Third Party Index

Snapshot 48288

Document
Trust center
URL
https://www.saleskong.com/trustcenter
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
172159 bytes
SHA-256 (raw)
a5bb9f1b1aaacae70b82f0a96ce22016f0a2a41612caab77e5c5ccf164c03f5a
SHA-256 (normalized text)
2f77d9f69545e4357417c9771acffac61a79007987b9dc24e8939bc562f28723

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust & security
Security and trust, by design.
Kong joins the conversations you connect and turns them into prep, follow-ups, and CRM updates. Your data is in our care: built in Europe, encrypted, and never used to train models.
View [email protected]
Hosting
EU by default
Primary processing in Google Cloud Frankfurt (europe-west3).
Standard
GDPR aligned
DPA incorporated into every customer agreement.
Model training
Never on your data
Customer conversations are not used to train LLMs.
Breach notice
24 hours
Notification without undue delay after we become aware.
Kong · Made in Sweden
Overview
Kong captures the customer conversations you choose to connect (email, calendar, meetings, and CRM) and turns them into prep, follow-ups, and next actions. Your data is in our care, and we built the product in Sweden with EU residency by default.
You remain the data controller. Kong acts as processor under our DPA and processes personal data only on your documented instructions.
Compliance
GDPR-aligned processing with a Data Processing Agreement in every customer contract.
Recording notices and consent workflows built into the product. You decide what gets captured.
Practices developed with the EU AI Act in mind: transparency, accountability, and risk management for AI features.
DPA governed by Swedish law; disputes resolved per the commercial agreement.
We follow ISO/IEC 27001 and SOC 2 control frameworks though we have not pursued formal certification yet.
Security controls
Encryption
TLS/SSL for data in transit.
AES-256 (or equivalent) for data at rest.
Access
Multi-factor authentication for access to sensitive systems.
Role-based permissions so staff only reach what their job requires.
Audit logging of access and material changes.
Infrastructure
Hosted on Google Cloud Platform in Frankfurt, Germany (europe-west3).
Network protections including firewalls, intrusion detection, and regular vulnerability assessment.
Vendor management with security requirements for third parties.
How we use your data
Kong processes call recordings, transcriptions, email and calendar metadata, CRM data, and AI-generated outputs strictly to provide the service, not for our own unrelated purposes.
Purpose limitation: we process data only for customer-defined use.
No LLM training on customer content.
Retention aligned to business need and your instructions; deletion or return on termination.
Least-privilege access for sub-processors. Each system gets the minimum data required.
Sub-processors
Kong uses the sub-processors below to run the service. We notify customers of material changes and apply the same protection standards through written agreements. Full legal entity details are in Appendix B of our DPA.
Sub-processor	Purpose	Location
Vercel	Hosting infrastructure	EEA/EU
Neon	Database	EEA/EU
Google Cloud	Storage, queues, auth, and AI processing	EEA/EU
Recall	Meeting recording and transcription	EEA/EU
Resend	Transactional email	EEA/EU
Microsoft	Authentication (Entra ID)	EEA/EU
OpenAI	AI processing	EEA/EU, USA
Intercom	Customer support	USA
Sentry	Error tracking and logs	EEA/EU
ElevenLabs	Transcription	EEA/EU
Stripe	Payments	EEA/EU
xAI	AI processing	USA
LangChain	AI evaluation and monitoring	EEA/EU
Slack	Optional customer notifications	USA
Deepgram	Transcription	EU
Data residency
We primarily process personal data in the European Union. Production workloads run in GCP Frankfurt. When data leaves the EU/EEA, we use appropriate safeguards such as Standard Contractual Clauses or adequacy decisions including the EU-U.S. Data Privacy Framework where applicable.
Privacy & GDPR
Your role as controller
You decide which conversations are captured and how outputs are used.
You obtain necessary consents and inform meeting participants.
You handle data subject requests; Kong assists where required.
Our role as processor
We process personal data only on your instructions.
We implement technical and organizational security measures.
Our DPA reflects GDPR Article 28 processor obligations.
Documents
Security whitepaperTechnical and organizational measures, encryption, access control, and governance.
Data Processing AgreementProcessor obligations, sub-processors, and breach notification terms.
Privacy PolicyHow Kong handles personal data across the service.
Terms of ServiceCommercial terms and how the DPA forms part of the agreement.
Incident response
Formal incident reporting and response procedures.
We notify affected customers without undue delay, no later than 24 hours after becoming aware of a personal data breach.
Containment, root cause analysis, and stakeholder communication.
Post-incident reviews to improve controls.
Security questions or document requests: [email protected].
©2026 Kong. All rights reserved. Made in Sweden.
LinkedIn