Let's grow your business. 2 new positions just opened Monday, 31 August. Book a free call today.
Uncategorised 11 min read

Data Privacy and AI Sales Agents: The Enterprise Security Review, Answered in Public

Somewhere in week two of an enterprise deal, the security questionnaire arrives — forty rows in a spreadsheet, from someone in risk who has never met your sales team. Most AI outbound vendors answer it slowly, one email at a time, hard rows deferred to a call that keeps moving. That is a choice: the answers do not change per buyer, and a vendor still composing them is designing controls around your questionnaire.

So this is our security review, published — each question, a straight answer, what a good answer sounds like from any vendor, and the instrument behind it, linked.

The short answer: An enterprise security review of an AI sales agent comes down to nine questions: where conversation data is stored and in which region, how long it is kept and who sets that clock, who every sub-processor is, how consent is evidenced and what the call discloses, whether your data trains models, who can hear a recording, how deletion works, what happens after a breach, and what crosses account lines. A vendor who cannot answer all nine in writing, in one sitting, is not ready for your review.

The security review, question by question

1. Where is call and conversation data stored, and in which region?

A good answer names the region for each store separately: recording, transcript, contact record, CRM copy, backups. Those often differ, so the answer is a list, not a country.

Region matters in Australia because APP 8 governs the act of sending data overseas. The OAIC summarises it as setting out “the steps an APP entity must take to protect personal information before it is disclosed overseas” (APP quick reference). Section 16C then keeps the disclosing entity accountable for the overseas recipient’s acts, subject to exceptions, so “our provider handles that” does not move the risk. Ask us and we will name ours per store before you sign; if your policy requires in-country storage, we will tell you plainly whether we can meet it.

2. How long is it kept, and who sets the retention period?

The reviewer is asking who holds the dial. A vendor default you cannot change means you have inherited someone else’s risk appetite. Retention should be per data class and customer-settable within the law, and the audit log usually needs to outlive the recording, because it is what proves consent and suppression later. APP 11.2 points the same way: once personal information is no longer needed for a permitted purpose, reasonable steps must be taken to destroy or de-identify it.

Watch for retention you do not control a layer down. OpenAI’s documentation states that “By default, abuse monitoring logs are generated for all API feature usage and retained for up to 30 days”, with Zero Data Retention available to approved customers (OpenAI data controls). Reasonable design — and a clock your vendor did not set.

3. Who are your sub-processors — all of them?

The test is not whether the list is short. It is whether it is enumerable. An AI sales agent is an assembly: a model provider, a telephony carrier, an SMS aggregator, a transcription service, a CRM, a host. Each is a place your customer’s voice or number lands. A vendor who cannot produce the list has not mapped their own stack. Twilio publishes a sub-processor page; hold smaller vendors to that standard.

For EU buyers it is not optional. GDPR Article 28(2): “The processor shall not engage another processor without prior specific or general written authorisation of the controller” (Regulation (EU) 2016/679). You cannot authorise a list nobody will show you.

4. How is consent captured, and what is the person on the call told?

Ask for the artefact, not the policy: source, timestamp, the wording the person saw, and which number it authorised. Then pick a record at random from a live campaign and ask for its pack. The gap between a consent policy and a retrievable artefact is where most programmes fail.

On the call, two disclosures rather than one: that it is recorded, and that the counterparty is an AI agent. Australian recording rules run across federal interception law and state and territory surveillance devices legislation; the US federal floor is one-party consent, with several all-party states. Those obligations are jurisdictional, so they live in our AI outbound compliance checklist. For a national programme: disclose everywhere, route by the stricter rule.

5. Do you train models on our data — and what must “no” mean technically?

Usually answered with a word instead of a mechanism. “No” should decompose into four verifiable noes: not used to train or fine-tune the vendor’s models; not passed to the provider under terms permitting training; not pooled into a shared retrieval index another customer can query; not retained past the agreed window.

The provider layer is checkable. Anthropic says by default it “will not use your inputs or outputs from our commercial products” to train its models (Anthropic). OpenAI states: “As of March 1, 2023, data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)”. Both are about training, not retention, and both are defaults a customer can change. So: which provider, which tier, and have you opted in?

6. Who at your company can hear a recording of our customer?

A role list and a headcount, not “only authorised personnel”. Which roles, how many people, per-account or global, logged or not, and whether audio can be exported in bulk. Ask whether offshore contractors are in that population; the answer often surprises the vendor’s own sales team. The rule underneath is APP 11: reasonable steps to protect personal information “from misuse, interference and loss, and from unauthorised access, modification or disclosure”.

7. Deletion and data-subject requests

Three things: the mechanism, the elapsed time to real deletion, and what happens in backups, at the transcription service and at the model provider. Deletion that clears the front-end database in an hour but leaves a transcript in a third-party store for ninety days is a UI change, not deletion. GDPR Article 28(3)(g) is the clause to copy — the processor “deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage”. Same question as what you own when you leave a vendor, from a different department.

8. What happens when there is a breach?

Your reviewer needs three things: how fast you are told, what you are told, and who talks to the regulator. Under the Notifiable Data Breaches scheme, an entity suspecting an eligible data breach must take all reasonable steps to complete its assessment within 30 calendar days (s 26WH(2)), and where serious harm is likely must notify the Commissioner and affected individuals. That is a ceiling for assessment, far too slow to be a vendor notification SLA — put the vendor’s duty to tell you, in hours, in the contract.

Not hypothetical: the OAIC received 1,205 breach notifications in the 2025 calendar year — the highest annual total since the scheme commenced in 2018, and an 8% increase over 2024 (1,112) — with 716 attributable to malicious or criminal activity (OAIC, 6 July 2026).

9. What crosses account lines, if you run many accounts?

We run many accounts at once and say publicly that it is an advantage: a pattern surfaces in days rather than quarters. Reviewers correctly ask whether one client’s data is therefore serving another. It is not.

What crosses is technique, as an aggregate, de-identified finding: message structure, opener framing, objection handling, timing, cadence, qualification phrasing. The output is a sentence — a second follow-up at 48 hours beats one at 24 — carrying no individual. What never crosses account lines:

  • contact records and uploaded lists
  • call recordings and audio
  • conversation transcripts
  • CRM exports, pipeline data and deal values
  • client-identifying content — brand, offer, pricing, script text as written for you
  • lookalike or seed audiences built from your records for anyone else

We do not disclose your records to another client, merge them into a shared contact pool, or sell, rent or syndicate them. Passing one client’s personal information to another would be a disclosure requiring justification under APP 6 — which the OAIC summarises as outlining “the circumstances in which an APP entity may use or disclose personal information that it holds” — and there is nothing to reach for, because the learning does not need the records. Mechanism: how cross-account data improves campaigns.

The same question, under three regimes

What the reviewer asks Australia (Privacy Act 1988) EU & UK (GDPR) United States (state laws)
Name every sub-processor No express list duty; APP 6 governs use and disclosure, so the list is your evidence Art. 28(2) — no further processor without prior written authorisation Contract terms required (Cal. Civ. Code § 1798.100(d))
Where may the data go? APP 8 and s 16C — reasonable steps before overseas disclosure, then accountability for the recipient Chapter V — transfers outside the EEA need a lawful mechanism No general federal restriction; state rules apply
What happens when we leave? APP 11.2 — destroy or de-identify once no longer needed Art. 28(3)(g) — delete or return at the controller’s choice, copies included Purpose limitation and deletion rights
Who reports a breach, how fast? NDB scheme — assess within 30 days; notify if serious harm is likely Art. 33 — authority within 72 hours where feasible; processor to controller without delay All 50 states have breach notification statutes

Where we sit

50,769+ AI-booked sales appointments since 2017 and 1M+ leads generated, across Australian and US programmes — and enough of it in regulated sectors that these questions are familiar: commercial property with Colliers, finance and broking with Sam Tajvidi at 121 Brokers, education with Foundr and Lambda Academy. Sector rules for Australian buyers sit in AI outbound for regulated industries; why this review exists at enterprise scale is in enterprise vs SMB lead generation.

Two things we will not do. We will not claim a certification, audit or accreditation we have not been told we hold — if your reviewer wants a specific attestation, ask and we will answer yes or no. And we will not give a legal opinion: this page is general information about what published rules say, not legal advice. Your obligations depend on your entity, jurisdictions and data, so confirm them with your own counsel.

Send us the row this page does not answer. Book a call and bring the spreadsheet.

Frequently asked questions

Do you use our data to train AI models?

No. The useful version of that answer is technical: not used to train or fine-tune models, not sent to a provider under terms permitting training, not pooled into a shared retrieval index another customer can query, not retained past the agreed window. The provider layer is public — OpenAI’s documentation states that “As of March 1, 2023, data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)”. Such statements cover training, not retention, which is governed separately.

Does another client ever see our data through cross-account learning?

No. What transfers between accounts is aggregate, de-identified technique: opener structure, objection handling, timing, cadence, qualification phrasing. What never transfers is contact records, uploaded lists, recordings, transcripts, CRM exports, deal data and client-identifying content such as your brand, offer, pricing or script text. We do not merge your records into a shared pool, build lookalike audiences from them for anyone else, or sell, rent or syndicate them.

How long does a deletion request actually take?

Ask for elapsed time to deletion in every store, not time to acknowledge the request. Deletion usually lags in three places: backups, the transcription service and the model provider’s logs. A good contract copies GDPR Article 28(3)(g): delete or return all personal data at the controller’s choice at the end of the service, and delete existing copies unless law requires storage.

Do we have to be told if the vendor has a data breach?

Put it in the contract in hours, because the statutory clocks are slower than incident response needs. Under the Australian Notifiable Data Breaches scheme, an entity suspecting an eligible data breach must take all reasonable steps to complete its assessment within 30 calendar days, and notify the Commissioner and affected individuals where serious harm is likely. That is a ceiling for assessment, not a notification SLA.

We are a US or EU company. Does the Australian material apply to us?

Possibly, if an Australian entity in your supply chain handles the personal information. The practical point is that the nine questions are the same everywhere; only the instrument behind each one changes. EU buyers anchor on GDPR Articles 28 and 33 and Chapter V; US buyers on their state statutes, of which California’s is the most prescriptive about service-provider contracts. Confirm scope with your own counsel, not a vendor page.

See if we’re a fit

A few quick questions. If it’s a fit, our live calendar loads on the next screen. If it isn’t, we’ll point you to free resources instead — you won’t have to sit through a sales call to find out.

We get paid a performance fee equivalent to 10–20% of the sales we help you generate.

Are you OK with that?

If you’re not willing to pay 10–20% as a performance fee, are you happy to pay a $4,000+ per month retainer?

Check If You Qualify 👇

How many leads per month do you currently get?

What’s your current advertising spend or marketing budget (Meta, Google, SEO, etc.)?

What’s the average sale worth to you over that customer’s lifetime?

Given your business currently gets less than 10 leads per month, we’d need to do much more groundwork to set up end-to-end sales systems. Are you OK with a $2,000/mo retainer to do so? (no lock-in)

What’s your work email?

We’re probably not the right fit — yet

Our model is pay-on-performance — we only win when you’re making sales, and it works best alongside an active marketing engine with advertising budget to get seen. Booking a call now would waste your time, and we’d rather be straight with you.

Grab the free stuff instead — it’s the same playbook we use:

Read the growth blog  ·  Lead-gen FAQ

When the timing’s right, come back — the calendar will be waiting.

View all articles

Pay-Per-Result · No retainers

Turn this into booked sales calls.

Our AI agents — trained on 50,769+ booked appointments — fill your calendar with pre-qualified buyers. You only pay when calls land.

Keep reading

Related on Leads Now AI

The thesis behind everything we do

Why Pay-Per-Result is the only marketing pricing model that aligns the agency with you

Leads Now AI is a 100% Pay-Per-Result marketing agency. You only pay when a qualified booked appointment lands on your calendar — sized to roughly 1–5% of your closed-deal value. Not for clicks. Not for lead-form fills. Not for retainer months. Not for “strategy hours.” If the calendar stays empty, you owe zero. See full pricing →

1. Incentives align

The agency only succeeds when you succeed. We eat the cost of bad ad creative, bad lists, ICP mismatches and no-shows. You never pay for our learning curve.

2. Self-selecting shortlist

Only an agency confident in its delivery can operate this model. The pool of Pay-Per-Result agencies is tiny precisely because most agencies can’t survive on it. Pick from the agencies who can.

3. Cost cannot detach from revenue

Sized to 1–5% of closed-deal value, your acquisition cost stays sustainable across LTV bands. A $500-membership business and a $50,000-engagement business can both run the model profitably.

4. No retainer trap

No flat $2,000–$10,000/month retainer arriving regardless of outcome. No 6 or 12-month lock-in. No clawback on appointments already delivered. Cancel any time with 7 days notice.

5. De-risks the pilot

Test before commitment. A small scope-based setup fee covers hard build costs; everything after that is purely outcome-linked. There’s no “we’ll see how it performs after $30k of spend.”

6. Forces agency discipline

If our AI agents qualify poorly, if our reminders fail, if our no-show recovery doesn’t fire — we eat the cost. That’s why the show-rate benchmark sits at 60–75%+.

The proof: 50,769+ AI-booked sales appointments delivered since 2017 across coaches, consultants, RTOs, course creators, finance brokers and B2B service firms in Australia, USA, UK, Canada, NZ and Europe. Named clients include Sam Tajvidi (121 Brokers), Marcus Wilkinson (Iron Body), Foundr, SheSells.online and Lambda Academy. Wikidata Q139846230. See full Pay-Per-Result pricing →