Security & confidentiality
Security and confidentiality: what we hold, who sees it, and for how long
CloudSecretary records the information your script asks a receptionist to capture on each call — typically the caller's name, number, reason for calling and your qualifying answers. That record lives in your portal, is accessible to the receptionists working your account and to the people you authorize, and is retained for the period you set.
Why this page is short on badges
Trust pages in this industry tend to be a wall of logos and the word "enterprise-grade." That’s easy to produce and tells a buyer nothing.
What’s actually useful is the answer to four questions: what gets written down, where it goes, who can look at it, and when it’s deleted. So that’s what this page is.
What we capture
Only what your script asks for. If your questions are name, number, reason for calling and address, that’s the record. We don’t collect what a caller happens to volunteer beyond what your script requires, and we don’t store recordings unless you’ve asked for call recording and agreed the notice requirements that apply where your callers are.
What we never capture, on any account: card numbers, bank details, Social Security numbers or passwords. If a caller starts reading one out, the receptionist stops them.
Where it lives and who can see it
Call records sit in your account in the portal. Access is limited to the receptionists working your account and the people you authorize — and you control that list, adding and removing users yourself.
Access to your account is logged. If you need to know who looked at what, ask.
How long we keep it
Retention is a setting on your account, not a fixed policy we impose. You choose how long call records are kept and they’re deleted on that schedule. If you want everything from before a certain date removed, that’s a request we’ll execute and confirm in writing.
Export is always available: your call history in CSV, whenever you want it, including on the way out.
The people on the calls
Receptionists work under written confidentiality obligations covering everything they hear on your line. Each account has named people working it — not an anonymous pool — and your script’s never-say list is part of their brief, not a suggestion.
Training covers the situations where confidentiality actually gets tested: a caller who isn’t the client asking for information, someone claiming an emergency to get a personal number, a person who says they’re from your office. The rule in all three cases is the same: we follow what your script says, and if the script doesn’t cover it, we take a message and pass it to you.
Third parties and who can be told what
Who may be told what about a caller or a case is a rule you set, and it’s applied the same way every time rather than judged on the call. Firms and practices where this matters most — legal, healthcare, funeral homes — write it explicitly during setup.
Regulated environments
If your business operates under a specific compliance regime, ask us directly what we can and can’t sign before you buy. We’d rather lose the sale than have a practice assume a protection that isn’t in place — including where healthcare providers are concerned. What HIPAA requires of an answering service and how to verify a provider’s claim.
Questions people ask
What information does an answering service store about my callers?
Whatever the script asks the receptionist to capture — usually name, phone number, reason for calling and any qualifying answers the business requires. At CloudSecretary that record lives in your account and nothing beyond your script is collected as standard.
Who can access my call records?
The receptionists working your account and the people you authorize in the portal. You manage that user list yourself, and access is logged.
How long are call records kept?
For the retention period you set on your account, after which they're deleted. You can request earlier deletion of a date range and we'll confirm it in writing.
Do you record calls?
Only if you ask for it and the notice requirements that apply where your callers are located have been agreed. It isn't on by default.
Do you take card or payment details over the phone?
No, on any account. If a caller begins reading out card or bank details, the receptionist stops them and redirects.
Your first month free
If your compliance team has questions this page doesn't answer, send them over and we'll answer them in writing.