SECURITY & PRIVACY

Know what happens to a call.

Recordings, transcripts, access, and deletion should be part of the setup conversation—not assumptions. This page separates what the current written policies say from details that still need confirmation.

Some setup and data-handling details are not yet confirmed.

Items marked [JEFF TO CONFIRM] are questions, not assurances. Read this page alongside the current Privacy Policy and Terms of Service.

Calls, recordings, and transcripts

The current Privacy Policy says the service may process call recordings and transcripts to operate call handling and support service quality. It does not specify whether every call is recorded, which settings apply to each call flow, or exactly where recordings and transcripts are stored. Those details must be confirmed for your setup. [JEFF TO CONFIRM]

If recording or transcription is enabled, callers should receive any notice required for the places where the calls take place. See “Call notice and applicable law” below.

Retention and summaries

The current Privacy Policy says recordings and transcripts are kept for the duration of the service agreement unless you request earlier deletion, then purged 90 days after account termination. Discuss retention and deletion before a build goes live. Whether an individual setup may use a different schedule, and how that would change the published policy, still needs confirmation. [JEFF TO CONFIRM]

Call summaries are delivered using the destination selected for the configured workflow. Confirm who can see each destination, any CRM records, and any shared devices or accounts that receive a summary. The exact recipients and access settings are setup-specific. [JEFF TO CONFIRM]

The assistant and caller notice

The intended call flow identifies the voice system as an assistant rather than pretending it is a person. The exact words and when they play should be reviewed and agreed during setup.

The existing Terms place responsibility on the customer to meet applicable call-recording consent and AI-disclosure requirements. Requirements differ by jurisdiction; decide the appropriate notice for your calls with qualified legal counsel. State-specific notice behavior in a configured call flow is not documented here. [JEFF TO CONFIRM]

Where data is handled and who can access it

The current Privacy Policy describes encryption in transit and at rest and role-based access controls. The actual storage and processing locations, the access roles for a particular account, and how access is reviewed are not specified on this page. Confirm the relevant locations and access arrangements for your setup. [JEFF TO CONFIRM]

The Privacy Policy also says that limited human review may occur for quality assurance. Ask which interactions may be reviewed, by whom, and under what confidentiality requirements.

Deletion requests

To request deletion of personal data, email hello@thryvhq.com with the subject line “Data Deletion Request.” The existing Privacy Policy explains verification, retention exceptions, and the timing it describes for deletion from active systems and backups. Refer to that policy for the current terms.

Use of data to improve AI models

The current Privacy Policy says aggregated, de-identified interaction data may be used to improve AI models. The Terms say identifiable business data will not be used to train models serving other clients. These statements do not establish whether customer data may be processed outside an account or whether any service provider uses call data to train its own models. The exact limits and controls need confirmation. [JEFF TO CONFIRM]

Questions or a deletion request? Contact hello@thryvhq.com. For deletion requests, use the subject “Data Deletion Request” as described in the Privacy Policy.