Security and privacy

Your clients' data, handled with care.

Suivo handles emails, calls, texts, and client data on behalf of your team. Here is exactly how it is stored, used, and protected.

Stored in Canada
Encrypted at rest
No AI training on your data
Role-based access

Data privacy

All data is stored in Canada on encrypted infrastructure (AES-256 at rest, TLS 1.3 in transit). We do not sell or share your data with third parties.

  • Canadian data residency — no cross-border transfers
  • Retention policies configurable per team
  • Full data deletion on account closure

Email and message handling

Suivo reads only what is necessary to process lead conversations. Emails are parsed for intent and context — not retained in raw form beyond the lead record.

  • OAuth connections — your password is never stored
  • Agents can disconnect any mailbox at any time
  • No email content used to train AI models

Phone and call handling

All parties are informed at the start of any Eva-handled call. Calls are recorded and transcribed in accordance with Canadian telecommunications law.

  • Disclosure at the start of every Eva call
  • Recordings accessible only to your team
  • Agents can delete recordings at any time

AI usage

All AI outputs are surfaced to agents for review before any action is taken. Suivo is a human-in-the-loop system by design. Nothing goes to a client without agent approval.

  • Your data is never used to train AI models
  • AI processing happens within Canada
  • All AI actions are logged and auditable

Team access controls

Role-based access is enforced at the database level. Agents see only their assigned leads. Team leads have visibility across the team. No one sees data outside their role.

  • Row-level security via Postgres RLS
  • All access events logged for audit
  • Team lead and agent roles are clearly separated

Client data protection

Client information is treated as sensitive personal information under PIPEDA. Teams are the data controllers — Suivo acts as a data processor on their behalf.

  • Clients can request deletion of their data
  • Full isolation between teams — no data shared
  • PIPEDA-aligned agreements available on request
 Have questions?

Questions about security?

We'll answer plainly. No lawyer-speak, no vague policy language.

Get in touch Privacy Policy contact@suivo.ca