Data Journey, Storage & Security
End-to-end data flow, GDPR compliance, and enterprise-grade security. By Alex Bisbe. January 14th, 2026.
High-Level Architecture Principles
Process 1 — Inbound Calls (DID / DDI)
Data Flow Diagram
Caller
|
v
Inbound Phone Number (DID / DDI)
|
v
Twilio (EU)
(Call routing, SIP, optional recording)
|
v
Voice Engine
- ElevenLabs (EU – default)
- Bland (US – backup, GDPR-compliant)
|
v
LLM Reasoning Layer
- Gemini 2.5 / Gemini 3 (Google – EU processing)
(NO DATA PERSISTENCE)
|
v
Voice Response (TTS)
(ElevenLabs)
|
v
VoiceB Control Plane
- Vercel (EU)
- PostgreSQL (EU)
|
v
Client CRM / SystemsWhat Happens Here
Storage Summary
Process 2 — Click-to-Call (API-Triggered Calls)
Data Flow Diagram
What Changes vs Inbound
Storage Summary
Process 3 — Web VOIP (Widget-Based Calls)
Data Flow Diagram
Additional Notes
Where Data Is Stored (Clear & Simple)
Stored in the EU
Not Stored Anywhere
Data Processing Agreement (DPA)
Roles
Covered Topics
Sub-Processors (Default)
Security Architecture
Infrastructure Security
Data in Transit
Data at Rest
Access Control
Retention & Deletion
What VoiceB Explicitly Does NOT Do
Enterprise Readiness
Bottom Line
Last updated
Was this helpful?

