Security and data protection

Clear roles. Traceable controls. No invented assurances.

This page describes how Absolute Connect handles customer data today. It separates the controls in place from work that is still in progress, so your legal, compliance and technology teams can review the position accurately.

Your firm

Data controller

The firm determines why and how its client personal data is used, including campaign purpose, audience and lawful basis.

Absolute Tech Solutions

Data processor

We process customer data on the firm’s documented instructions to provide Absolute Connect.

Residency & encryption

Keep customer data within the agreed geography.

The database and queue operate in UK/EU regions, and the messaging carrier processes in the EU. Data is encrypted in transit throughout. Message bodies, voice transcripts, conversation summaries and uploaded CSVs receive field-level AES-256-GCM encryption.

DatabaseUK/EU region.
QueueUK/EU region.
CarrierEU region.
Sensitive contentAES-256-GCM field-level encryption.

Consent, opt-out & rights

Make a client’s choice immediate and durable.

The firm remains responsible for its lawful basis, client notices and instructions. Absolute Connect makes consent changes traceable and builds the operational response into the product.

  • Immediate permanent opt-out: enforced at the database layer and not reversible by a future feature.
  • Whole-message matching: an opt-out keyword is matched against the whole message, so “don’t stop, I need this sorted” is treated as the real message it is.
  • Append-only evidence: every consent change is recorded to an append-only trail.
  • Subject access: built tooling locates the client record and relevant conversation material.
  • Erasure: empties the record, redacts every message and transcript, deletes the carrier’s recording, and keeps the opt-out honoured so re-import cannot re-enrol the client.

Retention & audit

Let the firm set retention. Keep the evidence fixed.

Retention is off until the firm switches it on, because the schedule must come from the firm’s own regulatory obligations rather than the platform’s guess.

  • Every staff action is recorded with the action, time and responsible user.
  • Approvals, sends, withholds, handoffs, administrative changes and support sessions are included.
  • The audit trail is held for seven years.
  • Neither the firm nor Absolute Tech Solutions can shorten that audit period.

Support access & logs

Absolute staff can look, with a reason, and cannot act.

Customer access is role-based. A support session is strictly read-only, requires a stated reason and is audited before it begins.

Read-only supportSupport staff cannot alter records, messages, settings or conversations.
Audited before entryThe person and stated reason are recorded before the session begins.
Nothing personal in logsBodies, transcripts, names, telephone numbers and email addresses are redacted before any log line is written.
Role-based accessFirm users receive access appropriate to their assigned role.

Sub-processors

Know which suppliers process customer data.

Every sub-processor is registered with its role, region and DPA state. Each firm can read the same live register inside its workspace at Settings → Privacy. Supplier names remain marked for confirmation.

Sub-processor register Scroll horizontally to see all columns

Sub-processorWhat it doesRegionDPA state
[Database provider — TO CONFIRM]Database and encrypted storageUK/EURegistered in product
[Queue provider — TO CONFIRM]Queues scheduled and live workUK/EURegistered in product
[Messaging carrier — TO CONFIRM]SMS and WhatsApp deliveryEURegistered in product
[Voice speech providers — TO CONFIRM]Speech-to-text and speech synthesisDue diligence in progressDue diligence in progress

Voice is available on request while we complete provider due diligence.

Accessibility & dependencies

Test access structurally. Review every runtime dependency.

Accessibility is treated as an ongoing engineering requirement. The website targets WCAG 2.2 AA and is checked with structural tests, keyboard review, reflow checks and manual review; automated results alone are not a conformance claim.

The initial public website uses self-hosted fonts, styles and assets. Any approved form handler or other future runtime service must be added to the integration inventory and reviewed for privacy, security, accessibility and performance before release.

What we do not claim

We will not imply a certification we do not hold.

No ISO 27001, SOC 2 or Cyber Essentials certification is asserted. The controls described on this page are intended to be specific and reviewable, and unresolved supplier or assurance details remain visibly marked rather than presented as complete.

Due diligence

Request the DPA and full sub-processor register.

Tell us which practice area and stakeholders are reviewing Absolute Connect. We will prepare the current documents for your discussion.

Book a demo