Legal
Audio is never stored. A DPA for every customer. SCC for transfers.
Updated 3 May 2026
Umasvoice is a service of the Finnish company Umas Oy (Business ID 3604932-4). Your call audio is never stored with us at any point, and personal data is processed in accordance with the GDPR. On this page we list the concrete technical and contractual safeguards, without marketing talk.
1. Technical security
- Audio is never stored: call audio is not stored permanently, the processing happens in real time and the audio is discarded after the processing.
- Server location: EU routing as the primary option; transfers outside the EU take place only under the standard contractual clauses and with a Schrems II assessment.
- Encryption at rest: text summaries and metadata are encrypted in line with standard industry practice.
- Encryption in transit: TLS on all connections, HSTS preload in use.
- Access control: two-factor authentication for all employees of Umas Oy; access restricted to the people who specifically need it.
- Logging: all access to data is logged; the customer receives the access logs on request.
- Backups: encrypted, with automatic rotation inside the EU.
2. Legislation
We comply with the following legislation:
- EU 2016/679 (GDPR), the General Data Protection Regulation, applicable to all personal data.
- Tietosuojalaki 1050/2018, the national Data Protection Act of Finland.
- Laki sähköisen viestinnän palveluista 917/2014 (Finnish Act on Electronic Communications Services), confidential communication and the protection of data in communications services.
- EU AI Act (2024/1689), the Artificial Intelligence Act, entering into force in stages from 2025 to 2027.
- Directive 2002/58/EC on privacy and electronic communications (ePrivacy), the special rules that apply to electronic communications.
3. Data processing agreement (DPA)
Every Umasvoice agreement includes a personal data processing agreement (DPA). You are the controller, Umas Oy is the processor. The agreement is in writing, in Finnish, and it covers:
- The purpose, the duration and the type of the processing.
- The categories of personal data (usually telephone numbers, names, the content of speech).
- The sub-processors by name (data centre, speech synthesis, speech recognition, language model, SIP operator) and their locations, with the full list in the annex to the DPA, not published on the website.
- The security measures (technical and organisational).
- Giving effect to the rights of data subjects (access, rectification, erasure, portability).
- The data breach notification procedure (72 h, Art. 33 GDPR).
- The rights of audit and inspection.
- The measures that apply when the agreement ends (return or deletion of the data).
Would you like to see the DPA template before subscribing? Send an email to info@umasity.com and we will provide it within a few business days.
4. EU AI Act transparency
Umasvoice falls within the scope of the Art. 50 transparency requirements of the EU Artificial Intelligence Act (2024/1689): at the start of the call, the caller is told clearly that the call is answered by an artificial intelligence. The service is not a high-risk system under Art. 6, and it does not process biometric identifiers, real-time emotion inference or social scoring. The default opening message of Umasvoice:
"Tervetuloa. Puhelusi käsitellään tekoälyn avulla. Miten voin auttaa?" (in English: "Welcome. Your call is handled with the help of artificial intelligence. How can I help?")
The text can be edited during onboarding, but the transparency element must remain. An impact assessment (DPIA, Art. 35 GDPR) is carried out together with the customer before the service is taken into production use, where the processing requires one. We do not use the service for the purposes prohibited by the EU AI Act, in particular biometric identification, social scoring or real-time emotion recognition.
5. Rights of the data subject
Under the GDPR the caller (your customer) is a data subject, with the following rights:
- Access to their own data (Art. 15), anyone may request a copy of the data retained about them (text summary and metadata).
- Rectification (Art. 16), incorrect data must be corrected.
- Erasure (Art. 17), retained data must be deleted on request, unless there is a lawful basis for retaining it.
- Restriction of the processing (Art. 18).
- Data portability (Art. 20), in a structured format.
- Right to object (Art. 21).
All requests are handled within 30 days. The support team is at info@umasity.com.