ARIA is built on three principles that are not up for negotiation: the data stays the customer's, the infrastructure sits in the EU, and conversations are not used to train other models. This page explains exactly what each one means in practice.
Where your data sits
Our entire production stack runs in the European Union, on Contabo servers hosted in Lauterbourg, France. Every business has its own isolated space, with its own separate database. Data storage and everything to do with written messages, meaning what ARIA receives and what she answers, stay in the European Union.
The one exception is telephony, and we say it explicitly because it is exactly the kind of detail a supplier would be tempted to hide. Transcribing what the person on the call says runs on our supplier's European access point. Voice synthesis, meaning ARIA's actual voice, is processed by a supplier outside the EU, covered contractually by standard contractual clauses. Telephony is not switched on for a business unless it asks for it, so if you do not use the phone, none of your data leaves the European Union.
The language model ARIA uses is Mistral AI, a French company, with processing in the European Union. The full list of the suppliers we use is in the DPA and it is updated there whenever it changes.
We take daily backups. The copy kept off the main server holds only the configuration and the knowledge base of your business, never the conversations or your customers' personal data.
Encryption
Data is encrypted in two directions:
- In transit (between you, your customer, and ARIA): TLS 1.3 mandatory, certificates issued by Let's Encrypt with automatic rotation.
- At rest (on disk): AES-256 for the database, AES-256 for backups. The keys are managed separately from the data.
Your conversations do not train models
The conversations between ARIA and your customers are never used to train our models, our suppliers' models, or any third party's. This principle is written explicitly into our Terms and into the DPA.
We use only aggregated and anonymised metadata (response time, escalation rate, distribution by language) to improve the product, never the actual content of the conversations.
Integrations with your systems
When ARIA connects to your existing systems (PMS, calendar, CRM), we use read-only permissions wherever possible. Where we read but do not write, the restriction is enforced in our own code, even if the key we get from the supplier would also allow writing.
How to ask for your data to be deleted
Under GDPR Art. 17, you have the right to ask for the deletion of any personal data processed by ARIA. Send an email to [email protected] and we answer within 5 working days at most, deleting the data within 30 days at most.
If you are a customer of a business that uses ARIA, we recommend you contact us directly through that business, they are the data controller, we are only the data processor.
AI transparency
ARIA identifies herself explicitly as an AI assistant at the start of a conversation with a customer who has not spoken to her before. She never claims to be human. At any time you can see in your panel exactly what she answered and when she handed the conversation to a colleague.
Organisational security
We are a small team. Access to the production systems is limited to the founders, through SSH keys, with no passwords. Every business runs isolated from the others, so access to one does not open the data of another.
In 2026 we do not have SOC 2 or ISO 27001 certification, we are too small to justify the cost of a formal audit now. We prefer to say that plainly rather than leave the opposite impression.
Reporting incidents
If you find a security vulnerability, write to us at [email protected] with the subject "Security". We answer within 48 hours at most. We do not have an official bug bounty programme yet, but we publicly acknowledge and thank anyone who reports a problem to us responsibly.
Questions?
Send us an email at [email protected]. We answer security questions as a priority, usually the same day.