AllCalls.io — Data Retention & Secure Disposal Policy

Last updated: 07/15/2026

211 N Union St suite 100, Alexandria, VA 22314, USA

This Data Retention & Secure Disposal Policy (the “Policy”) explains how AllCalls Technologies, Inc. (d/b/a “AllCalls.io”) (“AllCalls,” “we,” “us,” or “our”) retains, returns, deletes, and securely disposes of information processed through our website, platform, APIs, communications features, call delivery and routing services, and related support operations (collectively, the “Services”).

This Policy supplements our Privacy Policy, Terms & Conditions, and any applicable customer agreement, data processing addendum, business associate agreement, order form, or statement of work.

The periods below are our standard retention periods. Applicable law, a valid legal or regulatory hold, or a signed customer agreement may require a different period or process. Where requirements differ, AllCalls applies the shortest period that satisfies all binding requirements.

1) Purpose and Scope

This Policy applies to Customer Data and the operational, security, commercial, and compliance records needed to provide and support the Services. It covers information maintained in active applications, databases, call recording systems, transcripts, analytics stores, logs, archives, backups, exports, and approved subprocessor systems.

“Customer Data” includes content supplied by or collected on behalf of a customer, such as call audio, transcripts, caller or lead information, messages, files, account and campaign configuration, billing information, service telemetry, analytics, and related metadata.

2) Retention Principles

3) Standard Retention Periods

The longer applicable period controls when a record belongs to more than one category or is needed to keep a regulated record complete, authentic, searchable, or producible.

Regulated Call and Consent Records

Other Customer, Call, and Business Records

4) Customer-Specific Retention

AllCalls may configure retention by customer, tenant, campaign, call type, or data category. A customer may request a shorter period where lawful. Any longer or non-standard period must be documented and implemented before the affected data is collected when reasonably practicable.

A signed customer agreement may establish different retention periods, export formats, post-termination access periods, deletion timelines, backup treatment, or certification requirements. Such terms control to the extent permitted by law.

5) Data Return and Export

Upon a valid customer request or termination of the applicable Services, AllCalls will make the customer’s data available in a mutually agreed, reasonably usable format, ordinarily within thirty (30) days unless the applicable agreement specifies another period.

Exports use approved secure transfer methods and are limited to authorized recipients. We may verify the requesting person’s identity, authority, and requested scope before releasing data. Temporary transfer copies are deleted as described in Section 3.

6) Deletion and Backup Handling

Active systems. Unless a customer agreement requires faster action, AllCalls generally completes deletion from active systems within thirty (30) days after the applicable retention period expires, an approved deletion request becomes effective, or an agreed post-termination access period ends.

Backups. Residual copies in disaster-recovery backups are protected from ordinary use and age out through the normal backup cycle, which does not exceed ninety (90) days by default. If expired data is restored for recovery purposes, the applicable deletion instruction is re-applied before the restored environment returns to ordinary service.

Subprocessors. AllCalls directs applicable subprocessors to return or delete the same data and obtains confirmation when required by contract or risk level.

Confirmation. When required by contract or reasonably requested, AllCalls will provide a certificate or written confirmation after active-system and applicable subprocessor deletion is complete, identifying any remaining backup aging period or lawful retention exception.

7) Legal and Regulatory Holds

A legal or regulatory hold suspends ordinary deletion for records within its scope. Held records remain access-controlled and may be used only for the hold purpose and other legally permitted purposes.

When the hold is released, the ordinary retention schedule resumes. Records already past their retention period are deleted through the next controlled deletion cycle.

8) Secure Disposal

AllCalls selects a disposal method based on the data’s sensitivity, the storage media, the intended reuse or disposal scenario, contractual requirements, and risk. Depending on the system or media, disposal may include:

Electronic and physical media sanitization is aligned with the current version of NIST SP 800-88, Guidelines for Media Sanitization, or a demonstrably equivalent standard approved by AllCalls.

9) Subprocessors and Third Parties

AllCalls requires subprocessors that store or process Customer Data to maintain confidentiality and security, limit use to the authorized service purpose, follow applicable retention and legal-hold instructions, assist with data return and deletion, and provide evidence of completion when required.

Subprocessors may not sell Customer Data, use it for cross-context behavioral advertising, combine it for an unauthorized secondary purpose, or attempt to re-identify de-identified data. At termination or upon valid instruction, applicable Customer Data must be returned or deleted unless retention is required by law.

10) Artificial Intelligence and Derived Data

11) Privacy Requests

When AllCalls processes personal information on behalf of a customer, we act on verified instructions from that customer and provide reasonable assistance with applicable access, correction, deletion, portability, opt-out, or restriction requests.

A request received directly from an individual concerning customer-controlled data will ordinarily be referred to the applicable customer unless AllCalls is legally required or independently authorized to respond. A deletion request does not override a valid legal hold or another binding legal, regulatory, security, fraud-prevention, dispute, or contractual requirement.

12) Exceptions and Policy Review

Any lawful retention exception is limited to the data and purpose that require it. The retained information remains access-restricted and is deleted when the exception ends.

AllCalls reviews this Policy at least annually and after material changes to applicable law, regulation, customer requirements, products, data flows, storage architecture, subprocessors, or risk. We may update this Policy by posting a revised version with a new “Last updated” date. Material changes will not reduce protections promised in a signed customer agreement without appropriate authorization.


Questions about this Policy or a customer-specific retention requirement? Contact [email protected].