Secure AI with EU data residency – on dedicated Azure OpenAI infrastructure, not via public ChatGPT
The language model – the layer that understands callers and decides – runs in the EU (Azure OpenAI, Sweden Central). Only the conversation text is sent to the model, and Microsoft does not use it for model training.
How the AI is built
Language model: Azure OpenAI – Sweden Central (EU) — The Large Language Model operates exclusively through Microsoft Azure OpenAI in the EU region Sweden Central – no third-country transfer for language model processing.
Data residency in the EU — Language model processing, hosting and application data storage all take place in the EU: the language model in Sweden Central, hosting and database in Frankfurt.
What goes to the language model — Only the conversation text (transcript) is sent to Azure OpenAI, not the call audio. Microsoft does not use these inputs and outputs for model training.
No permanent audio storage — Call audio is not permanently stored by default – only transcripts and summaries are generated.
Transport and language layer: separate from the AI — Call delivery (Twilio), speech recognition (Deepgram) and speech synthesis (ElevenLabs) run through established US providers, engaged as data processors under Article 28 GDPR.
Data control
You decide which data goes to the AI
The AI never gets automatic access to everything. You decide, per company, which capabilities the assistant may use, what an input triggers, and which knowledge sources feed in. The role and permission management of each account stays active on top – both are enforced server-side, not just in the interface.
Enable capabilities individually — Per company you control which capabilities the assistant may read and which it may run – for example querying data, generating reports, creating reports, or time tracking. Reading and actions can be toggled separately.
Input rules instead of automation — You define what a voice note, a photo, or a shared location triggers. When something is ambiguous, the assistant asks back instead of deciding on its own.
Release knowledge sources deliberately — You choose which site documents, notes, and data the assistant knows. Anything not released does not feed into the chat.
Account permissions apply on top — The AI releases act as an additional layer above the existing roles and permissions. Effectively allowed is only what the company release and the account permission permit together – the assistant never sees more than the person does.
Compliance
Verifiable proof – not just promises
Security has to be verifiable. The following sources lead directly to Microsoft’s own security and compliance evidence for Azure and the Azure AI services – including downloadable audit reports and certificates.
Microsoft Service Trust Portal – audit reports & certificates
This is where Microsoft provides the actual evidence for download: ISO 27001/27018, SOC 1/2/3 and BSI C5.
Open source ↗Microsoft Trust Center
Microsoft’s central overview of security, privacy and compliance across all Azure services.
Open source ↗Azure security – documentation
How Microsoft secures the Azure platform technically (Azure Security Fundamentals): identity, encryption, network and data-center security.
Open source ↗Azure AI services – security
Microsoft’s overview of the security features of the Azure AI services that run the language model.
Open source ↗Azure OpenAI – data, privacy & security
Microsoft’s evidence: inputs and outputs are processed in isolation, not used to train the models and not shared with OpenAI.
Open source ↗Azure OpenAI – transparency & Responsible AI
Microsoft’s transparency note on how the Azure OpenAI models work, their limits and their safe use.
Open source ↗EU Data Boundary
Microsoft’s commitment to store and process data from EU customers within the EU/EFTA.
Open source ↗Legal framework
Beyond the technical platform, the AI phone assistant is designed for the requirements of European law: a fixed AI disclosure that lets deploying companies meet the transparency obligations of the EU AI Act (Art. 50), plus a data processing agreement under Art. 28 GDPR that is part of the contract at no extra charge.
We fully disclose which data processors are used – including the US services for telephony, speech recognition and speech synthesis (e.g. Twilio, Deepgram, ElevenLabs), safeguarded for third-country transfer through appropriate guarantees (EU Standard Contractual Clauses under Art. 46 GDPR or the EU-US Data Privacy Framework under Art. 45 GDPR).
Binding legal bases:
Key answers about secure AI at LiteLog
Frequently asked questions
Which AI model does the assistant use?
The language model runs via Microsoft Azure OpenAI in the EU region Sweden Central – not through public ChatGPT.
What data is sent to the AI?
Only conversation transcripts – never raw audio files. Microsoft does not use this data for training.
Does data leave the EU?
Language model processing stays in Sweden Central and hosting is in Frankfurt. Telephony and speech synthesis use US providers engaged as data processors under appropriate legal safeguards (SCC / EU-US Data Privacy Framework).
Is the service ISO 27001 certified?
The ISO 27001/27018, SOC and BSI C5 certifications apply to the underlying Microsoft Azure infrastructure. The service itself operates under GDPR compliance with disclosed subprocessors.
Is call audio saved?
No – audio is not permanently stored by default. Only transcripts and summaries are retained.
