- What data do you need?
- For a pilot, 500 closed cases: the complaint or call text, its date, and the decision your team made. We don't need patient or consumer names, account numbers or contact details. Remove them before export where you can.
- How do we send it?
- Through an encrypted upload link we issue per customer. Never by email attachment.
- Where is it processed?
- In our own Cloudflare account. Files are stored in U.S. data centers, and the models run on Cloudflare Workers AI under our account, not through an outside AI company's API. Cloudflare does not use customer content to train its models.
- Who can see it?
- Only Plumb staff working on your account, named on request. Access requires multi-factor authentication and is logged.
- How is it protected?
- Encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Each customer's data sits in its own storage, separate from other customers'.
- Do you train on our data?
- Only to tune the model that serves you. Your cases and corrections never train another customer's model, and we don't pool data across customers without your written consent.
- How long do you keep it?
- Pilot data is deleted within 30 days after the pilot ends, unless you become a customer. Backups expire within 35 days. We confirm deletion in writing on request, and you can ask us to delete everything at any time.
- What about health data?
- Device complaints can include health information. Device makers are usually not HIPAA covered entities, but we sign a business associate agreement on request and treat all complaint text as sensitive either way.
- What about consumer financial data?
- Collection calls and complaints include consumer financial information. We act as your service provider, use it only to deliver the service, and contract to the safeguards the Gramm-Leach-Bliley Act and the FTC Safeguards Rule expect of service providers.
- Call recordings?
- We prefer transcripts. If you send audio, we transcribe it with an open-source speech-to-text model running on Workers AI under our account.
- What if something goes wrong?
- We notify you within 72 hours of confirming an incident that affects your data, with what happened, what data was involved and what we're doing about it.
- Who else touches the data?
- Customer data: only Cloudflare, our infrastructure provider. We list every subprocessor and give 30 days' notice before adding one.
- Certifications?
- We don't hold SOC 2 or ISO 27001 yet. We'll complete your security questionnaire and walk your security team through this setup.
- What does Plumb decide?
- Nothing on its own. Plumb scores cases and routes them by thresholds you set. Your team makes and owns every regulatory determination and filing.