Voice data is among the most sensitive a business holds. This page states plainly how Kwinova handles it.
Separation
Every customer is a separate realm with its own database schema. Isolation is structural rather than a filter applied by each query, so one customer’s data cannot be returned to another by mistake.
In transit and at rest
SIP signalling runs over TLS and call media over SRTP on each leg. Portal and API traffic is HTTPS only. Stored recordings, transcripts and documents sit on encrypted storage.
Document search
Embeddings for the knowledge base are computed on our own infrastructure. Caller questions and document content are not sent to a third-party embedding service.
Access
Access to customer data by our staff is limited to those who need it for support or operations, is role-based, and is recorded in an audit trail. We do not use customer call content to train models.
Retention and deletion
You choose how long recordings and transcripts are kept; an automatic sweep deletes anything past that point. Deleting a company removes its schema and the data in it.
Sub-processors
Speech and language providers used to deliver the service are listed at [link], and we will give notice before that list changes.
Incidents
If a breach affects your data we will tell you within [number] hours of confirming it, with what we know, what we are doing and what you may need to do.
Certification
State here, accurately, which certifications Kwinova holds — and name none that it does not. Regulated deployments should be scoped with a data-processing agreement.
