Trust & security

Built for IT, compliance,
and your franchise auditor.

Service Managers shouldn't be the ones answering security questions. This page is for the people who will — your IT lead, your DPO, and your OEM compliance reviewer.

The four things IT cares about most

Where your data lives, who can see it, and what we can prove.

01 · Data residency

Customer data stays in the UK or EU.

All Otto infrastructure runs in AWS Frankfurt (eu-central-1). Call recordings on Cloudflare R2 in EU jurisdiction. UK region available on Enterprise. No customer data leaves the region without an explicit Data Processing Agreement.

02 · Consent & opt-outs

Per channel, per customer.

Email, SMS, WhatsApp and voice consent are tracked separately. STOP and UNSUBSCRIBE are honoured automatically and propagated to your DMS. Your franchise compliance team can pull a full consent history per customer, on demand.

03 · Audit trail

Every action recorded. Otto's included.

Every call Otto makes, every booking it creates, every consent change it processes — all logged with actor, timestamp, before/after state. Recordings retained 13 months. Audit log retained 7 years on Group and Enterprise.

04 · Encryption

At rest and in transit.

All customer data encrypted at rest with AWS KMS. TLS 1.3 in transit. DMS credentials envelope-encrypted with a separate key. Webhook traffic from telephony providers HMAC-verified on every call.

Compliance posture

What we have today. What's next.

An honest list — we don't claim certifications we don't hold yet. Where things are in progress, we say when.

Standard / controlTodayNext
GDPR — lawful basisDocumented per use case
GDPR — right to be forgottenSelf-service from dealer admin
Subject access requestsOne-click export per customer
UK & EU data residencyEU (Frankfurt) standard, UK on Enterprise
RFC 8058 unsubscribe (email)One-click, signed tokens
STOP / UNSUBSCRIBE handlingAutomatic on SMS & WhatsApp
Recording consentSpoken at call start, configurable per workshop
Encryption at restAWS KMS, KEK on credentialsCustomer-managed keys (Enterprise)
Encryption in transitTLS 1.3 throughout, HMAC on webhooks
SOC 2 Type 2Controls in place, audit window opening Q4 2026Type 2 report Q1 2027
ISO 27001In progress via Tjekvik group certification2027
Penetration testingAnnual, third-partyQuarterly under SOC 2
Recording retention13 months default, configurable
Audit log retention7 years (Group / Enterprise)
DPAStandard included on every planCustom on Enterprise
Sub-processor listPublic, updated on change
For OEM compliance reviewers

Pre-packaged for franchise audit.

If you operate under an OEM franchise standard (Audi, VW, BMW, Mercedes, Ford, JLR, Stellantis), we have an audit pack ready. Brand voice approval samples, recording examples, consent lifecycle documentation, data flow diagrams.

Most groups pass franchise compliance review on first pass. We handle the back-and-forth with the OEM compliance team directly if it helps.

Request the OEM pack →

What's in the pack

  • ✓ Brand voice approval recordings (5–10 sample calls)
  • ✓ Customer consent & recording lifecycle diagram
  • ✓ Data flow map (customer → DMS → Otto → channel)
  • ✓ Sub-processor list with regions
  • ✓ Standard DPA + GDPR Article 28 mapping
  • ✓ Pen test summary (latest)
  • ✓ Audit log sample export
Documents

DPA, sub-processors, privacy notice.

A standard Data Processing Agreement is included with every plan. A custom DPA is available on Enterprise. Sub-processors are listed publicly and dealers are notified on change.

Send your IT lead our way.

We've already answered most of their questions. The rest we'll handle on a 30-minute call.

Talk to security