Data Privacy Commitment

PIPEDA Compliance Statement

How UCSTAK protects Canadian personal information across every Managed Voice and AI service we operate.

UCSTAK commits to full compliance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) across every product we operate, from Managed Voice seats to our proprietary AI modules. Specifically, this statement explains how we apply PIPEDA’s ten fair information principles in practice.

1. Accountability

Our Privacy Officer owns our PIPEDA compliance and answers questions about how we handle personal information. You can reach our Privacy Officer at [email protected].

2. Identifying Purposes

We tell you why we collect personal information before or at the time we collect it. For example, our Privacy Policy sets out the purpose behind each category of data we collect, from account setup to AI-powered call summaries.

3. Consent

We collect and use personal information with your knowledge and consent, or your callers’ consent where you turn on call recording or AI features. Where a caller needs to know a call may be recorded, our platform can play an automatic disclosure message to help you meet that requirement.

4. Limiting Collection

We collect only the personal information we need to deliver, support, and bill for your Managed Voice and AI services. To that end, every request headed to an AI module passes through our Zero-Trust Proxy Router first. This identifies personal information in real time and limits what reaches AI processing to what the feature actually needs.

5. Limiting Use, Disclosure & Retention

We use and disclose personal information only for the purposes we identified when we collected it, unless you give further consent or the law requires otherwise. We also keep personal information only as long as your account stays active, plus a reasonable period for legal and tax purposes. Importantly, we never sell personal information to anyone.

6. Accuracy

We keep account, billing, and configuration information as accurate as the information you give us. If something changes, you can correct it at any time by contacting your account manager or [email protected].

7. Safeguards

We protect personal information with security measures matched to its sensitivity. All AI processing runs on private, Canadian infrastructure, and client data never crosses the Canada–U.S. border for processing or storage. In addition, we use encryption, two-factor authentication, and role-based access controls to limit who can see your data, and each client’s data stays logically separate from every other client’s.

8. Openness

This statement and our Privacy Policy sit publicly on our website, and we explain our privacy practices in plain language to anyone who asks.

9. Individual Access

You can ask what personal information we hold about you, and request a copy, a correction, or its deletion, by contacting [email protected]. We’ll respond within the timeframe PIPEDA sets.

10. Challenging Compliance

If you believe we haven’t met a commitment in this statement, contact our Privacy Officer at [email protected] first so we can address it directly. If our response doesn’t resolve your concern, you can also file a complaint with the Office of the Privacy Commissioner of Canada.

PHIPA Alignment for Healthcare Clients

For ambulatory healthcare and clinic clients, we design our infrastructure and data handling to also support Ontario’s Personal Health Information Protection Act (PHIPA), on top of our PIPEDA commitments.

No Public Model Training

We never use client voice transcripts, SMS content, or synced email to train third-party or public AI models. As noted above, each client’s data remains logically isolated from every other client’s.

Questions or Complaints

Reach our Privacy Officer at [email protected], or see our full Privacy Policy for more detail on how we collect, use, and protect personal information.