Enterprise Compliance Documentation Request
# support
n
Hey team — we're an active Vapi customer deploying AI voice agents for enterprise property management clients. One of our clients' legal counsel needs official compliance documentation before they'll sign our pilot agreement. Requesting: 1. DPA — we understand this is available for enterprise customers 2. Data retention documentation — which laws/regulations your retention policies comply with, specific retention periods for recordings/transcripts/logs 3. Deletion process — timeline and procedure when a customer requests data removal 4. Model training opt-out — confirmation on whether call data is used for training and how to opt out 5. Certifications — official documentation for SOC 2 Type 2, CCPA, GDPR, PCI DSS v4.0.1 (beyond what's on the Trust Center) We also emailed support@vapi.ai and submitted the enterprise sales form. This is time-sensitive — deal is blocked pending these answers. Would also love to get a dedicated account rep assigned as we're scaling deployments. Thanks.
c
Hey Nate, ---- 1. The Data Processing Agreement (DPA) is available on https://security.vapi.ai ---- 2. Data Retention Retention depends on compliance mode: • Standard (PAYG): Calls visible 14 days; chat 30 days • Enterprise: Configurable/unlimited (contract-based) • HIPAA Mode: 7–90 days (auto-deletion) • Zero Data Retention: No transcripts, recordings, logs, or metadata stored When compliance modes are off, transcripts, recordings, summaries, structured data, and metadata are stored. When HIPAA mode is enabled, sensitive data is not stored or is immediately scrubbed. Designed to support GDPR, CCPA/CPRA, HIPAA, and PCI DSS requirements. ---- 3. Deletion Process • API-based deletion (immediate) • Bulk deletion (enterprise) • Email request to support@vapi.ai (within 30 days) • Automated deletion per configured retention window • Account termination: deletion within 30–60 days SOC 2 Type II confirms deletion requests are fulfilled within 30 days unless legally required otherwise. ---- 4. Model Training- Customer data is not used to train LLMs by default. Written confirmation available in enterprise agreements upon request. ---- 5. Certifications & Compliance Status- All reports are available under NDA via https://security.vapi.ai Mailing you a copy of this on your mail thread too. For a dedicated account rep, you'll have to consider upgrading to enterprise. You can contact sales on https://vapi.ai/sales ----
n
thanks!
s
There was some misinformation in the above text. Here's the corrected version- Data Processing Agreement (DPA) Our DPA is publicly available at https://security.vapi.ai/. If you require a countersigned agreement, this is available under an Enterprise plan. Data Retention Retention depends on the selected compliance mode: * **HIPAA mode**: Zero data retention policy. Sensitive data is not stored or is immediately scrubbed. * **Standard mode**: There is no predefined retention period in the agreement. Transcripts, recordings, summaries, structured data, and metadata are stored. You may request deletion at any time or manually delete data via the API. Deletion Options * Immediate deletion via API * Bulk deletion (Enterprise only) * Email request to [support@vapi.ai](support@vapi.ai) (processed within 30 days) * Automated deletion based on a configured retention window * Account termination (data deleted within 30–60 days) Our SOC 2 Type II controls confirm that deletion requests are fulfilled within 30 days unless retention is legally required. Model Training Customer data is not used to train LLMs by default. However, our Terms of Service grant permission to use data for training when HIPAA mode is not enabled. Enabling HIPAA mode contractually opts you out of any such use. (Reference: https://vapi.ai/terms-of-service) Certifications & Compliance Compliance reports are available under NDA via https://security.vapi.ai/. Thanks @Nate for pointing them out.