Security & Data Governance
We build automations and AI agents for businesses processing sensitive client information. Here is how your data and your clients' privacy are strictly protected.
What data is collected during an automated workflow?
We enforce strict data minimization: only information strictly necessary to execute the task is processed (e.g., first name, phone number, party size for a restaurant reservation, or property criteria for a brokerage). No superfluous data is requested or stored.
Is your business data used to train AI models?
It depends on the provider. We would rather set it out for you than give you a convenient "no".
For text processing (OpenAI, Anthropic): no. The terms of their business APIs exclude reusing the data you send to train their models.
With Mistral (the European option, see point 03): their policy provides for training on your data unless you explicitly object — it is not off by default. We therefore activate that objection at go-live and confirm it to you in writing. Their retention of interface exchanges is separately limited to 30 rolling days.
For the voice agent (Retell AI, see point 03): no. We put the question to them in writing on 18 August 2026, and their answer of 20 August is unambiguous: Retell does not use call recordings, transcripts or agent configuration to train, fine-tune, evaluate or benchmark models — its own or third-party ones. Their own sub-processors are contractually restricted to delivering the service they provide. This commitment does not rest on a checkbox: it takes effect with the data processing agreement, which we sign before any go-live. We keep their written answer and pass it to you on request.
Where and how is data transferred?
There are three levels, and you choose. Which one applies depends on what your automation has to do. We decide together at the audit, before anything goes live.
Level 1 — no artificial intelligence: nothing leaves. Many automations need no AI at all: booking reminders, confirmations, supplier orders on stock thresholds, reports. Everything then runs on our own servers. Your data never leaves our infrastructure.
Level 2 — with a European AI. When AI processing is required, we can use Mistral, a French company whose servers are in the European Union and which falls under the GDPR. Your data then leaves Quebec — we say so rather than hide it — but it stays within a demanding framework, and we switch off training on your data (point 02).
Level 3 — with a US AI. Some processing today requires OpenAI or Anthropic. Data then goes to the United States. The same applies to the voice agent, which cannot run without a specialised provider (see below).
What we host ourselves, in every case: the entry points (web forms, webhook endpoints), this site's visitor analytics, and the automations we write. Encrypted transfers (HTTPS / TLS 1.3), firewall rules, rate limiting, restricted access.
What leaves: a voice agent cannot run without a specialised provider. We use Retell AI. Their privacy policy states the company is based in the United States and that personal information is "primarily stored and processed" there. They declare SOC 2 Type II and HIPAA certifications and GDPR compliance, and cover international transfers with Standard Contractual Clauses.
What this means for you: calls handled by a voice agent leave Quebec. You know it before you sign, not after. If that transfer is incompatible with your obligations, say so at the audit: some automations — reminders, form bookings, review monitoring — work without a voice agent and without that transfer.
Are voice agent phone calls recorded?
By default, voice streams are processed in real-time purely to understand the caller and transcribe the action item (name, booking time, inquiry). If you choose to retain recordings for quality control, an upfront consent disclosure is systematically announced to callers in accordance with Canadian & Quebec Law 25 regulations.
Retention is configurable at Retell AI, from 1 day to 2 years, agent by agent, for transcripts, recordings and logs. We set it to 7 days by default: enough to check a booking dispute on the Monday after a busy weekend, short enough to keep nothing useless. You can request a different duration — in which case we confirm the chosen value in writing before going live.
What happens if the AI does not know the answer?
Our agents are engineered with strict anti-hallucination guardrails: they never fabricate information. If an inquiry exceeds its defined operational scope, the agent politely offers to transfer the call to your human team or takes a structured callback message dispatched instantly to your phone/email.
How long is data retained?
Data is retained strictly for the duration necessary to execute the service, or according to statutory retention obligations (e.g. accounting records). Automatic purge policies for transit logs are configured according to your corporate governance requirements.
How do users request data access, rectification, or deletion?
You or your clients may exercise your rights to access, rectify, or permanently delete personal data at any time by contacting jessy@aichronoscorp.com. Requests are processed within 48 business hours.
Compliance with Quebec Law 25 & European GDPR
Our workflows adhere strictly to the requirements of Quebec Law 25 (Act respecting the protection of personal information in the private sector) and European GDPR standards: transparency on automated decision-making, cookieless analytics, right to human escalation, and rapid breach notification procedures.
Communication outside Quebec. Law 25 governs the communication of personal information outside the province. As soon as a voice agent is part of your project, that applies (point 03). We then hand you, before going live, a written list of the providers involved, the countries the data passes through, and the retention periods chosen — enough for you to run your own assessment and, if you wish, have your legal counsel validate it. We do not stand in for them.
Who owns the intellectual property and code?
You do. Custom integrations and workflows built for your organization are fully owned by your company upon project completion. We do not lock your operational data behind proprietary closed platforms.
Can we conduct our security audit in English?
Yes. Our security evaluations and operational discussions are available fluently in English and French.
Specific questions regarding your data flow?
We can address all aspects of data governance, security, and regulatory compliance applicable to your industry during your free 30-min audit.