Skip to content

Security and data residency

Where the call goes, what is kept, and who can see it.

Your clients will ask where the call goes, what is kept and who can see it. This page answers as the platform does, so both reviews read the same facts.

callerNew Zealand and Australiandata centresNew ZealandcalltranscriptrecordingAustraliacalltranscriptrecordingno path out
Calls, transcripts and recordings stay in New Zealand and Australian data centres, with no path out.
A row of server cabinets in a data centre aisle, lit from above
A data centre aisle. Calls are handled in New Zealand and Australian data centres, and nowhere else.

Data residency

Handled in New Zealand and Australia, nowhere else

Calls are handled in data centres in New Zealand and Australia, and nowhere else. That covers the call itself, the transcription and any recording.

What that means in practice

Call data does not go to the United States, Europe or anywhere else. Calls are not split by the country they came from, so a caller is never promised that their data stays on one side of the Tasman. Processing in Australasia also means the agent responds without the delay of an overseas service.

The legal basis, stated exactly

Both countries' privacy laws recognise the other as providing comparable protection, which is what makes running across the two lawful. There is no single trans-Tasman data residency law, and the platform does not claim one. A single-country-only arrangement is a conversation with a person, never a promise made on the phone.

Privacy law

The platform operates under the New Zealand Privacy Act 2020. A client, or a client's customer, can ask what is held about them, have it corrected and have it deleted. Data processing agreements and security questionnaires are handled by a person on request.

A call, its transcription and any recording stay inside New Zealand and Australian data centres. Nothing crosses to any other region.New Zealand and Australian data centresThe callTranscriptionAny recordingSummary sentBooking writtenno path to any other region

Where a call is handled, as stated in the platform's own knowledge base.

Retention

What is stored and for how long

By default, the platform keeps the metadata of a call and nothing else. Everything heavier is switched on by the client, not by us.

Kept by default

Call metadata: who rang, when, how long, and what happened. A structured summary is kept for a call that produced something, because a booking or a job needs it.

Off until switched on

Recordings and full transcripts are off by default. The client switches them on per account or per agent, switches them off again, and deletes older calls. Transcripts are not used to train models.

When an account closes

Everything outside the legal retention periods is deleted. A “How it works” map in the dashboard shows where every piece of information goes and how long the platform keeps its copy.

Connected systems

A short-lived working copy only: names, numbers, emails, and invoice details where overdue calling is on. It refreshes automatically and is deleted on disconnect. Contact import is off until asked for.

Calendars

Two permissions only: see and edit events, and list calendars. A rolling window a month back and three months ahead. The agent is told busy or free, never a title, an attendee or a location.

Health data

For a clinic, the caller recognition index is kept scrambled: no names and no readable numbers, and it expires and rebuilds. The agent never reads an appointment type, a reason, a note or a history.

The retention period for recordings while an account is open is set per destination in the “How it works” map rather than quoted here. Bring the question to the briefing and we will walk through the map for your clients' setup.

Access

Access and roles

Roles are narrow by default, and the client decides who else gets into their account. A partner's staff see a client's calls only because the client said so.

Four roles

Super admin is platform operations. Administrator is the partner. Company owner is your client. Company staff are narrowed to the named agents they work on, and adding staff carries no per-user charge.

What the agent hears

Only what the call needs. From a calendar, busy or free, never a title. From accounting, who is ringing and what they owe, never the ledger. From a clinic system, the scrambled index.

Locked agent rules

The agent never guesses, never pretends to be human, never takes card numbers, and never gives medical, legal or financial advice. A client cannot edit those rules out of an agent.

Your named person is let into a client's account only if the client ticks the box, and the client can remove them under Team without anyone's agreement. Where a client takes card payments on the call, the customer types the card on the payment gateway's own page and the agent never hears the number.

Two-factor authentication for dashboard sign-in is a question we would rather answer in the briefing against your clients' configuration than summarise here.

Outbound

Abuse protection and outbound rules

The platform makes calls as well as taking them, so the rules on who it may ring, and when, are fixed above the client.

Lists the business owns

Campaigns ring lists the client owns. Never bought, scraped or harvested numbers. A do-not-call request is honoured forever, and Australian Do Not Call Register rules are referred to a person.

Windows nobody can widen

Outgoing calls are never placed before 8am or after 10pm on the clock of the person rung, and campaigns stop at 8pm. A client can narrow that window, never widen it.

Blacklists and auditing

Blacklists and whitelists, with every change audited. Text campaigns honour STOP and count it. Lead automations fire once per enquiry, under a daily cap, never outside hours and never to a do-not-call number.

An Australian mobile is held to hours that are civil in every Australian time zone, and a contact-rate cap stops anyone being rung too often. The only exemptions to the window are on-call staff alerts and a fresh, verified demo call-back.

Due diligence

Questions we expect from your security review

Six we hear first. Longer questionnaires and data processing agreements go to a person.

Where is the call processed?
In New Zealand and Australian data centres, and nowhere else, including the transcription and any recording. Calls are not split by country of origin.
Is there a single trans-Tasman data residency law behind that?
No, and we do not claim one. Each country's privacy law recognises the other as providing comparable protection, which is what makes running across the two lawful.
Are calls recorded?
Not unless the client switches recording on. Recordings and full transcripts are off by default, can be enabled per account or per agent, and older calls can be deleted from the dashboard.
Who can see my clients' data?
Company staff are narrowed to the named agents they work on. A partner's named person is let into a client's account only when the client ticks the box, and the client can remove them at any time.
Are transcripts used to train anything?
No. Customer transcripts are not used to train models. Recordings and transcripts exist only when the client switches them on, and the client can delete older calls from the dashboard.
Can the agent be used to cold call?
No. It rings lists the client owns, never bought or scraped numbers, honours do-not-call forever, and is held to a calling window the client can narrow but not widen.

Next step

Bring your security review to the briefing

We will go through the questions above against your clients' setup, and the ones this page leaves for a person: retention periods, two-factor sign-in, your clients' compliance.