B4hours

Security and data handling

Your calls and data, handled like they matter.

You are trusting us with your customers' phone calls, your tenants' details, and the records your business runs on. Here is exactly how we treat them.

Encrypted in transit and at rest

Calls, recordings, transcripts and messages are encrypted in transit (TLS) and stored encrypted at rest by our hosting providers.

Locked-down access

Only the B4hours people working on your account can see your data, and every account they use is protected with multi-factor sign-in.

Callers are told

The AI introduces itself and lets callers know the call is recorded before it collects anything.

Your data, your call

You own it. We export it or delete it on request, and we never sell it or use it to market to anyone.

Every AI receptionist greeting tells the caller they are speaking with an automated assistant and that the call is recorded. That notice is how consent works for businesses under Canada's privacy law (PIPEDA): the caller knows before they share details, and can ask for a person or hang up.

Recordings and transcripts are used for one thing: running your service. They let you review every call, and let us fix the script when something goes wrong.

You decide how long recordings are kept. Tell us a retention period and we will set it, or ask us to delete specific calls at any time.

Where your data lives

B4hours runs on established cloud providers for hosting, telephony, email and AI processing. Some of them process data in the United States as well as Canada.

Before we build anything, we tell you which providers will touch your data and what each one does. If you have a data-residency requirement, raise it on the first call and we will tell you honestly whether we can meet it.

Because we connect to the tools you already run, most records stay in your own systems (your job software, calendar, accounting or property management platform). We do not copy your whole database into ours.

How we use AI

The AI models we use process your calls and messages to do the job in front of them: answer, classify, write the report. We use them under business terms where your data is not used to train the provider's models.

The AI only does what you have approved. It does not quote prices you have not given it, and anything it is unsure about goes to a person.

For anything that leaves the building, like a client report or an invoice, you choose whether a person approves it first.

Access and accounts

Access to your data is limited to the B4hours team members working on your account, and only for as long as they need it.

We connect to your software with the narrowest permissions it allows, using dedicated integration access rather than your personal login wherever the tool supports it.

When someone leaves your team or ours, their access is removed.

If something goes wrong

If we become aware of a breach that affects your data, we tell you promptly, normally within 72 hours of confirming it, with what happened, what was affected, and what we are doing about it.

Where a breach creates a real risk of significant harm, PIPEDA requires reporting to the Office of the Privacy Commissioner of Canada and notifying the people affected. We help you do that and keep the required records.

When you leave

Your phone number, your recordings and your data are yours. On cancellation we give you an export of what we hold, then delete it within 30 days unless you ask us to keep it longer or the law requires otherwise.

Security questionnaire or vendor review?

Property managers and larger operators often need one filled out. Send it to [email protected] and we will complete it before you sign anything.

Talk to us about your requirements

Questions about your data?

Ask on the demo call. We will walk through exactly which providers touch your calls and records, and what happens to them.

30-day money-back guarantee · Live in one week · Toronto & GTA · How we handle your data

Call the AIBook a Demo