Record European sales calls by the rules.
Security review is where call recording deals stall. Here is what GDPR asks of you and of your vendor, and how Claap answers each question.
- Where are recordings stored?EU hosting
- Is there a DPA?Yes, on request
- Do you train models on our calls?Never
- Does a bot join the call?Your choice, bot or no bot
- How long are recordings kept?Set by plan, unlimited on Enterprise
- Independent audit?SOC 2 Type II
What IT asks before a pilot, answered
- EU hosting
- GDPR
- SOC 2 Type II
- No training on your data
Is conversation intelligence GDPR compliant?
It can be. GDPR does not ban recording sales calls: it asks you to have a lawful basis, to tell participants they are recorded and why, to keep recordings no longer than needed, and to work with a vendor bound by a data processing agreement.
The tool does not make you compliant on its own. It decides how easy compliance is: where the data is hosted, whether a DPA exists, how visible the recording is, and who inside your company can see which calls.
- 01
Tell people
Say the call is recorded at the start, or let a visible bot say it for you.
- 02
Keep it proportionate
Record the calls you have a reason to record and set how long you keep them.
- 03
Choose a processor
Sign a DPA, check where data is hosted and which sub-processors touch it.
Security is the question every serious buyer asks
On our recorded sales calls this year, compliance came up more often than any single feature.
- recorded buyer calls raised hosting, security or the DPA before a pilot
- 12
- recorded buyer calls raised hosting, security or the DPA before a pilot
- raised consent, or whether a bot should be visible on the call
- 10
- raised consent, or whether a bot should be visible on the call
- of recordings on Claap use a visible meeting bot
- 34%
- of recordings on Claap use a visible meeting bot
- use the Chrome extension, with no participant added
- 14%
- use the Chrome extension, with no participant added
- Meeting bot34%
- Dialer calls29%
- API imports16%
- Chrome extension14%
- Desktop, mobile, other6%
What IT and legal ask first
Lines from recorded evaluation calls. Names removed.
“What about the data security? Where do you store our data? Data governance is the first priority.”
Heard from · Sales operations lead, aviationWhy this hurts
The sales team wants the tool; the security team decides. Bring the hosting and DPA answers to the first call, not the fifth.
“A high requirement is that it’s EU based and compliant, because we’re 27001 compliant.”
Heard from · Operations lead, AI scale-upWhy this hurts
A certified company has to show its vendors meet the same bar. Their own audits depend on it.
“They don’t like tools that hop on the call and say, hey, we’re recording, and there’s a bot living in the call.”
Heard from · Head of sales operations, ed-techWhy this hurts
Transparency matters, and so does the buyer’s comfort. The right answer is a choice per team: visible bot, or a recorder on the rep’s machine.
Compliance built into how calls are captured and stored
Decide how visible the recording is
- Turn on the visible bot and it appears in the participant list, so everyone knows the call is recorded.
- Or record from the desktop app or Chrome extension, and announce the recording yourself at the start.
- Consent workflows let your team handle buyers who prefer not to be recorded.
Visser & Co · DiscoveryRecording
Sam
Anneke
PieterNo bot joined the call
The answers your DPO asks for, ready
- A data processing agreement is available on request, with the list of sub-processors.
- Your calls are never used to train AI models, ours or anyone else’s.
- An independent SOC 2 Type II report covers how the platform is run.
- Where are recordings stored?EU hosting
- Is there a DPA?Yes, on request
- Do you train models on our calls?Never
- Does a bot join the call?Your choice, bot or no bot
- How long are recordings kept?Set by plan, unlimited on Enterprise
- Independent audit?SOC 2 Type II
What IT asks before a pilot, answered
Control who sees which call, and for how long
- Private spaces keep sensitive calls to the people who need them, and agents using the MCP inherit the same rights.
- Admins control recording and sharing across the workspace on Business, with SSO and SCIM on Enterprise.
- Storage runs 2 years on Pro, 3 on Business and unlimited on Enterprise, so you set a policy inside a known limit.
Claude · ChatGPT · Claap MCP
“What did we lose to last quarter, and did we see it coming on the calls?”
MCP claap.get_view · "Win-Loss Deals" · 44 rows · 8 typed columns
And in 31 of the 44, the objection was already on a call before the deal slipped.
Six questions to settle with your DPO
The same questions buyers put to us on recorded calls, in the order a security review asks them.
What is our lawful basis?
Most teams rely on legitimate interest for sales calls, documented in a short assessment. Some choose consent.
How do we inform participants?
A line in the invite, a sentence at the start of the call, or a visible bot. Write down which.
Is there a signed DPA?
Article 28 GDPR requires a processing agreement with your vendor. Ask for it before the pilot.
Where is the data hosted?
Ask where recordings and transcripts live, and which sub-processors can access them.
How long do we keep calls?
Pick a retention period that matches the purpose, and check the tool can delete recordings when you need to.
Are models trained on our data?
Get the answer in writing. Your buyers’ words should not train someone else’s AI.
GDPR and call recording, answered
Is it legal to record sales calls in the EU?
Yes, when you have a lawful basis, inform participants and keep recordings proportionate to the purpose. National rules add to GDPR: in France, recording a private conversation without the speaker’s consent is an offence under article 226-1 of the Code pénal. Check with your own counsel; this is not legal advice.
Do we need consent to record a prospect?
GDPR does not always require consent, legitimate interest can be a valid basis, but participants must be informed. Some countries require consent to record at all. The simplest practice is to say it at the start of the call, or let a visible bot announce it.
Where does Claap store call data?
Recordings and transcripts are hosted in the EU. Claap provides a data processing agreement on request, which lists the sub-processors involved, so your DPO can review the full chain before a pilot.
Does Claap train AI models on our calls?
No. Your recordings, transcripts and fields are never used to train models. They are processed to produce your summaries, fields and scores, and nothing else.
Is a recorder without a bot allowed under GDPR?
Yes, as long as participants are informed. Recording without a bot changes how the recording is visible, not your duty to tell people. Teams that want the notice built in can turn on the visible bot instead.
How long can we keep call recordings?
GDPR sets no fixed number: keep them as long as the purpose needs, then delete them. On Claap, storage runs 2 years on Pro, 3 years on Business and is unlimited on Enterprise, and your policy can be shorter than that.
Is Claap a European alternative to Gong?
Claap is built in Paris and hosts recordings and transcripts in the EU. Gong hosts in the US by default and offers an EU data center. Compare the DPA, the sub-processors and who can access your calls, not only the hosting region.

Bring your security questionnaire.
Book a demo and we will go through hosting, the DPA and access controls with your team.

