Trust and compliance
Customer data security, by design.
Phano reads your sensitive data for its diagnostics. Encryption, isolation, European hosting and least-privilege access are built into the product.
The measures in place
Whether you are a CSM or an Account Manager, your accounts' data stays protected from connection to diagnostic delivery.
Encryption in transit (TLS 1.3) and at rest (AES-256). Access tokens to your third-party tools are encrypted server-side.
Each organization's data is strictly isolated at the database level (Row Level Security). Your accounts are never accessible to another organization.
Phano connects to your tools through an OAuth manager: no passwords are stored, and permissions are read-only for most of what it analyzes.
Phano never alters your existing data: its only writes into your tools are dedicated fields and notes for its deliverables (diagnostics, meeting recaps). Data-quality corrections stay inside Phano or go through your explicit validation, with no automatic destructive merge.
Every sensitive operation is recorded in audit logs, kept for 12 months then purged automatically.
Multi-factor authentication (MFA) is available to strengthen access to your team's accounts.
By default, only technical cookies are used (session, CSRF protection, language), plus anonymous audience measurement exempt from consent (EU-hosted PostHog: page views only, no cookie or identification, objection available from the Privacy policy). Google audience measurement (GA4) and advertising conversions (Google Ads, first-party cookie) only load after your consent via the banner, revocable at any time.
Hosting and subprocessors
Your application data is hosted in the European Union. The database and authentication are located in Ireland; application hosting, the CDN and the OAuth manager are also in the EU.
Some specialized subprocessors (payments, transactional email, AI providers) are located in the United States and covered by standard contractual clauses (SCC) or a data processing agreement (DPA). The full list is in the privacy policy.
Artificial intelligence and privacy
Anonymization before analysis
Identifying data (names, emails, phone numbers) is anonymized automatically before anything is sent to an AI provider.
No training on your data
Data is sent on a per-request basis and is never used to train models.
SOC 2 Type II compliant providers
The AI providers we use are SOC 2 Type II compliant and offer contractual guarantees of data non-retention.
Frequently asked questions
Where is the data hosted?
In the European Union. The database and authentication are located in Ireland; application hosting, the CDN and the OAuth manager are also in the EU.
Is the data encrypted?
Yes, in transit (TLS 1.3) and at rest (AES-256). Access tokens for your third-party tools are encrypted server-side.
Can Phano write into my tools?
Analysis relies on least-privilege read access through OAuth. Writing is limited to the deliverables you enable, such as the recap pushed to the CRM, and stays reversible.
Is my data used to train AI models?
No. Identifying data is anonymized before anything is sent to an AI provider, calls are one-off and never used to train models. The providers we use are SOC 2 Type II compliant.
How do I exercise my GDPR rights?
Access, rectification, deletion and portability can be exercised from your workspace or by email. The privacy policy details retention periods and subprocessors.
Your CSMs see the risks, your Account Managers the opportunities. The first diagnostic arrives the same day.
Try for freeMeeting recording (Meeting Intelligence)
When you enable Meeting Intelligence, an assistant joins the online meeting to record it, transcribe it and produce a summary. This assistant is never deployed without your knowledge.
Consent announcement
On joining, the assistant announces in the meeting that it is being recorded and transcribed by an AI, and that any participant can object at any time. If someone objects, the assistant leaves the meeting.
Legal basis
Recording relies on legitimate interest (Art. 6.1.f GDPR), together with the right to object. Since an employee's consent is rarely valid due to the subordinate relationship, legitimate interest is the appropriate basis, in line with the EDPB 05/2020 guidelines on consent.
Retention periods
- Recordings and transcripts: 183 days maximum (about 6 months), then purged from the database and deleted from the recording provider.
- Summaries and diagnostics derived from the meeting: 365 days maximum (about 12 months).
- Raw verbatim: 30 days, cleared as soon as a structured summary exists (minimization).
Your rights
Meeting data is included in your GDPR export (Art. 15 and 20) and in account deletion (Art. 17), which also erases the media kept at the recording provider.
Your data belongs to you
In line with the GDPR, you can access your data, rectify it, export it in JSON format or delete it permanently. These rights can be exercised from your profile or by email at privacy@phano.ai, with a response time of 30 days.
Our commitments are detailed on the GDPR page and in the privacy policy.
Connect your tools with confidence.
The first diagnostic arrives the same day, on a foundation protected by design.