All articles
Setup, Trust And Privacy2 min read

Privacy questions to ask an AI call-answering service

Ask about notice, recording, retention, access, deletion, providers, incidents, and shutdown before routing customer calls.

A controlled call flow showing routing, business context, structured output, and owner review.

Before routing customer calls to an AI service, ask what data enters the system, why it is used, where it goes, how long it stays, who can access it, and how you stop the service. Treat answers as inputs to qualified privacy and legal review, not a compliance certificate.

Notice and recording

Ask what the caller hears before processing begins. If calls can be recorded, establish whether recording is on, what activates it, which notice applies, and whether the business can disable it. Do not assume transcription and recording have identical controls.

Data path and providers

Request a plain-language map from phone provider through speech or model services to stored job card. Ask which subprocessors handle audio, transcript, contact details, and operational logs, and in which regions.

Retention and deletion

Separate live audio, recordings, transcripts, structured cards, backups, and logs. Each may have a different retention period. Ask how deletion works, how long it takes to reach backups, and what the owner can remove without support intervention.

Access and tenant separation

Ask who at the business and provider can view each record, how access is authenticated, and how one business's callers are kept separate from another's. Review exports, support access, and audit history too.

Failure and shutdown

Find out what callers hear during provider failure, what partial data is retained, and whether uncertain records are clearly marked. Confirm how to turn routing off and test the rollback from an external phone.

Product boundaries

Ask whether customer data trains models, whether optional uses require separate agreement, and how instruction changes are versioned. Also test restricted actions: price, booking, diagnosis, payment, and attendance promises.

Max & Mia's product contract uses explicit routing, bounded recovery, owner review, and an MVP that excludes those autonomous commitments. Those design requirements do not replace a business-specific privacy assessment.

Pair this checklist with the routing guide and document answers before a live test.