How we handle your data
CX Foundry starts with data. We need call recordings or transcripts to drive the process, but we understand that handling sensitive customer data is a big responsibility. That’s why we use a dedicated secure environment, process, and toolset to receive, transcribe, and redact your data — operated under Waterfield Tech’s ISO/IEC 27001-certified Information Security Management System.
Read on to understand what we need from you and how we keep you, your customers and your data safe. Feel free to share with your information security team.
What we ask for
A representative sample of your customer interactions — typically 1,000+ audio recordings or text transcripts — plus enough operating context to make sense of them. You retain all right, title, and interest in your data.
How you share it
We securely share credentials to a Microsoft Azure Blob Storage location we provision for you. We’re flexible on format, but prefer high-quality stereo audio with separate channels for customer and service agent, or transcribed data with timestamps.
What we do with it
Inside the secure redaction environment, we:
Transcribe audio using Azure AI Services
Redact transcribed text of personal information by replacing detected personal data (names, dates of birth, phone numbers, government identifiers, payment-card numbers, addresses, email addresses) with labels.
Manually check the redacted output for residual personal information. Anything found is flagged and the redaction pass is repeated.
Where it lives
We provision two client-isolated Azure Blob Storage containers: one for non-redacted data, one for redacted. We apply least-privilege, role-based access. Only a small number of named delivery staff have access, and their actions are logged and monitored, with alerting on anomalies.
Only data that has completed redaction and review is approved to leave the redaction environment. After that, it continues to be tracked and managed under our broader ISO 27001 information security management system, where it is analyzed by approved AI tools and infrastructure from Microsoft, OpenAI, Google, and Anthropic that Waterfield has vetted.
Restricted data
We will not input or process the following using any AI tool, including approved AI, without your explicit written authorization: passwords, API keys, private keys, tokens, payment-card data, sensitive personal data including health data, or any information you have labeled "SENSITIVE INFORMATION, MUST NOT BE PROCESSED BY AI" or equivalent.
How long we keep it
180 days from the end of the engagement by default. After that, we securely delete from primary storage and from backups consistent with our backup rotation. You can ask us to delete earlier in writing; we will confirm completion within 14 calendar days.
What we never do
- We do not use or share your data to train, fine-tune, retrain, or improve any shared or general-purpose AI model.
- We only disclose it to approved providers where needed to deliver the engagement.
- We do not apply your data to work for any other client.
- We do not use your data outside the engagement you signed up for.
We may retain and use generic learnings and anonymized insights derived from your data, only where it would be impossible to extract or reconstruct your confidential information from them.
