How we protect your calls and your customers' data
This page describes, in plain English, how Contactless Trust™ handles the data that flows through your AI voice agent. We only state what is actually true today — where we hold no formal certification, we say so.
Last updated: 7 September 2026
Our certification status, stated plainly
Contactless Trust™ does not currently hold ISO 27001, SOC 2 or any other independent security certification, and we will never display a badge suggesting otherwise. If and when we complete an audit, we will publish the certificate and the auditor here so you can verify it yourself.
What we can point to today is how the service is actually built and operated, described below, plus the security evidence published by the platform that hosts this website — see our hosting platform.
What data the agent handles
- The audio of inbound calls to the number you point at your agent.
- A written transcript of each call.
- The details a caller gives so you can serve them: name, phone number, email, address and what they are asking for.
- Booking and enquiry records created from those calls.
The agent is not designed to collect card numbers, health details or other special-category data, and we ask you not to configure it to do so.
Where it lives and who can reach it
Call data and enquiry records are held with our hosting and telephony providers on infrastructure inside the EEA that is encrypted in transit (HTTPS/TLS) and encrypted at rest by those providers as standard. Access from our side is limited to the small team at Kaada Nordic MarTech in Stavanger who operate and review your agent, each with their own account.
Our internal lead and reporting views require a named sign-in and are excluded from search engines. We do not sell, rent or share your customer data with anyone for marketing.
How long we keep it
Call recording and transcription are off by default. If you ask us in writing to switch them on for your account, recordings are kept for 90 days by default and then deleted. You can ask for a shorter window — for example 30 days — and we will set it and confirm it in writing.
You can ask us at any time to delete a specific call, a specific customer's data, or everything we hold for you. See our privacy notice for your full rights under the GDPR.
Sub-processors
Delivering an AI voice agent means other providers are involved: a telephony provider to carry the call, speech and language model providers to understand and respond, and hosting providers for this website and your records. We will name the exact providers used for your account in writing before you go live, and we will tell you in advance if we change one. Email hello@contactlesstrust.com for the current list.
Transparency on the call
Our agents identify themselves as an automated assistant. They do not pretend to be a person, and they do not invent prices, availability or promises. Anything the agent should not handle is handed to a human. Callers are told that calls are recorded.
Human oversight
Every account gets a monthly human review of a sample of calls, so mistakes are caught by a person rather than left running. If something goes wrong on a live call, you can reach us and we can adjust or pause the agent.
Reporting a security problem
If you believe you have found a vulnerability or a data problem, email hello@contactlesstrust.com with the subject line “Security”. We aim to acknowledge within two working days, and we will keep you updated until it is resolved. Please do not test against live customer calls.
Kaada Nordic MarTech, org. nr. 936289835, Ytre Eiganesveien 13, 4022 Stavanger, Norway.