Trust & security
Security and trust, by design.
Kong joins the conversations you connect and turns them into prep, follow-ups, and CRM updates. Your data is in our care: built in Europe, encrypted, and never used to train models.
Hosting
EU by default
Primary processing in Google Cloud Frankfurt (europe-west3).
Standard
GDPR aligned
DPA incorporated into every customer agreement.
Model training
Never on your data
Customer conversations are not used to train LLMs.
Breach notice
24 hours
Notification without undue delay after we become aware.
Kong · Made in Sweden
Overview
Kong captures the customer conversations you choose to connect (email, calendar, meetings, and CRM) and turns them into prep, follow-ups, and next actions. Your data is in our care, and we built the product in Sweden with EU residency by default.
You remain the data controller. Kong acts as processor under our DPA and processes personal data only on your documented instructions.
Compliance
- GDPR-aligned processing with a Data Processing Agreement in every customer contract.
- Recording notices and consent workflows built into the product. You decide what gets captured.
- Practices developed with the EU AI Act in mind: transparency, accountability, and risk management for AI features.
- DPA governed by Swedish law; disputes resolved per the commercial agreement.
- We follow ISO/IEC 27001 and SOC 2 control frameworks though we have not pursued formal certification yet.
Security controls
Encryption
- TLS/SSL for data in transit.
- AES-256 (or equivalent) for data at rest.
Access
- Multi-factor authentication for access to sensitive systems.
- Role-based permissions so staff only reach what their job requires.
- Audit logging of access and material changes.
Infrastructure
- Hosted on Google Cloud Platform in Frankfurt, Germany (europe-west3).
- Network protections including firewalls, intrusion detection, and regular vulnerability assessment.
- Vendor management with security requirements for third parties.
How we use your data
Kong processes call recordings, transcriptions, email and calendar metadata, CRM data, and AI-generated outputs strictly to provide the service, not for our own unrelated purposes.
- Purpose limitation: we process data only for customer-defined use.
- No LLM training on customer content.
- Retention aligned to business need and your instructions; deletion or return on termination.
- Least-privilege access for sub-processors. Each system gets the minimum data required.
Sub-processors
Kong uses the sub-processors below to run the service. We notify customers of material changes and apply the same protection standards through written agreements. Full legal entity details are in Appendix B of our DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel | Hosting infrastructure | EEA/EU |
| Neon | Database | EEA/EU |
| Google Cloud | Storage, queues, auth, and AI processing | EEA/EU |
| Recall | Meeting recording and transcription | EEA/EU |
| Resend | Transactional email | EEA/EU |
| Microsoft | Authentication (Entra ID) | EEA/EU |
| OpenAI | AI processing | EEA/EU, USA |
| Intercom | Customer support | USA |
| Sentry | Error tracking and logs | EEA/EU |
| ElevenLabs | Transcription | EEA/EU |
| Stripe | Payments | EEA/EU |
| xAI | AI processing | USA |
| LangChain | AI evaluation and monitoring | EEA/EU |
| Slack | Optional customer notifications | USA |
| Deepgram | Transcription | EU |
Data residency
We primarily process personal data in the European Union. Production workloads run in GCP Frankfurt. When data leaves the EU/EEA, we use appropriate safeguards such as Standard Contractual Clauses or adequacy decisions including the EU-U.S. Data Privacy Framework where applicable.
Privacy & GDPR
Your role as controller
- You decide which conversations are captured and how outputs are used.
- You obtain necessary consents and inform meeting participants.
- You handle data subject requests; Kong assists where required.
Our role as processor
- We process personal data only on your instructions.
- We implement technical and organizational security measures.
- Our DPA reflects GDPR Article 28 processor obligations.
Documents
- Security whitepaperTechnical and organizational measures, encryption, access control, and governance.
- Data Processing AgreementProcessor obligations, sub-processors, and breach notification terms.
- Privacy PolicyHow Kong handles personal data across the service.
- Terms of ServiceCommercial terms and how the DPA forms part of the agreement.
Incident response
- Formal incident reporting and response procedures.
- We notify affected customers without undue delay, no later than 24 hours after becoming aware of a personal data breach.
- Containment, root cause analysis, and stakeholder communication.
- Post-incident reviews to improve controls.
Security questions or document requests: team@saleskong.com.