Data retention policy
Data Retention is the maintenance of information in the Playvox WFM production environments which can be accessed by an authorized user in the ordinary course of business. Information used in the development, staging, and testing of systems shall not be retained beyond its active use period nor copied into production or live environments. By default, the retention period of information shall be an active use period of exactly two years from its creation unless an exception is obtained permitting a longer or shorter retention period. After the active use period of information is over in accordance with this policy and approved exceptions, information must be archived for a defined period. Once the defined archive period is over, the information must be destroyed. Each employee and contractor affiliated with the company must return information in their possession or control to the organization upon separation and/or retirement. Information owners must enforce the retention, archiving and destruction of information, and communicate these periods to relevant parties.
Data archiving and removal policy
Playvox WFM defines archiving as secured storage of information such that the information is rendered inaccessible by authorised users in the ordinary course of business but can be retrieved by an administrator designated by Playvox WFM. Electronic records must be archived with strict access controls set by the information owner and appropriate to secure the confidentiality, integrity and accessibility of the information. Electronic records are stored in Amazon S3 Glacier vaults, clearly separated and identified by information owner, and customer (where applicable). By default, all Playvox business information should be archived for 7 years. Information must be destroyed at the end of the elapsed archiving period
Data storage policy
Whilst Playvox WFM does not hold highly sensitive data, we take security and privacy seriously, and our practices and procedures have been developed to protect and manage all data and service according to industry best practices. Playvox WFM intentionally minimises the storage of sensitive or confidential data points. Playvox WFM does not store any sensitive or PII end consumer / customer data, but does hold the required information on agents. This information includes: Agent first / last name, and Agent email address. All interaction data - such as phone calls, chats, emails etc, is only stored in summarised form - ie start and end times, and no end customer PII information is held. Playvox WFM makes use of the AWS data centers for operational infrastructure and services. AWS data centers have been designed and built from the ground up with security best practice in place. It has been assessed as compliant across a wide range of compliance programs including SOC, ISO/EIC 27001, ISO/EIC 27017, ISO/EIC 27018, ISO 9001, PCI DSS, and IRAP. See https://aws.amazon.com/compliance/programs/ for more details. Access to the Playvox WFM production network is restricted on a strict as-needed basis. It is based on the allocation of the least possible privilege for the minimum period of time, it is frequently audited and monitored, and is controlled by our Support Team. Access to production operational networks is protected through VPN / IP filtering and multifactor authentication. Root accounts are protected and only available under exceptional Policy and Procedures Narrative circumstances requiring authorization from the Playvox WFM directors, audited when used, and destroyed / rotated on completion of the required activity. Data hosting company
AWS, MongoDB Atlas
App/service has sub-processors
no