Trust · Data Protection
How we protect your data
Structured personal data is removed from your conversations before the coaching AI sees them.
What we redact
Before your conversation reaches our coaching AI, we automatically detect and tokenize structured personal data: email addresses, phone numbers, payment-card numbers, IBANs, BICs, postal codes, and URLs.
This runs wherever SonicR1's coaching AI processes your conversation — live coaching in real time and post-call debriefs.
How it works
Detected values are replaced with neutral tokens in memory before the request leaves our systems, so the coaching AI receives tokens in place of raw structured personal data.
Your team sees the real values in the product; the coaching model works from tokens.
Personal names in post-call analysis
When we generate your post-call debrief, personal names are automatically detected and removed from the transcript — in addition to the structured data above — before it is sent to our AI provider.
This applies to your post-call analysis and works across English and German conversations. As with all redaction, your team still sees the real names in the product.
Encryption
Identifying values are encrypted at rest with AES-256-GCM. The encryption key is held in an isolated secrets vault, separate from application credentials.
All data is encrypted in transit with TLS.
No model training
Your conversations are not used to train shared or general-purpose AI models. We use production AI endpoints under the model-improvement opt-outs and contractual restrictions the providers make available to us — an account-level opt-out at our speech-to-text provider, contractual terms at the model provider; the commitment is in section 6.4 of our DPA.
Your data rights
You can delete your account yourself in Settings. The request is held for 24 hours and can be cancelled at any point in that window; after that, deletion runs automatically.
Workspace owners and admins can also delete individual calls from the library, singly or in bulk.
Some things still need a person: a copy of your data, a correction, or winding down a workspace you share with others. Write to legal@sonicr1.com.
Retention & anonymization
Retention is configurable per workspace. After the retention window, the tokens generated during analysis can no longer be re-linked to their original values, while aggregate analytics remain available.
Audit integrity
Every redaction event is written to an audit trail that cannot be altered or overwritten while the call exists; it is removed together with the call when you delete it. More than the consent and erasure logs survives the deletion of an account. The identifying records deliberately retained are: the consent attestations and the erasure log (described in Annex 1, Part D of our DPA), the acceptance evidence for our Terms and DPA including the e-mail address that accepted them, the deletion request record itself, the workspace wind-down record, and billing and monthly usage aggregates. Also kept — the one people are most often surprised by — is the e-mail address of anyone on our do-not-send list, precisely so that the suppression keeps working once the account behind it is gone. Separately from those records, deleting an account does not remove the calls made from it: the account is unlinked from them — the reference goes, the content stays in the workspace — so a transcript may still name the person. That is account unlinking, not anonymisation.
EU data residency by default
Your calls, transcripts and AI coaching are stored in the EU (Frankfurt), and all AI processing runs on EU endpoints — no Customer data is routed to an AI endpoint outside the EEA. The AI endpoints are operated by Google Cloud EMEA Limited (Dublin, Ireland) and by AssemblyAI, Inc., a US-established provider serving EU endpoints; both are engaged under the EU Standard Contractual Clauses (2021/914, Module 3). Three supporting providers hold limited data outside the EU: background-job step state, which can include pseudonymised transcript text and generated CRM note text; transactional e-mail content and metadata; and hosting logs and control-plane data. All are named in section 11.5 and Annex 2 of our DPA. Your data is isolated per organization and never shared across tenants.
Learn more
See our Privacy Policy and Data Processing Agreement for full detail, or our Security overview for infrastructure and tenancy.