Enterprise Security & Governance

Data Privacy & Security Policy

Revision 4.2 • Enterprise Voice Infrastructure Standards

01. Data Collection & Purpose Limitation

PrimeIntake collects only operational customer data required to execute conversational voice reception, qualification, and appointment scheduling on behalf of our enterprise clients.

Customer contact information, call recordings, conversation transcripts, and CRM metadata are processed strictly to fulfill business logic defined by the client organization.

02. Encryption & Audio Stream Security

Voice streams and customer records are encrypted in transit using TLS 1.3 and at rest utilizing AES-256 bit encryption. Ephemeral voice data is processed in real time to perform qualification and CRM extraction without unencrypted intermediary caching.

03. SOC2 Type II Certified Infrastructure

PrimeIntake infrastructure undergoes regular third-party independent audits for SOC2 Type II compliance, verifying our organizational controls for security, availability, processing integrity, and confidentiality.

04. CRM & Calendar Integration Authorization

Direct bilateral integrations with Salesforce, HubSpot, Clio, ServiceTitan, and Google Calendar utilize credentialed, scoped OAuth2 / API access tokens. PrimeIntake accesses only the calendar slots, objects, and records required to fulfill scheduling requests.

Security & Compliance Office

To request our SOC2 Type II compliance report or custom enterprise security review:

security@primeintake.com