MiFID II: the seven questions an auditor asks first
Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide…
Read article →Compliance recording / Digital sovereignty
Voice, chat and email in a single archive, under European jurisdiction. Built for those who have to answer to an audit, and for those who have to guarantee the data never leaves where it belongs.
A Grupês product. More than thirty years integrating recording and compliance in Portuguese financial institutions.

Who trusts uPlayback
Leading financial institutions in the Portuguese market use uPlayback to retain and prove their regulated interactions. Why we do it this way →
One platform. Three channels. One promise.
Today your regulated interactions are scattered across systems that do not talk to each other. uPlayback covers the sources found in banking, insurance and contact centers, and brings them into a single sovereign archive, searchable and auditable.
Make it simple
Each pillar answers a concrete pain for decision-makers in Compliance, IT and Operations. Hover over each card to find out more.
MiFID II, DORA and GDPR aligned by design. Retention workflows and the right to erasure handled automatically. Audit-ready exports, with a complete and tamper-proof record of every action.
Legal requirements →Profile-based access control, AD / LDAP / Azure authentication, and workflow-controlled encryption and extraction. Every action by every user is logged. The audit trail is non-negotiable.
Audit trail →On-premises, private cloud or national cloud. The data stays at home, with no dependence on foreign hyperscalers and no exposure to the Cloud Act.
Data sovereignty →Before comparing suppliers
It is not a folder of audio files. It is where a financial institution keeps the interactions the law requires it to retain, voice, chat and email, so that years later it can find one of them, prove that nobody has tampered with it, and show it to a regulator beyond doubt.
Recording itself is the easy part. Almost every system records. The hard part comes afterwards: retaining each interaction for exactly as long as regulation requires, no more and no less; making sure a call from five years ago still exists and is still intact; and being able, when an auditor asks, to retrieve the right interaction in minutes rather than days.
Recording is the easy part. The hard part is finding it, proving it and retaining it, years later, under pressure, with the regulator waiting.
This is where a compliance archive beginsThe rules change name depending on the sector, but they all converge on the same point: the interaction has to exist, it has to be intact, and it has to be demonstrable. And they pull in directions that, at first glance, contradict one another.
MiFID II / Retain
Record communications connected to transactions, even those that merely could have led to a transaction, and keep them for five years, up to seven at the regulator's request. And keeping them is not enough: they have to be deliverable, legible and organised.
DORA / Withstand
It shifts the question from «do you have the data?» to «what if the system that keeps it stops?». It requires continuing to operate and to reach the records during an incident, with recovery objectives that are tested, not merely written down.
GDPR / Erase
It pulls the other way: what MiFID II requires you to retain, the GDPR requires you to erase once there is no longer a basis for keeping it. A serious archive does not pick a side. It retains by channel and country and erases automatically, on the record, proving both.
Keeping regulated interactions in a cloud subject to foreign law raises a question no contract can settle: the US Cloud Act allows US authorities to compel providers under American jurisdiction to hand over data, even when that data sits physically in Europe. That is why, with uPlayback, where the data lives is your choice.
| Scenario | Where the data sits | Jurisdiction | Suited to |
|---|---|---|---|
| On-premises | On the client's own servers | The client's | Full control and owned infrastructure |
| European private cloud | Dedicated infrastructure in the EU | European Union | Sovereignty without running servers |
| Sovereign national cloud | Portuguese territory | Portugal | The strictest sovereignty requirement |
The questions they ask first
No. uPlayback does not record, it archives. You carry on recording where you record today; what changes is that the interactions all come to live in a single governed archive, instead of scattered across systems that do not talk to each other.
It comes in. Migrating the history is a one-off project, planned with you, in which what already exists is imported while keeping the metadata that underpins retention and the audit trail. The past does not lose its trail when the archive changes.
It depends on the environment, but the team who will use it day to day picks it up quickly: it is one search, not three systems. The part that takes time is the migration and the integrations, and that is planned together, not pushed through in one go.
No. The first step is an assessment that takes a few minutes and gives you your risk level on the spot. Only after that does comparing suppliers make sense.
Choose your lens
Compliance, Technology and Operations measure success differently. Start with the question that is yours.
Compliance & audit
Measured by the absence of surprises in an audit. Configurable retention, a tamper-proof audit trail and exports ready to serve as evidence.
Legal requirements →Architecture & sovereignty
Measured by service continuity. Sovereign architecture, double encryption and integration with the stack you already have.
On-premises vs cloud →Day-to-day operation
Measured by response time to requests and by throughput. Retrieval from a single portal and portability without lock-in.
Portability →Use cases
Select the sector closest to yours to see the capabilities most relevant to your operation.

Compliance recording aligned with MiFID II and DORA. Any interaction can become evidence.

An archive ready for audit, long after the policy was issued.

Multi-tenant compliance recording for outsourced operations, with independent SLAs.

Aligned with ANACOM. Evidence retrievable by complaint number or contract.
Start with the essentials
Before comparing suppliers, it is worth measuring where you stand today. Our assessment has three short evaluations, covering compliance, sovereignty and operations, and returns a report with your risk level, high, medium or low.
MiFID II & Beyond
Multi-channel compliance, digital sovereignty and operational resilience, analysed by the team that manages more than 100M recordings for banking and insurance.
MiFID II Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide…
Read article →
Sovereignty Where your recordings live has stopped being a technical decision. It is a decision about legal exposure, and it belongs to the board.
Read article →
DORA Since January 2025, operational resilience is a regulatory outcome, not a document. What that demands of every capture pipeline.
Read article →Compliance, integrations and deployment answered live, with your environment on the table and a person on the other side, not a generic pitch.