TelonicDocs
English

Security and data protection

Storage, retention and deletion

What Telonic stores, how you set how long each kind of content is kept, and how data is deleted, including from backups and when your contract ends.

On this page
  1. What can be stored, and what you decide for each
  2. When conversation content cannot be kept
  3. How data is deleted
  4. Backups
  5. When your contract ends
  6. In practice
  7. What your team controls
  8. Related

You decide what is kept, for how long, and when it is deleted. Nothing is stored without your permission, and you set a retention period (how long something is kept before it is deleted) for each kind of content, in line with your own data policy and the rules that apply to you. This page sets out what can be stored, how retention and deletion work, what happens to backups, and what happens to your data when your contract ends. It is the reference page for retention across the documentation.

What can be stored, and what you decide for each

Kind of contentWhat it isWhat you decide
Call recordingsThe audio of a call. Recorded only once the caller has consentedWhether calls are recorded, and for how long recordings are kept
Transcripts and messagesThe text of each conversation, on every channelWhether they are kept, for how long, and whether personal information in them is masked
Summaries and outcomesA short account of each conversation and how it endedWhether they are kept, and for how long
The customer recordThe history of each customer across channels and departmentsWhether it is kept, and for how long
Audit recordEach action the agent took, the sources it used, the rule or trigger that applied, and the outcomeHow long it is kept

You can set different periods for different kinds of content. Your team sets and changes retention through the controls it holds in the console (the web application your team uses), and every change is logged.

When conversation content cannot be kept

Where your policy does not allow conversation content to be kept, zero content retention is configured during implementation. The agent works from the conversation in progress and from your own systems, and nothing from the conversation is stored after it ends, or content is held only in storage you control. Continuity between conversations then comes from what your own systems hold.

A content-free audit record is still kept, for the period you set. It records what the agent did, the sources it used, the rule or trigger that applied and the outcome, without the words of the conversation. When a customer or a regulator asks what happened, you can still show it.

How data is deleted

Data is deleted in two ways. At the end of each retention period, content that has reached the end of its period is deleted automatically. On request, an authorised administrator on your team can delete a conversation or a customer's data before its period ends.

Deletion on request is how you act on a data subject request (a request from an individual to see, correct or delete the personal data held about them). Your team finds what is held about that person through the customer record, which brings their conversations on every channel together, and through search, and provides it or deletes it as the request requires. Each deletion is logged, without the content that was deleted.

Data the agent has written into your own systems, such as a note in your CRM (customer relationship management system) or a claim in your claims system, is governed by those systems' own retention and deletion. Your CRM remains the system of record for customer and account data, and the Telonic record is the system of record for conversation history.

Backups

Backups and disaster recovery copies are encrypted and stay in the same country as your deployment. Data you delete is removed from live systems when you delete it, and from backups as those backups expire on their normal cycle, rather than by editing each backup.

When your contract ends

At the end of your contract, your data is returned to you in a standard format, then deleted from live systems, and from backups as they expire. If you prefer, it is deleted without being returned. You receive written confirmation once deletion is complete.

ContentHow it is returned
Customer record, summaries, outcomes and transcriptsStructured data files in a standard format, such as CSV or JSON (common file formats for tables and structured data)
Call recordingsStandard audio files, referenced to their conversations
Audit recordStructured data files in a standard format

If you move to a different hosting option during your contract, for example from a UAE region to your own cloud account, the move is a migration agreed and scheduled with you. Data is moved encrypted and never leaves the countries you have permitted.

In practice

Sahel Crest Properties, a Dubai developer, sets retention before going live.

  1. Its data protection officer keeps call recordings for one year and transcripts for the length of each buyer's payment plan plus two years. The audit record is kept for five years.
  2. Rania, a buyer who decided not to proceed, asks the developer to delete her personal data.
  3. An administrator finds Rania's record, which holds her calls, messages and emails with the agent, and deletes it. The deletion is logged without the deleted content.
  4. The sales team deletes her enquiry from the developer's CRM, which Telonic wrote to, under the CRM's own process.
  5. Rania's data is removed from backups as they expire. The developer confirms the deletion to Rania.

What your team controls

  • Whether each kind of content is kept, and for how long.
  • Whether conversation content is stored at all.
  • Deletion of a conversation or a customer's data on request.
  • Whether your data is returned before deletion at the end of your contract.