GDPR is our foundation, not an option

Loomira processes calls, transcripts and customer data under European rules — technically and contractually. Here’s how.

EU provider chain

For each AI building block we use EU endpoints wherever the provider makes them available to us — and state openly where that is not yet the case:

  • Speech recognition — Soniox (EU processing)
  • Speech synthesis — ElevenLabs (currently global endpoint, standard contractual clauses; a switch to EU residency is planned — only the response text is sent)
  • Language model — Google Vertex AI (EU region)

Hosted in the EU

The app and its data run in the AWS eu-central-1 region in Frankfurt am Main. Transcripts, messages and customer data are stored in the EU; call audio is not stored.

Data processing agreement (DPA)

The DPA under Art. 28 GDPR is part of the terms and accepted electronically at signup — with annexes covering data categories, sub-processors and TOMs. It is publicly available at any time.

Art. 50 AI Act transparency

Loomira identifies itself to callers as an AI at the start of the conversation — as the EU AI Act (Art. 50) requires. That disclosure is part of the flow, not optional.

Salted caller hashes

Phone numbers aren’t kept in clear text for analytics: where we need to recognise a returning caller, we work with salted hashes rather than the raw number.

Subprocessors

We maintain a public list of our sub-processors — with purpose, location and third-country basis — and announce changes in advance, as set out in the DPA.

Questions about data protection?

Get started — the DPA, privacy policy and sub-processor list are publicly available before the first real call.