Skip to main content

Introduction

This document forms part of the Data Localization & Security Assessment Report (SAR) for our voice agent platform.
It provides a clear overview of all third-party vendors engaged in processing, transmitting, or storing customer data, along with official statements on their data retention practices.
Our objective is to:
  1. Identify all relevant third-party providers involved in Text-to-Speech (TTS), Speech-to-Text (STT), Large Language Models (LLM), Telephony, and Cloud Hosting.
  2. Demonstrate compliance with data localization, security, and privacy regulations through documented evidence of vendor commitments.
  3. Establish internal controls ensuring zero or minimal retention wherever feasible.
This appendix supports our claims with:
  • Vendor Inventory Table – mapping vendors, data types shared, purposes, transfer methods, and compliance measures.
  • Data Retention Evidence Appendix – direct quotes and source links from vendor documentation confirming their retention and usage policies.

1. Third-Party Vendor Inventory

The table below lists the categories of third-party service providers we use, along with details on the nature of the data shared and the safeguards in place. This inventory is reviewed annually and updated whenever a new vendor is onboarded or an existing vendor’s scope changes.

2. Third-Party Data Retention Evidence Appendix

For each vendor category, we have gathered official statements from vendor documentation regarding their data retention and usage practices. These references allow auditors to independently verify compliance claims.

3. Implementation & Internal Controls

  • Data Minimization: We configure each integration to share only the minimum necessary data. Where possible, we strip or anonymize PII before sending it to vendors.
  • Encryption: All API calls are encrypted in transit (TLS 1.2+), and sensitive data is encrypted at rest.
  • Zero Retention Settings: Vendors that support zero retention (e.g., OpenAI ZDR, Gemini no-caching, ElevenLabs Zero Retention Mode, Deepgram mip_opt_out) are configured accordingly.
  • Periodic Review: Vendor policies are reviewed quarterly to ensure ongoing compliance with local regulations and customer contractual obligations.

4. Conclusion

This appendix demonstrates that:
  • All third-party vendors with access to customer data have been identified.
  • We have gathered and documented evidence of their retention policies.
  • Where possible, we actively configure services for zero or minimal data retention.
This approach provides transparency, satisfies regulatory requirements, and ensures our voice agent platform adheres to best practices for data localization and security.

Questions and Concerns

If you have questions about our data sharing practices or wish to exercise your data rights, please contact our Data Protection Officer at contact@revrag.ai.