Compliance

Compliance

Certification status, Australian privacy obligations, and payment card handling.

Certification status

FrameworkPosition
SOC 2 Type IIControls are implemented and mapped. Audit timing is agreed per customer contract.
ISO/IEC 27001:2022Annex A controls are aligned. Follows the same audit cadence.
Australian Privacy PrinciplesCompliant.
PCI DSSCard numbers and CVVs are masked in every stored transcript, at every redaction level. See payment card handling below.

Contact support if you need an audit date for procurement.

Australian Privacy Principles

Meddle processes personal information on behalf of its customers. In most cases the customer holds the obligations under the Privacy Act and Meddle is the service provider.

Cross-border disclosure

Australian Privacy Principle 8 governs disclosure of personal information to overseas recipients, and several components of a voice call are processed outside Australia. The Data residency page lists them individually, including:

  • speech synthesis
  • the models that are not served from an Australian region
  • telemetry
  • the automated telephony recovery path

Telemetry defaults to metadata only, so personal information is not disclosed to those recipients unless a workspace changes the setting.

Notifiable data breaches

We will notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable after assessing that a breach is likely to result in serious harm.

Assessment of a suspected breach is completed within thirty days. Our response procedure includes rotating affected credentials and auditing the period of exposure.

Access and correction

Individuals exercise access and correction rights through the customer whose agent handled the call, since that customer holds the relationship. Meddle supports customers in responding.

Account holders can request export and deletion of their own account data directly.

General Data Protection Regulation

Where a customer's callers are in the European Union, Meddle acts as a processor. A data processing agreement is available from support and is not part of the standard terms.

That agreement commits us to returning or permanently deleting customer data within thirty days of termination, with audit log entries retained. Account and workspace deletion are covered under Access control.

Payment card handling

Meddle does not take card payments on behalf of customers, and agents are not designed to collect card numbers.

Transcripts are masked

Where a caller speaks a card number regardless, redaction removes it from the stored transcript. Card numbers are validated with a checksum before masking, and card verification values are matched by keyword context.

Neither can be retained by configuration. Both are masked at every redaction level, including the level that otherwise stores transcripts verbatim.

Recordings are not masked

Redaction operates on transcripts only. It does not touch the call recording, which is stored as unredacted audio in a private Australian bucket.

Recording is on by default, and a recording is kept for thirty days.

A caller who reads a card number aloud on a recorded call has therefore spoken it into audio we hold, even though the transcript is masked.

If your callers may do this, turn call recording off for that agent. It is a per-agent setting on the Privacy page.

Our own payments

Our own payments run through a certified payment provider. Card details do not transit or rest on Meddle infrastructure.

Subprocessors and documents on request

Contact support for any of these:

  • The current subprocessor list, provided in writing for a security or privacy review.
  • A data processing agreement, signed separately from the standard terms.
  • Security and privacy schedules.
  • The region configuration for compute, model inference and speech recognition, described on the Data residency page.

On this page