Skip to main content
At Famulor.io, we believe that Data Sovereignty is a fundamental requirement for modern AI communication. This Trust Center provides full transparency regarding our infrastructure, our specialized sub-processors, and the technical safeguards we employ to protect sensitive data. This page serves as the dynamic Annex to our Data Processing Addendum (DPA) and is updated regularly to reflect our current technical stack.

1. Our Sovereignty Commitments

To meet the strict requirements of the European market (including Art. 9 GDPR for healthcare and sensitive sectors), we operate under four core principles:
PrincipleDescription
EEA-First PolicyAll core processing of voice and text data occurs on servers located within the European Economic Area (EEA).
No-Training GuaranteeWe contractually ensure that none of our AI providers are permitted to use your data (audio, transcripts, or prompts) to train or improve their foundational models.
Zero Retention CapabilityWe provide a “Zero Retention Mode” for highly sensitive environments, where data is processed in-memory and purged immediately after the interaction.
Encryption ExcellenceAll data is encrypted in transit using TLS 1.2+ and at rest using AES-256.

2. System Status & Availability

Transparency regarding our system performance is key to a reliable partnership. You can monitor our live status at any time: Live Status Monitor: https://status.famulor.io/

3. Infrastructure & Platform Hosting

These providers host the Famulor.io platform, including the backend logic, databases, and customer dashboard.
ProviderPurposeProcessing Location
Amazon Web Services (AWS)Core Platform, Databases & API LogicFrankfurt, Germany (EU)
Vercel Inc.Frontend & Web InterfaceFrankfurt, Germany (EU)

4. Artificial Intelligence (LLM)

These models handle the reasoning and conversation logic. We utilize Enterprise-grade instances to ensure data isolation and sovereignty.
ProviderModel / ServiceProcessing Location
Microsoft Ireland (Azure)OpenAI Models (GPT-4o, o1, etc.)Sweden Central (EU)
Google Cloud (Vertex AI)Gemini 1.5 Pro / FlashEU Regions (EU Data Residency)
Anthropic, PBCClaude 3.5 Models (via EU Partners)EU Regions
Microsoft Ireland (Azure)Meta Llama 3 (Open Source)EU Regions (Sweden/Germany)

5. Speech Services (STT & TTS)

Specialized providers for real-time transcription (Speech-to-Text) and voice synthesis (Text-to-Speech).
ProviderCategoryService / PurposeProcessing Location
Soniox, Inc.STTHigh-Precision TranscriptionEU Region (Enterprise Node)
ElevenLabs Inc.TTSAI Voice Models (Enterprise Plan)Frankfurt, Germany (EU)
Cartesia AI, Inc.TTSUltra-Low Latency Voice (Sonic)EU Region (per DPA)
Microsoft Ireland (Azure)STT/TTSWhisper & Azure Neural SpeechSweden Central (EU)

6. Business Operations & Billing

Providers used for transactional security and administrative management.
ProviderPurposeProcessing Location
Stripe Payments EuropeSecure Payment ProcessingIreland (EU)
SendGrid (Twilio)Transactional & System EmailsEU Regions

7. International Data Transfers & Safeguards

For providers with US-based parent companies (e.g., Microsoft, Google, Vercel, Soniox), Famulor ensures compliance via:
  • Data Residency: Configuring services to process data exclusively on EU-based nodes.
  • Legal Frameworks: Utilization of the EU-U.S. Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs).
  • Enterprise Agreements: Specialized contracts that prevent third-party access and data usage for model training.

8. Technical and Organizational Measures (TOMs)

Our security framework is designed for maximum accountability and isolation:
MeasureDescription
Multi-TenancyStrict logical separation of customer data. Every account operates in an isolated environment.
Agency & Whitelabel ArchitectureWe offer a specialized Agency Dashboard that allows partners to manage multiple, fully isolated sub-accounts from a central interface.
Access ControlAccess is restricted to one authorized user per account to ensure clear accountability. The implementation of native Multi-Factor Authentication (MFA) is currently on our development roadmap. We recommend securing access via SSO providers (Google/Microsoft) with enabled MFA.
User-Controlled Data RetentionTo support the GDPR principle of storage limitation, users can independently configure automatic deletion schedules (1 to 24 months) for Calls, Leads, Chats, and SMS.
Audit LoggingComprehensive logging of all system-critical actions for traceability.
ContinuityAutomated daily backups stored encrypted within the European Union.
Last Updated: March 2026