Trust Center
Variable levels of customer data, depending on deployment.
The Lont Platform can run without holding any customer data. How much it holds depends on the data source, where AI is used and the region.
What the Trust Center covers.
- The Lont Platform
- The product your team configures and your customers watch.
- Customer data in the product
- What you send the platform, what happens to it, how long it is kept, and who else processes it.
- Contract terms take precedence
- Where your contract differs from this page, on any subject, the contract applies. Contracts can set stricter terms.
The data path depends on the deployment.
The three steps below are the standard pattern. The four factors underneath decide how a deployment follows it.
- 01
You encrypt
You select the fields the journey needs (name, product, language, policy type, renewal date) and encrypt them before sending them to Lont.
- 02
Lont assembles and displays
Lont decrypts the variables at runtime and uses them only to select and display the approved video for that viewer.
- 03
The session clears
Decrypted variables are held in memory only, never written to disk, and discarded when the view ends.
What changes the path
All are settled when the deployment is designed and written into the agreement.
- Data source
- A trigger that carries encrypted variables is a different path from an integration that reads your system of record. The source decides what reaches Lont and in what form.
- AI use
- Speech generated from a variable sends that text to the voice provider. Translation and script assistance run on OpenAI models and process scripts only; personalized content is not translated.
- Region
- Azure regions can be selected, EU regions included. Your agreement can require written approval before data is processed outside a region.
- Contract terms
- Stricter handling, shorter retention, faster notification: whatever the agreement sets is what the deployment runs.
Controls that apply to every deployment.
Data security
- Encryption before transfer
- Where the data source supports it, you encrypt personalization variables before they are sent to Lont.
- Runtime-only decryption
- Variables are decrypted only while the video is assembled and displayed.
- Never written to disk
- Decrypted variables are held in memory only.
- Access control and traceability
- System access is restricted. Relevant system activity is logged.
Privacy operations
- Purpose limitation
- Personal data is processed on your instructions, for your communication, and not for Lont's own purposes.
- Confidentiality
- Everyone with access to confidential data is bound by confidentiality obligations.
- Data subject rights
- Lont assists with access, correction, portability, deletion and restriction requests.
- Separation of records
- Personalization variables are kept separate from the platform's technical and engagement records.
Assurance
- Security review
- Written answers on how controls are designed and operated, on request.
- Audit cooperation
- Customer agreements provide for security and privacy audits.
- Subprocessor obligations
- Data-protection obligations are passed down to subprocessors by contract.
- Incident notification
- Within 72 hours of discovery, or sooner where the agreement requires it.
How long data is kept.
| Data | What it is | Kept for |
|---|---|---|
| Decrypted personalization variables | The values used to assemble one viewer's video | Not stored. Held in memory for the view, never written to disk. |
| Playback telemetry | Segment plays, skips, rewatches, call-to-action clicks | 72 hours, then removed. |
| Rendered output | Assembled video and audio cached for delivery | Up to 1 week on the CDN. Contains no personal data. |
| Application and audit logs | Back-end and admin activity of your team's accounts, not your customers | 1 year by default, anonymized. Configurable per customer. |
| After the contract ends | Everything still held for your deployment | Per the contract terms. Deletion confirmation available. |
Customer data is not used to train models.
Variables assemble one viewer's communication and nothing else.
Selective
AI is applied only to the parts of the workflow you select.
Human sign-off
Scripts and scenes can require your approval before release.
Deterministic
The same approved inputs and rules produce the same video. Nothing changes unless you change it.
One exception: speech generated from a variable sends that text to the voice provider. Translation runs on OpenAI models and applies to scripts only; personalized content is not translated, so no personal data reaches them.
Allowlist details for restricted networks.
If your outbound traffic is controlled, Lont supplies the allowlist for your deployment on request.
- Platform and API
- Endpoints for platform and API traffic.
- Media delivery
- Endpoints that load the player and deliver video to viewers.
- Configured integrations
- Additional endpoints for each integration you enable.
- Connection requirements
- Domains, ports, protocols, purpose and deployment notes.
Preparing for SOC 2 and ISO 27001.
- In preparation
- Lont is preparing for SOC 2 Type II attestation and ISO 27001 certification, building controls and documentation against both frameworks.
- Updates
- Audit start dates and outcomes will be published on this page.
- Available now
- The controls and retention periods on this page, your agreement, the subprocessor list, and a call with our team.
Subprocessors that can process customer data.
| Provider | What it does | What it can process |
|---|---|---|
| Microsoft Azure | Cloud infrastructure for the Lont Platform | Personalization variables during the live session; the platform's technical and engagement records |
| Text-to-speech provider | Generates spoken audio for video scenes | The spoken text, including any personalization variable in it, such as a name |
Voice providers (ElevenLabs, Azure Speech, AWS Polly) are selected per deployment; a journey can use one or several. Translation runs on OpenAI models and processes scripts only, never personalized content.
Documents for your review.
On request
Data processing agreement
Roles, instructions, safeguards, audit rights, incident notification, deletion.
RequestOn request
Security review
Written answers to your security questionnaire, and a call with our team.
RequestOn request
Network allowlist
Domains, endpoints, ports and protocols for your deployment.
RequestFrequently asked questions.
What customer data does Lont use?
Only the variables the journey needs: for example a name, product, language, policy type or renewal date. You define the source fields and the rules.
Does Lont store personalization variables?
Decrypted variables are never written to disk. They are held in memory for the view and discarded when it ends. What reaches Lont, and in what form, depends on the data source; that is settled per deployment and written into the agreement.
How are personalization variables protected?
Where the data source supports it, you encrypt them before transfer and Lont decrypts them at runtime only. Other patterns are set out in your agreement.
Is customer data used to train AI models?
No. AI assists with content, translation, tone and variants where you choose it. Customer records are never training data.
Does data leave the platform when AI is used?
Only for speech. The spoken text goes to the voice provider, including any variable in it. Translation and script assistance run on OpenAI models and process scripts only; personalized content is not translated.
Where is data processed?
In the Azure region selected for your deployment, EU regions included. Your agreement can require written approval before data is processed elsewhere.
How long is data kept?
Decrypted variables: never stored. Playback telemetry: 72 hours. Rendered output: up to 1 week on the CDN, with no personal data in it. Application and audit logs: 1 year by default, anonymized, configurable per customer. Contract terms can shorten any of these.
How quickly are incidents reported?
Within 72 hours of discovery. A shorter window can be set in your contract.
Where is Lont on SOC 2 and ISO 27001?
Lont is working toward SOC 2 Type II attestation and ISO 27001 certification. Audit start dates and outcomes will be published on this page.
How does Lont work with subprocessors?
Under contract, for defined services, with data-protection obligations passed down. The two that can process customer data are listed above.
Does Lont provide network allowlist information?
Yes, per deployment: domains, endpoints, ports and protocols for platform access, media delivery and enabled integrations. Sent to your team, not published.
What if our contract says something different?
The contract applies, on any subject.
Contact.
- privacy@lont.aiPrivacy, data protection and due diligence
- security@lont.aiVulnerability reports and security questions
Lont is a trade name of Infuse Video Inc., 1007 North Orange Street, 4th Floor, Wilmington, DE 19801, United States.