A Swiss server does not by itself make an AI phone assistant compliant. Check the entire data flow, the organisations involved and the purpose of processing. A name, callback number or enquiry linked to a person can involve personal data even when no audio recording is retained.
Last updated: 15 September 2026. This guide distinguishes legal foundations, practical checks and AlpenAgent’s project-specific implementation. It does not replace an assessment of your particular use.
Who remains responsible under the FADP?
The Swiss Federal Act on Data Protection (FADP) also applies to AI. The FDPIC guidance discusses transparency and an impact assessment where processing is likely to present a high risk. Whether that applies depends on the data, purpose and deployment.
Outsourcing does not remove the controller’s responsibility. The FDPIC explains contractual processing, security and subprocessors. Identify who determines the purpose, who processes on instructions and who handles access or deletion requests. A signed data processing agreement is one part of the review, not proof that the technical implementation is appropriate.
Follow the call through every system
Call → telephony → speech/voice provider → language model → automation → CRM/calendar → logs and storage. This is a review template, not a claim that AlpenAgent always uses one stack. A combined service may perform several stages.
| Stage | What to establish |
|---|---|
| Telephony | Numbers, connection records, forwarding and the operators involved. |
| Speech and model | Audio, transcription, prompts, processing countries and provider reuse. |
| Automation | Content copied into workflows, error messages and notifications. |
| Calendar / CRM | Fields written and the permissions needed. |
| Storage | Review audio, full text, summaries, backups, support access and retention separately. |
Our practical recommendation is to record the provider, country, purpose, data type, access and retention for each stage. “No audio stored” does not tell you whether transcripts or error logs contain the conversation.
Treat recording as a separate decision
Recording non-public conversations involves criminal-law rules as well as privacy law. Consent is generally relevant, with narrowly defined exceptions for certain business transactions and emergency services. These are not blanket permission to record business calls or reuse them for analytics. Read the scope and purpose limits in the FDPIC recording guidance.
We recommend leaving persistent audio recording off until its purpose is established. A structured note may be enough. If recording is needed, settle the notice, any required consent, its timing and an alternative for callers who decline. Do not automatically extend the legal treatment of a recording to transcription or every other AI processing step.
Swiss hosting does not describe the whole supply chain
International disclosures require checking the destination and the applicable protection mechanism. The FDPIC sets out adequacy, safeguards and exceptions. A US destination is neither automatic prohibition nor automatic clearance. Check the specific recipient and current basis, including support access from other countries.
AlpenAgent’s architecture varies by project. International services such as Retell AI or European providers may be used. Some components, including self-hosted n8n automation, can run on an Infomaniak VPS in Switzerland. That does not mean all audio, transcription, model processing and subprocessors remain in Switzerland.
Agree these points before deployment
- Processing agreement, current subprocessors and the change-notification process.
- Permitted purposes, including whether the provider uses data for training or its own activities.
- Separate retention for audio, transcripts, summaries and backups; do not invent one universal statutory deadline.
- Role-based access and a workable access, correction and deletion process.
- Incident contacts, fallback operation and an accountable person in the business.
- Understandable caller information and a reachable human alternative.
Introducing the assistant clearly as AI is our implementation recommendation for a transparent opening. Do not rely solely on a long privacy page. Test requests for a person, refusal of recording and deletion of a test enquiry across every system.
A property manager may receive information about tenants; salon or garage conversations can also contain sensitive details. Limit questions and free text to what the task requires. Give unclear or sensitive situations a human route.
Trace one test enquiry through deletion
Before launch, use a fictional test person to check the planned data handling. Do not use a real customer’s details. Submit a callback request and identify every system containing a record afterwards. Look beyond the CRM: notifications, failed workflows and support views may contain additional copies. This exercise is our operational recommendation, not a legally prescribed test procedure.
Next, request the agreed deletion. The responsible person should explain what was removed immediately, what is retained separately and how backups are handled. Also check whether retrying a failed workflow later recreates the deleted record. Clicking “delete” successfully in one interface does not establish that every copy has disappeared.
Test access with actual roles
An appointments team might need a date, service and callback number without needing every note from a damage report. Create separate test accounts for the intended roles and attempt to open records outside their remit. Document what is actually visible. For support incidents, establish who may approve additional access and how that access ends. Sharing one administrator account across the team does not provide that separation.
When changing provider, ask for a useful export of your business information and an explanation of how its access ends. Shutdown involves API keys, calendar sharing and automations as well as the phone number. Identify outstanding callbacks and which system will become authoritative afterwards. This makes the transition manageable without asserting an automatic entitlement to every conceivable export feature.
For subsequent changes, set a review trigger: a new model, subprocessor, recording setting or integration should prompt another check of the affected data flow. Retain the reviewed configuration and date. Otherwise, a once-correct inventory can become inaccurate while the website continues to display the same general privacy statement.
Use the selection worksheet to ask these questions before signing. The AlpenAgent AI phone assistant is scoped around your requirements; the budget guide helps include ongoing operation in the decision.
FAQ
Does Swiss hosting guarantee FADP compliance?
No. It describes part of the infrastructure. Purposes, contracts, access, data flows and other providers still need review.
Must every conversation be saved?
No. Decide whether audio, a transcript or a short structured note serves the purpose. Assess recording separately.
Is there one retention deadline for every AI phone assistant?
There is no universal period covering all data and purposes. Define justified periods by data type and account for any specifically applicable retention duties.