Data Handling & Responsible AI

How CCG handles your data — and your customers' data.

Managed AI only works if the data handling is as disciplined as the automation. This page documents how CCG processes, retains, and protects information across every agent we deploy — and how humans stay in the loop.

Data processing

  • CCG-managed agents process only the information needed to do the job: caller name, phone number, appointment preferences, service inquiries, and the business knowledge you approve for the agent to use.
  • Each client runs in its own isolated workspace. Your conversations, customers, and knowledge base are never shared with, visible to, or used to train agents for other clients.
  • We do not sell client or end-customer data, and we do not use your conversation data to train general-purpose AI models.

Retention

  • Conversation transcripts, appointment records, and follow-up logs are retained in your workspace for as long as your subscription is active, so you have a complete audit trail.
  • You can request deletion of specific records or your full workspace at any time. On cancellation, workspace data is retained for 90 days to allow reactivation or export, then deleted.
  • SMS opt-out records (STOP requests) are retained indefinitely as required to honor carrier and regulatory suppression obligations.

Voice recording & consent

  • AI-answered calls are transcribed so the agent can respond and so you have a record of what was said. Callers are told they are speaking with an AI assistant at the start of the call.
  • Where call recording is enabled, a disclosure is played before recording begins, consistent with applicable one-party and two-party consent requirements. Recording can be disabled per client.
  • Agents never ask callers to speak sensitive identifiers aloud (full email addresses, payment card numbers, Social Security numbers). Instead, the agent texts a secure link where the customer enters details themselves.

Human escalation

  • Every agent is configured with explicit escalation rules: requests it cannot handle, upset callers, and out-of-scope topics are handed to a human — by transfer, callback request, or text to your team.
  • Agents operate within approved knowledge and approved actions. They do not make commitments, quotes, or policy decisions outside the boundaries you set.
  • A governance log records what the agent did and why, so a human can review any interaction after the fact.

Sector-specific compliance

  • Messaging programs run on carrier-registered A2P 10DLC brands and campaigns with documented opt-in, and STOP/START/HELP handling on every text program.
  • For clients in regulated sectors (healthcare, financial services, legal), deployments are scoped during the strategy engagement: what data the agent may collect, where it is stored, who can access it, and which contractual controls are required before go-live.
  • CCG does not claim blanket regulatory certifications. Where a sector requires specific agreements or technical controls, those are documented and agreed in writing before the relevant data flows are enabled.

Sub-processors

  • CCG agents run on a small set of infrastructure providers: cloud hosting and database (Lovable Cloud), telephony and messaging (Twilio), calendar integration (Google), payment processing (Paddle, as merchant of record), and AI language models (via Lovable AI Gateway).
  • Each provider is bound by its own data-processing terms, and each integration is configured per-client so credentials and data stay scoped to your workspace.
  • A current sub-processor list is available on request as part of any engagement or diligence process.

Need documentation for your own compliance review?

We provide a data-processing description, sub-processor list, and sector-specific scoping worksheet as part of every strategy engagement.