Security and data protection
Hosting and data residency
The four ways a Telonic deployment can be hosted, where your data is processed and stored, and how to choose.
On this page
You decide where your deployment runs, and your customers' conversations are processed there. Telonic can be hosted in a UAE region, in a Saudi Arabian region, in your own cloud account, or on your own premises. All processing for your deployment, including the speech and language models, runs in the region you choose, unless you explicitly choose a language model provider outside it. This page sets out each option, what stays inside your chosen region, and how to decide.
Four hosting options
| Option | Where it runs | Who operates the infrastructure | Typically chosen when |
|---|---|---|---|
| UAE region | Telonic's deployment in a cloud region located in the UAE | Telonic | Your customers and your data policy are UAE-based |
| Saudi Arabian region | Telonic's deployment in a cloud region located in Saudi Arabia | Telonic | You process data belonging to Saudi residents, or your policy requires data to stay in the Kingdom |
| Your own cloud account | Inside a cloud account your organisation owns, in the region you choose | Your organisation owns the account; Telonic deploys and runs the software in it | Your security policy requires customer data to stay within infrastructure you control |
| Your own premises | On infrastructure in your own data centre | Your organisation, with Telonic, to your requirements | Your policy or regulator requires on-premises systems |
Each option runs in a cloud region (a group of data centres a cloud provider operates in one country) or in your own facilities. Regional hosting uses major cloud providers' data centres in the UAE and in Saudi Arabia, and the provider and region are named in your agreement. For your own cloud account, Microsoft Azure, AWS, Google Cloud and Core42 are supported. On-premises deployments run open-weight language models (models whose weights can be run on your own hardware) and self-hosted speech models, and the computing capacity required is sized with you during implementation.
UAE region
Operated by Telonic
Saudi Arabian region
Operated by Telonic
Your own cloud account
You own the account. Telonic runs the software
Your own premises
Set up to your requirements
In every option, processing for your deployment runs inside the boundary, unless you explicitly choose a language model provider outside it.
Where your data is processed
All processing for a deployment runs in the region you choose. That includes the parts people most often ask about: speech recognition, the language model and voice synthesis each run on models and providers deployed in that region. The transcript, the customer record and the agent's decisions are produced and held there too.
A provider that processes outside your chosen region is used only if you explicitly choose it, and only a language model can be chosen this way. If you do, personal information is redacted before any data reaches it: each item is replaced with a placeholder, and the real values are restored in the reply inside your deployment. Speech recognition and voice synthesis always run in your chosen region. See Models and providers.
| Part of a conversation | Where it is processed |
|---|---|
| Call audio and the SIP connection (the standard link that carries calls from your phone system) | Your chosen region |
| Speech recognition (turning speech into text) | Your chosen region |
| The language model (understanding and deciding the reply) | Your chosen region, unless you explicitly choose a language model provider outside it, in which case personal information is redacted first |
| Voice synthesis (speaking the reply) | Your chosen region |
| Lookups and write-backs to your systems | Between your chosen region and your systems, over encrypted connections |
| The customer record, transcripts and logs | Stored in your chosen region, only with your permission, for the period you set |
For a step-by-step view of a single conversation, see How data flows through a conversation.
How your customers' messages reach your deployment
Your customers reach you through networks you already use, and those networks carry the conversation to your deployment. Your carrier carries phone calls, Meta's WhatsApp platform carries WhatsApp messages, and your email provider carries email. Each operates under its own terms, as it does today. Meta, for example, receives and briefly stores WhatsApp messages on its own infrastructure before they reach your deployment.
From the moment a conversation arrives at your deployment, it is processed in your chosen region. For WhatsApp, Telonic connects through Meta's Cloud API, or through your existing business solution provider if you have one.
What is stored, and for how long
Nothing is stored without your permission. For each kind of content, such as call recordings, transcripts, summaries and the customer record, you decide whether it is kept and for how long. Calls are recorded only once the caller has given consent.
Personal information is redacted (removed or masked) before data leaves your deployment for anywhere other than your own systems and your own customers, such as a provider outside your region or an analytics export. Redaction applies to reports and exports by default.
Where your policy does not allow conversation content to be kept, the deployment can run without storing it, or store it only in storage you control. See Storage, retention and deletion.
Backups and disaster recovery copies are encrypted and stay in the same country as your deployment.
How your data is protected in every option
| Protection | How it works |
|---|---|
| Encryption in transit | Every connection between your systems and your deployment is encrypted with TLS (Transport Layer Security), version 1.2 or higher. For call audio, see Voice: connecting your telephony over SIP |
| Encryption at rest | Stored data is encrypted with AES-256 (the Advanced Encryption Standard, using 256-bit keys) |
| Key management | Keys are managed through the hosting environment's key management service (the cloud service that creates, stores and controls access to encryption keys). In your own cloud account, customer-managed keys are supported. |
| Separation | Each customer's deployment and data are kept separate from every other customer's. In the regional options, separation is logical by default, and a dedicated environment is available |
| Access | Your team signs in through your own identity provider (the system that manages your staff's logins), with multi-factor authentication (a second check beyond a password). Each person and each agent has only the access its role needs, and access and changes are logged |
See Encryption, Access control and single sign-on and Deployment separation.
Who at Telonic can reach your deployment
Access by Telonic staff is limited to named engineers, working from the UAE or your chosen country. Access is time-limited, and every access is logged. For deployments in your own cloud account or on your own premises, each access needs your approval.
In your own cloud account or on your own premises, every component runs inside your environment. Only operational health signals, containing no customer data, are sent to Telonic, and you can switch these off.
Choosing an option
Start from three questions:
- Whose data is it, and where do they live? If you process data belonging to Saudi residents, Saudi data protection law applies to that data wherever it is processed. Hosting in a Saudi Arabian region keeps processing in the Kingdom. Your legal team decides what the law requires of you.
- What does your own policy require? If your security policy says customer data must stay in infrastructure you control, choose your own cloud account or your own premises.
- What does your regulator or your procurement require? If your organisation may only use cloud infrastructure that holds a particular local accreditation, hosting in your own cloud account or on your own premises means the deployment runs inside the environment you have already approved.
We work through these questions with your IT, security and legal teams before implementation, and record the answer in your agreement. The legal detail is on Data protection in the UAE and Saudi Arabia.
The hosting option is agreed before implementation. You can move to another option after go-live through a migration agreed with you in advance. Data is moved encrypted and never leaves the permitted countries.
In practice
A Saudi insurer with policyholders in the Kingdom and the UAE deploys Telonic for claim status and document collection.
- Its data protection officer confirms that policyholder data must be processed and stored in Saudi Arabia.
- The insurer chooses the Saudi Arabian region. Speech recognition, the language model and voice synthesis for its deployment all run on providers deployed in that region.
- Its security team sets retention: call recordings for the period its claims policy requires, and transcripts and summaries for the life of the policy plus the period it specifies.
- When Nora, a policyholder in Riyadh, calls about her claim, the call audio, the transcript and the agent's decisions are processed and stored in the Saudi Arabian region.
- The agent looks up her claim in the insurer's claims system over an encrypted connection, and writes the outcome back to the same system.
- When the insurer's analytics team exports a monthly report, personal information is redacted before the export leaves the deployment.
What your team controls
- The hosting option and region, agreed before implementation.
- Whether any provider outside your region may be used, and for what.
- Whether each kind of content is stored, and for how long.
- Who in your organisation can see stored data.
- In your own cloud account, the encryption keys.
Related
- How data flows through a conversationSecurity and data protection
- Models and providersAgents
- Storage, retention and deletionSecurity and data protection
- Deployment separationSecurity and data protection
- Data protection in the UAE and Saudi ArabiaLegal and compliance
Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.