Kept by default
Call metadata: who rang, when, how long, and what happened. A structured summary is kept for a call that produced something, because a booking or a job needs it.
Security and data residency
Your clients will ask where the call goes, what is kept and who can see it. This page answers those questions the way the platform answers them, so your security review and theirs read the same facts.
Data residency
Calls are handled in data centres in New Zealand and Australia, and nowhere else. That covers the call itself, the transcription and any recording.
Call data does not go to the United States, Europe or anywhere else. Calls are not split by the country they came from, so a caller is never promised that their data stays on one side of the Tasman. Processing in Australasia rather than offshore also means the agent responds without the delay people expect from an overseas service.
Both countries' privacy laws recognise the other as providing comparable protection, which is what makes running across the two lawful. There is no single trans-Tasman data residency law, and the platform does not claim one. A client that needs a single-country-only arrangement is a conversation with a person, never a promise made on the phone.
The platform operates under the New Zealand Privacy Act 2020. A client, or a client's customer, can ask what is held about them, have it corrected and have it deleted. Data processing agreements and security questionnaires are handled by a person on request.
Where a call is handled, as stated in the platform's own knowledge base.
Retention
By default, the platform keeps the metadata of a call and nothing else. Everything heavier is switched on by the client, not by us.
Call metadata: who rang, when, how long, and what happened. A structured summary is kept for a call that produced something, because a booking or a job needs it.
Recordings and full transcripts are off by default. The client switches them on per account or per agent, can switch them off again, and can delete older calls from the dashboard. Customer transcripts are not used to train models.
Everything outside the legal retention periods is deleted. A "How it works" map in the dashboard shows where every piece of information goes and how long the platform keeps its copy, per destination.
A short-lived working copy only: names, numbers, emails, and invoice details where overdue calling is on. It refreshes automatically and is deleted on disconnect. Contact import is off until asked for, takes contact details only, and is deleted on disconnect by default.
Two permissions only: see and edit events, and list calendars. A rolling window about a month back and three months ahead. The agent is told busy or free and the next free time, never a title, an attendee or a location.
For a clinic, the caller recognition index is kept scrambled: no names and no readable numbers, and it expires and rebuilds. The agent never reads an appointment type, a reason, a treatment note, a date of birth, an address or a history.
The retention period for recordings while an account is open is set per destination in the "How it works" map rather than quoted here. Bring the question to the briefing and we will walk through the map for your clients' setup.
Access
Roles are narrow by default, and the client decides who else gets into their account. A partner's staff see a client's calls only because the client said so.
Super admin is platform operations. Administrator is the partner. Company owner is your client. Company staff are narrowed to the named agents they work on, and adding staff carries no per-user charge. Your named person can be let into a client's account only if the client ticks the box, and the client can remove them under Team without anyone's agreement.
Only what the call needs. From a calendar, busy or free and the next free time, never a title, an attendee or a location. From accounting, who is ringing and what they owe, never the ledger. From a clinic system, a scrambled index with no names and no readable numbers, and never an appointment type, a reason or a note.
The agent never guesses, never pretends to be human, never takes card numbers, and never gives medical, legal or financial advice. Those rules are locked, and a client cannot edit them out of an agent. Where a client takes card payments on the call, which is in early access, the customer types the card on the payment gateway's own page from a link the agent texts, and the agent never hears the number.
Two-factor authentication for dashboard sign-in is a question we would rather answer in the briefing against your clients' configuration than summarise here.
Outbound
The platform makes calls as well as taking them, so the rules on who it may ring, and when, are fixed above the client.
Campaigns ring lists the client owns. Never bought, scraped or harvested numbers. A do-not-call request is honoured forever, there is a contact-rate cap, and the Australian Do Not Call Register rules are referred to a person rather than decided by the agent.
Outgoing calls are never placed before 8am or after 10pm on the clock of the person being rung, and campaigns stop at 8pm. A client can only narrow that window. An Australian mobile is held to hours that are civil in every Australian zone. The only exemptions are on-call staff alerts and a fresh, verified demo call-back.
IP and phone blacklists and whitelists, with every change audited. Text campaigns honour STOP and count it. Lead automations never ring outside the business's hours, never ring a do-not-call number, fire once per enquiry and sit under a daily cap.
Due diligence
Six we hear first. Longer questionnaires and data processing agreements go to a person.
Next step
We will go through the questions above against your clients' setup, and the ones this page leaves for a person: retention periods, two-factor sign-in and anything your clients' own compliance asks for.