Skip to content

PCI & Data Handling Policy

This page describes uContact's positioning with respect to cardholder data, the tools available to prevent its storage, and the platform's data retention and deletion policy.

Platform positioning

uContact is not a payment application. By design, uContact does not present a payment form, and it does not authorize, settle, or store payment transactions as a function of the service. net2phone operates uContact as a service provider, not as the merchant that collects payments.

Cardholder data is not stored, and should not be. uContact does not hold cardholder data as a deliberate function of the service. Card data can only enter the platform incidentally during a contact-center interaction, in two ways:

  • Voice: a customer speaks a card number or CVV while a call is being recorded.
  • Text channels: a customer types card details into a message.

Both situations are preventable, and uContact provides the tools to keep that data out of storage, logs, and audit:

  • The card-data detection engine masks any card number or CVV in text channels before it is stored, shown to the agent, sent out, logged, or audited.
  • The recording pause/resume control lets the agent stop the recording before any payment data is spoken, so it is never written to the recording file.

Payment collection must be redirected to an external platform. uContact must not be used to deliberately collect card data. If a customer needs to build a flow that takes a payment, that collection must be redirected to a dedicated external payment platform (for example a PSP-hosted page, a pay-by-link, or a DTMF-isolated IVR) operated outside uContact. That way the payment pathway stays out of uContact's cardholder data environment (CDE), and uContact's role stays limited to handling the conversation, not the payment.

Data Lifecycle

Unlike other systems that move data to a temporary "recycle bin," uContact has an immediate and irreversible data deletion model.

Scope of deletion

The management unit is the Interaction. When a deletion order is executed on it, the system instantly eliminates all associated data:

  • Media: Audio files (MP3) from calls.
  • Text: Complete message history in text interactions.
  • Metadata (CDR): All database records indicating that the interaction existed (dates, participating members, duration, etc.).
Important!

uContact does not have a mechanism for recovering deleted information. Once deletion is confirmed (whether manual or automatic), the information permanently disappears from storage systems and audit records.

Botito

Retention policy configuration (automatic)

To ensure regulatory compliance without constant manual intervention, the system uses an automatic retention engine based on time.

Operation and costs

By default, all platform instances are delivered with a standard configuration of 1 year (365 days) of data retention.

  • Period modification: The retention value is an infrastructure parameter. If you require a different number, you need to contact the Support team to request the configuration change in your instance.
  • Cost impact: Keep in mind that requesting an extension of the retention period (retaining data for more than 1 year) will increase cloud storage consumption, which may generate additional costs in your service.
  • Execution: Once an interaction exceeds the established time limit, the system automatically executes the deletion process, permanently removing the audio and metadata without possibility of recovery.

uContact by net2phone