Security & trust

Your agency's data stays inside your agency.

Polca is built around enforced tenant boundaries, scoped access, data portability, and calling controls that support the compliance program your agency operates.

Operational controls

The protections behind the product.

Plain-language details about how Polca separates agency data, handles records, and enforces calling workflows.

01

Agency isolation

Every authenticated request resolves the user and agency before accessing tenant data. Enforced row-level boundaries prevent one agency from reading another agency's records.

02

Scoped users and roles

Seats and administrative capabilities belong to a specific agency environment. Account access can be revoked without waiting for a long-lived remembered session to expire.

03

Data ownership and export

Your contacts, scripts, recordings, summaries, and presentation history remain your agency's data. Export and offboarding expectations are documented in the Privacy Policy and Terms.

04

Defined retention

Call recordings are retained for approximately 90 days unless an Order Form or legal hold requires otherwise. Production deletion and backup aging are described in the Privacy Policy.

05

Consent and suppression controls

DNC and opt-out controls apply across AI and human dialing. The agency remains responsible for the lawful basis and consent attached to the leads it chooses to contact.

06

Calling identity and traceability

Calls travel through an authorized carrier network with attestation, while recordings, dispositions, and follow-up outcomes preserve an operational history for the agency.

Tenant boundary

Identity first. Agency context second. Data access last.

Authenticated userSession rechecked
Agency contextTenant resolved
Enforced data boundaryAgency rows only
Policies and agreements

Read the source documents.

The operational overview above does not replace the governing agreements. These documents define responsibilities, retention, acceptable use, and data processing.

Privacy PolicyData categories, retention, exports, deletion, and visitor rights.Read Privacy →
Data Processing AddendumController and processor responsibilities for agency personal data.Read DPA →
Calling & AI VoiceCalling roles, consent responsibilities, suppression, and voice workflows.Read Calling terms →
Acceptable UseProhibited conduct, lead requirements, investigations, and enforcement.Read AUP →
Terms of ServiceThe agreement governing access to and use of the platform.Read Terms →

This page is an operational overview, not a certification or legal opinion. Questions about a specific agency deployment can be addressed during onboarding or by emailing security@polca.ai.