Skip to content

Security and data residency

Where the call goes, what is kept, and who can see it.

Your clients will ask where the call goes, what is kept and who can see it. This page answers those questions the way the platform answers them, so your security review and theirs read the same facts.

callerNew Zealand and Australian data centresNew Zealandcall, transcriptand recordingAustraliacall, transcriptand recordingno path to any other region
Calls, transcripts and recordings stay in New Zealand and Australian data centres, with no path out.
A row of server cabinets in a data centre aisle, lit from above
A data centre aisle. Calls are handled in New Zealand and Australian data centres, and nowhere else.

Data residency

Handled in New Zealand and Australia, nowhere else

Calls are handled in data centres in New Zealand and Australia, and nowhere else. That covers the call itself, the transcription and any recording.

What that means in practice

Call data does not go to the United States, Europe or anywhere else. Calls are not split by the country they came from, so a caller is never promised that their data stays on one side of the Tasman. Processing in Australasia rather than offshore also means the agent responds without the delay people expect from an overseas service.

The legal basis, stated exactly

Both countries' privacy laws recognise the other as providing comparable protection, which is what makes running across the two lawful. There is no single trans-Tasman data residency law, and the platform does not claim one. A client that needs a single-country-only arrangement is a conversation with a person, never a promise made on the phone.

Privacy law

The platform operates under the New Zealand Privacy Act 2020. A client, or a client's customer, can ask what is held about them, have it corrected and have it deleted. Data processing agreements and security questionnaires are handled by a person on request.

A call, its transcription and any recording stay inside New Zealand and Australian data centres. Nothing crosses to any other region. New Zealand and Australian data centres The call Transcription Any recording Summary to the client Booking or job written No path to any other region.

Where a call is handled, as stated in the platform's own knowledge base.

Retention

What is stored and for how long

By default, the platform keeps the metadata of a call and nothing else. Everything heavier is switched on by the client, not by us.

Kept by default

Call metadata: who rang, when, how long, and what happened. A structured summary is kept for a call that produced something, because a booking or a job needs it.

Off until the client turns it on

Recordings and full transcripts are off by default. The client switches them on per account or per agent, can switch them off again, and can delete older calls from the dashboard. Customer transcripts are not used to train models.

When an account closes

Everything outside the legal retention periods is deleted. A "How it works" map in the dashboard shows where every piece of information goes and how long the platform keeps its copy, per destination.

Connected systems

A short-lived working copy only: names, numbers, emails, and invoice details where overdue calling is on. It refreshes automatically and is deleted on disconnect. Contact import is off until asked for, takes contact details only, and is deleted on disconnect by default.

Calendars

Two permissions only: see and edit events, and list calendars. A rolling window about a month back and three months ahead. The agent is told busy or free and the next free time, never a title, an attendee or a location.

Health data

For a clinic, the caller recognition index is kept scrambled: no names and no readable numbers, and it expires and rebuilds. The agent never reads an appointment type, a reason, a treatment note, a date of birth, an address or a history.

The retention period for recordings while an account is open is set per destination in the "How it works" map rather than quoted here. Bring the question to the briefing and we will walk through the map for your clients' setup.

Access

Access and roles

Roles are narrow by default, and the client decides who else gets into their account. A partner's staff see a client's calls only because the client said so.

Four roles, each narrower than the last

Super admin is platform operations. Administrator is the partner. Company owner is your client. Company staff are narrowed to the named agents they work on, and adding staff carries no per-user charge. Your named person can be let into a client's account only if the client ticks the box, and the client can remove them under Team without anyone's agreement.

What the agent is told

Only what the call needs. From a calendar, busy or free and the next free time, never a title, an attendee or a location. From accounting, who is ringing and what they owe, never the ledger. From a clinic system, a scrambled index with no names and no readable numbers, and never an appointment type, a reason or a note.

Locked rules on the agent

The agent never guesses, never pretends to be human, never takes card numbers, and never gives medical, legal or financial advice. Those rules are locked, and a client cannot edit them out of an agent. Where a client takes card payments on the call, which is in early access, the customer types the card on the payment gateway's own page from a link the agent texts, and the agent never hears the number.

Two-factor authentication for dashboard sign-in is a question we would rather answer in the briefing against your clients' configuration than summarise here.

Outbound

Abuse protection and outbound rules

The platform makes calls as well as taking them, so the rules on who it may ring, and when, are fixed above the client.

Lists the business owns, only

Campaigns ring lists the client owns. Never bought, scraped or harvested numbers. A do-not-call request is honoured forever, there is a contact-rate cap, and the Australian Do Not Call Register rules are referred to a person rather than decided by the agent.

Calling windows nobody can widen

Outgoing calls are never placed before 8am or after 10pm on the clock of the person being rung, and campaigns stop at 8pm. A client can only narrow that window. An Australian mobile is held to hours that are civil in every Australian zone. The only exemptions are on-call staff alerts and a fresh, verified demo call-back.

Blacklists, whitelists and an audit trail

IP and phone blacklists and whitelists, with every change audited. Text campaigns honour STOP and count it. Lead automations never ring outside the business's hours, never ring a do-not-call number, fire once per enquiry and sit under a daily cap.

Due diligence

Questions we expect from your security review

Six we hear first. Longer questionnaires and data processing agreements go to a person.

Where is the call processed?
In New Zealand and Australian data centres, and nowhere else, including the transcription and any recording. Calls are not split by country of origin.
Is there a single trans-Tasman data residency law behind that?
No, and we do not claim one. Each country's privacy law recognises the other as providing comparable protection, which is what makes running across the two lawful.
Are calls recorded?
Not unless the client switches recording on. Recordings and full transcripts are off by default, can be enabled per account or per agent, and older calls can be deleted from the dashboard.
Who can see my clients' data?
Company staff are narrowed to the named agents they work on. A partner's named person is let into a client's account only when the client ticks the box, and the client can remove them at any time.
Are transcripts used to train anything?
No. Customer transcripts are not used to train models. Recordings and transcripts exist only when the client switches them on, and the client can delete older calls from the dashboard.
Can the agent be used to cold call?
No. It rings lists the client owns, never bought or scraped numbers, honours do-not-call forever, and is held to a calling window the client can narrow but not widen.

Next step

Bring your security review to the briefing

We will go through the questions above against your clients' setup, and the ones this page leaves for a person: retention periods, two-factor sign-in and anything your clients' own compliance asks for.