Telephony data retention & tenant-initiated deletion

Twilio non-marketing lines (US/CA) — Zango Portal

Effective date: May 14, 2026Draft — counsel sign-off pending

This page summarizes how Gozango ("Zango") retains and deletes telephony data processed through Zango Portal when your business uses Twilio-backed non-marketing numbers (for example business_direct, personal_direct, and operational extra where enabled). It is designed to support tenant compliance programs and privacy expectations, including references to the GDPR and CCPA. It does not replace legal advice to your business.

Related documents

  • Engineering ADR for always-on recording: GOZ-945 — ADR A.5 (recording policy + consent) — see docs/adr/twilio-recording-policy.md in this repository for the canonical text.
  • Markdown copy of this policy (for legal review): repository path docs/legal/telephony-data-retention-and-deletion.md

1. Scope

Applies to call recordings, voicemail audio, transcripts stored in Zango that describe those calls or voicemails, and SMS/MMS message bodies (plus delivery metadata we surface in the CRM timeline) for the Twilio non-marketing product surface. Marketing numbers that remain on CTM (CallTrackingMetrics) are out of scope for this policy.

2. Default retention

Retention is measured from completion of the underlying communication (call, voicemail capture, or message delivery) unless a shorter period applies because you successfully requested deletion or a legal hold freezes processing.

CategoryDefault retention
Call recordings (Twilio + CRM references)18 months
Voicemail audio18 months
Transcripts derived from those recordings/voicemail18 months from transcript generation
SMS/MMS bodies & surfaced metadata24 months

Carriers and Twilio may retain data under their own policies; this table governs primary Zango-visible copies and purge targets for Phase 9 automation (GOZ-980 — PR 19 cutover infra).

3. Tenant-initiated deletion (authentication & scope)

  • Who may request deletion: authenticated tenant administrators (primary owner today; expanded roles once shipped behind the Phase 9 control plane). Verification may include MFA challenges, proof of billing entitlement, or in-bound contact using numbers on file.
  • Scope: defaults to removing telephony payloads in §2 for the requesting business tenant. Narrower scopes (date ranges or contact subsets) are supported where the deletion API/UI exposes them.
  • Operational targets: acknowledgement within ~5 business days after verification opens; purge within ~30 calendar days absent legal hold or subprocessor incident.
  • Preserves: finance/billing artifacts required by law, security telemetry summarized as non-content signals, and data subject to lawful preservation notices.
  • Channel:until self-serve deletion ships, submit through the in-product Support Center and reference "telephony data deletion". Engineering tracks execution under the Phase 9 audit log workstream.

4. Audit trail

Authorized deletion flows emit structured audit entries capturing who requested the action, the scope identifiers (including ticket correlation), timestamps in UTC, and success or failure codes suitable for SOC (Service Organization Control) style review. Operators see minimized fields where feasible to reduce re-identification risk.

5. GDPR/CCPA-aligned consumer inquiries

Your business acts as controller for conversations with consumers; Zango processes telephony payloads as directed by your account. Consumers should contact your privacy team first. When a consumer contacts Zango directly, we coordinate with your authorized administrators unless applicable law requires an immediate substantive response without your involvement.

6. Changes & sign-off

This page will be finalized when counsel signs off alongside Workstream F (Terms of Service update). Extending retention beyond the durations above or materially changing deletion obligations will be communicated ahead of the new effective date.

Support Center · Terms of Service