"Data in Europe" appears on every provider's website and doesn't mean the same thing on all of them. This is about which questions your data protection officer is going to ask, and which of them stop existing depending on where the processing happens.
It isn't "are you GDPR compliant?". Everyone says yes. The one that blocks is this:
Is there an international transfer of personal data, and on what legal basis?
When a provider processes personal data outside the European Economic Area, that transfer needs its own justification: standard contractual clauses, an impact assessment, and the analysis of whether the destination country offers equivalent safeguards. Since Privacy Shield fell, that last point carries an uncertainty no lawyer signs off with enthusiasm.
That work costs weeks and money, and it has to be redone every time the framework changes.
If no data leaves, that work doesn't exist. It isn't that it's easier to justify: there is nothing to justify. That's the practical difference between "data in Europe" and "processed entirely in Spain".
Article 5(1)(b) of the GDPR requires data to be processed only for the purpose it was collected for. The industry's usual formula is:
We don't use your personal data for other purposes.
And, a few paragraphs further down, permission to use the same data once aggregated or "anonymized".
It's worth stopping there, because with audio that door is bigger than it looks. An audio file with the customer's name stripped is still a person's voice. Voice is an identifier; "anonymizing" a recording by removing its metadata is an operation that sounds right and isn't.
The useful question for a provider: what stays stored, and for how long? If the answer is "nothing", purpose limitation stops being a policy you have to believe and becomes a technical consequence.
A voice system is usually a chain: whoever receives your audio isn't always the one who transcribes it, or the one who summarizes it. Every link is one more processor to document, and sometimes one outside Europe that the intermediary doesn't mention.
Direct question: are there sub-processors, and who are they? If the provider transcribes with a model and summarizes by calling a third party, that has to be in the contract and in your record of processing activities.
In most projects, sovereignty is one argument among several. In these, it decides:
Three questions a serious provider answers in writing and without hedging:
Ours are in the privacy documentation, article by article. And if
anything written there doesn't square with what you see, write to support@uttera.ai: we'd
rather correct a page than have someone sign with the wrong idea.
Anything to add or correct? Write to support@uttera.ai. If you correct us, we edit the post and credit you.