How data security works at Lansy AI
Lansy AI is built around protecting the people it listens to, customers and employees alike, and anonymizes conversations before any analysis.
- One principle runs through the product: complete privacy by design.
- Voice and personal details never reach external AI systems. They stay inside the local perimeter.
- Biometric, personal, and sensitive data is anonymized on our own protected infrastructure before any text goes out for semantic analysis.
Audio and meaning are processed separately
The system is deliberately split into two layers with different access levels: voice is processed only on our side, and external analysis models see nothing but anonymized text.
Audio layer
Models inside the Lansy AI perimeter
Recordings, voiceprints, and spectrograms are biometric personal data. This layer runs on our isolated servers with open models. Voice never leaves the protected perimeter.
Meaning layer
Enterprise APIs see text only
Lansy AI uses Google Gemini and OpenAI GPT to understand context, assess sales and service standards, and run analytics. They receive text already cleared of personal data. After analysis, some details are put back so the Lansy AI portal shows real names instead of placeholders.
Every conversation goes through four protected stages
One conversation, from raw audio to a report in the portal.
01
Local audio processing
The raw audio file lands on our server: models transcribe speech, cut out employees’ private talk, and separate speakers by role. The file is stored encrypted (AES-256) in isolated storage, and nothing leaves our infrastructure.
02
Automatic anonymization
Named entity recognition (NER) scans the transcript and masks personal details with generic labels. Emails, addresses, card and account numbers are masked the same way.
My name is Ahmed, my number is +971 50 123 4567
My name is [NAME], my number is [PHONE]
03
Context and meaning analysis
Anonymized text with labels goes to an external model through an Enterprise API under Zero Data Retention: the provider neither stores it nor trains on it. The model checks script adherence, finds mistakes, counts conversion triggers, and writes recommendations.
04
Safe display in the portal
Reports come back to the client portal, where access follows the role. By default an employee sees only their own conversations — access to other people’s conversations, and to unmasked personal data, is granted individually by the client’s administrator.
Personal talk never reaches analysis
During a shift an employee may step aside for a private call or chat with a colleague on a break. Those conversations are classified automatically and excluded from analysis.
Anything work-related
Recognized by context and sent for analysis as usual.
A private conversation
Removed from the transcript and never counted in the analysis.
Safer, faster, and more accurate
Personal details are removed at the moment of transcription — before the text reaches a database or goes out for AI analysis. Three reasons why that serves both sides.
01
Security and legal compliance
Removing personal data on the spot rules out a leak of sensitive information and supports compliance with regional data protection laws. External models physically cannot memorize your data or train on it.
02
Speed and infrastructure costs
Storing and shipping raw audio to external clouds makes infrastructure expensive and slow. Converting audio to text and clearing personal data on a local server keeps the product fast and affordable.
03
Fewer tokens, sharper context
Long personal entities (full names, addresses, document numbers) are replaced with short system labels, which cuts the load on the model, so it can focus on the substance and business goals of the conversation.
Security guarantees
Audio leaving the perimeter
Never
Voice is processed locally end to end; the audio stream is never handed outside.
Third-party AI training on your data
Never
Enterprise APIs only, with no request history retained.
External AI access to personal data
Never
Text is cleared by the entity recognition engine before it reaches an external model.
Private talk inside a shift
Never
Lines unrelated to work are flagged by a classifier and dropped from the transcript before analysis.
Encryption
Supported
Audio and text are stored encrypted (AES-256), and every organization gets an isolated workspace.
Regional speech recognition
Supported
Models tuned for Arabic and English.
Deployment options
On request
On-premise deployment inside your own perimeter is discussed with enterprise clients.
More questions about security
Who is the data controller?
The client company is the controller. Lansy AI acts as the processor under a data processing agreement, in line with the DIFC Data Protection Law 2020. Decisions about the purposes of processing, and contact with regulators, stay on the client’s side.
Which data protection laws does Lansy AI work under?
Lansy AI supports compliance with UAE Data Protection Law (Federal Decree-Law No. 45 of 2021) and the Saudi Personal Data Protection Law. COLLABO TECH LTD is registered in the DIFC and processes data under the DIFC Data Protection Law 2020, and under the GDPR where a person is located in the EEA.
Where is the data physically stored?
On infrastructure in the region where the client works — the UAE or Saudi Arabia. Every organization gets an isolated workspace. Any material change to processing locations is announced to clients in advance.
How long are recordings kept?
A recording is stored for as long as transcription requires and no longer than seven days. After transcription the original audio is deleted irreversibly, and analysis runs on the anonymized transcript.
Do employees have to agree to recording?
Yes. Before the first shift with Lansy AI, every employee reviews and signs a consent form as part of onboarding. Consent can be withdrawn later — processing stops and the data is deleted, unless the law requires keeping it longer.
What happens to a recording if the internet drops?
The device keeps recording and stores the audio locally, then uploads it once the connection is back. Gaps in connectivity are visible in the report.
Who sees an employee’s personal reports?
By default, only the employee and their authorized manager. Wider access is granted individually by the client’s administrator. Lansy AI publishes no rankings and shares no individual scores with the rest of the team.
Need more detail?
We walk your security team through the architecture and the processing model, and answer their questions.