You are an FCA-regulated firm. Before you send us a single recording, your risk function will want to know exactly where the data goes, who touches it, and what happens to it afterwards. This page answers that in full, so you can evidence the outsourcing due diligence expected under SYSC 8 without waiting on a questionnaire.
These are every third party that touches conversation data, what they do, and where they do it. There are two. This list is contractual — it forms part of our Data Processing Agreement, and we notify clients in advance of any change to it.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| AWS | Hosting, storage, and AI analysis via Amazon Bedrock | Call recordings, chat transcripts, derived analysis | eu-west-2 London, UK |
| Deepgram | Speech-to-text transcription of call audio | Call audio and resulting transcripts. Chat reviews do not touch Deepgram at all. | EU endpoint Germany |
Foundation model providers are deliberately absent from this list. Analysis runs through Amazon Bedrock inside our own AWS account, and Bedrock does not share inputs or outputs with model providers, who have no access to prompts, outputs, or service logs. The model comes to your data. Your data does not go to the model provider.
These are contractual commitments in our DPA, not marketing claims.
All storage and analysis takes place in the United Kingdom, in AWS eu-west-2 (London).
Call audio is transcribed via Deepgram's EU endpoint, where processing occurs within EU-based AWS regions currently located in Germany. Transfers from the UK to the European Economic Area are permitted under UK adequacy regulations, so no additional transfer mechanism is required. A UK region is on Deepgram’s roadmap, indicatively for early 2027. We have not been given a committed date, and we are not treating it as one. If and when it becomes available, we intend to adopt it, at which point call audio would not leave the United Kingdom at any stage. Until then, the position above is what applies.
Where any other processing takes place outside the UK, we rely on UK adequacy regulations or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
Call recordings, chat transcripts and derived conversation-level data are permanently deleted within 30 days of report delivery, or earlier on your written instruction. The report itself is yours, retained by you as controller of your own records. Website enquiry data is held separately, is never combined with conversation data, and is retained only as long as needed to manage our relationship with you.
For conversation data, you are the data controller and Cognifai is the data processor. We process recordings only on your documented instructions, under a signed Data Processing Agreement executed before any data is shared. An NDA is signed before that, at the scoping stage.
Where recordings contain special category data — most commonly health information disclosed during a call — you remain responsible for the controller-side lawful basis. Our processing is limited to the analysis you instruct, under the safeguards set out on this page.
We hold a completed supplier due diligence pack, our standard DPA, and sub-processor terms ready to send. If your risk function has its own questionnaire, send it over and we will return it inside two working days. Email info@cognifai.uk.