Privacy and data storage

“Our vendor is local, so our calls stay local.” That covers one link in six.

It is the most common reassurance in any voice agent procurement, and it is often true of the company on the invoice. A phone call through an agent usually passes through more companies than that.

Seen through a glass wall into a small meeting room: a man in a dark knit jumper sits at a pale oak table reading a thick stapled document, his phone lying beside his elbow, while a woman in a dark navy blazer stands by the window with a mobile to her ear.

“We chose a local vendor, so our calls stay local.”

The sentence comes up in almost every voice agent procurement. It goes into the minutes, it reassures the data protection officer, and it is rarely checked again. It is often true of the company on the invoice. That just isn't the company that hears most of the call.

Why it is easy to believe

There are three good reasons the sentence survives.

The contract. You have one agreement, one invoice and one name to deal with. Everything that happens behind that name sits in a sub-processor annex that few people read after signing.

The marketing. Sovereignty has become a selling point in its own right. When OVH completed its acquisition of the French transcription service Gladia this summer, “deeper European data residency guarantees” was one of the headline arguments. It is a real argument – for the one link it applies to.

The telephony. The number is local, the carrier is local, and the call arrives on a local network. The first link in the chain is often exactly as local as it sounds. It is easy to let the first link stand for the whole chain.

What actually happens to a call

A customer calls and gives her name, date of birth and what she is calling about. Before the agent has answered her, the call has usually passed through these links:

  1. The phone line. The carrier receives the call and passes the audio on. This part is often local all the way.
  2. The platform. The company you have a contract with, which runs the conversation. This is where the configuration lives, and usually the logs.
  3. Speech recognition. The audio becomes text – with the name, the date of birth and the reason for calling in it. This is often a separate, specialised service.
  4. The language model. The text is sent to the model that decides what the agent will say. The most widely used models come from a handful of large US companies. Many of them offer processing in Europe, but that is a choice someone has to have made – it does not happen by itself.
  5. Speech synthesis. The reply is turned back into audio. Sometimes by yet another vendor.
  6. Storage afterwards. Recordings, transcripts and analytics can sit somewhere other than where the call was processed in real time.

If the agent runs on a speech-to-speech model, links three, four and five collapse into one. That makes the chain shorter. It does not automatically make it more local.

Each of the six links can be a separate company, in a separate country, with its own sub-processors. “Our calls stay local” is only true if it is true for all six. It is the same pattern that runs through the rest of a voice agent: every link in the call has its own owner, and capacity is the lowest of four numbers owned by four parties. Data flow follows the same logic.

Want to talk it through with someone who has done this before?

Fifteen minutes on a call. We will tell you honestly whether a voice agent fits your setup – and what has to be settled before it goes live.

15 minutes · no obligation · pick your own time

Where the data sits, and who can demand it

Even when all six links process the call in Europe, the question is only half answered. There are two questions here, and they are often merged into one.

The first is where the data is processed and stored. The second is who can demand that it be handed over. A US vendor with a data centre in Frankfurt is still subject to US law, including the CLOUD Act of 2018, which allows US authorities to require data the company controls – regardless of where it is stored. A European data centre answers the first question. It does not answer the second.

That does not rule such vendors out. Transfers to the US currently rest largely on the EU–US Data Privacy Framework, which the EU General Court upheld in September 2025. The case has been appealed to the Court of Justice of the EU – the same court that struck down both of its predecessors, Safe Harbor and Privacy Shield. GDPR applies across the EU and, through the EEA Agreement, in Norway too, so this affects Nordic businesses equally.

Where your threshold should sit is a question for your data protection officer, not for a blog post. But you are the data controller, and you cannot assess a chain you have not seen.

Three questions that settle it

Which companies touch the audio or the text of a call? Not “our sub-processors”. A list of names, one line per link in the chain above.

Where is it processed, and where is it stored afterwards? Two answers per link. Real-time processing and the storage of recordings are often in two different places, and how long the record should be kept is a separate decision.

Who owns the company processing it? This is the question a European data centre does not answer, and it is the one most often missing from the reply you get.

The sentence isn't false

It is incomplete. “Our calls stay local” usually describes the first link in the chain and leaves the next five unanswered.

Threll.ai builds voice agents in Norwegian, Swedish and Danish, and our telephony runs over Telenor's SIP trunk on Nordic infrastructure. That is one link. Put the three questions to us as well – and to everyone else you are considering.