Security and data handling
What Zenvox does with your calls, who can read them, what you can take back, and what we do not promise.
What this page covers
A call that reaches Zenvox produces three things: a recording, a transcript and a written request. Those three things belong to your business. This page says where they live, who can open them, how long they stay, and how you take them back or have them erased.
It also says what we do not do. A security page that lists only its strengths teaches nobody anything: the limits are further down, in the second column, written in the same plain words as the rest.
The data residency statement appears at the bottom of every page on this site, and it is written in one single place in our code so that it cannot say two different things on two pages.
Who can open your files
- Access is tied to your business and your site: an account from another business gets a not-found page, with no hint that the file exists
- Each role on your team sees the screens its rights allow; a screen that is not allowed is absent from the menu, not greyed out
- Every view and every action leaves a timestamped trace in your business record
- Removing an access takes effect on work already scheduled, not only on new work
What becomes of a call
- The caller is told about the recording at the start of the call, as Law 25 requires
- The recording, the transcript and the request are attached to the same customer file
- Someone who asks not to be contacted again is recorded as such, across every channel at once
- A phone number is not an identity: two people sharing a line stay two files
Taking back or erasing
- You export your files, your transcripts and your archived recordings from your workspace
- An export that cannot include everything names what it left out, instead of staying silent
- A requested deletion also removes derived items — summaries, drafts, attached documents
- Leaving blocks neither your number nor your data: both go with you
What we hold to
- Traffic between your browser and Zenvox is encrypted in transit, and recordings are encrypted at rest
- Access secrets for third-party services are encrypted, and are neither displayed nor exported
- The list of our subprocessors is public, and we keep it current when it changes
- We tell you if an incident touches your data, with what we know at the time we write
- A person responsible for the protection of personal information is named and reachable
What we do not promise
- We hold no external security certification, and we display no badge for one.
- Live voice processing runs through a subprocessor outside Canada; that is stated at the bottom of every page, with how long its copy is kept.
- The privacy impact assessment Law 25 calls for on that transfer is being drafted: it is not finished.
- Centralised identity connection for your organisation is a separate project from ordinary security; it is not open to everyone today.
- No measure makes data untouchable: what we describe reduces risk, it does not remove it.
A question, an access request, a deletion
Write to the person responsible for the protection of personal information. It is an address that is read, not a form that disappears. Say which business you are writing about and what you are after; an access or deletion request is handled within the timeframe Law 25 sets.
Pages that go with this one
Responsibilities in your province
Find the guide for your province or territory to review the rules relevant to your business and the sources to consult.
Choose my province or territory