You're handing us your phone line. Here is exactly what happens to what comes down it — in plain language, with no certification badges we haven't earned.
What matters for your risk assessment is which country your data is processed in and whose law reaches it, so that is what this table states.
We don't publish our suppliers' names here, and you can have the list. Naming every vendor on a public page is a standing invitation to anyone probing the service, so this page describes what each one does and where it runs instead. That is not a way of avoiding the question: if you need the actual names — for a security review, a procurement form, a vendor questionnaire or a privacy impact assessment — email info@askmuse.ca and we will send you the current sub-processor list, what each one handles, and where it runs. We'll answer whether you're a customer yet or not.
Where it lives, stated plainly: your leads, recordings and transcripts belong to you — locked to your account by the database itself, never sold, never shared, and deleted when you ask. The infrastructure that holds and processes them is in the United States: your database in US East, and the software that answers your calls in the same region. That means US law can apply to it. PIPEDA permits that and requires us to tell you, which is what this line is for. If you run a Punjabi or Hindi line, the audio is transcribed by a specialist provider outside North America, because the general engines handle those languages badly — we'll name it and its region on request. If you have questions about where your data lives, email us — we'll tell you exactly where we stand.
Everything moves over encrypted connections (HTTPS and secure WebSockets) — the website, the dashboard, and the call audio. Stored data sits on managed, encrypted infrastructure. Our API keys and secrets are never placed in anything a browser can read.
The speech-to-text provider on our English, French and Spanish lines is told, on every single request, not to use your calls to train its models — a flag we send each time, and a test fails the build if we ever stop. Our other AI providers handle your calls under their own API terms. Our sub-processor list, which we send on request, says which terms apply to each one.
One thing we won't pretend about. If you handle health information — a clinic, a dental practice, a physio room — talk to us before you go live. What that needs is a written agreement between us and you, and we will sign one. We would rather tell you that than sell you a badge.
Calls and leads stay in your dashboard until you close your account or ask us to remove them. Ask us to delete a particular call, lead or recording and we will, and we'll confirm when it's done. Ask us to close your account and we remove your business details, your leads, your recordings and your transcripts — and we'll confirm that too.
Under PIPEDA you can ask what we hold about you, get a copy, correct it, or have it deleted. Email info@askmuse.ca and a human — the person who built this — will action it. No ticket queue, no retention team trying to talk you out of it.
Every call is written up as a transcript so your summaries are accurate and you can check what was said. Audio recording is a separate switch, and it is off until you turn it on. When it is on, a spoken notice tells the caller at the start of the call. You're responsible for meeting the consent rules that apply to your business and province — we'll help you word it.
CASL, Canada's anti-spam law. Every follow-up text Muse sends says who it is from and ends with "Reply STOP to opt out". A number that replies STOP is not texted again.
PIPEDA, Canada's private-sector privacy law. Your leads, transcripts and recordings are locked to your account by the database itself, encrypted in transit and at rest, never sold or shared, and deleted when you ask. Where they are stored is stated above, as PIPEDA requires us to tell you. Our Privacy Officer is accountable for all of it and answers at info@askmuse.ca.
CRTC calling rules. The only calls we place for you are call-backs to someone who has just rung your business. Each one happens inside the permitted calling hours, says who is calling and on whose behalf, and ends if they ask not to be called. We never cold-call anyone.
Recording. Audio recording is off until you switch it on, and when it is on, the caller hears a notice at the start of the call.
If we ever discover a breach affecting your data, we will tell you directly — by email and by phone — with what happened, what was affected, and what we're doing, and we will report it as PIPEDA requires. You will not learn about it from a blog post.