Security and data protection
How data flows through a conversation
The path a call or a WhatsApp message takes through your deployment, where each provider sits relative to your region, and what is stored at each point.
On this page
Your security and architecture teams need to draw the data flow for their own risk assessment: where a conversation enters, which provider touches it, what is stored, and what leaves the region. This page follows a voice call and a WhatsApp message through a Telonic deployment step by step. All processing for your deployment runs in the region you choose, unless you explicitly choose a language model provider outside it, and this page shows exactly where that boundary sits.
What sits inside your region, and what sits outside
Unless you choose a language model outside your region, everything that processes a conversation sits inside your region boundary. That includes the SIP endpoint (the address in your deployment that receives calls), speech recognition (turning speech into text), the language model (understanding the conversation and deciding the reply), voice synthesis (speaking the reply), the customer record and the audit log. Backups and disaster recovery copies are encrypted and stay in the same country.
Three things sit outside the boundary. The networks your customers already use, such as your carrier and Meta's WhatsApp platform, carry conversations to your deployment under their own terms. Your own systems, such as your CRM (customer relationship management system) or booking system, connect to the deployment over encrypted connections. A language model outside your region is used only if you explicitly choose one, and it receives text with personal information redacted first.
A voice call, step by step
- The call arrives as it does today. Rania dials your number. The call reaches your carrier, and your phone system applies the routing rules you have set.
- The call reaches your deployment. Calls routed to the agent travel over a SIP trunk (a virtual phone line between two phone systems) to the SIP endpoint in your region. SIP signalling is encrypted with TLS (Transport Layer Security, the standard encryption for data sent over networks) 1.2 or higher, and the audio with SRTP (Secure Real-time Transport Protocol, which encrypts call audio) by default. Your trunk is authenticated with IP allow-listing (accepting connections only from agreed network addresses) and SIP digest credentials (a username and password check on each call), and mutual TLS (where both sides present a certificate) is supported.
- Consent comes first. The agent asks for consent to record. Until the caller answers, only the consent answer is recorded, and nothing else from that part of the call is stored. Recording starts only if consent is given.
- Speech becomes text in your region. Speech recognition, running in your region, turns Rania's speech into text as she speaks.
- The agent decides the reply. The language model interprets the request within the agent's limits, using facts looked up in your systems over TLS. Amounts and dates are inserted directly from your system's record, not retyped by the model.
- If you chose a language model outside your region. Before the text leaves, each piece of personal information is replaced with a placeholder. The reply comes back, and the real values are restored inside your deployment.
- The reply is spoken in your region. Voice synthesis turns the reply into speech, which returns to Rania over the same encrypted connection.
- Work is completed in your systems. Actions such as changing a booking or logging a claim are written to your systems over TLS, using only the permissions your IT team granted.
- A person takes over when needed. The handover brief is delivered into the system your team works in: your contact centre platform, your CRM or the Telonic console (the web application your team uses). The call carries a conversation reference in a SIP header.
- The conversation is recorded as you have set. The summary, outcome, transcript and, with consent, the recording are stored in your region, if you have chosen to keep them, for the period you set. The audit log records each action, its sources and the rule or trigger that applied.
A WhatsApp message, step by step
- Meta carries the message. A customer messages your WhatsApp number. Meta receives, processes and briefly stores the message on its own infrastructure, under its own terms, as it does for every business on WhatsApp.
- The message reaches your deployment. Telonic connects through Meta's Cloud API (Meta's hosted service for WhatsApp business messaging), or through your existing Meta business solution provider if you have one. The message arrives by webhook (a message one system sends another when something happens), over TLS.
- Voice notes, images and documents are read in your region. A voice note is transcribed by speech recognition in your region. Images and documents are read by a model running in your region.
- The customer is identified. The agent matches the phone number to the customer record, and runs the identity check you have set before sharing account details, such as a booking reference with a date of birth, or a one-time passcode.
- The agent decides the reply. As on a call, the language model works within your limits, with facts from your systems over TLS. The same redaction and restoration apply if you chose a language model outside your region.
- The reply goes back through Meta. The reply is sent to Meta over TLS, and Meta delivers it to the customer.
- The conversation is recorded as you have set. The summary, outcome and messages are stored in your region if you have chosen to keep them, and the audit log records each action.
What is stored, where, and when
Nothing is stored without your permission, and you set how long each kind of content is kept.
| Data | When it is created | Where it is held | How long |
|---|---|---|---|
| Consent answer | At the start of every call where consent is asked, whatever the answer | Your region | The period you set |
| Call recording | Only after the caller consents, and only if you keep recordings | Your region | The period you set |
| Transcript and messages | During the conversation | Your region | The period you set. Card numbers are redacted. Masking of other personal information in stored transcripts is configured during implementation, to your settings |
| Summary and outcome | When the conversation ends | Your region | The period you set |
| Customer record | Built across conversations | Your region | The period you set |
| Audit record | At every action | Your region | The period you set. With content storage off, a content-free record of actions, sources, triggers and outcomes is still kept |
| Credentials for your systems | During implementation | Encrypted in a secrets store (a service built to hold credentials securely) in your region | Until the connection is removed or the credential is replaced |
| Backups | On the backup schedule | Encrypted, in the same country as your deployment | Until each backup expires |
| WhatsApp messages at Meta | In transit | Meta's infrastructure | Briefly, under Meta's terms |
| Text sent to an out-of-region language model, if you choose one | Per reply | The provider you chose | Personal information replaced with placeholders. Zero data retention wherever the provider offers it, and no use for training |
What leaves your region, and how it is protected
| Destination | What it receives | How it is protected |
|---|---|---|
| Your own systems | What each permitted lookup or action needs | TLS 1.2 or higher, and only the permissions your IT team granted |
| Your customers | The agent's replies | Carried by the channel, as today |
| Your carrier and Meta | The conversation, carried as it is today | Their own terms. The link to your deployment is encrypted |
| A language model outside your region, only if you choose one | Conversation text, retrieved facts and the agent's instructions | Personal information replaced with placeholders, restored inside your deployment. Encrypted in transit |
| Reports and exports | The content you select | Personal information redacted by default |
In practice
Qamar Stays, a hotel group, hosts its deployment in the Saudi Arabian region and keeps every provider in-region.
- Faisal calls the reservations line at 11pm. The group's phone system routes the call over its SIP trunk to the endpoint in the Saudi Arabian region.
- He agrees to recording. Speech recognition, the language model and voice synthesis all run in the region.
- The agent looks up reservation QS-48213 in the group's reservation system over TLS, confirms the extra night at the booked rate, and writes the change back.
- The recording, transcript and summary are stored in the region for the periods the group has set. The audit log records the lookup, the change and the rule that permitted it.
- The next morning, the revenue team exports a report of overnight changes. Faisal's name and phone number are redacted in the export by default.
What your team controls
- The hosting region, and whether any language model outside it may be used.
- Whether recordings, transcripts, summaries and the customer record are kept, and for how long.
- Masking of personal information in stored transcripts, configured during implementation.
- Which systems the agent can reach, and the actions it can take in each.
- Where handover briefs are delivered.
Related
- Hosting and data residencySecurity and data protection
- Personal information redactionSecurity and data protection
- Models and providersAgents
- Voice: connecting your telephony over SIPChannels
- Storage, retention and deletionSecurity and data protection
Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.