VOOQIO
Security & compliance

Privacy and security built for Canadian service teams.

Clear answers on PIPEDA-aligned practices, Canadian data residency, retention controls, and what VOOQIO does — and does not — claim for health or US healthcare buyers.

Security & Compliance preview

Procurement-ready without overclaiming

Use this page when buyers ask about PIPEDA, Ontario health privacy, encryption, subprocessors, or US HIPAA. We separate what VOOQIO provides from what your business must configure.

  • PIPEDA-aligned Privacy Policy, Terms, and Data Processing Agreement (DPA)
  • Canadian workspace residency with encryption and tenant-scoped isolation
  • Customer-controlled retention — including metadata-only mode for stricter minimization

24/7

Always-on AI answering

30+

Languages · chat & voice

Same day

Go live

PIPEDA

Aligned practices · Canada

Framework scope

What applies to VOOQIO

Honest boundaries for Canadian privacy, Ontario health-adjacent use cases, and US healthcare buyers.

Primary framework

PIPEDA (Canada — primary)

VOOQIO is designed for Canadian service businesses under PIPEDA-aligned practices: documented Privacy Policy and DPA, controller/processor roles, Canadian workspace residency, encryption, tenant isolation, retention controls, and breach notification commitments.

Shared responsibility

PHIPA & provincial health privacy

Ontario clinics and other health-adjacent teams may process personal health information. Your organization is typically the custodian/controller. VOOQIO processes data on your instructions — configure retention, consents, and what Sarah collects. We do not offer a separate PHIPA certification or health-trustee attestation.

Not in scope today

HIPAA (United States)

VOOQIO is not positioned as a HIPAA-covered platform for US healthcare providers. We do not offer a Business Associate Agreement (BAA) or a US healthcare compliance pack. US buyers requiring HIPAA should treat VOOQIO as out of scope unless a custom enterprise agreement is negotiated separately.

What you will find

Policies, residency, and operations

Documentation topics we cover for security and privacy reviews.

Roles: controller vs processor

When you use VOOQIO for your business, you are typically the controller of your staff and customer data. VOOQIO acts as a processor for that data when we handle it strictly on your configuration and contract. Account, billing, and website analytics may be controlled by VOOQIO as described in our Privacy Policy.

Data residency & cross-border processing

Workspace data for Canadian customers is processed and stored in Canada (Central). Some subprocessors — for example telecommunications, AI inference, or payment partners — may process limited data in other jurisdictions under contractual safeguards described in our Privacy Policy and DPA.

Retention & minimization

You can configure rolling deletion windows or metadata-only storage so transcripts and chat bodies are not kept longer than your policy requires. Lead contact details, billing usage, and audit metadata may be retained separately for operations and invoicing.

Subprocessors

We use vetted providers for hosting, voice, messaging, email, analytics, and payments. Subprocessors are bound by written terms requiring an equivalent level of protection. Request an updated subprocessor summary through your account team or support channel.

Security incidents

We maintain an incident process and will notify affected business customers without undue delay after becoming aware of a breach of security leading to unauthorized access to personal information processed on their behalf, consistent with applicable law and our DPA.

Export, deletion & wind-down

Customers can export workspace data and request deletion according to in-product capabilities and contract terms. At termination, we delete or return personal information as described in the DPA, subject to legal retention requirements.

Technical controls

Controls in production

The safeguards procurement and IT reviewers ask about most often.

Canadian workspace residency

Production workspace data for customers is processed and stored in Canada (Central). Infrastructure choices are documented for procurement reviews.

Encryption in transit & at rest

Calls, messages, and workspace records are protected with TLS in transit and encryption at rest for sensitive production data.

Tenant isolation (RLS)

Each customer workspace is scoped with row-level security in production so one tenant cannot read another tenant’s leads, calls, or messages.

Configurable retention

Eligible plans support rolling deletion (30 / 90 / 180 days) or metadata-only mode that avoids storing transcript and chat message bodies.

Automated purge jobs

Scheduled retention jobs redact or remove aged call and message content according to the policy configured for the workspace.

Audit-friendly operations

Sensitive platform and tenant actions are logged for security review. Every workspace sign-in requires multi-factor authentication in production.

Shared responsibility

Who does what

Your business (controller)

  • Obtain and document consents for call recording, AI processing, and messaging where your jurisdiction requires them.
  • Configure retention, intake fields, and integrations so Sarah only collects what your policies allow.
  • Respond to end-customer privacy requests for data you control as the organization serving those individuals.
  • Classify sensitive data before uploading it — do not submit health, financial, or other restricted categories without appropriate agreements.

VOOQIO (processor)

  • Process personal information on documented customer instructions through the Services and DPA.
  • Maintain technical and organizational measures appropriate to a communications platform of this nature.
  • Notify customers without undue delay of security incidents affecting their workspace data, consistent with law and our incident process.
  • Support reasonable data export and deletion requests according to product capabilities and contract terms.

VOOQIO describes privacy and security controls as “PIPEDA-aligned practices.” That is not a government certification, SOC 2 attestation, or legal guarantee. Formal compliance depends on your use case, configuration, and applicable law. Contact us for procurement questionnaires or a DPA review.

Ready when you are

Ready to stop losing customers to missed calls?

Book a live demo and hear how Sarah can support your business from the first call to the final follow-up.