TelonicDocs
English

FAQ

Legal and compliance questions

Direct answers to the questions legal, compliance and risk teams ask about data protection, consent, contracts and decisions.

On this page
  1. The law and your obligations
  2. Will using Telonic keep us within UAE and Saudi data protection law?
  3. What do UAE and Saudi data protection laws require?
  4. Does recording a call need the caller's consent?
  5. What about rules on outbound calls and marketing messages?
  6. How does Telonic approach the regulation of AI?
  7. Can the agent make decisions about our customers, such as a claims decision?
  8. Your data
  9. Where is our data stored?
  10. Who at Telonic can see our data?
  11. Which third parties process our data?
  12. What happens if there is a data breach?
  13. Can we get our data back if we leave?
  14. Contracting and assurance
  15. Who is the contracting entity?
  16. Which security certifications do you hold?
  17. Can we audit how the agent handled a particular customer?
  18. Related

These are the questions legal, compliance and risk teams ask most often, answered directly. They cover what the relevant laws require in plain terms, what the product does to support your obligations, and what your agreement with Telonic contains. Each answer links to the page with the full detail.

Note

This page is general information, not legal advice. Your organisation is responsible for its own compliance, and should take its own legal advice on how the law applies to it.

The law and your obligations

Will using Telonic keep us within UAE and Saudi data protection law?

Telonic is built so you can meet your obligations: processing in the region you choose, nothing stored without your permission, retention periods you set, access limited by role, personal information redacted before data leaves your deployment, and a full record of what the agent did. Whether your deployment meets the law is a judgement for your legal team, because it depends on your data, your customers and your purposes. We do not make compliance claims on your behalf. We walk your legal team through exactly how the product handles each requirement.

See Data protection in the UAE and Saudi Arabia.

What do UAE and Saudi data protection laws require?

In the UAE, the Federal Decree-Law on the Protection of Personal Data sets rules on consent and the other grounds for processing, individuals' rights over their data, security, breach notification and transfers outside the country, and detailed rules continue to be issued. In Saudi Arabia, the Personal Data Protection Law and its implementing regulations, overseen by the Saudi Data and Artificial Intelligence Authority (SDAIA), apply to the personal data of people in the Kingdom, including when it is processed outside it, and set conditions for transfers abroad. Both give individuals rights to know how their data is used and to ask for it to be corrected or deleted.

See Data protection in the UAE and Saudi Arabia.

The agent asks for consent at the start of every call, as part of the call flow. UAE law requires the consent of all parties to record a call, so calls are recorded only once consent is given. Before that, only the consent answer is recorded, and nothing else from that part of the call is stored. The caller's answer is kept against the conversation, so you can show it later.

See Call recording and consent.

What about rules on outbound calls and marketing messages?

Before any outbound call or message, the agent checks your do-not-contact list and any opt-out. Outbound messages go only to customers whose opt-in is on record, and marketing calls are placed only within permitted hours. UAE rules on telemarketing restrict when and how businesses may call people for marketing, and WhatsApp has its own opt-in rules, set by Meta. Screening numbers against do-not-call registers is configured during implementation.

See Contact rules for outbound messages and calls.

How does Telonic approach the regulation of AI?

Both the UAE and Saudi Arabia have published national principles for the responsible use of AI, and more detailed rules continue to be issued. The product works in ways your teams can assess against those principles: the agent identifies itself as AI, decisions that need judgement stay with your people, every action is logged with its stated reason, and every change is tested before release, with your approval for any change of model or provider. We walk your legal and risk teams through each point that matters to you.

See Responsible use of AI.

Can the agent make decisions about our customers, such as a claims decision?

The agent handles the conversation and the process, and decisions that need judgement or authority stay with your people. In insurance, it never assesses liability, sets a settlement amount, or approves or declines a claim, because those functions are not connected to it. It takes the first notice of loss, answers from the approved policy wording, requests documents and keeps the policyholder updated, and every conversation is on record.

See Decision boundaries and Insurance.

Your data

Where is our data stored?

In the region you choose: a UAE region, a Saudi Arabian region, your own cloud account or your own premises. Nothing is stored without your permission, and you set how long each kind of content is kept. Backups and disaster recovery copies are encrypted and stay in the same country as your deployment.

See Hosting and data residency and Storage, retention and deletion.

Who at Telonic can see our data?

Only named engineers who operate and support your deployment, working from the UAE or from your chosen country, with access that is time-limited and logged. In your own cloud account or on your own premises, each access needs your approval. Staff with access are background-checked and trained in security.

See Access control and single sign-on.

Which third parties process our data?

Sub-processors (companies that process personal data on Telonic's behalf, such as the cloud provider and the model providers for your deployment) are listed in your data processing terms, and the list is available on request. You receive 30 days' notice of any change, with the right to object. For WhatsApp, Meta receives, processes and briefly stores messages on its own infrastructure before they reach your deployment, as it does for every business on WhatsApp.

See Sub-processors.

What happens if there is a data breach?

Telonic follows a defined incident response process. Personal data breaches are notified to your named contacts without undue delay, and within 24 hours of becoming aware of a breach affecting your data, with updates as the investigation continues. The notification sets out what is known at the time about what happened, which data is affected and what is being done, to support your own obligations.

See Incident response.

Can we get our data back if we leave?

Yes. Your data is yours, and Telonic processes it only on your instructions. When the agreement ends, your data is returned to you in a standard format, then deleted from live systems and from backups as they expire, and you receive written confirmation of the deletion.

See Contracts and data processing terms.

Contracting and assurance

Who is the contracting entity?

Your agreement is with Mirchandani Technologies L.L.C-FZ, Meydan Free Zone, Dubai, the company that provides Telonic. Your data processing terms form part of that agreement.

See Contracts and data processing terms.

Which security certifications do you hold?

We take your security team through our controls in full, complete your security questionnaire, and share our architecture under a non-disclosure agreement. The platform is tested by independent penetration testers (security specialists who try to break in, so weaknesses are found and fixed) at least once a year and after major changes. If a specific certification is a requirement for contracting, tell us at the start so we can work through it together.

See Security and data protection overview.

Can we audit how the agent handled a particular customer?

Yes. Every conversation is recorded with what was looked up, the rule or trigger that applied, each action taken and the agent's stated reason. When a customer or a regulator asks what the agent did and why, your team can open the conversation and show them. If your policy does not allow content to be stored, a content-free audit record of actions, sources, triggers and outcomes is still kept for the period you set.

See Audit trail and decision records.


Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.