Your firm
Data controller
The firm determines why and how its client personal data is used, including campaign purpose, audience and lawful basis.
Security and data protection
This page describes how Absolute Connect handles customer data today. It separates the controls in place from work that is still in progress, so your legal, compliance and technology teams can review the position accurately.
Your firm
The firm determines why and how its client personal data is used, including campaign purpose, audience and lawful basis.
Absolute Tech Solutions
We process customer data on the firm’s documented instructions to provide Absolute Connect.
Residency & encryption
The database and queue operate in UK/EU regions, and the messaging carrier processes in the EU. Data is encrypted in transit throughout. Message bodies, voice transcripts, conversation summaries and uploaded CSVs receive field-level AES-256-GCM encryption.
Consent, opt-out & rights
The firm remains responsible for its lawful basis, client notices and instructions. Absolute Connect makes consent changes traceable and builds the operational response into the product.
Retention & audit
Retention is off until the firm switches it on, because the schedule must come from the firm’s own regulatory obligations rather than the platform’s guess.
Support access & logs
Customer access is role-based. A support session is strictly read-only, requires a stated reason and is audited before it begins.
Sub-processors
Every sub-processor is registered with its role, region and DPA state. Each firm can read the same live register inside its workspace at Settings → Privacy. Detailed supplier names, regions and DPA states are withheld from the public website and can be supplied during due diligence.
Voice is available on request while we complete provider due diligence.
Accessibility & dependencies
Accessibility is treated as an ongoing engineering requirement. The website targets WCAG 2.2 AA and is checked with structural tests, keyboard review, reflow checks and manual review; automated results alone are not a conformance claim.
The public website uses self-hosted fonts, styles and assets. The demo form posts only to Absolute Connect’s first-party application endpoint. Any future runtime service must be added to the integration inventory and reviewed for privacy, security, accessibility and performance before release.
What we do not claim
No ISO 27001, SOC 2 or Cyber Essentials certification is asserted. The controls described on this page are intended to be specific and reviewable, and supplier details withheld from public release can be requested during due diligence.
Due diligence
Tell us which practice area and stakeholders are reviewing Absolute Connect. We will prepare the current documents for your discussion.