Security, compliance, and privacy — by design.
VoiceConnect handles sensitive conversations for businesses across healthcare, veterinary, and service industries — across the United States, Canada, and Europe. Here’s how we protect the data our platform touches, and how we meet the regulatory obligations that apply to your business.
Three commitments.
Security
- Encryption of data in transit and at rest
- Role-based access controls and least-privilege access
- Audit logging of access to sensitive data
- Configurable data retention and deletion
- Breach notification protocols aligned to applicable law
Compliance
- PIPEDA-aligned data handling across Canada
- US healthcare: we act as a Business Associate and sign BAAs for HIPAA-covered customers
- Canadian healthcare: aligned with provincial health-information law, including Ontario PHIPA, with service-provider agreements
- Veterinary: governed by veterinary confidentiality law and owner-privacy rules — not HIPAA
- TCPA-safe (US) and CASL-compliant (Canada) calling practices
Privacy
- You own your data — we process it only to provide the service
- We do not use your data or your callers’ data to train base AI models
- Sub-processors bound by confidentiality and data-protection terms
- Full transparency through our Privacy Policy and Data Processing Addendum
Built for every border you cross.
Healthcare and privacy law works differently in the US, Canada, and Europe. VoiceConnect is built to meet the obligations that apply to your business, wherever you operate.
United States
For HIPAA-covered healthcare customers, VoiceConnect operates as a Business Associate. We sign a Business Associate Agreement (BAA), and protected health information is handled on HIPAA-eligible infrastructure. Non-healthcare deployments are covered by our standard security and privacy commitments.
Canada
There is no single Canadian equivalent to HIPAA. Canadian healthcare data is governed by PIPEDA together with provincial health-information laws such as Ontario’s PHIPA. For Canadian healthcare customers, we sign service-provider agreements with the confidentiality, safeguard, retention, and breach-notification terms these laws require. Cross-border data transfers are handled under PIPEDA’s comparable-protection standard, with Quebec Law 25 privacy-impact assessments where applicable.
Europe
For customers in the European Economic Area and the UK, VoiceConnect aligns with the GDPR as a data processor. We support data-subject rights — access, erasure, and portability — and breach notification within GDPR timelines, and provide Data Processing Agreements incorporating Standard Contractual Clauses for international transfers on request. For healthcare and other high-risk processing, we work with customers to support their Data Protection Impact Assessments (DPIAs).
Need our compliance documentation?
Our Data Processing Addendum, Business Associate Agreement, and current sub-processor list are available to customers and prospects on request. Reach our team at legal@voiceconnect.io.