Compliance is not a feature. It is the foundation.
This page documents APIP's data handling practices, DNC/TCPA compliance process, retention policy, and subprocessor list. If you have questions not answered here, contact us directly.
- 01Number acquired · source + date stampedPASS
- 02TCPA cell classification (carrier lookup)PASS
- 03National DNC Registry (FTC)PASS
- 04State DNC (FL, TX, CA, NY)SUPPRESS
- 05Litigator-flag databasePASS
- 0614-day re-screen scheduledPASS
- 07Audit log writtenPASS
How APIP handles personal and property data.
Encryption at rest
All data is encrypted at rest using AES-256. Encryption keys are managed by AWS KMS with automatic rotation.
Encryption in transit
All data in transit is encrypted using TLS 1.3. No plaintext transmission of personal data is permitted.
Access controls
Role-based access control (RBAC) limits data access to authorized personnel. All access events are logged.
Data minimization
APIP collects only the data necessary to fulfill the stated purpose. Unnecessary personal data is not retained.
Retention limits
Personal data is retained for no longer than 24 months from last active use. Deletion is automated and logged.
No sale of personal data
APIP does not sell personal data to third parties. Data is used only for the purposes described in the Privacy Policy.
Seven steps from number to compliant call sheet.
APIP's DNC/TCPA compliance process is documented, auditable, and automated. No number reaches a call sheet without completing all seven steps.
- National DNC Registry (FTC)
- State DNC lists, all active states
- Litigator flag database
- TCPA cell classification
- 14-day automated re-screen
- Full audit log on request
- 01
Number acquisition
Phone numbers are sourced from entity filings, registered agent records, and Tier 1 enrichment providers. Source and acquisition date are stamped on every number.
- 02
TCPA cell classification
Every number is classified as landline or mobile using carrier lookup. Mobile numbers are flagged for TCPA consent requirements before delivery.
- 03
National DNC screen
All numbers are screened against the FTC National DNC Registry. Registered numbers are suppressed from the call sheet and flagged in the record.
- 04
State DNC screen
Numbers are screened against state DNC lists for FL, TX, CA, NY, and all other states with active registries. State suppression is applied independently.
- 05
Litigator flag screen
Numbers are screened against known TCPA litigator databases. Flagged numbers are suppressed and logged with the litigator database source and match date.
- 06
14-day re-screen
All active numbers are re-screened on a 14-day cycle. New DNC registrations, litigator additions, and classification changes are applied automatically.
- 07
Audit log
Every screen event is logged with timestamp, registry version, result, and suppression action. Full audit logs are available to operators on request.
Data retained only as long as legally required.
Retention periods are set by data category, legal basis, and operational necessity. Automated deletion runs on schedule. Manual review is required only for billing records subject to statutory retention.
| Data category | Retention | Legal basis | Deletion |
|---|---|---|---|
| Property records (non-personal) | Indefinite | Legitimate interest | On account closure |
| Owner entity data | 24 months | Legitimate interest | Automated at 24m |
| Contact data (phone, email) | 24 months | Legitimate interest | Automated at 24m |
| DNC screen logs | 36 months | Legal obligation | Automated at 36m |
| CRM outcome feedback | 36 months | Legitimate interest | Automated at 36m |
| Access logs | 12 months | Security | Automated at 12m |
| Billing records | 7 years | Legal obligation | Manual review |
Every third party that touches APIP data, documented.
APIP maintains data processing agreements (DPAs) with all subprocessors that handle personal data. This list is updated when subprocessors are added or removed.
| Subprocessor | Purpose | Location | DPA |
|---|---|---|---|
| Amazon Web Services | Infrastructure, storage, compute | US-East-1 | SIGNED |
| FTC DNC Registry | National DNC compliance screen | United States | N/A |
| Enrichment Provider T1 | Phone, email, contact enrichment | United States | SIGNED |
| Enrichment Provider T2 | Extended contact enrichment | United States | SIGNED |
| GoHighLevel | CRM delivery integration | United States | SIGNED |
| Stripe, Inc. | Payment processing | United States | SIGNED |
Questions, corrections, and data requests.
For data subject requests, compliance questions, DPA inquiries, or subprocessor updates, contact our compliance team directly. We respond within 2 business days.
support@nuro.is →