ModelCharter

Is Vapi GDPR compliant?

Unverified

Vapi · Audio

Not verified. Check Vapi's terms for a GDPR Data Processing Agreement (DPA) before processing EU personal data in Vapi.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

Data Processing Agreement
Not verified
No public DPA was confirmed. Do not process EU personal data until the vendor supplies suitable processor terms.
EU data residency
Confirmed
Vapi documents an EU data-residency option; confirm it is enabled for the account and workload in scope.
Default data training
Opt-out required
By default, call recordings, transcripts and logs may be retained to help train and improve the AI models. Enabling HIPAA mode (hipaaEnabled true) disables data persistence entirely, which stops this use.
Business-tier training
Opt-out required
Any plan with HIPAA mode (hipaaEnabled true) enabled and only HIPAA-compliant provider keys configured: a per-assistant configuration flag, not a separate paid tier. is the business tier recorded for this profile.
Practical risk: Vapi's default configuration retains call data and can use it to improve the service; you have to explicitly turn on HIPAA mode to disable storage and training use, and even then you choose HIPAA-compliant providers yourself. Treat it as developer infrastructure that requires deliberate configuration.

How to make a decision

Check the precise account tier, written contract and intended data before approving Vapi. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Vapi

See the full Vapi risk profile, with every data-handling fact and its source, or browse all rated AI tools.