Security & Compliance — GDPR-Compliant AI Voice Agents | Hanc.AI
GDPR Built for EU AI Act EU-Hosted

Enterprise-grade Security. GDPR by Design.

Built for compliance officers, DPOs, and legal teams. Every layer is designed with data protection at its core.

Full documentation: security.hanc.ai

GDPR Compliance

Built for GDPR Across All 24 Roles

Every voice agent role is built with GDPR compliance as a core function, not an add-on.

Recording Off by Default

Call recording is disabled unless the customer enables it. Recording notice is configurable per agent and market.

Data Deletion on Request

Cascading account deletion and per-record deletion via the platform and API.

Right to Access

Full data export capabilities in machine-readable format.

Data Hosting

EU Data Hosting. EU-First Processing.

Data is stored in the EU and core processing runs in EU data centers.

Hetzner & Azure EU

Primary infrastructure on Hetzner (Germany) and Azure EU. ISO 27001 certified.

Encryption at Rest & in Transit

AES-256 at rest by our infrastructure providers. TLS 1.2/1.3 for web and API traffic.

Transparent International Transfers

International transfers exist and are documented per provider in our compliance documentation, available at security.hanc.ai.

AI Safety

Anti-Hallucination by Design

Every response is grounded in your verified knowledge base.

RAG-Based Responses

Retrieval-Augmented Generation ensures grounded answers.

Confidence Scoring

Real-time confidence assessment. Low confidence triggers escalation.

Escalation to Human

Automatic handoff when AI reaches knowledge boundaries.

Employee Privacy

Employee Data Protection

Special protections for internal-facing agent roles (M1-M10).

Works Council Compatible

Designed for Betriebsrat compliance in DACH markets.

Minimal Data Collection

Only strictly necessary data. No employee profiling.

Separate Data Handling

Employee data stored separately with stricter controls.

European Compliance

Built for European Data Protection Law

One platform, built for European data protection law. We operate under the GDPR and the equivalent regimes of the United Kingdom and Switzerland.

GDPR

European Union — General Data Protection Regulation

revDSG

Switzerland — Revised Federal Act on Data Protection

UK GDPR

United Kingdom — UK GDPR

Certifications

Certifications

Our infrastructure and payment providers hold industry-standard certifications. Hanc.AI's own technical and organisational measures are documented and available for review on request.

Hetzner ISO 27001

Infrastructure hosted on ISO 27001 certified data centers

Stripe PCI

Payment processing through PCI DSS Level 1 certified Stripe

Have compliance questions?

Our security team is ready to support your due diligence process.

Your phone, finally
working for you.

Start free in 60 seconds. No credit card. Cancel anytime. Just the phone, picking itself up.

Start free
Book a Meeting