- Home
- Security & deployment
Your data, on your infrastructure.
Run Intalkive on-premise, in a private cloud or as a hosted service. Recordings, transcripts and analytics stay within the boundaries you set, and personal data is masked before analysis.
- On-premise, private cloud, hostedYou choose the deployment model.
- Masking at sourceID, IBAN and card numbers are masked before storage.
- Encryption and auditEnd-to-end encryption, role-based access, full audit trail.
- GDPR and EU AI ActCompliance support by design.
Deployment that fits your requirements
The same software, models and rules, with three hosting options. Move between them as your requirements change, without re-implementing.
On-premise
Every component runs in your own data center or in a network segment with no internet route.
- Audio and text never leave your network
- No international data transfers
- Your own key management and identity provider
- Optional air-gapped deployment
Private cloud
A dedicated environment in the region you choose, with models running inside it.
- Dedicated tenant
- Region of your choice
- You schedule updates
- Private connectivity
Hosted
We run the infrastructure; you focus on outcomes.
- ISO 27001-certified data centers
- Data processing agreement (DPA)
- Masking at source
- Move on-premise whenever you need
Data protection at every layer
End-to-end encryption
Audio and text are encrypted in transit and at rest; keys can live in your own key management.
Masking at source
National IDs, IBANs, card numbers and health details are masked in text and audio; analysis runs on masked data.
Role-based access
You decide who can access what; integrates with your identity provider.
Audit logs
Admin actions, access to conversations and integration calls are written to tamper-evident logs.
Retention and deletion
Retention per call type; deletion propagates to backups and integrated systems.
Human oversight
You define the AI's mandate and the rules for handing over to people.
Controls mapped to the regulation
How Intalkive's controls map to the relevant articles of the GDPR and the EU AI Act.
Data minimization and storage limitation
Personal data is masked before analysis; retention periods are enforced automatically per call type.
Lawful basis and transparency
Recording and analysis notices can be configured in the greeting.
Automated decisions
Decisions with significant effects are handed to a person with the full context.
Data protection by design
Masking at source, role-based access and short default retention.
Processors
In an on-premise deployment no third party accesses personal data in production.
Security of processing
Encryption in transit and at rest, pseudonymization and audit logs.
Data protection impact assessment
We provide data-flow diagrams and security documentation for your DPIA.
International transfers
With on-premise or EU private-cloud deployment the transfer question never arises.
AI disclosure
The Voice Assistant tells callers they are speaking with an AI at the start of the call.
On on-premise and GDPR

GDPR-Compliant AI Voice Agents: The Complete Guide for European Contact Centers
How to deploy a GDPR-compliant AI voice agent in the EU: lawful basis, AI Act disclosure, Article 22 escalation, DPIA and on-premise processing.

On-Premise vs Cloud AI for Contact Centers: Data Sovereignty, GDPR and Control
On-premise AI contact center or cloud? Compare data residency, transfers, sub-processors and control for speech analytics and voice agents in the EU.

PII Redaction in Call Recordings: How Speech Analytics Meets GDPR Requirements
How speech analytics detects and masks names, IBANs, card numbers and health data in call recordings to meet GDPR minimization and security rules.
Frequently asked questions
If your question is not here, our team is happy to answer it.
Does an on-premise deployment need internet access?
No. Speech recognition and language models can run fully locally; in air-gapped deployments updates are delivered through a controlled channel.
Is Intalkive GDPR-certified?
There is no general certificate that makes a product 'GDPR-certified'. Intalkive is built to support your GDPR obligations by design, and we provide the documentation you need for your DPIA and records.
Who can access recordings?
Only the roles you define. Access is role-based, access to unmasked data is authorized separately and every access is written to the audit log.
Does the Voice Assistant disclose that it is an AI?
Yes. The greeting is configured to tell callers they are speaking with an AI, that the call is recorded and how to reach a person.
Let's map your data flows together.
We will walk your DPO, security and contact-center teams through the deployment options and share diagrams you can use directly in your DPIA.