# RoEx Tonn API — Security and Data Handling Summary

Last reviewed: September 2026

This summary describes current public positions. The signed agreement controls where it differs. Procurement-specific terms are discussed under an enterprise agreement.

## Customer audio

- Customer audio is not used for model training, fine-tuning, evaluation or benchmarking.
- Source audio, intermediate files and previews are deleted from temporary storage after processing and are not kept long-term.
- Upload URLs expire after 1 hour. Output URLs expire after 24 hours.
- Audio processing and storage run on Google Cloud Platform in the EU region europe-west1 (Belgium). GCP is the infrastructure subprocessor for audio storage and processing.
- Customers may provide URLs to audio in their own storage when those URLs are reachable by the service.
- RoEx does not claim ownership of customer content or output. Customers submitting audio for end users must hold the necessary rights and submit requests under their own account.

## Metadata and enterprise terms

- Request logs and usage records are retained for billing and debugging. Erasure may be requested via support@roexaudio.com; no public erasure timeframe is stated.
- A DPA, formal incident-notification commitment, contractual SLA and metadata retention/erasure terms are available only under an enterprise agreement, negotiated with guaranteed monthly volume.
- The C++ SDK can be licensed for deployment on customer infrastructure under an annual agreement. Confirm supported platforms with RoEx.

## Items not stated as public commitments

- Encryption specifics beyond HTTPS transport and GCP-managed defaults.
- Security certifications such as SOC 2 or ISO 27001.
- A public metadata-retention duration or erasure service level.
- A complete subprocessor list covering billing, email and analytics vendors.

For security questions or current procurement materials, contact info@roexaudio.com.
