Trust & security

Security and trust, by design.

Kong joins the conversations you connect and turns them into prep, follow-ups, and CRM updates. Your data is in our care: built in Europe, encrypted, and never used to train models.

Hosting

EU by default

Primary processing in Google Cloud Frankfurt (europe-west3).

Standard

GDPR aligned

DPA incorporated into every customer agreement.

Model training

Never on your data

Customer conversations are not used to train LLMs.

Breach notice

24 hours

Notification without undue delay after we become aware.

Kong · Made in Sweden

Overview

Kong captures the customer conversations you choose to connect (email, calendar, meetings, and CRM) and turns them into prep, follow-ups, and next actions. Your data is in our care, and we built the product in Sweden with EU residency by default.

You remain the data controller. Kong acts as processor under our DPA and processes personal data only on your documented instructions.

Compliance

  • GDPR-aligned processing with a Data Processing Agreement in every customer contract.
  • Recording notices and consent workflows built into the product. You decide what gets captured.
  • Practices developed with the EU AI Act in mind: transparency, accountability, and risk management for AI features.
  • DPA governed by Swedish law; disputes resolved per the commercial agreement.
  • We follow ISO/IEC 27001 and SOC 2 control frameworks though we have not pursued formal certification yet.

Security controls

Encryption

  • TLS/SSL for data in transit.
  • AES-256 (or equivalent) for data at rest.

Access

  • Multi-factor authentication for access to sensitive systems.
  • Role-based permissions so staff only reach what their job requires.
  • Audit logging of access and material changes.

Infrastructure

  • Hosted on Google Cloud Platform in Frankfurt, Germany (europe-west3).
  • Network protections including firewalls, intrusion detection, and regular vulnerability assessment.
  • Vendor management with security requirements for third parties.

How we use your data

Kong processes call recordings, transcriptions, email and calendar metadata, CRM data, and AI-generated outputs strictly to provide the service, not for our own unrelated purposes.

  • Purpose limitation: we process data only for customer-defined use.
  • No LLM training on customer content.
  • Retention aligned to business need and your instructions; deletion or return on termination.
  • Least-privilege access for sub-processors. Each system gets the minimum data required.

Sub-processors

Kong uses the sub-processors below to run the service. We notify customers of material changes and apply the same protection standards through written agreements. Full legal entity details are in Appendix B of our DPA.

Sub-processorPurposeLocation
VercelHosting infrastructureEEA/EU
NeonDatabaseEEA/EU
Google CloudStorage, queues, auth, and AI processingEEA/EU
RecallMeeting recording and transcriptionEEA/EU
ResendTransactional emailEEA/EU
MicrosoftAuthentication (Entra ID)EEA/EU
OpenAIAI processingEEA/EU, USA
IntercomCustomer supportUSA
SentryError tracking and logsEEA/EU
ElevenLabsTranscriptionEEA/EU
StripePaymentsEEA/EU
xAIAI processingUSA
LangChainAI evaluation and monitoringEEA/EU
SlackOptional customer notificationsUSA
DeepgramTranscriptionEU

Data residency

We primarily process personal data in the European Union. Production workloads run in GCP Frankfurt. When data leaves the EU/EEA, we use appropriate safeguards such as Standard Contractual Clauses or adequacy decisions including the EU-U.S. Data Privacy Framework where applicable.

Privacy & GDPR

Your role as controller

  • You decide which conversations are captured and how outputs are used.
  • You obtain necessary consents and inform meeting participants.
  • You handle data subject requests; Kong assists where required.

Our role as processor

  • We process personal data only on your instructions.
  • We implement technical and organizational security measures.
  • Our DPA reflects GDPR Article 28 processor obligations.

Incident response

  • Formal incident reporting and response procedures.
  • We notify affected customers without undue delay, no later than 24 hours after becoming aware of a personal data breach.
  • Containment, root cause analysis, and stakeholder communication.
  • Post-incident reviews to improve controls.

Security questions or document requests: team@saleskong.com.