1. Roles and Infrastructure (CCPA Compliance)
Under the California Consumer Privacy Act (CCPA) and subsequent US state privacy laws, Praveg AI operates strictly as a Service Provider / Data Processor. The Client utilizing our AI infrastructure acts as the Data Controller.
- No Data Brokering: Praveg AI explicitly guarantees that customer lead data, phone numbers, and conversational contexts routed through our nodes are never sold, shared, or monetized.
- Zero AI Model Training: Client Data, including conversational transcripts and business logic, will never be utilized to pre-train, fine-tune, or optimize public or internal Large Language Models (LLMs).
- Isolated Processing: Data is used exclusively to fulfill the AI voice routing and processing requirements requested by the Client.
2. TCPA Compliance Mandate (Crucial)
The Telephone Consumer Protection Act (TCPA) strictly regulates automated outbound dialers. Clients utilizing Praveg AI for outbound US campaigns assume full liability for obtaining explicit written consent.
- Mandatory Intake Checkbox: Clients must update their digital forms to include explicit TCPA consent language. Example: "By submitting this form, I agree to receive automated calls and texts regarding my inquiry."
- E.164 Global Telecom Formatting: Praveg AI utilizes autonomous Length-Based Heuristics to strictly format all inbound and outbound numbers to international E.164 standards, ensuring absolute global compliance across multi-tenant dispatch nodes.
3. Zero-Retention Annihilation & Private Vaulting
To exceed both CCPA requirements and Financial GLBA (Gramm-Leach-Bliley Act) data minimization standards, Praveg AI enforces a Zero-Retention architecture:
- Instant Sub-Processor Purge: Voice interactions processed by third-party telecom channels are strictly transient. Upon call completion, Praveg AI executes an immediate
DELETEcommand, permanently eradicating call logs, audio, and transcripts from third-party servers. - Sovereign Vault Custody: Telemetry and audio artifacts are siphoned securely into Praveg AI’s self-managed, encrypted private vaults. The Client retains absolute ownership of this data.
- Cryptographic Isolation: All stored data utilizes Row-Level Security (RLS) to enforce mathematically absolute multi-tenant isolation. No tenant can access, view, or cross-contaminate another tenant's digital footprint.
4. Financial Security Protocols (GLBA)
For Wealth Management and Financial Services clients, Praveg AI affirms that our architecture satisfies standard Confidentiality & Non-Disclosure requirements. All SIP trunking, telecom handoffs, and webhook payloads are secured via end-to-end TLS encryption, and processed inside certified SOC2-compliant cloud infrastructure to ensure Non-Public Personal Information (NPI) remains impenetrable.
Legal & Compliance Desk
Praveg AI Security Operations