Avoma can be run inside a GDPR-compliant setup, but your call data leaves the EU. Avoma, Inc. is a US company that, by its own security page, hosts all of its software in AWS facilities in the USA. It publishes a proper Article 28 Data Processing Addendum, incorporates the EU Standard Contractual Clauses, and self-certifies to the EU-US Data Privacy Framework. Those are the tools that make an EU-to-US transfer lawful on paper. What none of them change is that the recordings, transcripts, and AI analysis sit on US infrastructure and fall under US jurisdiction. This piece quotes Avoma's own current documents, retrieved 2026-07-26.
Is Avoma GDPR compliant?
The honest answer is conditional. Avoma gives you the documents a GDPR-compliant deployment needs: a signed Data Processing Addendum, Standard Contractual Clauses for the transfer, and a Data Privacy Framework self-certification. An EU controller who signs the DPA, completes a transfer impact assessment, and accepts the residual risk can use Avoma lawfully. So Avoma is not non-compliant by default.
But GDPR compliance for a recording tool is not only about paperwork. It is also about where identifiable personal data physically lives and which jurisdiction can compel it. On both counts, Avoma's own documents point to the United States. Call recordings and transcripts of EU data subjects are personal data, and Avoma stores and processes them on US infrastructure under a US legal regime. That is lawful with the right transfer mechanism, but it is the opposite of keeping EU data in the EU.
Who Avoma is and where it processes data
Avoma is operated by Avoma, Inc., a US company. Its DPA states the relationship plainly: "Customer is the Data Controller and Avoma, Inc. and applicable Affiliates are the Data Processor." That is the standard Article 28 split, with your organization as controller and Avoma as processor.
Where the processing happens is answered by Avoma's security page, which is unusually direct about it: "Avoma hosts all its software in Amazon Web Services (AWS) facilities in the USA," with "100% of Avoma's primary application servers" inside its own US virtual private cloud and data held in "AWS-managed PostgreSQL RDS and ElasticSearch data storage systems." The documents Avoma publishes disclose no EU AWS region and no EU data-residency option. Recordings and transcripts are encrypted at rest and in transit, but they sit in the US.
Sources, retrieved 2026-07-26: avoma.com/data-processing-addendum, avoma.com/security.
Avoma's DPA and the EU-US transfer mechanism
Avoma's Data Processing Addendum is a complete Article 28 agreement. It commits Avoma to process personal data only on your instructions, it grants a notice-and-object right on sub-processors, and it names the transfer basis for moving EU data to the US.
On international transfer, the Avoma DPA states: "Customer authorizes the transfer of Personal Data to any jurisdiction outside the EEA, including the United States, for the purpose of providing the Service pursuant to the Data Controller to Data Processor EU Model Clauses." Separately it confirms: "Avoma, Inc. self-certifies to and complies with the Data Privacy Framework." So the transfer rides on two layered mechanisms: the EU Standard Contractual Clauses (the EU Model Clauses) and the Data Privacy Framework.
Avoma's Privacy Policy repeats the framework claim: "Avoma complies with the EU-US Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework." The Data Privacy Framework is the third attempt at a durable EU-US transfer basis. Safe Harbor was struck down in 2015 and Privacy Shield in 2020, and the DPF is itself under active legal challenge. A compliance posture that leans on it carries standing risk if the framework is invalidated during your contract term, at which point you fall back to the SCCs and a fresh transfer assessment.
Sources, retrieved 2026-07-26: avoma.com/data-processing-addendum, avoma.com/privacy-policy.
Avoma's sub-processors: transcription and AI
Under Article 28, a processor can only engage sub-processors on terms that flow the same obligations down the chain, and the controller has the right to know who they are. Avoma's DPA gives a general authorization and points to its trust center: "Customer hereby provides Avoma with a general authorization to engage the Sub-Processors listed at https://trust.avoma.com/subprocessors."
That trust-center page is access-gated and returned an automated-fetch block on 2026-07-26, so we could not capture it verbatim. Rather than quote text we did not retrieve, we flag it: an EU controller should open trust.avoma.com/subprocessors directly and read the current list before signing. Public references to that list name US-based cloud and AI vendors, including AWS for hosting and third-party transcription and large-language-model providers for the AI features. Verify each entry and its location against the live page, because each sub-processor is another party with access to your call data and its own legal exposure.
Sources, retrieved 2026-07-26: avoma.com/data-processing-addendum. The trust-center sub-processor page could not be retrieved verbatim (access-gated); verify it directly.
Residency, sovereignty, and the CLOUD Act
The distinction that matters here is between residency and sovereignty. Residency is where the data physically sits. Sovereignty is which jurisdiction can compel it. Avoma's documents describe US residency for everything: US AWS hosting, US-based sub-processors, and a transfer mechanism whose entire job is to legitimize sending EU data to the US.
Because Avoma, Inc. is a US company operating on US infrastructure, it falls under the US CLOUD Act, which can compel a US provider to produce data within its possession or control regardless of where servers physically sit. A DPA and the SCCs are contracts between two private parties. They govern conduct, not jurisdiction, and they cannot contract that reach away. For the wider mechanics of how this statute interacts with EU data protection, see our explainer on the CLOUD Act and EU data sovereignty for AI.
Where Avoma is genuinely solid
Credibility cuts both ways, so it is worth being clear about what Avoma does well. Its security posture is legitimate, and its paperwork is complete.
- SOC 2 Type II. Avoma's security page states its design, security, and operations were "successfully evaluated and certified by an independent audit for SOC 2 Type II compliance."
- A real, public DPA. The Article 28 addendum exists, is published, and incorporates the EU Standard Contractual Clauses as the transfer safeguard alongside DPF self-certification.
- Sub-processor change rights. The DPA commits Avoma to notify customers of sub-processor changes and gives an objection window, which is exactly what Article 28 expects.
- Encryption in transit and at rest, including call recordings and transcripts.
None of that is in dispute. The gap is not the quality of Avoma's security program. It is the jurisdiction that program runs under. A US company on US infrastructure can hold every certificate on the list and still be reachable by US legal process, which is precisely the risk a DPA cannot close.
The EU-native alternative
If the requirement is that call recordings and their analysis stay under EU jurisdiction rather than being transferred out under a framework, Avoma does not meet it. The structural answer is a provider with no US hosting and no US AI provider in the analysis loop. Numi is a sovereign meeting assistant built on that principle: EU data residency, self-hosted open-source transcription, no US AI provider in the loop, and a GDPR Article 28 processor agreement (Auftragsverarbeitungsvertrag) behind it. For the full field of EU-native options, see our guide to Gong alternatives for the DACH region in 2026, and compare the data practices of the major tools on our compliance comparison hub.