Phone Agent: Data Privacy, Security, Data Flow

Change history (1 entry)
  • 12/08/2026Initial publication of this page. Consolidates existing information on architecture, data flow, data types, AI model, sub-processors and security measures of the Phone Agent from the DPA, supplementary DPA, sub-processor list, IT security measures and data privacy overview.

This page consolidates the information relevant to the LoyJoy Phone Agent on architecture, data processing, data privacy and security measures. It summarizes existing provisions from the DPA, supplementary DPA, sub-processor list, IT security measures and data privacy overview, and does not replace these documents.

1. Purpose and Scope

The LoyJoy Phone Agent enables voice dialogues between callers and an AI-powered agent via the LoyJoy Platform. It is used to resolve customer inquiries over the phone end-to-end or to hand them over to human staff.

For a clear understanding of the processing, it helps to distinguish the following areas:

  • Telephony: Answering, routing and technical control of the call.
  • Real-time AI processing: Converting speech to text and back, and generating the response.
  • LoyJoy Platform: Orchestrating the dialogue, process control, storing transcripts and configuration data.
  • Knowledge access: Access to tenant-specific knowledge sources to answer domain questions.
  • Connected customer systems: Optional connection to the tenant’s CRM, ERP or other systems via APIs.

The specific configuration, in particular which systems are connected and which retention periods apply, may vary by tenant and customer project. This page describes the standard case.

2. Simplified Architecture

Simplified architecture of the LoyJoy Phone Agent A caller connects via a telephony entry point to the LoyJoy Platform. The LoyJoy Platform orchestrates the dialogue, processes speech via Microsoft Azure using the gpt-realtime-1.5 model, accesses knowledge sources and optionally customer APIs, and stores persistent platform data with Google Cloud EMEA. easybell is shown as a dashed, optional backup telephony path and is not active in standard operation. Caller Telephony entry point / active telephony path LoyJoy Platform Agent orchestration, process and dialogue control Microsoft Azure gpt-realtime-1.5 Speech-to-speech EU Data Zone Knowledge sources optional customer APIs (tenant-specific) Google Cloud EMEA Persistent platform data easybell Optional backup path, not active in standard operation
Simplified representation. The specific configuration may vary by tenant and customer project. Dashed elements are optional and not active in standard operation.

3. Data Flow

  1. The phone call arrives via the telephony entry point.
  2. The audio stream is transmitted encrypted to speech processing.
  3. Speech-to-speech processing takes place using gpt-realtime-1.5 via Microsoft Azure (EU Data Zone).
  4. The LoyJoy Platform controls the agent, including knowledge lookups and, where applicable, tool calls to connected customer systems.
  5. The audio response is delivered to the caller.
  6. Transcript and call recording are optionally stored, depending on the tenant configuration.
  7. The conversation is analyzed and summarized, and automatically deleted after the configured period.

4. Data Types and Storage

Data typePurposeSystems involvedPermanent storageDefault retentionConfigurability
Telephony metadataTechnical answering, routing and control of the callTelephony entry point, LoyJoy PlatformNo, unless carried over into logs or conversationsTechnical sessionNot separately configurable
Live audio streamReal-time speech processing during the callTelephony entry point, Microsoft Azure (gpt-realtime-1.5)NoTechnical sessionNot configurable
TranscriptDialogue management, traceability, analysisLoyJoy Platform, Google Cloud EMEAYes, as a conversation message30 daysConfigurable per tenant
Call recording (optional)Quality assurance, evidence, analysisLoyJoy Platform, Google Cloud EMEAYes, only if enabled30 daysEnablement and period configurable
Summary and analytics dataEvaluation, reporting, quality analysisLoyJoy PlatformYesSame as associated transcriptConfigurable per tenant
Tool calls and technical logsTraceability, error analysis, security monitoringLoyJoy Platform, customer APIs where applicableYes, as part of loggingPer deletion conceptRole-based access

The following applies as a binding statement:

  • The live audio stream is not permanently stored by LoyJoy.
  • Transcripts are stored as conversation messages.
  • The default retention period for phone transcripts is 30 days.
  • Call recording is optional.
  • The default retention period for enabled call recordings is 30 days.
  • Different retention periods can be configured per tenant.

5. AI Model and Processing Region

  • Voice model currently in use: gpt-realtime-1.5.
  • Processing takes place via Microsoft Azure.
  • Current deployment type: EU Data Zone.
  • Customer data transmitted via the Phone Agent is not used to train or improve the base model.

As of August 12, 2026, for the model and region information.

6. Sub-Processors

  • Microsoft Azure: Currently active speech-to-speech processing, EU Data Zone.
  • Google Cloud EMEA: Hosting of persistent LoyJoy platform data.
  • easybell: Optional backup telephony provider, currently not active in standard operation.

The full list is available in the Sub Processors List.

7. Security Measures

The following measures apply to the Phone Agent, among others:

  • TLS encryption for data transmission
  • Encryption of platform data at rest
  • Logical tenant separation
  • Role-based access control
  • Two-factor authentication (2FA)
  • Logging of relevant access
  • Automated deletion periods
  • Daily backups under the applicable backup policy
  • Restrictive production access
  • Incident and vulnerability management

Details are available in the technical and organizational measures (TOMs) and the IT security measures. For security reasons, no credentials, specific endpoints, network configurations or other attack-relevant details are published here.

8. Responsibility and Customer Configuration

Before going live, tenants should clarify the following points:

  • Legal basis and privacy notice toward callers
  • Enabling or disabling call recording
  • Retention periods for transcripts and recordings
  • Permissible call content
  • Whether identity verification is required
  • Connected customer systems
  • Roles and export rights in the LoyJoy Manager
  • Whether a data protection impact assessment is required
  • Handover to human staff

9. Further Documents

Frequently Asked Questions