GDPR is our foundation, not an option
Loomira processes calls, transcripts and customer data under European rules — technically and contractually. Here’s how.
EU provider chain
For each AI building block we use EU endpoints wherever the provider makes them available to us — and state openly where that is not yet the case:
- Speech recognition — Soniox (EU processing)
- Speech synthesis — ElevenLabs (currently global endpoint, standard contractual clauses; a switch to EU residency is planned — only the response text is sent)
- Language model — Google Vertex AI (EU region)
Hosted in the EU
The app and its data run in the AWS eu-central-1 region in Frankfurt am Main. Transcripts, messages and customer data are stored in the EU; call audio is not stored.
Data processing agreement (DPA)
The DPA under Art. 28 GDPR is part of the terms and accepted electronically at signup — with annexes covering data categories, sub-processors and TOMs. It is publicly available at any time.
Art. 50 AI Act transparency
Loomira identifies itself to callers as an AI at the start of the conversation — as the EU AI Act (Art. 50) requires. That disclosure is part of the flow, not optional.
Salted caller hashes
Phone numbers aren’t kept in clear text for analytics: where we need to recognise a returning caller, we work with salted hashes rather than the raw number.
Subprocessors
We maintain a public list of our sub-processors — with purpose, location and third-country basis — and announce changes in advance, as set out in the DPA.
Questions about data protection?
Get started — the DPA, privacy policy and sub-processor list are publicly available before the first real call.