1. πŸ—οΈ Platform
  • HMS Sovereign Introduction
  • πŸš€ Get Started
    • Authentication
    • Quickstart
  • 🧩 Core Concepts
    • Assistants
    • Calls
    • Phone Numbers
    • Webhooks
  • πŸ—οΈ Platform
    • Privacy policy
    • Dashboard Security
    • Billing and Credits
    • EU Data Sovereignty
    • Voice Selection
    • Whitelabel Portal
  • πŸ› οΈ SDKs
    • Node.js SDK
  • πŸͺ Webhooks
    • Assistant Request
    • End of Call Report
    • Webhooks Overview
    • Webhook Security
    • Status Update
    • Tool Calls
  • βš™οΈ Configuration
    • Analysis Templates
    • Custom Tools
    • SIP Trunks
    • Tool Templates
  • ✨ Features
    • AI Generation
    • Autonomous Silence Handling
    • Call Analysis
    • Call Transfers
    • Campaigns Setup
    • Outbound Campaigns
    • Voicemail Detection
    • Web Calls
    • Privacy & Compliance Features
  • πŸ”— Integrations
    • MCP Server
    • BYOK Setup
    • Provider Pricing
    • xAI Grok Integration
  • πŸ“– Reference
    • Error Codes
    • Rate Limits
    • Troubleshooting
Book a meeting
Linkedin
Github
πŸ“„ Documentation
πŸ”Œ API ReferenceπŸ€– MCPπŸ• ChangelogπŸ“¦ SDK🟒 Status
πŸ“„ Documentation
πŸ”Œ API ReferenceπŸ€– MCPπŸ• ChangelogπŸ“¦ SDK🟒 Status
  1. πŸ—οΈ Platform

EU Data Sovereignty

HMS Sovereign enables EU-hosted voice AI calls with strong data residency guarantees, ensuring your data is processed and stored exclusively within the European Union. For organizations with the highest compliance requirements, we also offer fully on-premise deployment options.
πŸ‡ͺ
EU Data Residency - When configured with Gladia, Mistral, and Local TTS, your voice AI data is processed and stored exclusively within the European Union. All platform infrastructure is hosted by a German company on German servers.

Infrastructure & Hosting#

HMS Sovereign's platform infrastructure runs on dedicated virtual servers provided by Hetzner Online GmbH, a German company headquartered in Gunzenhausen, Bavaria. Servers are located in Nuremberg, Germany. This means:
Data residency: All data is stored and processed exclusively within the EU (Germany)
Physical security: The data center is located in Germany and subject to EU regulations
Corporate jurisdiction: The infrastructure provider is a German company incorporated under German law, fully subject to EU data protection legislation and not subject to the US CLOUD Act
This is a meaningful distinction from many competing platforms that rely on US-headquartered cloud providers. The entire HMS Sovereign stack β€” from infrastructure to application to AI providers β€” involves only EU-incorporated entities.

The EU Stack#

ComponentProviderServer LocationProvider HQLegal Entity
PlatformHMS SovereignNuremberg, DENetherlandsDutch BV
Speech-to-TextGladiaEU-West (France)*FranceFrench SAS
Language ModelMistralEuropeFranceFrench SAS
Text-to-SpeechLocal ModelsNuremberg, DENetherlandsDutch BV
InfrastructureHetzner Online GmbHNuremberg, DEGermanyGerman GmbH
*Gladia routes requests to EU-West by default. Gladia manages their own infrastructure failover; in rare cases of EU-West unavailability, Gladia may fall back to non-EU servers. See Gladia section below.

HMS Sovereign (Platform & TTS)#

Dutch BV headquartered in the Netherlands. All application logic and TTS models run on EU-located servers in Nuremberg, Germany.

Gladia (Speech-to-Text)#

French SAS headquartered in Paris. Requests are routed to their EU-West region by default.

Mistral (Language Model)#

French SAS headquartered in Paris. Models trained and hosted in Europe.

Infrastructure Provider#

HMS Sovereign runs on servers provided by Hetzner Online GmbH, a German company. Servers are physically located in Nuremberg, Germany. As a German entity, Hetzner is subject to EU law and GDPR, and not subject to the US CLOUD Act.

Data Flow#

Under normal operating conditions, data does not leave the European Union. The entire voice AI pipeline runs within EU borders (Germany and France). See the note on Gladia failover below.

Setup Guide#

Step 1: Add Gladia API Key#

Navigate to Integrations in your HMS Sovereign dashboard, or add via API:
Get your Gladia API key at gladia.io

Step 2: Add Mistral API Key#

Add your Mistral API key for EU-based language model processing:
Get your Mistral API key at mistral.ai

Step 3: Configure Your Assistant#

Create or update your assistant with the EU-only configuration:

Step 4: Verify Configuration#

Your voice AI calls are now fully EU-sovereign. Test by making a call to your assistant's phone number.

Provider Details#

Gladia (Speech-to-Text)#

Company: Gladia SAS (French Societe par Actions Simplifiee)
Headquarters: Paris, France
Features:
EU-West region for GDPR-compliant processing (default)
90+ languages supported
Code switching (automatic language detection mid-conversation)
Real-time translation capabilities
Custom vocabulary support
Recommended Settings:
{
  "provider": "gladia",
  "model": "solaria-1",
  "code_switching": true
}
Gladia Infrastructure Failover
Gladia routes requests to their EU-West region (France) by default. Gladia manages their own infrastructure and may automatically fail over to non-EU servers (us-east) in the event of EU-West unavailability. This is a Gladia infrastructure decision outside HMS Sovereign's control. For organizations that cannot accept any possibility of data leaving the EU, we recommend using on-premise STT via our Enterprise On-Premise Solutions.

Mistral (Language Model)#

Company: Mistral AI SAS (French Societe par Actions Simplifiee)
Headquarters: Paris, France
Available Models:
ModelUse CaseSpeed
mistral-small-latestFast responsesFastest
mistral-medium-latestBalanced (recommended)Medium
mistral-large-latestMost capableSlower
ministral-8b-2410LightweightFast
Pricing: 5-10x more cost-effective than US alternatives

Local TTS (Text-to-Speech)#

Operated by: HMS Sovereign (Flireo B.V.)
Headquarters: Netherlands
Features:
Hosted entirely on HMS Sovereign infrastructure
No external API calls for voice synthesis
Low latency voice generation
Multiple voice options available
Local TTS keeps all voice synthesis within HMS Sovereign's EU infrastructure in Nuremberg, ensuring complete control over the final audio output.

Recording Consent (DTMF Opt-In)#

HMS Sovereign offers a built-in recording consent flow that lets callers actively opt in before any recording or AI processing begins. This is an opt-in feature that can be enabled per assistant.

How It Works#

When enabled, the following happens before any AI interaction:
1.
The caller hears a TTS-spoken consent message (using the assistant's configured TTS provider)
2.
The caller presses 1 to agree β€” recording starts and the AI assistant begins
3.
The caller presses 2 to hang up β€” the call ends immediately, no data is stored
4.
If no key is pressed within 10 seconds, the message repeats once, then the call ends
Crucially, no audio is sent to any STT provider, no LLM is invoked, and no recording starts until the caller presses 1. The only external call before consent is the TTS synthesis of the consent message itself.

Privacy Guarantees Before Consent#

ActionBefore consentAfter consent (press 1)
Audio sent to STT❌ Neverβœ… Yes
LLM invoked❌ Neverβœ… Yes
Recording started❌ Neverβœ… Yes
Data stored❌ Neverβœ… Yes
TTS used (consent message)βœ… Yesβœ… Yes

Configuration#

Enable the consent flow by adding recording_consent to your assistant configuration:
{
  "recording_consent": {
    "enabled": true,
    "message": "This call may be recorded and will be processed by an AI assistant. Press 1 to agree, or press 2 to hang up."
  }
}
Or via API:

Compliance Use Cases#

GDPR Article 6/7: Explicit consent for processing voice data, with a clear opt-out path
CCPA: Prior notice and opt-out for recording
Regulated industries: Healthcare, finance, and legal sectors that require explicit consent before AI interaction
Call centers: Replacing manual "this call may be recorded" announcements with a verifiable, logged consent step
The consent message is spoken by your assistant's own TTS provider, so it uses the same voice your callers will hear during the conversation. No extra voice configuration is needed.

Compliance Benefits#

GDPR Compliant#

All AI providers (Gladia, Mistral) are EU companies subject to EU data protection laws from the ground up. HMS Sovereign (Flireo B.V.) is a Dutch company. The infrastructure provider (Hetzner) is a German company. Data is processed and stored exclusively within the EU under normal operating conditions.

Data Residency#

All processing occurs within EU borders (Germany and France) under normal operating conditions. The only exception is Gladia's infrastructure failover behavior, which is outside HMS Sovereign's control.

Schrems II#

No transatlantic data transfers are required. Data stays within the EU, eliminating legal uncertainty from EU-US data flows. Note the Gladia failover caveat above.

US CLOUD Act#

The AI providers (Gladia, Mistral), HMS Sovereign (Flireo B.V.), and the infrastructure provider (Hetzner Online GmbH) are all EU-incorporated entities and are not subject to the US CLOUD Act. This is a meaningful advantage over platforms that rely on US cloud infrastructure.

Comparison: US vs EU Stack vs On-Premise#

AspectFully US-BasedHMS Sovereign (EU Stack)On-Premise / Blackbox
Data leaves EUYesUnder normal conditions: NoNo
Subject to US CLOUD ActYesNoNo
GDPR-native AI providersPartialFullFull
Schrems II concernsYesMinimalNone
Requires SCCsYesNoNo
Typical latency (EU users)HigherLowerLowest
Full corporate sovereigntyNoStrongFull
EU-incorporated infra providerNoYes (Hetzner, Germany)Yes
Important for Regulated Industries
Organizations in healthcare, finance, government, and legal sectors often have strict data residency requirements. Our standard EU stack provides strong data residency within the EU, with Hetzner (German GmbH) as the infrastructure provider. The one nuance is Gladia's potential failover behavior. For absolute data sovereignty guarantees β€” where no possibility of data leaving the EU exists β€” see our Enterprise On-Premise Solutions.

Legal Entities#

HMS Sovereign#

Legal Name: Flireo B.V.
Entity Type: Dutch Besloten Vennootschap (BV)
Jurisdiction: Netherlands
Role: Platform provider, application logic, and Local TTS
Data Processing: All platform data processed on EU-located servers in Nuremberg, Germany

Gladia#

Legal Name: Gladia SAS
Entity Type: French Societe par Actions Simplifiee
Jurisdiction: France
Role: Speech-to-Text processing
Data Processing: Audio transcription in EU-West region (France) by default; see failover note above

Mistral AI#

Legal Name: Mistral AI SAS
Entity Type: French Societe par Actions Simplifiee
Jurisdiction: France
Role: Language Model inference
Data Processing: LLM inference on European infrastructure

Infrastructure Provider#

Legal Name: Hetzner Online GmbH
Entity Type: German Gesellschaft mit beschrΓ€nkter Haftung (GmbH)
Jurisdiction: Germany
Role: Virtual server hosting (compute and storage)
Server Location: Nuremberg, Germany (EU)
Data Access: No application-level access. Provides compute resources only. All data is encrypted at rest and in transit. As a German entity, fully subject to EU law and GDPR.

FAQ#

Is my data ever processed outside the EU?
Under normal operating conditions, no. When using Gladia + Mistral + Local TTS, all data processing occurs within the European Union (Germany and France). The one exception is Gladia's infrastructure failover: in the event of EU-West unavailability, Gladia may route requests to non-EU servers. This is a Gladia infrastructure decision outside HMS Sovereign's control.
Do I need Standard Contractual Clauses (SCCs)?
No. Under normal operating conditions, data never leaves the EU, so SCCs for transatlantic data transfers are not required.
What about the US CLOUD Act?
The AI providers (Gladia, Mistral), HMS Sovereign (Flireo B.V.), and the infrastructure provider (Hetzner Online GmbH) are all EU-incorporated entities and are not subject to the US CLOUD Act. This is a strong advantage over platforms relying on US cloud infrastructure.
Can I mix EU and non-EU providers?
Yes, but you would reduce your data sovereignty posture. For maximum compliance, use all three EU providers together.
Is there a latency difference?
EU users typically experience lower latency with the EU stack since all processing happens geographically closer (Nuremberg and France). For users outside Europe, latency may be slightly higher.
What if I need an absolute guarantee that data never leaves the EU?
The standard EU stack provides strong data residency, but Gladia's failover behavior means an absolute guarantee cannot be given for STT. For that level of certainty, we offer dedicated on-premise deployment with on-premise STT models β€” see Enterprise On-Premise Solutions.

Enterprise On-Premise Solutions#

For enterprise clients in highly regulated industries -- such as government, defense, healthcare, finance, and critical infrastructure -- where absolute data sovereignty is required, HMS Sovereign offers fully on-premise and blackbox deployment options.

Blackbox On-Premise Deployment#

A self-contained, turnkey appliance that runs the entire HMS Sovereign stack on your own hardware or in your own data center:
Complete isolation: No external network dependencies. The entire voice AI pipeline (platform, STT, LLM, TTS) runs on infrastructure you own and control.
No third-party involvement: No non-EU entity at any level of the stack. Full corporate sovereignty.
Air-gapped capable: Can operate in fully air-gapped environments with no internet connectivity.
Your security perimeter: Fits within your existing physical security, network policies, and access controls.

What Is Included#

ComponentDetails
HMS Sovereign PlatformFull platform deployment on your infrastructure
Speech-to-TextOn-premise STT models
Language ModelOn-premise LLM inference
Text-to-SpeechOn-premise TTS engine
Management & MonitoringDashboard and tooling for operations

Compliance Guarantees#

Zero data egress: No data ever leaves your physical premises
Full CLOUD Act immunity: No US or non-EU entity is involved at any level
Schrems II irrelevant: No cross-border data transfers of any kind
Audit-ready: Full control over logging, monitoring, and access trails
Custom DPA: Tailored Data Processing Agreement to meet your specific regulatory requirements
Anything is possible. Whether you need a single rack in your own data center, a fully air-gapped deployment, or a custom hybrid architecture, we work with your security and compliance teams to deliver a solution that meets your exact requirements. No compromise.

Get Started#

Contact our enterprise team to discuss your on-premise requirements:
Email: enterprise@flireo.com
Subject: On-Premise / Blackbox Deployment Inquiry
Our team will work with your IT, security, and legal departments to scope and deliver a deployment tailored to your compliance needs.

Related Documentation#

BYOK Setup Guide - Learn how to add your own API keys for any provider
Assistant Configuration - API reference for creating and configuring assistants

For more information about our EU data sovereignty offering, contact us at support@flireo.com or consult with your legal team regarding specific compliance requirements.
Last updated: March 2026
Modified atΒ 2026-03-28 09:29:48
Previous
Billing and Credits
Next
Voice Selection
Built with