Grammateas ← Home
Ελληνικά English Deutsch Français Español

Trust

Security

Grammateas listens to your business's calls. That is trust that has to be earned with engineering, not with assurances. Here is exactly what applies.

Last updated: 12 September 2026 · This English version is provided for convenience; in case of divergence the Greek text prevails.

Where the data is

The application, the database, the recordings and the transcripts are hosted on servers inside the European Union (Germany). The telephone lines belong to Greek providers. Which third party sees what, by name: Sub-processors.

Encryption

Separation between customers

Every row of data carries a customer identifier and every query to the database is filtered by it — this is not a coding convention but a rule enforced at the data-access layer. One customer's data cannot appear to another, not even through a mistake in the application code.

Access and logging

What the model is never allowed to do

The greatest risk in an artificial-intelligence system is that someone talks it into doing something it should not. So:

Retention and erasure

You decide whether calls are recorded and for how long they are kept (12 months by default). Recordings that expire are deleted automatically, from storage and from the database. Erasing one person's data takes a single action and removes the identifying details, the words of every conversation, the notes and the recordings — keeping only anonymous statistics.

Backups and continuity

Daily backups with restores that are actually tested. If the service does not answer, your calls fall back to your phone system's existing flow — nobody is left hanging.

Reporting a vulnerability

If you have found something, write to us at i.kotrotsios@rm.gr with "Security" in the subject. We answer within two working days. We will not take legal action against anyone who researches in good faith, does not access other people's data, does not disrupt the service and gives us reasonable time to fix the issue before going public.

In an incident that carries a risk, we inform the customers concerned within 24 hours and the data protection authority within 72 hours, as the GDPR requires.