Your customers' conversations, handled properly
Gimiq handles transcripts, call recordings and customer records, so the controls around them matter as much as the features. This page sets out how data is encrypted, where it lives, who can reach it, and how long it is kept.
The controls that are always on
These are not enterprise upsells. They apply to every workspace on every plan, because a control you have to buy is a control most people won't have.
Encryption everywhere
TLS 1.2+ in transit and AES-256 at rest, applied uniformly to transcripts, call recordings, attachments and database backups.
Role-based access control
Permissions are granted by role, not by person. Agents, managers, admins and read-only viewers each see only what their role allows.
Single sign-on and MFA
SAML 2.0 and OIDC single sign-on with SCIM provisioning on enterprise plans, so joiners and leavers follow your identity provider.
Immutable audit logs
Every configuration change, data export, permission grant and AI action is recorded append-only, with actor, timestamp and parameters.
Automatic PII redaction
Card numbers, national IDs and other patterns you define are masked before storage, and voice payment capture uses a PCI-safe pause.
Configurable data residency
Choose the region your data is processed and stored in, with EU and US regions available and no cross-region replication by default.
What happens to your data
The questions a security review will ask, answered directly rather than buried in a policy PDF.
What we store
Conversation transcripts, call recordings where you enable them, customer records you sync, knowledge base content, and the audit log.
How long we keep it
Retention windows are set per data type and per queue. When a window closes, deletion runs automatically rather than on request.
Who can reach it
Your team, via the roles you grant. Gimiq staff access is break-glass only, requires an approved ticket, and is logged and time-limited.
What trains the models
Your conversations are not used to train shared foundation models. Your indexed content grounds answers for your workspace only.
Where it flows
Subprocessors are documented, and each integration you enable is scoped to the specific data it needs rather than blanket access.
Deletion on request
A subject deletion request removes the individual across transcripts, recordings, tickets and search indexes in a single operation.
Reporting a vulnerability
If you believe you have found a security issue, email support@gimiq.co with “security” in the subject line. We acknowledge reports within one business day and will agree a coordinated disclosure timeline with you. Please test only against your own workspace — never against another customer's data.
For DPAs, subprocessor lists, penetration test summaries or completed security questionnaires, contact our team.
Security questions
Still deciding? Talk to our team or browse the full FAQ.
Bring your security review
We would rather answer the hard questions before you sign than after. Send us your questionnaire and we will work through it.