EU.vapi.ai
# support
l
Hi! We are planning on migrating our account to the EU-dashboard instead. I have a few questions about the EU-dashboard though, since I don't seem to find any information online: - Is it fully EU/GDPR compliant? - Should we setup and integrate our own LLM, STT and voice accounts in order to be 100% compliant or can you assure that the models provided in the agent setting are also EU-hosted? - Anything else we need to take into account for our agents to be GDPR and EU compliant using your platform to host them? Thanks in advance!
r
From the current Vapi documentation, the EU dashboard is positioned to support GDPR compliance, but full compliance still depends on how your agents are configured and which providers you use. For the strongest EU/GDPR setup, most teams usually bring their own EU-hosted LLM, STT, TTS, and storage providers to ensure regional control over processing and retention. I couldn’t find a clear confirmation that every default model available in the agent settings is strictly EU-hosted, so it would be best for Vapi support to confirm exactly which providers guarantee EU-only processing and data residency. You’ll also want to review subprocessors, retention policies, recordings/transcripts handling, and DPA coverage to make sure everything aligns with your compliance requirements. @Lajna
s
Hi! Thanks for reaching out. Here is the breakdown for the EU dashboard and GDPR:
1. Is it fully EU/GDPR compliant? Yes. eu.vapi.ai is hosted on infrastructure in Frankfurt (AWS eu-central-1). All Vapi-stored data, including recordings and transcripts, remains within the EU. Detailed security and compliance information can be found at security.vapi.ai.
2. Should we use our own LLM/STT/Voice accounts? For full EU data residency across the entire stack, we recommend using Provider Keys (BYOK). While Vapi is hosted in the EU, default providers (like OpenAI) may route data to US endpoints. To ensure 100% EU processing, use your own keys for Azure OpenAI (EU regions) and Deepgram (EU Cloud).
3. Anything else to take into account? Ensure you handle Recording Consent properly at the start of your calls. You can also use our API to delete call records. Please note that you should conduct your own due diligence to ensure your specific implementation meets all your local regulatory requirements.