Secure AI with EU data residency – on dedicated Azure OpenAI infrastructure, not via public ChatGPT
The language model – the layer that understands callers and decides – runs in the EU (Azure OpenAI, Sweden Central). Only the conversation text is sent to the model, and Microsoft does not use it for model training.
How the AI is built
Language model: Azure OpenAI – Sweden Central (EU) — The Large Language Model operates exclusively through Microsoft Azure OpenAI in the EU region Sweden Central – no third-country transfer for language model processing.
Data residency in the EU — Language model processing, hosting and application data storage all take place in the EU: the language model in Sweden Central, hosting and database in Frankfurt.
What goes to the language model — Only the conversation text (transcript) is sent to Azure OpenAI, not the call audio. Microsoft does not use these inputs and outputs for model training.
No permanent audio storage — Call audio is not permanently stored by default – only transcripts and summaries are generated.
Transport and language layer: separate from the AI — Call delivery (Twilio), speech recognition (Deepgram) and speech synthesis (ElevenLabs) run through established US providers, engaged as data processors under Article 28 GDPR.
Compliance
Verifiable proof – not just promises
Security has to be verifiable. The following sources lead directly to Microsoft’s own security and compliance evidence for Azure and the Azure AI services – including downloadable audit reports and certificates.
Microsoft Service Trust Portal – audit reports & certificates
This is where Microsoft provides the actual evidence for download: ISO 27001/27018, SOC 1/2/3 and BSI C5.
Open source ↗Microsoft Trust Center
Microsoft’s central overview of security, privacy and compliance across all Azure services.
Open source ↗Azure security – documentation
How Microsoft secures the Azure platform technically (Azure Security Fundamentals): identity, encryption, network and data-center security.
Open source ↗Azure AI services – security
Microsoft’s overview of the security features of the Azure AI services that run the language model.
Open source ↗Azure OpenAI – data, privacy & security
Microsoft’s evidence: inputs and outputs are processed in isolation, not used to train the models and not shared with OpenAI.
Open source ↗Azure OpenAI – transparency & Responsible AI
Microsoft’s transparency note on how the Azure OpenAI models work, their limits and their safe use.
Open source ↗EU Data Boundary
Microsoft’s commitment to store and process data from EU customers within the EU/EFTA.
Open source ↗Legal framework
Beyond the technical platform, the AI phone assistant is designed for the requirements of European law: a fixed AI disclosure that lets deploying companies meet the transparency obligations of the EU AI Act (Art. 50), plus a data processing agreement under Art. 28 GDPR that is part of the contract at no extra charge.
We fully disclose which data processors are used – including the US services for telephony, speech recognition and speech synthesis (e.g. Twilio, Deepgram, ElevenLabs), safeguarded for third-country transfer through appropriate guarantees (EU Standard Contractual Clauses under Art. 46 GDPR or the EU-US Data Privacy Framework under Art. 45 GDPR).
Binding legal bases:
Key answers about secure AI at LiteLog
Frequently asked questions
Which AI model does the assistant use?
The language model runs via Microsoft Azure OpenAI in the EU region Sweden Central – not through public ChatGPT.
What data is sent to the AI?
Only conversation transcripts – never raw audio files. Microsoft does not use this data for training.
Does data leave the EU?
Language model processing stays in Sweden Central and hosting is in Frankfurt. Telephony and speech synthesis use US providers engaged as data processors under appropriate legal safeguards (SCC / EU-US Data Privacy Framework).
Is the service ISO 27001 certified?
The ISO 27001/27018, SOC and BSI C5 certifications apply to the underlying Microsoft Azure infrastructure. The service itself operates under GDPR compliance with disclosed subprocessors.
Is call audio saved?
No – audio is not permanently stored by default. Only transcripts and summaries are retained.
