nixflexBack to home

Trust & Security

Last updated: July 9, 2026

Security is built into how Nixflex works, not bolted on afterwards. This page explains, in plain terms, how we protect your data and your callers.

1. Encryption everywhere

Every call and every request is encrypted. Live audio streams over secure WebSocket (WSS) and HTTPS while a call is in progress. Stored recordings and transcripts are encrypted at rest using AES-256. All API traffic uses TLS. Your data is protected in transit and at rest at every stage.

2. Your data stays in the EU/UK

Call data, recordings, and transcripts are stored on EU/UK infrastructure and do not leave the region by default. This keeps you aligned with GDPR and UK GDPR, and gives European and regional customers data residency they can rely on.

3. We never handle payments

Nixflex does not take, store, or process card or payment details on a call. If a caller needs to pay, that happens through your own payment provider, never through our engine. Because card data never touches our systems, your Nixflex usage stays out of scope for PCI-DSS by design - one less compliance burden for you.

4. You control retention

Call recordings and transcripts are automatically deleted after 90 days. You can also delete any call, recording, or agent yourself at any time through the API. If you want your entire account removed, email us and we delete everything within 30 days.

5. Your data is yours

We never sell your data, share it with third parties for their own use, or use your calls to train models. Access to your data is authenticated with your own API key and limited to you and your authorised team. When you bring your own Twilio number, your telephony stays in your own account under your own control.

6. Privacy by design

A Data Processing Addendum (DPA) is available for customers who need one under GDPR or UK GDPR - email us to request it. Our full Privacy Policy explains how we act as a processor and controller, and how to exercise your data rights.

7. On our roadmap

We are continuously strengthening our security posture. Formal certifications such as SOC 2 are on our roadmap as we grow. We would rather tell you honestly where we are today than claim a badge we have not earned - if you have a specific compliance requirement, get in touch and we will tell you exactly what we can support.

8. Questions

Security questions, vendor assessments, or a DPA request? Email support@nixflex.com and we will help.