Skip to main content

Security and Data Protection

Last reviewed: August 8, 2026

This page is for the person doing vendor review. It covers what our agents can and cannot reach, the services we rely on, where data sits, how we control access, what happens if something goes wrong, and which certifications we do not hold. If you need a document rather than a web page, we will complete your security questionnaire or sign a data processing agreement.

What we do not hold

We would rather you learn this on the first page than in week six of procurement. Call Force Global does not hold:

  • A SOC 2 Type I or Type II report.
  • An ISO 27001 certificate, or any other ISO certification.
  • A PCI DSS attestation of compliance.
  • A HIPAA certification. No such certification exists for any company, from any body. Anyone who shows you one is showing you a training certificate or a vendor logo.

What we do have is written controls, a Business Associate Agreement signed with a healthcare client on July 30, 2026, and a willingness to answer any question in writing and put the answer in the contract. If your procurement process requires an audited report today, we are not the right vendor yet, and we will say so on the first call.

What our agents touch, and what they do not

For regulated work, Call Force Global operates as a fronter. Our agents capture information, answer status questions, qualify, schedule and follow up. They do not hold professional licences, and they do not perform licensed work such as quoting, binding, adjusting claims, or giving regulated advice. Any call that moves toward licensable territory is warm transferred to your licensed staff, who keep the regulatory accountability. Our compliance page covers the operational side of that boundary in more detail.

  • Agents work in your systems. Your CRM, agency management system, helpdesk, dialer and telephony stay yours, under logins your administrator issues and can revoke at any time.
  • We do not ask for database exports. Our standard model is access to your system, not a copy of your customer data sitting on our side.
  • Card data. Where a program includes taking a payment, that happens inside your own payment tool. Call Force Global does not store card numbers, and because we hold no PCI attestation, card entry belongs in systems you control.
  • Access is scoped to the campaign. Agents and supervisors see the program they are assigned to, and not other clients' programs.

Subprocessors

These are the services behind callforce.global and our own internal operations. Tools chosen by you for your program, such as your CRM or dialer, are not on this list because they are your subprocessors, not ours.

  • Vercel Inc. (United States): hosting and content delivery for this website.
  • Hetzner Online GmbH (Germany): the cloud server that runs our internal automation and applications.
  • Supabase Inc. (United States): database storage and authentication for applications, bookings and staff accounts.
  • Google LLC (United States): Google Analytics 4, website traffic analytics.
  • Microsoft Corporation (United States): Microsoft Clarity, heatmaps and session replay of on-page activity. Clarity masks text typed into form fields by default.
  • Cloudflare, Inc. (United States): Turnstile, the anti-spam check on our forms.
  • Cal.com, Inc. (United States): meeting scheduling.
  • Resend, Inc. (United States): delivery of transactional email such as confirmations and replies.
  • Stripe, Inc. (United States): client payment processing. Card details go directly to Stripe and are never stored on our systems.

Fonts are served from our own servers, so no font provider receives a visitor's IP address. We do not run advertising pixels or social media trackers on this site.

Where data lives and how it crosses borders

Call Force Global Inc. is a Canadian company headquartered in Toronto. The services above store and process data in Canada, the United States and the European Union. Delivery teams work from the Caribbean and Latin America, connecting to client systems rather than holding local copies of client data.

When information crosses a border it stays subject to our Privacy Policy and to the contractual commitments we hold with each provider, and it may also be subject to lawful access requests in those countries. We will name the processing locations relevant to your program in writing before you sign.

Encryption and the website itself

  • In transit: every page and form on callforce.global is served over HTTPS with TLS. The site sends an HTTP Strict Transport Security header, so browsers refuse to fall back to an unencrypted connection.
  • Browser hardening: every response carries a content security policy that restricts which scripts and frames can load, plus X-Content-Type-Options, X-Frame-Options and a strict referrer policy.
  • At rest: application data, bookings and staff accounts live in Supabase, with row level security policies limiting what an anonymous or authenticated client can read and write.
  • Secrets: API keys and service credentials are held in server-side environment configuration, never in the pages this site serves.

People, access and offboarding

  • Confidentiality agreements: every contractor signs an agreement that makes client data, customer information, call recordings, scripts, internal processes and proprietary systems strictly confidential, and that obligation continues after the engagement ends.
  • Least privilege: dashboard and system access is granted by role and by campaign assignment. People get the access their job needs and nothing beyond it.
  • Screening: what we can screen for varies by country and by program. We do not publish a blanket background check claim because it would not be true in every market we hire in. Ask before you sign and we will confirm in writing exactly what we run for your program.
  • Offboarding: when someone leaves, their access is removed and their staff account data is deleted within 90 days of separation, which is the retention line published in our Privacy Policy.
  • Access reviews: we review system access and permissions on a regular basis so that accounts do not outlive the reason they were created.

Call recording, transcripts and AI quality assurance

Where a program records calls, the caller is told at the start of the call and may ask that recording stop, as set out in our Terms of Service. Recordings are transcribed and scored against the program's quality and compliance rubric, and the results appear in the client portal.

  • Who can see them: the Call Force Global quality and operations staff assigned to that program, your own supervisors through the client portal, and the agent whose call it was, for coaching.
  • Automated scoring is not an automated decision about a person: scores flag calls for human review, and a person makes the call on coaching, escalation or removal from a campaign.
  • Storage and retention: where the recording lives and how long it is kept are set per program in the service agreement. Where your own telephony does the recording, the recording stays in your system and we work from your access.
  • Job applicants: voice recordings submitted with an application are transcribed and analysed with automated tools, a person reviews the results, and no hiring decision is made by software alone. Applicants can ask for a manual review instead.

HIPAA-adjacent work and BAAs

We run HIPAA-aware workflows for healthcare programs, and a Business Associate Agreement is available on request for qualifying engagements. We execute the BAA before any protected health information is handled, and the BAA defines the scope of what agents may access.

To be precise about the language: our workflows are designed to be HIPAA-aligned, our agents receive PHI handling training, and we sign BAAs. None of that is a certification, and we will never describe it as one.

Incident response and breach notification

If we become aware of a security incident affecting client or consumer data, we investigate immediately, contain what we can, and contact the affected client without undue delay and in any case within 72 hours of confirming the incident. That first message will tell you what we know at that point, including what we do not yet know, and we follow up as the picture becomes clearer rather than waiting for a complete story.

For personal information belonging to website visitors, applicants and staff, our commitment is the one in our Privacy Policy: we will notify you if a breach occurs that affects your data. As a Canadian company we handle personal information in line with the Personal Information Protection and Electronic Documents Act, which includes its breach reporting obligations.

No system is perfectly secure. We would rather describe the process we follow when something goes wrong than claim nothing ever will.

Request a DPA or a security review

Email info@callforce.global with the subject line "security review" and tell us what you need. We respond within 5 business days.

  • Security questionnaires: send yours and we will complete it. Where the honest answer is "we do not do that", that is the answer you will get.
  • Data processing agreement: we will sign your DPA or provide ours.
  • Business Associate Agreement: available for qualifying healthcare engagements.
  • Non-disclosure agreement: we sign these routinely, before scoping calls if you prefer.
  • By phone: 1 (844) 287-9234. By mail: Call Force Global Inc., 375 University Avenue, Suite 3268, Toronto, ON M5G 2J5, Canada.

Last reviewed

This page was last reviewed on August 8, 2026 by Miki Furman, Founder and CEO. It describes our practice as of that date. If something here stops being true, we update the page rather than letting it age quietly.

See also our Compliance and Security overview, Privacy Policy, Terms of Service, and Accessibility Statement.