Where your data lives, which AI models process it, how it is protected, and every third party involved: the four questions every due diligence review asks, answered in one place.
Last updated: August 2026
Yes, Voltade stores personal data on behalf of its customers: typically business contact records (names, phone numbers, email addresses), conversation and message history, and the operational data customers connect to the platform. Voltade acts as a data intermediary (processor); the customer remains the data controller.
Primary region: AWS Asia Pacific (Singapore), ap-southeast-1
Production databases, file storage, and encrypted backups reside in the AWS Singapore region. Amazon Web Services is our primary cloud infrastructure provider; Cloudflare provides DNS, CDN, WAF, and DDoS protection at the network edge. Microsoft Azure is used as secondary cloud and AI compute for specific workloads, and Hetzner (EU) hosts selected workloads only where contracted for EU/GDPR engagements.
Voltade's agents use frontier large language models accessed via API through a central model gateway, which enforces provider allow-lists, logging, and per-tenant controls. We do not train, fine-tune, or host our own foundation models, and customer data is never used to train any AI model: inputs are processed ephemerally (retrieval-augmented generation) and are not retained by model providers for training.
| Model Provider | Purpose | Processing Location | Safeguards |
|---|---|---|---|
| Anthropic (Claude) | Primary large language models for agent reasoning and drafting | API access, US-hosted inference | Zero data retention available under API terms; no training on customer data |
| OpenAI (GPT) | Large language models for selected tasks | API access, US-hosted inference | API data excluded from training by default; enterprise retention controls |
| Google (Gemini) | Large language models for selected tasks | API access, US-hosted inference | Paid API data not used to train models |
The specific model versions in use evolve with the frontier; the providers, controls, and no-training guarantees above are contractual and stable. Per-engagement model details are available on request.
Beyond encryption and isolation, dedicated privacy-enhancing technologies (e.g. homomorphic encryption, differential privacy) are not currently deployed; data minimisation, contractual no-training terms, and ephemeral processing are the operative safeguards for AI workloads.
Every third party involved in delivering Voltade's services is published in our sub-processor register: AWS (primary hosting), Cloudflare (edge network), Microsoft Azure (secondary cloud & AI compute), Anthropic, OpenAI, and Google (AI models via API), Hetzner (EU hosting where contracted), SigNoz/Sentry (observability), and Windmill (self-hosted automation). Each is bound by a written agreement with data protection obligations equivalent to those we owe our customers, per our Personal Data Protection Policy. No customer engagement is subcontracted to any other party without the customer's knowledge and agreement.
For a due diligence questionnaire, DPA, or the exact data flows of your engagement, contact [email protected].