Table of Contents
See how Weflow handles AI processing without retention and keeps your conversation data inside your Salesforce org.
Book a demo
Or use our free web app.

Zero Data Retention Explained: What Happens to a Transcript After the AI Reads It

See how Weflow processes call transcripts with ZDR and lands them as native Salesforce records you own.
See it live

Zero Data Retention means one specific thing: the LLM provider that processes your call transcript does not keep it once processing is done. That's the whole scope of the term. It's a real safeguard, and it's narrower than most vendors let you assume.

The trouble is that "does the AI keep our data" is actually three questions wearing one coat: whether the processor retains the transcript, whether anything said on your calls trains a model, and where the transcript ends up living and who owns it. Three separate commitments, three separate answers. A vendor can be truthful about one and silent on the other two.

So this piece follows a single sales call from the moment it ends, through the AI layer that reads it (the summarizer, the field extractor, an assistant like Ask Weflow AI), into the CRM, and names what is retained at each step and by whom. Including the part vendors skip: Zero Data Retention does not mean your data disappears. The transcript survives on purpose, and where it survives is the question that matters.

What zero data retention actually means for AI processing

Zero Data Retention means transcripts and prompts sent to an LLM provider for processing are not retained by that provider after the response comes back. It governs the processing layer. Nothing else.

Without it, the default posture at an API provider is that inputs and outputs sit on their side for some window, available for logging, abuse review, or human inspection. ZDR removes that window. The transcript goes in, the summary comes out, and there's no copy left behind at the processor.

That's a narrow, checkable promise, which is exactly why it's worth having. It is also why a security reviewer who reads "Zero Data Retention" on a trust page and stops reading has answered roughly a third of their own question.

Why security reviews now ask what the AI keeps

Two shifts stacked on top of each other.

The first generation of conversation intelligence tools kept the recordings, the transcripts, and everything derived from them in the vendor's own cloud. Gong is the clearest example: the data displays inside Salesforce through embedded components, but it doesn't live there as native records. So "where does our conversation data sit and who can reach it" never had a clean answer, because the honest answer was "in the vendor's system, under the vendor's controls."

Then AI processing arrived and added a second fear on top of the first. The transcript now passes through a model, and the default assumption in every security review is that anything sent to a model is retained somewhere or learned from.

For European buyers this stopped being a preference years ago. In Germany and Austria a recording tool doesn't fail on features, it fails at the works council: you have to document what is captured, where it's processed, and who can hear it, in writing, for the whole sub-processor chain.

And the commercial owner cannot overrule any of it. That's why vendors lose these deals quietly and usually never learn why.

The three things buyers conflate about AI and call data

Processing retention, model training, and storage ownership are three independent questions with three independent answers. A vendor claim about one guarantees nothing about the other two.

The questionWhat it governsWhat a real answer looks like
Does the AI processor keep our transcript?The LLM provider's side of the processing stepZero Data Retention stated for every named LLM sub-processor, not only the vendor's own systems
Does our call data train someone's model?Whether what your customers say improves a model you don't ownA flat no in the DPA, extended explicitly to sub-processed providers
Where does the transcript live and who owns it?Storage, jurisdiction, and what you keep at the end of the contractA named object, in a named system, in a named region, that stays yours if you cancel

AI processing retention: does the LLM keep your transcript?

This is the layer ZDR actually names, and the only one it names. The question is whether the model provider that processed the transcript holds a copy afterwards.

The catch is that "the vendor" is rarely one company. Your conversation intelligence tool sends the transcript to one or more model providers, and those providers are sub-processors. A ZDR commitment that covers the vendor's own database but not the model provider underneath it answers nothing.

So the useful version of the question names the chain: which providers touch the transcript, where are they listed, and does the retention commitment hold at each one.

Model training: does your call data train someone's model?

Training is a separate commitment from retention, and it's the one that kills deals. Data can be unretained and still used for training. It can be retained and never trained on. Neither implies the other.

This is the question a works council asks in exactly these words, and it's the one where a vague answer reads as a no. What you need is the commitment stated flatly, in the DPA rather than on a marketing page, and extended through the whole chain including sub-processed LLM providers.

A vendor that answers "we don't train on your data" and then can't say the same about the model provider they route to has told you half of a sentence.

Storage and ownership: where the transcript actually lives

After processing, the transcript persists somewhere. It has to, because the transcript is the asset. The real questions are whose system it lands in, under whose jurisdiction, and whether it survives the vendor relationship.

There are two architectures here and the difference isn't cosmetic.

Vendor cloudYour CRM
Transcripts and derived intelligence live in the vendor's system and display inside Salesforce through embedded componentsTranscripts and summaries land as native Salesforce records in your org
Access, permissions, and reporting follow the vendor's modelAccess follows your existing Salesforce permissions and role hierarchy
Cancel the subscription and the archive goes with itCancel and the records stay, because they were always yours

Data ownership is the question ZDR can't touch, and it's the one that decides what you're holding in three years.

What happens to a Weflow transcript, step by step

Weflow is the Revenue AI Orchestration platform for sales, customer success, and RevOps teams. Here's the physical journey of one recorded meeting, and what exists where at each stage.

  1. The meeting starts. The notetaker joins the Zoom, Teams, or Google Meet call. Consent flows are configurable: a pre-meeting email on Microsoft Teams with an opt-in or opt-out link, and an in-call chat message with a removal option that triggers immediate permanent deletion of all recording data for that call.
  2. The call is recorded and transcribed. Weflow transcribes 96 languages and detects the spoken language automatically. At this point you have audio, video, and a transcript inside your Weflow instance.
  3. The transcript goes to the AI layer. This is the step Zero Data Retention governs. The transcript is sent to LLM providers for processing, and those providers do not retain it afterwards. It's also not used to train any model, at Weflow or at the sub-processed provider.
  4. The outputs come back, within 30 to 60 seconds of the meeting ending. An AI summary in whatever format your admin configured, a drafted follow-up email, and proposed Salesforce field updates.
  5. The rep reviews the field updates. AI Field Updates are suggestions shown beside the current CRM value. Nothing changes in Salesforce without the user confirming, and required fields stay locked.
  6. The durable assets land in your Salesforce. Weflow writes conversation data into two native Salesforce objects: a recording object holding the summary and full transcript, and an indexing object. The summary is also written onto the Salesforce Event, so it appears on the opportunity activity timeline.
  7. The video file goes to your own storage. Weflow deliberately keeps video out of Salesforce because CRM storage is expensive and heavy. Video files are exported through the public API into the customer's own cloud storage, and Weflow links out to them.
  8. Later queries follow the same rules. When someone asks Ask Weflow AI what happened on that account, the transcript is read again by the AI layer under the same retention and training commitments.

The summary that lands on the record is the thing your reviewer will actually be looking at, so it's worth seeing what it contains.

Weflow post-meeting summary with structured sections and speaker timeline

Read as a retention map, the same journey looks like this:

AssetWhere it lives after processingWho controls it
Transcript sent to the LLM providerNowhere. Not retained by the providerNot applicable
Full transcript and AI summaryNative Salesforce objects in your orgYou, under your Salesforce permissions
Structured field values (methodology fields, next steps, and so on)Your Salesforce fields, standard or customYou, after a rep approves them
Video fileYour own cloud storage, exported via the public APIYou
Working data in the Weflow instanceThe region of your Salesforce, overridable to EU or UKYou, set at configuration

What zero data retention does not cover

Zero Data Retention is not "your data disappears." The transcript persists, in your Salesforce, by design, because a transcript nobody can read is a transcript nobody can use.

ZDR governs one hop in the chain. On its own, it answers none of the following:

  • Storage location. ZDR says nothing about which region the transcript is stored in once processing is finished.
  • Ownership. ZDR is compatible with a vendor keeping your entire archive in their own cloud and taking it back at the end of the contract.
  • Model training. A separate commitment that has to be stated separately, and extended to sub-processors.
  • Consent. ZDR has nothing to say about whether the participants on the call knew they were being recorded, or how the notice was delivered.
  • Access control. ZDR does not decide who inside your company can open the recording once it's stored.
  • Capture scope. ZDR doesn't govern what gets pulled in to begin with, which is the thing your reps are actually anxious about.

That last one is worth sitting with, because it's the objection that surfaces in week one of a rollout rather than in the security review.

And the executive version of the same problem, which is about access rather than capture:

Neither of those is a retention question. They're capture and access questions, and they need their own controls: per-meeting recording and workspace-access settings rather than a per-person switch.

Weflow Calendar inside Conversation Intelligence with recurring meeting tooltip

What to ask a conversation intelligence vendor in writing

The standard is "in writing, for the whole chain." A sales engineer saying "we don't train on your data" on a Zoom call is not an artifact you can hand to legal, and it doesn't cover the model provider they route to. Send these, and expect them answered in the DPA or in a document you can attach to the review.

  • Which LLM providers and other sub-processors touch our conversation data, where are they listed publicly, and in which jurisdiction does each one operate?
  • Do those LLM providers retain our transcripts after processing completes, and is that commitment contractual?
  • Is our conversation data ever used to train AI models, at your company or at any sub-processed provider?
  • Does the retention and training commitment cover every AI feature that reads conversation data, or only the initial transcription?
  • Where is our data processed and stored, and can we pin the region to the EU or UK?
  • Where does the transcript physically end up after processing, in your system or in ours, and in which object?
  • What happens to our transcripts, summaries, and recordings if we cancel?
  • Will you notify us before a sub-processor changes, and can we object before it takes effect?
  • Can we see your most recent SOC 2 Type II report under NDA, with the audit date and the certifying body?
  • Are you ISO 27001 certified today, or is it in progress?
  • What is your breach notification window, and is it in the contract?
  • How do users authenticate, and what happens to their access when we deactivate them in our identity provider?
  • Can a rep exclude a single meeting or a single message, and can the consent notice be configured per region?

How Weflow answers the retention, training, and residency chain

Here's the same list, answered. Including the two lines where the answer is no.

The buyer's questionWeflow's answer
Do LLM providers retain our transcripts after processing?No. Weflow runs Zero Data Retention on AI processing: transcripts sent to LLM providers are not retained by those providers once processing completes.
Is our conversation data used to train AI models?No. Customer data is never used to train AI models, and the commitment extends to sub-processed LLM providers.
Who are the sub-processors, and will you tell us before they change?Weflow maintains a public sub-processor list with advance notice of changes, so you can object before a change takes effect.
Where is the data processed and stored?Weflow is a German company hosted in Frankfurt. Your instance is spun up in the region where your Salesforce is hosted, and that can be overridden to keep data in the EU or UK. Infrastructure runs on AWS and Google Cloud with selectable EU, US, and APAC regions. TLS 1.2+ in transit, AES-256 at rest.
Where does the transcript end up?In your Salesforce, as native records: a recording object holding the summary and full transcript, plus an indexing object. Video files are exported through the public API to your own cloud storage rather than stored in Salesforce.
What contractual artifacts do we get?A Data Processing Agreement with EU Standard Contractual Clauses, and breach notification within 48 hours.
Which certifications are in place today?SOC 2 Type II (held since 2021), GDPR, HIPAA, and CCPA, with regular third-party penetration testing. Certificates and controls are published in the trust center.
How do people sign in?Salesforce authentication only, via OAuth and whatever SSO or two-factor your Salesforce org already enforces. There's no email-and-password login and no separate Weflow identity.
Are you ISO 27001 certified?No. ISO 27001 is in progress, not certified. If your policy mandates it today, treat it as a gap rather than a roadmap item you can wave through.
Are you FedRAMP certified?No. US government contractors that require FedRAMP are not a fit for Weflow.
Does Zero Data Retention mean our data disappears?No, and we'd rather say so plainly. The transcript and summary persist in your Salesforce by design. ZDR governs the AI processing layer, not storage.

The two "no" rows are the honest cost of this position. We'd rather you find them here than three weeks into a procurement cycle.

Walk through the product yourself, no call required.

FAQ: zero data retention and conversation data

Does Weflow use customer call data to train AI models?

No. Weflow never uses customer data to train AI models, and that commitment extends to the sub-processed LLM providers that process transcripts. Nothing said on your calls improves a model you don't own.

Does zero data retention apply to Ask Weflow AI queries?

Yes. Zero Data Retention and the no-training commitment are platform-level, so they cover the AI features that read conversation data, not only the initial transcription. When someone asks Ask Weflow AI a question that pulls in transcripts, CRM fields, and activity history, the same rules apply to that processing step.

Where do Weflow recordings and transcripts physically sit?

Your Weflow instance is created in the region where your Salesforce is hosted, and that can be overridden to keep data in the EU or UK. Transcripts and summaries land as native Salesforce records inside your own org. Video files are exported through the public API to your own cloud storage rather than stored in Salesforce, because CRM storage is expensive and heavy.

What happens to your transcripts if you cancel Weflow?

They stay, because they were never in a vendor cloud to begin with. Transcripts, summaries, and the structured field values written from calls live as native Salesforce records you own, so they remain reportable and permissioned after the subscription ends. That's the structural inversion of the model where losing the subscription loses the archive.

Is Weflow ISO 27001 or FedRAMP certified?

ISO 27001 is in progress and not yet certified, so procurement teams that mandate it should treat it as unfinished. Weflow is not FedRAMP certified, and US government contractors that require FedRAMP are not a fit.

What happens if a rep's account is compromised?

Sign-in to Weflow happens through your Salesforce authentication only, using OAuth and whatever SSO or two-factor your org enforces. There's no separate Weflow password to phish, and deactivating the user in Salesforce cuts their Weflow access immediately. Field writes also respect your existing Salesforce validation rules, permissions, and role hierarchy, so the tool can't do anything the user couldn't do themselves.

By
Weflow

Weflow is a modular Revenue AI platform for RevOps leaders and revenue teams, powering pipeline, forecasting, and deal inspection for 200+ B2B companies. The team behind Weflow also hosts the RevOps Lab podcast and runs RevOps Chat, the Slack community for 1,000+ RevOps practitioners.

More articles by
Weflow

Related articles

Zero Data Retention Explained: What Happens to a Transcript After the AI Reads It

See what Zero Data Retention means and where a transcript goes after the AI reads it.

Where does your call data physically sit? EU data residency for conversation intelligence

Learn where conversation intelligence call data sits and how to vet EU data residency claims.

Does your AI assistant respect Salesforce permissions? Ask-AI and field-level security

Learn whether Ask Weflow AI inherits Salesforce field-level security or uses service-account access.

Why MEDDIC fields stay blank in Gong (and how to fill them)

Learn why MEDDIC fields stay blank in Gong and how to fill them with AI field updates or better setup

What are AI field updates? Turning sales calls into structured Salesforce data

Learn how AI field updates turn sales calls into structured Salesforce fields, not summaries.

How to keep board and executive calls out of your shared call recording library

Learn how to use Weflow consent flows to keep board and executive calls out of the shared library.

Stop Pasting Snapshots into Claude: Account-Level Deal Intelligence with Ask Weflow AI

Decide if Ask Weflow AI or Claude is better for account-level deal intelligence and data-driven reviews.

Conversation Intelligence Workflows for Call Scoring, Deal Risk, and Salesforce Updates

Learn conversation intelligence workflows for call scoring, deal risk, and Salesforce updates.