 or replace a review of our application and processes.
Published provider assurance — follow the links for scope, report access and certificate details.
| Provider | Published assurance | Source |
|---|---|---|
| Supabase | Provider publishes SOC 2 Type 2 assurance and ISO 27001 certification. | Supabase security documentation |
| Vercel | Provider publishes a SOC 2 Type 2 attestation and ISO 27001:2022 certification. | Vercel assurance documentation |
| Google Cloud | Provider publishes SOC 2 Type II reports and ISO/IEC 27001 certification for its stated service scope. | Google Cloud SOC 2ISO 27001 |
Start with our DPA, Annex 3 technical measures and Security Overview. For further questions, send your security questionnaire to legal@sonicr1.com.
Documentation updates
DPA v1.10 clarifies authorised Google-hosted model scope, EU-only inference and the limits of provider retention assurances.
DPA v1.9 clarifies how deleting a call removes its source excerpts from knowledge-base suggestions.
DPA v1.7 updates retention, Inngest CRM-job data, data-rights provisions and operational contacts.
Need more detail for your review?
Email legal@sonicr1.com with your data-protection questions, security questionnaire or request for provider documentation.