Phone Agent: Data Privacy, Security, Data Flow
Change history (1 entry)
- 12/08/2026Initial publication of this page. Consolidates existing information on architecture, data flow, data types, AI model, sub-processors and security measures of the Phone Agent from the DPA, supplementary DPA, sub-processor list, IT security measures and data privacy overview.
This page consolidates the information relevant to the LoyJoy Phone Agent on architecture, data processing, data privacy and security measures. It summarizes existing provisions from the DPA, supplementary DPA, sub-processor list, IT security measures and data privacy overview, and does not replace these documents.
1. Purpose and Scope
The LoyJoy Phone Agent enables voice dialogues between callers and an AI-powered agent via the LoyJoy Platform. It is used to resolve customer inquiries over the phone end-to-end or to hand them over to human staff.
For a clear understanding of the processing, it helps to distinguish the following areas:
- Telephony: Answering, routing and technical control of the call.
- Real-time AI processing: Converting speech to text and back, and generating the response.
- LoyJoy Platform: Orchestrating the dialogue, process control, storing transcripts and configuration data.
- Knowledge access: Access to tenant-specific knowledge sources to answer domain questions.
- Connected customer systems: Optional connection to the tenant’s CRM, ERP or other systems via APIs.
The specific configuration, in particular which systems are connected and which retention periods apply, may vary by tenant and customer project. This page describes the standard case.
2. Simplified Architecture
3. Data Flow
- The phone call arrives via the telephony entry point.
- The audio stream is transmitted encrypted to speech processing.
- Speech-to-speech processing takes place using
gpt-realtime-1.5via Microsoft Azure (EU Data Zone). - The LoyJoy Platform controls the agent, including knowledge lookups and, where applicable, tool calls to connected customer systems.
- The audio response is delivered to the caller.
- Transcript and call recording are optionally stored, depending on the tenant configuration.
- The conversation is analyzed and summarized, and automatically deleted after the configured period.
4. Data Types and Storage
| Data type | Purpose | Systems involved | Permanent storage | Default retention | Configurability |
|---|---|---|---|---|---|
| Telephony metadata | Technical answering, routing and control of the call | Telephony entry point, LoyJoy Platform | No, unless carried over into logs or conversations | Technical session | Not separately configurable |
| Live audio stream | Real-time speech processing during the call | Telephony entry point, Microsoft Azure (gpt-realtime-1.5) | No | Technical session | Not configurable |
| Transcript | Dialogue management, traceability, analysis | LoyJoy Platform, Google Cloud EMEA | Yes, as a conversation message | 30 days | Configurable per tenant |
| Call recording (optional) | Quality assurance, evidence, analysis | LoyJoy Platform, Google Cloud EMEA | Yes, only if enabled | 30 days | Enablement and period configurable |
| Summary and analytics data | Evaluation, reporting, quality analysis | LoyJoy Platform | Yes | Same as associated transcript | Configurable per tenant |
| Tool calls and technical logs | Traceability, error analysis, security monitoring | LoyJoy Platform, customer APIs where applicable | Yes, as part of logging | Per deletion concept | Role-based access |
The following applies as a binding statement:
- The live audio stream is not permanently stored by LoyJoy.
- Transcripts are stored as conversation messages.
- The default retention period for phone transcripts is 30 days.
- Call recording is optional.
- The default retention period for enabled call recordings is 30 days.
- Different retention periods can be configured per tenant.
5. AI Model and Processing Region
- Voice model currently in use:
gpt-realtime-1.5. - Processing takes place via Microsoft Azure.
- Current deployment type: EU Data Zone.
- Customer data transmitted via the Phone Agent is not used to train or improve the base model.
As of August 12, 2026, for the model and region information.
6. Sub-Processors
- Microsoft Azure: Currently active speech-to-speech processing, EU Data Zone.
- Google Cloud EMEA: Hosting of persistent LoyJoy platform data.
- easybell: Optional backup telephony provider, currently not active in standard operation.
The full list is available in the Sub Processors List.
7. Security Measures
The following measures apply to the Phone Agent, among others:
- TLS encryption for data transmission
- Encryption of platform data at rest
- Logical tenant separation
- Role-based access control
- Two-factor authentication (2FA)
- Logging of relevant access
- Automated deletion periods
- Daily backups under the applicable backup policy
- Restrictive production access
- Incident and vulnerability management
Details are available in the technical and organizational measures (TOMs) and the IT security measures. For security reasons, no credentials, specific endpoints, network configurations or other attack-relevant details are published here.
8. Responsibility and Customer Configuration
Before going live, tenants should clarify the following points:
- Legal basis and privacy notice toward callers
- Enabling or disabling call recording
- Retention periods for transcripts and recordings
- Permissible call content
- Whether identity verification is required
- Connected customer systems
- Roles and export rights in the LoyJoy Manager
- Whether a data protection impact assessment is required
- Handover to human staff
9. Further Documents
Frequently Asked Questions
No. The live audio stream is not permanently stored by LoyJoy; it is processed exclusively in real time for transcription and speech synthesis.
30 days by default. Tenants can configure a different retention period in the LoyJoy Platform.
No, call recording is optional and must be actively enabled by the tenant. The default retention period for enabled recordings is 30 days.
No. Customer data transmitted via the Phone Agent is not used to train or improve the underlying base model.
No. easybell is provided solely as an optional backup telephony path and is not active in standard operation.