← All articles

Evaluation

Vapi vs. Retell AI: an India DPDP data localization review

Compare Vapi and Retell AI for Indian enterprise voice workloads across storage, processing, retention, deletion, vendors, and DPDP obligations.

Two managed voice platforms compared across storage processing retention and transfer controls for an Indian enterprise

Take it with you

CSVFree and ungated

India voice-platform data-control scorecard

A vendor review sheet for mapping audio, transcripts, logs, subprocessors, retention, deletion, and transfer controls.

india-voice-platform-data-control-scorecard.csv

Download CSV

First, kill the bad question.

“Which one is DPDP compliant, Vapi or Retell?” sounds tidy. Procurement teams love tidy. But a platform is not compliant in the abstract, and India’s Digital Personal Data Protection Act does not create a blanket rule that every byte of personal data must stay inside India.

That changes this comparison quite a bit.

The useful question is: can your company explain where each class of call data goes, why it goes there, how long it stays, who can touch it, and what happens when a person asks for erasure or withdraws consent?

Voxeval reviewed the public documentation available in July 2026. Vendor features and contract terms can change, so confirm the current position in writing before buying. This is a product and control review, not legal advice.

A Mumbai procurement meeting, slightly uncomfortable

Here is a fictional scene.

An insurer plans a renewal agent for customers across Maharashtra. The security lead asks, “Is the audio in India?” The product lead says, “We turned off recordings.” Someone from operations points out that transcripts still appear in the call dashboard. Legal asks about model providers. Nobody has a diagram.

Messy.

That meeting is the real DPDP test.

The answer can change because one team swapped a speech provider, another enabled summaries for supervisors, procurement renewed a subprocessor term nobody mapped, or an engineer moved recordings into a Mumbai bucket while the live orchestration path stayed exactly where it was.

Audio storage is one row in a much larger sheet. A call can touch telephony, orchestration, speech recognition, a language model, text-to-speech, observability, support tooling, and the insurer’s own CRM. Turning off one recording does not erase the rest of the route.

A data-control map for reviewing Vapi and Retell AI under an Indian enterprise workload

What the law actually says

Section 16 of the DPDP Act lets the Central Government restrict transfers of personal data to notified countries or territories. That is different from “all personal data must remain in India.” Other sector rules, contracts, regulator expectations, or a company’s risk policy may still demand a tighter setup.

The 2025 Rules also arrived with phased commencement. So a buyer needs a current obligation map, not a slide copied from an older sales deck.

For a voice agent, start with these questions:

  • Purpose. Why are you collecting the audio, transcript, tool output, and call metadata?

  • Does the customer get a clear notice in the languages they actually use?

  • Retention is not “as long as the dashboard has it.” Pick a period for each data class and make deletion work downstream.

  • Which overseas processors receive the data, and under what contract?

  • Can you answer an access, correction, grievance, or erasure request without hunting through five vendors?

The platform comparison sits inside that map.

Vapi: more routing choices, still homework

Vapi’s public data-flow documentation describes two paths. Customers can use Vapi-managed storage, or configure their own storage and provider keys. Its docs also describe an ephemeral orchestration layer on US or EU infrastructure, while system logs may remain with Vapi. The zero-data-retention page explains controls intended to reduce stored call data.

That flexibility can be useful for an Indian enterprise that wants recordings in its own bucket and direct agreements with speech or model providers.

But do not translate “bring your own storage” into “all processing occurs in India.” Those are different claims. Audio may be transiently processed elsewhere. Provider APIs receive data. Operational logs may follow another route. Your exact configuration decides the answer.

Questions we would put to Vapi:

  • Draw the route for live audio when our storage is in Mumbai.

  • Which system logs remain, with which fields and retention?

  • Can support staff access transcript or call data? Show the approval trail.

  • If we use our own model keys, which payloads still pass through Vapi systems?

  • Deletion across backups and subprocessors. How long, exactly?

Not hostile questions. Buying questions.

Retell AI: simple controls, a residency constraint

Retell’s public docs let customers disable storage for selected data and configure retention. Its retention documentation says call data is retained indefinitely by default unless the account changes the setting. That default deserves attention in any personal-data review.

Retell’s public community response on regional hosting said its infrastructure was hosted in AWS US-West-2 and the region was not customer-configurable at that time, with EU hosting discussed as future work. Public community answers are not a contract. Still, an Indian buyer should treat that as a prompt for direct written confirmation, especially if internal policy asks for processing in a named region.

Questions for Retell:

  • Which call artifacts are covered when storage is disabled?

  • What remains for abuse, billing, debugging, or service operation?

  • Is US-West-2 still the only hosting region for our proposed plan?

  • What is the shortest supported retention, and does it cover backups?

  • Can our team export an evidence trail for deletion and access requests?

The easy mistake is comparing one vendor’s “no recording” toggle against another vendor’s storage architecture. Match control to control.

No fake winner here

Vapi may fit a team that wants more provider and storage control, and has engineers who can own the resulting data map. Retell may suit a team that wants a more contained managed setup and accepts its documented region and retention constraints after contract review.

Or neither may pass your policy.

Suppose a bank requires all live audio processing, transcript storage, logs, and support access to remain inside a specific Indian environment. Public documentation alone does not prove either managed platform meets that condition. You may need private deployment terms, a different architecture, or a narrower workload.

Now flip the case. A retailer may permit overseas processing after its legal review, while demanding short retention, clear notice, encryption, restricted support access, and a tested deletion path. Region is still relevant. It just is not the only row.

Run a call-data fire drill

Vendor questionnaires produce lovely PDFs. Fire drills produce evidence.

Create a test customer and place a fictional renewal call. Use invented details only. Then:

  1. Find every copy of its recording, transcript, summary, tool payload, and log identifier.
  2. Ask an operator with ordinary permissions what they can view.
  3. Delete the call through the supported workflow.
  4. Check exports, analytics, webhooks, your CRM, provider dashboards, and backups covered by the vendor’s stated process.
  5. Time the work. Record what could not be verified.

One more run: disable recording before the call and see what still appears. Teams are often surprised by summaries, event logs, or downstream copies they never classified.

Score evidence, not sales language

Voxeval’s India voice-platform data-control scorecard is intentionally unscored. Your legal, security, procurement, and product owners fill in the requirement, vendor evidence, contract reference, test result, owner, and open risk.

Why no ready-made score out of 100? Because “EU processing available” could be a pass for one company and a hard fail for another. A weighted number hides the reason.

Make the vendor show the route. Make your own team prove deletion. Then sign the risk that remains, by name.

Reference list

Sources

  1. Digital Personal Data Protection Act, 2023
  2. Digital Personal Data Protection Rules, 2025
  3. Vapi data flow and regional storage
  4. Vapi zero data retention
  5. Retell AI privacy and data storage controls
  6. Retell AI data retention
  7. Retell AI data-residency clarification