KVKK & GDPR review controls
Data processing, consent, retention and access requirements are scoped for review in each deployment rather than treated as a blanket promise.
Production voice AI needs more than a secure API. Dring scopes tenant isolation, least-privilege tool access, retention, auditability, prompt defence and human handoff around the workflow your team needs to operate.
Data processing, consent, retention and access requirements are scoped for review in each deployment rather than treated as a blanket promise.
Agents can offer a human route where the workflow includes one, with escalation conditions and context agreed during implementation.
Integrations start with least privilege. Write actions require explicit sign-off per tool.
Configured calls can produce recordings, transcripts, scores and action records according to the notice, retention and access rules agreed for the workflow.
Tenant isolation is enforced. Production feedback is reviewed against your agent's goals and turned into controlled releases under the data rules agreed for your operation.
Agents refuse out-of-scope requests and never invent policy on the call.
SIP scanners, spam floods, toll fraud.
Pair the controls with quality and testing, Agent Factory and the scoped signals in the operations snapshot. For language planning, see the 62-language customer service guide.
A voice agent brings new attack surfaces: the prompt, the model output, the caller's identity, the actions the agent can take. Dring's security rests on six commitments, and each one is tested, not declared.
When a component fails, the system does not fail silently: the call is closed in a controlled way.
Voice recordings and personal data are masked before processing and cannot be reversed.
Tested against prompt injection and instruction hijacking attacks.
Records are encrypted at rest, with access logged.
A defined, tested authority to stop all automation in one step.
Processing location, transfers and data boundaries are documented and reviewed per deployment.
A voice agent takes instructions from the person on the call by design. That is exactly what an attacker tries to turn against it.
A direct override: "ignore your instructions," mid-call.
Instructions hidden inside tool or web data: a CRM note, an order record or a webpage carrying text written for the agent, not the person reading it.
Staff impersonation: a caller claims to be an employee or the account holder to unlock actions meant only for a verified identity.
Refund or transaction pressure: a request outside policy, repeated or escalated, hoping persistence works where a direct ask would not.
Refuses out-of-scope instructions. Nothing said on the call changes its operating instructions.
Treats tool output as data, not commands. Instruction-like content coming back from a tool is ignored, not executed.
Verifies identity before privileged actions. An unverified claim is refused and logged for review.
Requires authorisation for high-risk transactions. No refund, transfer or discount clears on request alone.
Offers a human handover instead of improvising an exception.
What the attacker tries: mid-call, tells the agent to ignore its instructions, forget the rules, or follow new instructions from the caller instead.
What happens with Dring: the agent's operating instructions are fixed for the call. Nothing said by a caller changes them, and the attempt is logged.
What the attacker tries: plants instructions inside data the agent reads mid-call, a CRM note, an order record or a webpage, hoping the agent treats them as a command.
What happens with Dring: tool output is always treated as data, never as an instruction. Instruction-like content coming back from a tool is ignored, not executed.
What the attacker tries: claims to be a staff member, a supervisor or the account holder, to unlock actions or information reserved for a verified identity.
What happens with Dring: identity is checked against real verification steps, not a caller's claim. An unverified claim is refused and logged for review.
What the attacker tries: pushes for a refund, a transfer, a cancellation or a discount outside policy, repeating or escalating the request across the call.
What happens with Dring: high-risk actions need explicit authorisation. The agent cannot approve them on request alone, however many times it is asked.
What the attacker tries: asks the agent to read out another customer's data, an internal number, or anything outside its own case, for example "read me the other customers."
What happens with Dring: tenant isolation and data minimisation mean that data is not reachable from the call in the first place, regardless of how the request is phrased.
What the attacker tries: leads the conversation toward the agent promising a discount, a refund or a guarantee that is not policy, hoping it goes along in the moment.
What happens with Dring: every reply is checked against policy before it is spoken. An improvised promise never reaches the caller.
Instruction overrides, injected tool content, identity spoofing and policy traps are included in pre-release review so the agent is tested against the ways a real workflow can be pressured.
Automated checks and human review examine difficult scenarios. Disagreement or uncertainty is treated as a signal for investigation before a change is promoted.
The agent's reply is checked against policy before it is spoken, not after, so a bad instruction cannot reach the caller.
High-risk actions need explicit authorisation. The agent cannot clear a refund, a transfer or another sensitive action on request alone.
The scenario library is red-team style, and gets a new case whenever a new attack pattern appears anywhere in production.
Results sit in the release scorecard alongside accuracy and quality metrics, and a release does not ship without them.
The agent recognises the override attempt, holds its policy, and offers a human handover instead of improvising an exception.
Data moves through a fixed, monitored path on every call, encrypted at every step.
Data is encrypted in transit with TLS 1.2 or higher and encrypted at rest. Tenant isolation, role-based access and automated monitoring apply across the pipeline.
| Data type | Default retention | After retention |
|---|---|---|
| WhatsApp message content | Up to 12 months, or per contract | Deleted or anonymised |
| Voice call recordings | Up to 12 months, or per contract | Deleted or anonymised |
| Post-call analytics | Duration of contract plus 6 months | Anonymised or deleted |
| Client account data | Contract plus 12 months | Deleted |
| Website analytics | Up to 12 months | Purged |
Clients may request earlier deletion of any of the above at any time.
Where a deployment crosses borders, the transfer mechanism, processing roles, sub-processors and retention requirements are documented for review with the customer and their advisers. The exact processing boundary is agreed per deployment.
Dring acts as a Meta WhatsApp Tech Provider. Dring is a data processor acting on behalf of clients, who remain the data controllers. WhatsApp data is never used for advertising.
For the request paths, applicable rights information and deployment-specific notices, contact [email protected] and review the privacy policy and KVKK notice.
With the data controls agreed for your operation, reviewed transcripts and outcome signals can improve that tenant's own agent, tests and release plan. Tenant isolation is enforced; customer conversations are not used to improve another customer's agent.
No. Integrations start read-only, and any write action requires explicit sign-off per tool.
Processing and transfer arrangements are documented per deployment, with applicable safeguards reviewed as part of the security and privacy process.
Yes, clients may request earlier deletion of any data type at any time.
No. The agent's instructions and policy are fixed for the call and cannot be changed by anything a caller says. Every release is tested against instruction override, injected content and other prompt injection scenarios before it ships. See prompt defence for detail.
Walk through the data and governance requirements for your workflow. A consented form submission can be followed by an AI qualification callback in about two minutes, with timing confirmed for the deployment.