Data Governance & Security Overview — ISO 27001 ISMS — Informational document for integrators & partners
| Prepared for | Integration partner — informational use |
| Date | March 2026 |
| Classification | Confidential — Limited distribution |
| Owner | CISO, TelSmart BV |
| ISMS status | In preparation — ISO 27001 certification in progress |
1. Scope & Organisation
This document describes how TelSmart handles its customers' data. It provides an overview for partners and integrators who work with TelSmart and for whom questions around security and GDPR are relevant.
1.1 Legal entity & locations
| Company name | The Smart Group BV (TelSmart) |
| Primary location | Torhoutsesteenweg 236, 8210 Zedelgem |
| Secondary location | Grootrees 12, 2460 Kasterlee |
| ISMS scope | Software development and implementation of cloud-based VoIP telephony and related integration solutions |
| IT infrastructure | Fully within ISMS scope: both on-premise and AWS environment |
1.2 Departments in scope
Management — Sales — Internal IT — Development — DevOps — Finance — HR — Support / Deployment
2. Data location & Infrastructure
2.1 Primary hosting — AWS Frankfurt
| Cloud provider | Amazon Web Services (AWS) |
| Region | eu-central-1 — Frankfurt, Germany (within EU/EEA) |
| Services | EC2 (compute), ECS (containers) |
| Redundancy | Minimum 2 availability zones for all critical services |
| Exception | SBCs (Session Border Controllers): manual intervention in case of failure |
| Primary connection | Colt (primary) + Sewan (failover) |
| Internet customers | edpnet, via Proximus infrastructure |
All customer data remains within the European Economic Area. No data is stored outside the EU/EEA.
2.2 Backup policy
AWS Cloud backup (production services)
- Daily automated backups via AWS Backup Plans
- Backup data remains within eu-central-1 (Frankfurt)
- Stored encrypted via AWS KMS — AES-256
- Retention period: minimum 30 days for daily backups; long-term in accordance with the data retention policy
- Annual restore test: IT performs at least one full restore in a test environment and documents the result
- Responsibility: IT Manager / System Administrator, reported to the CISO
On-premise (House of Happiness)
- Backups managed via Proxmox, stored on Synology NAS
- Daily backups, offloaded to Backblaze
⚠ Detailed per-service recovery procedures are in preparation and are being documented by the System Administrator.
3. Data protection & Encryption
3.1 Encryption overview
| Asset / System | Encryption method | Algorithm / Protocol |
| Laptops / endpoints | BitLocker disk encryption | AES-128 / AES-256 |
| VPN connections | FortiClient / AWS Endpoint VPN | TLS 1.1 or higher |
| Websites & APIs | SSL certificates | SHA-256 |
| Email traffic | Mandatory encryption | TLS |
| Passwords | Hashing (preferred) or disk encryption | PBKDF2-256 |
| Recordings & summaries | AWS KMS encryption | AES-256 |
3.2 Defense-in-depth approach
- Layer 1 — Policy: information security policy, clean desk, teleworking guidelines
- Layer 2 — Access management: need-to-know, Active Directory security groups, MFA
- Layer 3 — Encryption: data in transit (TLS) and at rest (AES-256)
- Layer 4 — Logging & monitoring: event logging for detection of malicious activity
- Layer 5 — Pseudonymisation / anonymisation where applicable
4. Access management
4.1 Principles
- Prohibited by default, unless explicitly permitted (default-deny principle)
- Need-to-know basis: access tied to role and demonstrable necessity
- Privileged access limited to approved personnel, reviewed annually
- MFA applied where technically possible
- On leaving employment: immediate blocking, rights revoked, account retained for 6 months for forensic purposes
4.2 Annual review per system
| System | Responsible |
| Active Directory (AD) | IT Manager |
| AWS | IT Manager |
| Telsy / Unify / … | Application Owner |
| Odoo (ERP) | COO |
| Marketing tools | Marketing Manager |
| Administrative tools | COO |
5. Call recordings & AI summaries
5.1 How it works
TelSmart offers its customers the ability to record calls. These recordings are automatically processed by an AI system that generates a summary. Both the recording and the summary are stored encrypted on AWS Frankfurt (eu-central-1).
5.2 Retention periods
| Type of data | Standard period | Deviation possible? |
| Call recordings | 1 year | Yes — in written consultation with the customer |
| AI summaries | 1 year (same as recording) | Same as recording |
5.3 Legal framework in Belgium
Belgian law does not prohibit the recording of calls by a participant in that call. The relevant legislation is as follows:
Criminal Code Art. 314bis & WEC Art. 124 — recording by a participant permitted
- Art. 314bis of the Criminal Code only prohibits the recording of calls by persons who are NOT participating in that call, without the consent of all parties.
- As long as the user is themselves a participant in the call, recording is legally permitted — even without informing the other party or parties in advance (confirmed by case law of the Court of Cassation and legal doctrine, including Evocaat, elfri.be).
- WEC Art. 124 prohibits taking note of information that is "not intended for you" — this does not apply when you are yourself a participant in the call.
Use and distribution of the recording — this is where the responsibility lies
- Recording is permitted; what you do with the recording afterwards is, however, subject to strict rules.
- The recording may not be distributed or shared outside your own organisation without a lawful basis (Art. 8 ECHR — right to private life).
- Any use outside your own context (e.g. publication, passing on to third parties) may constitute a violation of Art. 8 ECHR and the GDPR, regardless of the lawfulness of the recording itself.
- The recording remains personal data under the GDPR: the controller (TelSmart's customer) bears responsibility for lawful processing and security.
Retention period — no statutory period, but a GDPR principle
- There is no specific statutory retention period for call recordings in Belgium.
- The GDPR requires that data not be kept longer than necessary for the processing purpose (storage limitation principle, Art. 5 GDPR).
- TelSmart applies 1 year as the standard period; longer retention is possible in written consultation with the customer, provided there is a demonstrable purpose.
Rights of data subjects
- Right of access to and a copy of their recordings (Art. 15 GDPR)
- Right to erasure, unless a statutory retention obligation applies (Art. 17 GDPR)
⚠ Responsibility for the lawful use and distribution of recordings lies with the customer as controller. TelSmart acts as processor and acts exclusively in accordance with the customer's instructions, as laid down in the data processing agreement.
5.4 Privacy by design — access control for summaries
- Per user, it can be configured that only the person concerned can consult their own summaries.
- Summaries that are set to "private" remain private — including from the employer.
- On leaving employment: TelSmart does not grant the company access to summaries set to private.
- Historical private settings are always respected — what was private stays private.
- This principle applies consistently, regardless of who requests access (HR, management, etc.).
- Private contacts list (available from June 2026): employees can add private contacts to a personal list. Calls with these contacts are automatically excluded from recording. This is particularly relevant for companies where employees use a company mobile phone for both professional and personal calls.
This is in line with CBA 81 (employee privacy) and the GDPR principle of data minimisation.
6. GDPR compliance
6.1 Data retention — overview
| CRM contacts | Max. 5 years after last contact — deleted thereafter |
| CDR records (call data) | Period to be documented — see points of attention |
| Call recordings | 1 year as standard; longer in written consultation with the customer |
| Invoices (incoming and outgoing) | 10 years (statutory accounting retention obligation) |
| Employee HR files | 7 years after termination of the employment contract |
| Employee email archive | 6 months after end of contract |
⚠ CDR records and voice recordings do not yet have an established retention period in the current ISMS documentation. This is being added in consultation with the DPO.
6.2 Data breach & incident procedure
- Notification to the Data Protection Authority (DPA) within 72 hours where there is a likely risk to data subjects (Art. 33 GDPR)
- The DPO coordinates the incident response and assembles an incident response team
- Data subjects are informed when a high risk exists (Art. 34 GDPR)
- All data breaches are recorded in the incident register (Freshdesk)
- Contact point for data breaches: sec.incidents@telsmart.eu
6.3 Rights of data subjects
- Right of access: TelSmart can show the stored data on request
- Right to erasure: requests handled in consultation with the DPO within 30 days
- Erasure is not possible for data that must be retained by law
7. Cloud Governance
7.1 Approval process for new cloud services
Every new cloud service must be approved in advance via an IT request. The assessment covers:
- Purpose and business justification
- Geographic storage location of data
- Presence of PII data
- SSO and MFA capabilities
- Privacy Policy and End User Agreement
- Relevant certifications (ISO 27001, SOC-2, …)
- Exit strategy: data portability, recovery, data erasure after termination
After review by the CISO, approval follows from the management team. Upon approval, a cloud service owner is appointed.
7.2 Password management
Access credentials for all cloud services are managed via the company-wide password manager: 1Password.
8. Disclaimer
This document has been drawn up on the basis of TelSmart's internal ISO 27001 ISMS documentation and is intended as an informational overview for partners and integrators.
The legal section relating to call recordings (Section 5.3) is based on publicly available Belgian laws and regulations (GDPR, WEC Art. 124) and sector guidelines. TelSmart advises consulting a qualified lawyer for specific legal questions.
This document is confidential and intended solely for the recipient. Further distribution requires written permission from TelSmart's CISO.
Let's make it frictionless.