How do answering services protect my business information?
A service holds your prices, rules, calendar and client names, not only caller data. Who can read them, what is logged, and what you get back if you leave.
By Prashant Chandra, founder of BotsDontSleep.ai — 24/7 AI receptionist for Canadian businesses.
No phone needed — call directly from your browser. 5-minute demo.
Four mechanisms, and you should be able to get all four in writing. An answering service holds more of your business than owners expect: your price list, your service rules, your calendar, your client names, and a recording of every call that discussed any of them. At BotsDontSleep.ai that material is encrypted in transit and at rest, access is scoped to your team by role, access is logged, and the retention window is yours to set. The service answers 24/7 at $0.60 CAD per answered minute with $0 setup. The harder question is not encryption, which every serious provider has. It is how many people on the provider's side can read your prices, and what you get back on the day you cancel.
What business information does an answering service actually hold?
Two categories, and the one owners worry about is the smaller of the two.
The first is caller information: the number, the name, the reason for calling, the recording and the transcript. That is the category most security pages are written about, and we cover it separately in whether an AI phone system is secure for customer data.
The second is your own commercial information, which is the subject here. To answer a call properly, a service has to be told your prices and discount rules, which services you will and will not take, your hours and closures, who is on call and on which nights, your intake questions, your escalation thresholds, and the names of the staff a caller might ask for. Add the calendar it books into and the lead list it builds, and a provider ends up holding a fair description of how your business makes money. A broker's line is the worked example: within a month it holds the quote questions, the carriers you place with and a list of renewal dates, which is most of what sits behind an AI receptionist for insurance brokers.
That second category never appears in a privacy policy, because it is not personal information. It is commercial information, and nobody is obliged to tell you how it is handled unless you ask.
Who at the provider can see your prices, clients and calendar?
This is the question that separates providers, and the answer depends almost entirely on whether people answer your calls.
A staffed answering service works from a script on a screen. Whoever is on shift sees your greeting, your rules, your prices and the caller's details for as long as the call lasts, and the roster changes week to week. That is not carelessness, it is how shift work operates: dozens of agents may read your script over a year, and you will never know their names. PATLive and services like it publish minute plans rather than staffing details, which is part of why our comparison with PATLive looks at the staffing model and not only the rate.
A virtual receptionist narrows that to a named handful trained on your account, which is one of the reasons the model costs more. The exposure is smaller and more accountable, and turnover still moves it. Professional firms care about this more than trades do, which shows up in questions about a virtual receptionist in Ottawa, where callers routinely name a file before they name themselves.
An AI service removes the shift. Your configuration is data in a system rather than a script read by whoever is working, and the people who can open it are the ones operating and tuning your agent, under role-scoped access and audit logging. The exposure does not vanish. It gets small enough to list and to log.
How is your information protected in practice?
Four mechanisms do the work, and each is a question you can ask directly.
Encryption in transit and at rest covers the data while it moves and while it sits in storage. Role-scoped access means your staff see your calls and your configuration and nothing belonging to another business, in either direction. Access logging means there is a record of who opened what, which matters because most data problems are internal rather than dramatic. And your call content is never used to train models for other clients, which is the one worth getting in writing, because a hedge there usually means yes.
Our privacy policy sets out the caller side of this in plain language. For the commercial side, ask for it in the service terms, since it will not be in a privacy policy at all.
What happens to your business information if you cancel?
You should be able to leave with your lead list, your recordings and your transcripts, and you should establish that before you sign rather than on the day you give notice.
This is the least-asked question in the category and the one with the most money attached. A year of answered calls is a database: every enquiry that came in, what each caller wanted, which ones booked and which did not. If a provider exports it as a PDF of call summaries rather than a file you can load into a spreadsheet, cancelling costs you the asset as well as the service.
Three specifics are worth settling in writing. What format the export comes in, and whether it includes transcripts or only message fields. How long you have to request it after the account closes. And whether anything is deleted on cancellation rather than held, because "we delete everything when you leave" sounds reassuring and means your records go with them.
At BotsDontSleep.ai there is no contract and no monthly minimum, which makes leaving easy and makes this question more important rather than less. An arrangement you can exit next month is only genuinely low-commitment if what you built up comes with you.
Who can change where your calls go?
Your carrier controls the forwarding, and that account is the one worth locking down.
An answering service receives whatever your number forwards to it. Changing that forwarding is a carrier-side action on your own telecom account, so the security that matters is the PIN or passphrase on that account rather than anything the service holds. Set it, and record who at your business is authorized to change it.
On the provider side, establish who may ask for changes to your agent or script. A single named person for price and routing changes suits most businesses under ten staff. The failure mode is dull: a well-meaning staff member calls, asks for a rule to be changed, and the change is made because the request sounded reasonable. That is worth a line in the setup notes, and it is the detail a consultancy with a tightly held client roster raises first, which is why it sits in the checklist behind our AI receptionist for consulting firms.
How do the options compare on business-information risk?
| Option | Who sees your prices and rules | Turnover exposure | Access log | Your data on cancellation |
|---|---|---|---|---|
| Voicemail | Nobody | None | No | The messages on the handset, if any |
| In-house receptionist | One person, who also remembers it | Leaves with them, including the knowledge | No | Stays in your office, in their format |
| Live answering service | Whoever is on shift, from a script | Shift roster, changing weekly | Rarely offered | Export set by the provider's plan |
| Virtual receptionist | A named, trained handful | Account team changes | Sometimes | Export set by the provider's plan |
| AI receptionist | Your team, plus the people tuning your agent | Not a shift model | Yes, scoped by role | Recordings, transcripts and lead data on request |
The row that catches people out is the second one. An in-house receptionist is the lowest-exposure option on paper and the worst on continuity, because the prices, the quirks and the regulars live in one head and leave with it.
What an answering service cannot protect you from
Four things, and no provider should tell you otherwise.
No system is impossible to breach. What you are buying is a set of controls that make a breach unlikely and a mistake recoverable. A provider claiming more than that is describing marketing rather than engineering.
Your information passes through third parties. Telephony, speech-to-text, a model provider and hosting are separate services under confidentiality obligations, and your configuration and your callers' words cross all of them. If your requirement is a signed agreement naming every subprocessor, a specific data residency, or an audit right, ask before you buy. Those are reasonable requirements and we would rather say early that we are the wrong fit.
We make no compliance certification claim. We can describe what the product does — encryption in both places, role-scoped access, audit logging, redaction options, a retention window you set, no training on your calls. Whether that satisfies the obligations that apply to your business is a question for your own legal or privacy advisor, with our terms and privacy policy in front of them. Disclosure and consent rules for recording differ by province and by call type, and the obligation to tell callers sits with you rather than with us.
And the largest exposure in most small businesses is not the vendor. It is the shared inbox every member of staff can read, the spreadsheet of client numbers on a laptop with no password, and the call notes in a notebook that goes home in a coat pocket. Handing the phone to a service with scoped access and an audit log often tightens things rather than loosening them, which is an uncomfortable finding and a common one.
What should you get in writing before you forward your line?
Six items. Any provider worth buying from will put all six in an email, and the ones that stall on the last two have answered the question.
- Who can read your configuration. Ask how many people on their side can open your prices, rules and scripts, and whether that access is logged. A number and a yes, or a change of subject.
- Whether your calls train anything. You want a flat no on training models that serve other clients, stated plainly rather than hedged.
- The retention window, and who sets it. Ask whether it is a setting on your account or a fixed company policy, and ask for the deletion path for a single record before you need it.
- The export, in detail. File format, whether transcripts are included, and how long after cancellation you can still ask. A promise to "provide your data" is not an answer.
- Who may request changes. Name the people at your business allowed to change prices, routing and on-call rules, and have the provider confirm they will not act on anyone else.
- The subprocessor list. Categories at minimum: telephony, speech-to-text, model provider, hosting. A provider that will not describe its own supply chain cannot tell you where your information is.
Does protecting your information cost extra?
No. There is one rate and the controls are inside it.
BotsDontSleep.ai charges $0 setup and $0.60 CAD per answered minute, billed by the second, with no contract, no monthly minimum, and no security tier to upgrade into. A business at 300 answered minutes a month pays about $180. A twenty-second wrong number costs about 20 cents rather than a full call charge. Encryption, scoped access, audit logging, a retention window you set and an export on request are not line items, and a product that prices them separately has told you what it thinks they are worth.
Testing any of it takes one phone call. Maryann, our demo agent, answers at 437-494-9110 at any hour, in any of 90+ languages. Ask her something invented and specific, then email support@botsdontsleep.ai for the transcript. Whether a provider can produce a call on request is the exercise.
Frequently asked questions
- How do answering services protect my business information?
- Four mechanisms, and you should be able to get all four in writing: encryption in transit and at rest, access scoped to your team by role, access logging so there is a record of who opened what, and a retention window you set rather than one the provider fixes. With BotsDontSleep.ai your call content is also never used to train models for other clients. Encryption is the part every serious provider has; the questions that separate them are how many people on their side can read your prices and what you get back when you cancel.
- What business information does an answering service hold?
- Two categories. Caller information — the number, the name, the reason for calling, the recording and the transcript. And your own commercial information: your prices and discount rules, which services you take, your hours and closures, your on-call rota, your intake questions, escalation thresholds, staff names, the calendar it books into and the lead list it builds. The second category is not personal information, so it does not appear in a privacy policy and nobody has to tell you how it is handled unless you ask.
- Who at an answering service can see my prices and scripts?
- It depends on whether people answer your calls. A staffed service shows your script and prices to whoever is on shift, and the roster changes weekly, so dozens of agents may read it over a year. A virtual receptionist narrows that to a named, trained handful. An AI service holds your configuration as data rather than a script read by whoever is working, so access is limited to the people operating and tuning your agent, scoped by role and logged.
- Can I get my call recordings and lead list back if I cancel?
- With BotsDontSleep.ai, yes — recordings, transcripts and lead data are available on request. Settle this with any provider before you sign rather than on the day you give notice, because a year of answered calls is a database of every enquiry, what each caller wanted and which ones booked. Ask what format the export comes in and whether it includes transcripts or only message fields; a PDF of call summaries is not an export you can use.
- Is my call data deleted when I close my account?
- Ask, because the answer cuts both ways. A provider that deletes everything on cancellation sounds careful and means your records leave with the account. Our position is that recordings, transcripts and lead data are held while the account is active or as long as legal, tax or dispute-resolution obligations require, and specific records can be deleted on request at any time by emailing support@botsdontsleep.ai.
- Can an answering service change where my calls are forwarded?
- No. Forwarding is controlled on your own telecom account with your carrier, so the service receives whatever your number sends it and cannot redirect your line. That makes the PIN or passphrase on your carrier account the security worth tightening, and it is worth recording who at your business is authorized to change it.
- Who at my own business should be allowed to change the call rules?
- Name one person for price, routing and on-call changes if you have fewer than ten staff, and have the provider confirm in writing that it will not act on requests from anyone else. The failure mode is ordinary rather than dramatic: a well-meaning staff member phones, asks for a rule to be changed, and the change is made because the request sounded reasonable.
- Do answering service staff change often?
- At a staffed call centre, yes — shift rosters turn over, which is how shift work operates rather than a sign of carelessness. Virtual receptionist providers assign a smaller named team, and turnover still moves it. An AI service has no shift roster, so the set of people who can open your configuration is small enough to list and to log.
- Is an AI answering service safer than a staffed one for confidential information?
- On exposure to your commercial information, usually, because there is no shift roster reading your script and access can be scoped and logged. On judgment during a difficult call, a trained human is still better. If your rule is a human voice on every call, a staffed service is the honest recommendation even at several times the per-minute rate.
- What should I get in writing from an answering service before signing?
- Six items: who on their side can read your configuration and whether that access is logged; whether your calls train models serving other clients; the retention window and who sets it; the export format and the deadline for requesting it after cancellation; who at your business may request changes; and the subprocessor categories — telephony, speech-to-text, model provider, hosting. Any provider worth buying from puts all six in an email.
- Does an answering service hold anything a privacy policy does not cover?
- Yes, and it is the larger half. A privacy policy covers personal information about callers. Your prices, discount rules, service exclusions, on-call rota, escalation thresholds and client names are commercial information, which sits in the service terms if it is addressed anywhere. Ask for that part specifically rather than assuming the privacy policy speaks to it.
- Is BotsDontSleep.ai certified compliant with privacy regulations?
- We make no compliance certification claim. What we can describe is what the product does: encryption in transit and at rest, role-scoped access, audit logging, redaction options, a retention window you set, and no training on your calls. Whether that meets the obligations that apply to your business is a question for your own legal or privacy advisor, and disclosure rules for recording calls differ by province, with the obligation to tell callers sitting with you.
- Does protecting my business information cost extra?
- No. BotsDontSleep.ai charges $0 setup and $0.60 CAD per answered minute, billed by the second, with no contract, no monthly minimum and no security tier to upgrade into. A business at 300 answered minutes a month pays about $180. Encryption, scoped access, audit logging, a retention window you set and an export on request are included rather than priced separately.
Last reviewed: October 2026. Pricing and capability details verified against our current service.