Privacy policy and GCC data sovereignty
This policy covers personal data processed by Ittisal as a platform and as a processor acting for tenants. It describes where data lives, what encryption applies, and the conditions under which nothing leaves your perimeter.
Where data is stored
Tenant data is stored in the hosting region selected at deployment: UAE (Dubai) or Qatar (Doha) for managed deployments, or infrastructure you control for self-hosted deployments. Databases, media servers, object storage, the event bus and the inference tier are all deployed within that boundary.
Channel providers are the only mandatory egress. A WhatsApp message necessarily transits the Meta Cloud API, and a telephone call transits your carrier. Recognition, generation and synthesis each have an in-boundary counterpart that can be selected per flow; when those tiers are selected, no call audio and no transcript crosses the perimeter.
- Managed regions: UAE (Dubai), Qatar (Doha)
- Self-hosted: any infrastructure under tenant control, including air-gapped inference
- Cross-border transfer only where a tenant explicitly selects a managed AI tier
- No training on tenant audio, transcripts or CRM data under any plan
Technical measures
Data at rest is encrypted with AES-256-GCM, including recordings in object storage and credential material in the configuration store. Keys are held per tenant and rotated outside the deployment image, so a compromised image does not yield a usable key.
Data in transit uses TLS 1.3 on every internal and external leg, with SRTP available on the media path. Outbound webhooks are signed with HMAC-SHA256 over the raw body and carry a timestamp in the signature base to prevent replay.
- AES-256-GCM at rest, per-tenant keys rotated outside the image
- TLS 1.3 on every leg; SRTP available for media
- Recording retention configurable per tenant, with hard deletion on expiry
- Transcript redaction policy declared per flow variable
Data subject requests and access control
Tenants remain the controller for end-customer personal data; Ittisal acts as processor under the deployment agreement. Requests for access, correction or deletion are executed by the tenant administrator through the platform, and we assist where a request touches infrastructure the tenant does not operate.
Access to tenant environments by Ittisal personnel requires a named support authorisation from the tenant, is time-boxed, and is recorded in the audit trail the tenant can read.
- Controller: the tenant. Processor: Ittisal, under the deployment agreement
- Deletion executes against records, transcripts and recordings together
- Support access is authorised, time-boxed and logged for tenant review
- Sub-processors are limited to the channel and AI providers a tenant selects
Privacy enquiries
Write to [email protected] for policy questions, the current sub-processor list, or a copy of the deployment data-processing agreement. We respond within five working days.
This policy was last updated in September 2026. Material changes are notified to tenant administrators at least 30 days before they take effect.