Legal
Security Overview
Ajora | Ajora B.V. | Version 1.0 | April 2026
1. Infrastructure & Data Location
All customer data is stored and processed within the European Union.
| Component | Provider | Location |
|---|---|---|
| AI processing | Amazon Web Services EMEA SARL (Bedrock) | Frankfurt, Germany |
| Encryption key management | AWS Key Management Service | Frankfurt, Germany |
| Application & database | Hetzner GmbH (VPS) | Nuremberg, Germany |
| Database backups | Hetzner Storage Box | Falkenstein, Germany |
2. Encryption
- All data at rest is encrypted using AES-256
- Organisation accounts receive a dedicated encryption key per tenant
- Encryption keys are managed exclusively by AWS KMS and never stored in plaintext
- All data in transit is encrypted using TLS 1.2 or higher
- On account deletion, the encryption key is destroyed first, rendering all data cryptographically inaccessible before permanent deletion
- Database backups are encrypted using AES-256 before transfer
3. Access Control
- Production systems are accessible only via TailScale VPN with per-user authorisation
- Access is limited to two authorised personnel
- Multi-factor authentication is enforced for all personnel
- AWS access is fully logged via CloudTrail and reviewed periodically
4. Data Minimisation
- Call audio is deleted immediately after transcription
- Usage logs are automatically purged after 90 days
- Customer data is logically segregated by account
5. Backups & Availability
- Automated daily encrypted database backups
- Backups stored in a separate EU location (Hetzner Falkenstein)
- 30-day retention
- Restore procedure tested and verified
6. Patch Management
- Application dependencies are monitored for known vulnerabilities via Dependabot
- Security patches are applied based on severity within a reasonable timeframe
7. Incident Response
Ajora maintains a documented Data Breach Response Plan covering:
- Immediate containment once the incident is confirmed
- AP (Autoriteit Persoonsgegevens) notification within 72 hours per GDPR Article 33
- User notification without undue delay where high risk exists
- Post-incident review and post-mortem within 2 weeks of resolution
8. Sub-processors
All sub-processors are bound by Data Processing Agreements and GDPR-compliant transfer safeguards.
| Sub-processor | Location | Purpose | Safeguard |
|---|---|---|---|
| AWS EMEA SARL | EU (Frankfurt) | AI processing, encryption key management | EU processing |
| Twilio Inc. | Ireland | Call routing and recording | EU-US DPF |
| ElevenLabs Ltd. | United States | Speech-to-text transcription | EU-US DPF |
| Mollie B.V. | The Netherlands | Payment processing | EU processing |
| Google Ireland Ltd. | EU / United States | Website analytics (consent-based) | EU-US DPF |
9. Personnel Security
- All personnel with access to personal data are bound by confidentiality obligations
- Personnel receive data protection and security awareness training
- Access to personal data is limited to personnel who need it to fulfil their duties
10. Contact
For security-related questions: [email protected]
Ready to upgrade your phone calls?
Your account first, then the app
You set up your account and subscription here on the site. Then you download the app from the App Store or Google Play and log in with the same details.