Back to all posts

Data privacy and AI phone agents: what owners should ask

You're handing a stranger your customers' conversations the moment you deploy this. Here's what's worth asking before you do. Ten questions to ask.

AP
Arjun Patel
Co-founder

Deploying an AI phone agent means every customer conversation your business has — questions, complaints, appointment details, sometimes personal information volunteered along the way — now runs through a system built by someone else. Most business owners don't stop to ask what happens to that data before they turn it on. They should. Here's what's actually worth asking, of us or anyone else in this category.

What data actually flows through

Start with the basics: call audio and its transcript, chat and SMS conversation logs, and whatever business or customer information the agent needs to pull in to answer a question or make a booking — availability from your calendar, prices from your service list, sometimes a returning customer's past appointment. None of this is unusual for a system that needs to actually do the job. What matters is what happens to it afterward.

Where is it actually processed

Data residency is a fair thing to ask about directly — where physically does the processing happen, and does that match where your customers are. AIVA processes voice calls on regional infrastructure: Mumbai for calls in India, Frankfurt and Virginia for calls in Europe and the US. That's partly a speed decision — processing closer to the caller is a big part of keeping response times fast — but it's also a reasonable answer to a reasonable privacy question: your customers' calls aren't being routed through servers on the other side of the world by default, the way they would be with a system built around one central hub regardless of where a call actually came from.

A quick note on encryption — the baseline you should expect

Encryption is closer to a baseline expectation at this point than a genuine differentiator, and it's worth naming plainly rather than treating as a selling point: data is encrypted, and the underlying practices are audited annually, with the specifics documented on our security page rather than restated in full here. What's actually worth spending your attention on as a buyer isn't whether a vendor encrypts data — assume every serious one does — it's the questions that follow: where processing physically happens, how long data is kept, and who can reach it afterward.

How long is it kept, and can you get it out

Ask any vendor two specific questions: what's the default retention period, and can you export your own data. AIVA retains conversation data for 90 days by default, visible the whole time on the analytics dashboard, and it's exportable — you're not locked out of your own customers' conversation history, and it's not held indefinitely by default either. If a vendor can't give you a straight answer to either question, that's worth noting.

This matters more for some businesses than others

The stakes here scale with what your customers are actually telling you. A retail store's AI receptionist mostly fields hours and stock questions — low sensitivity, low stakes if something is slightly mishandled. A clinic, a law firm, or a financial advisory practice is a different situation entirely, because the conversations routinely include health details, case specifics, or account numbers volunteered mid-call, sometimes without the caller pausing to think about what they just said out loud. If your business sits in that second category, treat this entire list of questions as non-negotiable rather than a nice-to-have, and read a vendor's answers against your own regulatory obligations, not just their marketing language.

What happens if you cancel

A related question that's easy to forget to ask until after you've already signed up: what happens to stored conversation data if you stop using the product. Whether it's deleted, on what timeline, and whether you can pull an export first are all things worth getting a plain answer to before you commit, not after. Cancellation terms are exactly the kind of detail that's easy to skip past during a sales conversation and awkward to discover you never actually asked about.

Who sees the conversation when a human takes over

When AIVA can't resolve something and hands off to a person, that handoff carries the conversation context so the customer doesn't repeat themselves — which means it's worth asking, of any vendor, who that person actually is. Is it someone on your own team, or a third party? Does the handoff only share what's needed for that specific conversation? These aren't hypothetical questions — they're exactly the kind of thing that determines whether "AI with human handoff" is a real safeguard or just a phrase on a features page.

What reaches your connected tools, and what doesn't

If you've connected a calendar or CRM through one of AIVA's integrations so the agent can check availability or pull up a returning customer's history, that connection is itself a data question worth understanding on its own terms — what specifically gets read from that system, and does anything get written back beyond what you'd expect, like a new booking or a status update. This isn't unique to AIVA; it's true of any tool you connect to a system holding customer records, and it's worth asking about explicitly for whichever integration you're turning on, rather than assuming the connection only flows in the direction you expect it to. A concrete version of the question: if you connect a shared calendar so the agent can check open slots, does it only ever write a new booking into it, or can it also read the titles of other, unrelated events already sitting on that same calendar? For a solo practitioner sharing one calendar across personal and business bookings, that's not an abstract distinction.

Compliance language varies more than it should in this category — "compliant," "certified," and "aligned with" aren't the same claim. It's worth asking any vendor which one they're actually making, and what it covers, rather than taking a badge at face value.

Certifications: what's actually true right now

Since this is where vague claims tend to creep in across the category, here's the direct version for AIVA rather than a badge without context: SOC 2 Type II is in progress, not a completed audit yet. ISO 27001 alignment is self-attested, meaning the practices are believed to match the standard rather than having been independently certified against it by a third party. Neither of those is a reason to avoid asking the question — it's the reason the question matters. A vendor who states this plainly, including where the gaps are, is giving you more useful information than one whose page just shows a logo and a checkmark. Certifications also aren't static — a Type II audit in progress today is a different claim in six months, which is one more reason to ask a vendor for their current status directly rather than relying on a page that may not have been updated recently.

The short list worth asking anyone

Where is customer data physically processed, and does that match where your customers actually are? What's the default retention period, and is it configurable? Can you export your data, and what happens to it if you cancel? Who internally — and externally — can access raw transcripts, and is that access logged? What happens to data during a human handoff specifically? Which compliance claims are actually completed audits, and which are self-attested?

None of these questions are unusual to ask, and a vendor confident in their answers should be able to give them directly, not redirect you to a sales call. You can see more of how AIVA approaches this on our security page, read the technical detail in our docs, or ask us the list above directly before you sign anything.

Share
AP
Written by
Arjun Patel
Co-founder

FAQ

Common questions.

Both, by default — call audio and its transcript are kept together, which is what lets a business actually verify what was said if a question comes up later, rather than relying on a text summary alone.

Regionally — Mumbai for calls in India, Frankfurt and Virginia for calls in Europe and the US — matching where the calls actually originate, rather than routing everything through one central location by default.

90 days by default, and it's exportable, so you're not locked out of your own customers' conversation history and it isn't held indefinitely either.

Ask this directly before signing up. What happens to stored conversation data on cancellation is exactly the kind of policy that should be stated plainly by any vendor, rather than left for you to assume or discover later.

SOC 2 Type II is in progress, not yet complete. ISO 27001 alignment is self-attested rather than third-party certified. It's worth asking any vendor exactly which of these claims they're making rather than trusting a badge on a page.

Whoever on your team has dashboard access — the same access model you'd expect to control for any other business tool. It's worth asking any vendor whether that access is logged, since who can see something and whether it's tracked are two different questions.

Data reaches the systems it needs to for the agent to actually work — your calendar or CRM, if you've connected one. That's a fair thing to ask about specifically for any integration you turn on, rather than assuming either way.

They're not the same claim. 'Compliant' usually implies a completed third-party audit against a specific standard. 'Self-attested' means the practices are believed to match a standard's principles without outside verification. Ask which one a vendor is actually making.

Like this? Get more.

One email a month. Engineering deep-dives, product launches, customer stories. No fluff.

4,200+ subscribers. Unsubscribe anytime.