For DPOs and Compliance Leads

Where your call data goes is a document you can read, not a claim you have to trust.

The first question in any vendor assessment: where is our customer call data processed, and who touches it? For Numi the answer is EU infrastructure hosted in Frankfurt, with transcription running on a self-hosted model rather than a third-party vendor, governed by an Article 28 DPA and a published, dated subprocessor list you can read before you sign. Below are the four questions a data protection assessment turns on, each answered with the document that backs it.

01Where is the data processed?

In the EU, hosted in Frankfurt, Germany. Call audio, transcription, storage and the coaching analysis all run on EU infrastructure. Transcription uses a self-hosted Whisper large-v3-turbo model, so audio is not handed to a separate transcription vendor to process.

This matters because a DPA is only as strong as where the data physically sits. Residency in the EU under a single provider is control you can point to, not a promise layered on top of someone else's cloud.

02Who are the subprocessors?

Named, located and dated in a published list. Numi maintains a subprocessor list that names each processor, what it does, and where it operates. A DPO should never have to infer a vendor's supply chain from marketing copy, so we publish it and date it. Read it, and assess any residual exposure against your own risk posture.

If you want the counter-example, our comparison pages document, from competitors' own DPAs and subprocessor lists, where several US-headquartered tools actually send meeting data. It is the same primary-source method, applied to them.

03Is there an AVV under Article 28?

Yes. Numi provides an Article 28 GDPR data processing agreement, the Auftragsverarbeitungsvertrag or AVV, covering the processing scope, subprocessor terms, security measures and data-subject assistance a controller needs to sign off. It is available to review before you commit, not after.

The AVV sits alongside the residency and subprocessor facts above rather than standing in for them. Contract plus control is the combination that survives an audit.

04What is the US transfer exposure?

Whatever the subprocessor list says, in writing. Transfer exposure is a question you answer by reading the processor chain, not by accepting a slogan. Numi's residency and self-hosted transcription are designed to keep the core processing in the EU, and the subprocessor list is where any onward transfer is disclosed so you can evaluate it under Chapter V of the GDPR.

We do not hand you a sweeping slogan and ask you to trust it, because a credible DPO would not accept one. We give you the list and the DPA and let the documents make the case.

"It is not too late to achieve technological sovereignty in some critical technology areas."

Ursula von der Leyen ยท President, European Commission

Assess Numi against your own bar.

Numi is in private beta with compliance-conscious EU sales teams. Get early access, then read the DPA and subprocessor list against your vendor checklist.

Get Early Access

EU residency (Frankfurt). Article 28 DPA and a published subprocessor list.