Skip to main content

How call recording works at bOnline

Below is a summary of how bOnline handles call data and call recordings for our VoIP services, with links to the relevant terms.


1. Data Processing Agreement (DPA)

Our Data Processing terms for business customers are incorporated into:

  • bOnline General Business Terms and Schedules, which govern the provision of our VoIP and related services

  • bOnline Privacy Policy, which sets out how we process personal data in line with UK GDPR and (where applicable) EU GDPR

These documents are available here: https://www.bonline.com/terms-privacy/


2. bOnline’s role – Data Processor

For call data generated by your use of the service, including:

  • Call metadata (e.g. calling and called numbers, timestamps, call duration), and

  • Optional call recordings and associated transcripts

bOnline generally acts as a Data Processor, processing this data on your documented instructions as the customer (Data Controller), for the purposes of providing and supporting the telephony service.
Separately, for data relating to our direct relationship with you as a customer (e.g. billing contact details, account administration), we act as a Data Controller, as described in our Privacy Policy.


3. Location of call data and recordings

Core call recordings

  • Call recordings are stored in Google Cloud Storage in the europe-west2 (London) region, i.e. in data centres located in the United Kingdom.

  • Storage buckets are restricted to access by a small, privileged group of authorised bOnline developers/staff for operational and support purposes.

Advanced Call Recordings – transcription

For customers who enable Advanced Call Recordings (AI transcription and related features):

  • Audio/recordings are securely transmitted to Deepgram, our speech-to-text provider, solely for the purpose of generating transcripts.

  • These customers are opted out of Deepgram’s Model Improvement Program, so audio and transcripts from your account are not used to train or improve Deepgram’s AI models.

Deepgram acts as a sub-processor under our data processing terms. They maintain SOC 2 and other data privacy/compliance certifications.


4. Encryption at rest


All customer data stored in Google Cloud Storage is encrypted at rest by default using Google-managed encryption keys. This is enforced at the storage layer and cannot be disabled.


Within our own implementation:

  • We rely on Google Cloud’s built-in encryption at rest, plus strict access controls and logging on our side.

Transport of audio and metadata between our systems, Google Cloud, and Deepgram is protected using TLS/HTTPS.


5. Retention of call recordings

Where you have chosen 12-month or 7 year call recording retention:

  • Call recordings are retained for 12 months or 7 years from the date of the call depending on the package,

  • After this period they are scheduled for deletion in line with our retention policy, so they are no longer accessible via the customer portal or our internal tools.

6. Sub-processors

For the telephony and call-recording components relevant to your query, the key sub-processors are:

Did this answer your question?