Compliance & data

Telecom compliance, data retention, and erasure.

Every call your agents make creates data - a transcript of what was said, sometimes a recording, and a few structured fields you asked the agent to capture. That data is useful (it’s how you review calls and report on outcomes), but it’s also personal information about real people, and India’s DPDP Act plus RBI-style rules for regulated industries put you on the hook for how long you keep it and what you do when someone asks you to delete it.

This page is about data governance - the account-wide controls that decide how call data is stored, when it’s automatically deleted, how you honor an erasure request, and the proof oyehello keeps that you called people the right way. The good news: most of it runs on its own. You set a couple of policies once, and the platform enforces them on every call and every night, without you having to remember.

This page vs. Compliance packs. They sound similar but do different jobs. Compliance packs (see that guide) are calling-time rules attached to each agent - Do-Not-Disturb scrubbing, calling-window hours, how often you can dial the same person. This page is data-time rules for your whole workspace - how call data is kept, deleted, and erased after the fact. One decides who gets called and when; the other decides what happens to the data those calls produce.


How oyehello protects your call data

Before the individual settings, it helps to know the defaults you get without touching anything:

  • Your data is isolated to your workspace. Transcripts, recordings, and contacts belong to your workspace alone - other tenants on the platform can never see them.
  • Recording is optional and off unless enabled. If you never turn recording on, there simply are no recording files to worry about - only transcripts exist.
  • Data residency is set at signup. Indian workspaces are pinned to India (Mumbai) storage. It’s shown read-only on your Workspace card because moving data between regions after the fact isn’t something you want to happen by accident.
  • Compliance proof is kept separately from personal data. Consent, grievance, and audit records are stored with an internal reference to a contact - never their name or phone number - so they can survive an erasure while the personal data is wiped. More on that below.

You don’t configure any of this per call. It’s simply how the platform is built.


Data retention

What it is. A workspace-wide policy that says how long transcripts and recordings are kept before they’re automatically deleted. You’ll find it as Recording retention on your Workspace card, under Account → General.

Why it matters. “Keep customer data no longer than you need it” is a core DPDP principle - and honestly, it’s just good hygiene. Holding years of old call recordings is a liability, not an asset. A retention window turns “we should really clean this up someday” into something that happens on its own, every night, forever.

How to set it. Pick a window from the dropdown:

  • 30 days - the tightest option; good if you only need call data for immediate follow-up.
  • 90 days - the default, and a sensible middle ground for most teams.
  • 180 days
  • 1 year - the longest, for teams with a genuine reason to keep call data around (e.g. dispute windows in a regulated vertical).

Once set, a background retention sweep runs automatically once a day. Anything older than your window gets cleaned up: the transcript text is wiped from the call record, and the recording file is deleted from storage - both the database entry and the actual audio bytes. The rest of the call record (that it happened, its outcome, its duration) stays, so your reporting and totals don’t suddenly develop holes.

What the sweep never touches: your compliance proof. Consent records, grievance logs, and audit trails are deliberately excluded from the retention sweep - they’re your evidence that you called people correctly, and they hold no personal transcript content, so they’re kept regardless of the window.

  • Tip: shorter is safer from a privacy standpoint, but set it to the shortest window you can actually operate with. If your team reviews calls a month later or you handle disputes that surface after 60 days, don’t set 30 and lose the evidence you need.

Erasing a specific contact’s data (DPDP)

What it is. The DPDP Act gives individuals the right to have their personal data deleted on request. oyehello lets you honor that for one specific contact, on demand, without waiting for the retention window. You’ll find it as the Data and privacy card under Account → General.

Why it matters. When someone writes in and says “delete my information,” you need to be able to do it - completely, provably, and without accidentally nuking your compliance records at the same time. This tool does exactly that.

How to do it. In the Data and privacy card, enter the contact’s reference - the external ID you uploaded them with in your calling list, which is what a person will typically quote in their request. Confirm in the dialog (it’s deliberately a two-step, because this can’t be undone), and the platform wipes everything personal about that contact:

  • Their contact identity - name, phone number, and any custom attributes.
  • Every transcript from their calls.
  • Every recording of their calls, including the audio files themselves.
  • Any call notes or reasons elsewhere in the platform that quoted their conversation.

When it finishes, you’ll see a confirmation of exactly what was removed - for example, “3 transcript(s) wiped, 1 recording(s) deleted. Compliance records kept.”

Two details worth knowing, because they’re doing important work quietly:

  • The number goes on your do-not-call list. Erasing a contact automatically adds their phone number to your workspace’s suppression list, so even if that same number is re-imported later under a fresh reference, your agents won’t dial it. A deletion request and a “don’t contact me” request usually come together, and this treats them as one.
  • Your proof survives. Consent, grievance, and audit records for that contact are kept - but they only ever held an internal reference, never the person’s name or number, so nothing personal remains. And a record is written of who ran the erasure and when, so you can demonstrate the request was honored.

This is irreversible. There’s no undo and no recycle bin - that’s the point of an erasure. Make sure you’re erasing the right reference before you confirm. Only workspace admins can run it.

  • Tip: the identifier to enter is the external reference from your uploaded list, not the person’s phone number. If you’re not sure what reference a contact was uploaded with, check your calling list before you start.

Two kinds of record are kept for you automatically as calls happen - and, as covered above, they’re the ones that survive both the retention sweep and a contact erasure, because they’re your legal defensibility.

When consent is relevant to a call, it’s captured and logged as a record tied to the contact. This is your evidence that you had a basis to make the call - the thing you’ll want on hand if a call is ever questioned. It happens as part of the call flow; you don’t maintain it by hand.

Grievances

If a caller raises a complaint on a call, it’s logged as a grievance and surfaced on your console’s Compliance page, alongside your packs.

  • You’re alerted immediately. When a grievance is captured on one of your calls, the platform emails your workspace so it doesn’t sit unseen.
  • There’s a resolution clock. Regulated grievances carry an RBI-style 30-day window to resolve. The console shows each grievance’s state and flags any that go overdue, and a daily digest email reminds you about newly-overdue ones - so nothing quietly slips past the deadline.
  • You resolve them in the console. Open the Grievances card, review the complaint, and mark it resolved once it’s handled.

Why keep these forever? Consent and grievance records are the difference between “we believe we called correctly” and “here’s the proof.” They carry no transcript content and no personal identifiers, so keeping them costs you nothing on the privacy side - which is exactly why erasure and retention leave them alone.


The AI & recording disclosure

What it is. At the start of every call, the agent tells the caller two things when they apply: that they’re speaking with an AI assistant, and - only if the call is actually being recorded - that the call is being recorded.

Why it matters. This is a legal and ethical baseline, not a nice-to-have. People have a right to know they’re talking to a machine and whether they’re on tape. Getting it wrong isn’t just bad form - in regulated verticals it’s a violation.

How it works. You don’t write this disclosure and you can’t accidentally turn it off - it’s enforced in the platform itself, not left to the prompt you wrote. A few things it handles for you:

  • It’s spoken in the caller’s language, and if the caller switches language mid-call, the disclosure adapts.
  • The recording notice is only spoken when the call is genuinely being recorded - no false “this call is recorded” on a call that isn’t.
  • In regulated calls, the agent won’t reveal any account or personal details until it has verified it’s speaking to the right person - the disclosure comes first, sensitive information only after identity is confirmed.

In plain terms: this is one less thing to get right yourself. However you brief your agent, the required disclosure is guaranteed to be spoken, correctly and in the right language.


For developers

Erasure isn’t only a console button - it’s also available over the API (/v1), so you can wire “delete this contact” straight into your own privacy or support workflow. If a deletion request comes in through your helpdesk, your system can call the erasure endpoint directly and get back the same confirmation of what was removed. See API keys & the developer API to get started.


That’s the last of the Account settings. Between your compliance packs deciding who and when you call and these controls deciding what happens to the data afterward, the compliance side of oyehello is designed to run quietly in the background so you can focus on the calls themselves. If you’re just getting oriented, head back to the Introduction for the map of everything else.