Security and data protection
Personal information redaction
What personal information Telonic redacts, when and how it does so, and how your team checks the result.
On this page
Personal information should go only where it is needed: to you, your systems and your customers. Telonic finds personal information in conversation data and redacts it (removes it, or replaces it with a placeholder) before data leaves your deployment for anywhere else, such as a provider outside your region for the language model (the AI model that understands the conversation and decides the reply), or an analytics export. This keeps the data your customers share within the boundary you have chosen, and limits what any other party receives to what it needs. This page lists what is redacted, when, how it is detected and how your team checks it.
What is redacted
| Kind of personal information | Example (fictional) |
|---|---|
| Names, in Arabic and Latin script | "ريم الحارثي", "Reem Al Harthi", "Reem Alharthy" |
| Phone numbers | "+971 50 123 4567", "0501234567" |
| Email addresses | "reem.h@example.com" |
| National identity numbers, including Emirates ID and Iqama numbers | "784-XXXX-XXXXXXX-X" |
| Passport numbers | "N1234567" |
| Payment card numbers | "4111 1111 1111 1111" |
| Bank account numbers and IBANs (international bank account numbers) | "AE12 0000 0000 0000 0000 000" |
| Dates of birth | "born on the fourteenth of March" |
| Street addresses | "Villa 12, Street 4, Al Barsha" |
Booking, policy and claim references are not redacted, so the agent and your team can follow a case from one conversation to the next.
When redaction happens
| Situation | What happens |
|---|---|
| Text sent to a language model outside your region, only if you choose one | Personal information is replaced with placeholders before the text leaves. The real values are restored in the reply inside your deployment |
| Reports and exports | Redacted by default |
| Any other destination outside your deployment, other than your own systems and your own customers | Redacted before the data leaves |
| Card numbers spoken or typed in a conversation | Redacted |
| Transcripts stored inside your deployment | Masked to your settings, configured during implementation |
Your own systems and your own customers receive the real values, because they need them. A lookup in your reservation system has to carry the guest's name, and a reply to a policyholder has to address her correctly. Everything else that leaves your deployment is redacted first.
Card details do not need to enter the conversation at all. For payments, the agent sends a payment link from your payment provider, so card data stays with that provider. The agent never asks for card details, because payments are taken through links from your payment provider. If a card number is spoken or typed anyway, it is removed from the transcript and masked in the recording.
How placeholders work with a language model outside your region
When you choose a language model outside your region, each piece of personal information in the text is replaced with a labelled placeholder, such as [NAME_1] or [PHONE_1], before the text leaves your deployment. The model sees the structure of the conversation, and can reply to it, without the values themselves. When the reply returns, the placeholders are replaced with the real values inside your deployment. The mapping between each placeholder and its value never leaves your deployment.
This applies to everything the model receives: the customer's words, the facts retrieved from your systems and the agent's instructions. Amounts and dates in the reply are inserted directly from your system's record rather than retyped by the model, so they match your system's record whichever model writes the sentence around them.
How personal information is detected
Detection runs inside your deployment, in your chosen region, on text: typed messages, transcripts produced by speech recognition (turning speech into text), and text read from documents and images. It combines two methods. Structured items, such as phone numbers, identity numbers, card numbers, IBANs, email addresses and dates, are recognised by their patterns, including numbers read out on a call. Names and street addresses are recognised in Arabic script and in Latin script.
The technical detail
Names are the hardest item to detect well in this region. "Noor" can be a person's name or the word for light, one Arabic name can be spelled several ways in Latin letters, and customers often switch between Arabic and English in the same sentence. That is why detection is tested before go-live (the point at which the agent starts handling real customers) against examples in the languages, dialects and formats your customers use, and again after any change to it.
Your team can review redacted transcripts and exports in the console (the web application your team uses) and report anything that was missed. Detection is automated, so it is tested and reviewed rather than assumed.
In practice
Sahel Crest Properties, a Dubai developer, hosts in the UAE region and chooses a language model outside the region for its English and Arabic enquiry line.
- Its data protection officer approves the choice in writing, and it is recorded in the agreement and the list of sub-processors (companies that process personal data on Telonic's behalf).
- Rania, a buyer, messages on WhatsApp: "مرحبا، أنا رانيا خوري. I'd like a viewing of the two-bedroom at Creek Rise. My email is rania.k@example.com."
- Inside the deployment, her name and email address are replaced with placeholders. The model receives the request, the project name and the placeholders.
- The agent books the viewing in the sales team's calendar using her real details, which never left the deployment.
- At month end, the marketing team exports enquiry volumes by project. Names, phone numbers and email addresses are redacted in the export by default.
What your team controls
- Whether a language model outside your region is used at all. With every provider in your region, text is never sent to a model provider outside it.
- Masking of personal information in stored transcripts, configured during implementation.
- Who in your organisation can see unredacted conversations inside your deployment, through roles.
Related
- How data flows through a conversationSecurity and data protection
- Models and providersAgents
- Storage, retention and deletionSecurity and data protection
- Reports and exportsQuality and analytics
- Data protection in the UAE and Saudi ArabiaLegal and compliance
Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.