A law firm in Auckland rang us last year. Mid-size, 40 staff, handling family court matters. They wanted AI voice agents for appointment reminders and intake calls. One condition: "Not a single byte of patient data stays on your servers."
Fair enough. When you're dealing with custody disputes and protection orders, data leaking isn't a PR problem. It's a career-ending liability.
We built them a zero-retention deployment in 3 days. Here's exactly how it works.
Why "Delete It Later" Isn't Good Enough
Most AI voice platforms store everything by default. Call recordings. Transcripts. Caller IDs.
They'll tell you it's "encrypted at rest." Sure. But encrypted data sitting on someone else's server for 90 days is still data on someone else's server.
When the Privacy Commissioner comes asking questions, "we encrypted it" doesn't cut it. You know what satisfies regulators? "We didn't need to keep it."
Retention is risk. Every day data sits in a database, it's a target. A breach waiting for the right vulnerability.

Data flows through, then disappears. No storage, no breach risk.
What a Voice Platform Stores by Default
Before you configure anything, our platform keeps:
For most businesses, that's fine. For regulated industries? A compliance nightmare waiting to happen.
It also stores knowledge base retrievals and dynamic variables. Everything your webhooks pass in gets logged.
The Three-Layer Privacy Architecture We Deploy
Layer 1: Opt-Out of Sensitive Data Storage
We can disable persistent storage entirely. Call recordings, transcriptions, logs, caller IDs, all processed during the call, then wiped within 10 minutes.
Ten minutes. Not 30 days. Not "upon request." Automatically.
That Auckland law firm? Their intake calls process in real time. The AI agent asks screening questions and captures appointment preferences.
Routes urgent matters to the right lawyer. And 10 minutes after the call ends, our voice infrastructure has zero record of it.
Layer 2: PII Redaction for What You Do Keep
Sometimes you need the transcript but not the sensitive details. Our PII redaction automatically detects and strips:
You configure it per agent in the Security & Fallback Settings. Tick the boxes for what you want redacted.
Every transcript replaces "My name is Sarah Thompson, I live at 42 Queen Street" with "[REDACTED]." Your team still gets the conversation context. Nobody gets the personal details.
Layer 3: Webhook-Based Streaming
Here's where it gets clever. We configure webhooks that stream call data directly to your systems during the call. No intermediate storage on our side.
CRM needs the transcript? Pushed there in real time. Case management system needs the call outcome? Webhook fires the moment the call ends.
Recording URLs expire in 10 minutes. If your team needs to review a call, they do it immediately. Or your webhook stores it in your own secure archive.
The result: we process the call. Your systems store what you need. We keep nothing.

Three layers: opt-out, redaction, and webhooks. Your data, your servers.
The Compliance Stack Behind It
Waboom AI is built on voice infrastructure that carries the certifications that actually matter:
Certification is the floor, not the answer. What matters for your risk register is what we actually keep, and for how long. That is the configuration work described above, and it is the part most providers skip.
Where call data crosses a border, we meet cross-border accountability requirements through documented arrangements with our voice infrastructure partner. If you need that written into a procurement pack, ask us and we will walk your compliance team through it.
Where the Data Actually Sits
Be sceptical of any provider who tells you everything stays in your country. Most of them are describing where the database lives and quietly leaving out the voice runtime.
Here is the honest split for a standard Waboom agent. Your transcripts, structured call data, audit logs, contact lists and billing records sit in our Sydney region. The live audio stream, the raw recording file, and the speech and language processing that happen during the call are handled offshore. We store the link to a recording, not the recording itself.
That is why zero retention matters more than geography. If the audio is wiped in ten minutes and the transcript never leaves your systems, the question of which data centre held it for those ten minutes gets a lot smaller.
Who Actually Needs This?
Not everyone does. If you're a real estate agency calling warm leads, our standard setup with encryption in transit and at rest is plenty. Don't over-engineer your compliance posture.
But these industries need the full stack:
Healthcare and Telemedicine. Patient intake, appointment reminders, medication adherence calls. HIPAA requires you to account for every piece of PHI. Zero retention means there's nothing to account for.
A GP practice in Hamilton we work with processes 200 appointment reminder calls daily. Zero data stored on external servers.
Financial Services. Loan application pre-screening, KYC verification calls, account servicing. Your compliance officer wants to know exactly where customer financial data lives. Answer: only on your servers.
Legal Services. Client intake, appointment scheduling, matter triage. Legal privilege means client communications stay protected. An AI agent that stores conversations on a third-party server? That's a privilege waiver waiting to happen.
Enterprise B2B Sales. Calling across NZ, Australia, and Asia-Pacific means juggling the Privacy Act, the Australian Privacy Act, and GDPR. Minimising your data footprint simplifies the whole mess.
Real Numbers From Real Deployments
That Auckland law firm? Here's what changed:
The operational gains surprised even us. You'd expect time savings, but 22 hours per week off manual intake? Zero privacy complaints in 11 months?
The Hamilton GP practice tells a similar story:
These aren't vanity metrics. They're the numbers that let your compliance team sleep at night. For more on how we handle privacy regulations specific to NZ and Australia, we've written a detailed guide.
Webhook Security: The Details That Matter
Pushing data via webhooks only works if the infrastructure is locked down. Here's what we configure for every deployment:
Webhook signature verification, every payload gets cryptographically signed. Your receiving system validates the signature before processing. Spoofed webhooks get rejected.
IP allow-listing, only our known IP ranges can hit your webhook endpoints. Everything else gets blocked at the firewall.
TLS encryption, all webhook payloads travel over HTTPS. No exceptions.
Retry logic with expiry, if your endpoint goes down temporarily, we retry with exponential backoff. After the retry window, the data gets purged. No indefinite queuing.
This matters because the webhook is your data pipeline. If it's not secured, you've moved the vulnerability from our storage to your API endpoint.
We've seen competitors skip this step. Don't be them.
Curious about related attack vectors? Read how we handle prompt injection attacks against AI agents. Most platforms ignore it entirely.
The Bottom Line
Zero retention isn't about paranoia. It's about designing a system where there's nothing to breach. Nothing to subpoena. Nothing to explain to a regulator.
Your customers get the same quality AI voice experience. Your legal team gets a clean audit trail leading to your own systems.
Your compliance officer ticks the box and moves on.
The technology exists today. Our platform supports it natively. We've deployed it across law firms, healthcare providers, and financial services in New Zealand and Australia.
The only question is whether your current platform can say the same.
Ready for zero-retention AI voice agents?
Frequently Asked Questions
What exactly does "zero retention" mean for AI voice calls?
Our voice infrastructure processes your call data in real time: speech recognition, AI responses, knowledge base lookups. But it stores nothing after the call ends.
All recordings, transcripts, and metadata get automatically purged within 10 minutes. Your own systems receive what they need via webhooks during the call.
Can I still access call recordings and transcripts with zero retention enabled?
Yes, but you capture them in real time. We configure webhooks that stream transcripts and recording URLs to your own systems during or immediately after each call.
Recording URLs expire within 10 minutes. Your team either reviews them immediately or your webhook stores them in your own secure archive.
Which compliance certifications does Waboom AI hold?
Waboom AI is built on voice infrastructure certified to SOC 2 Type II, HIPAA, PCI-DSS, GDPR, and ISO 27001. Certification covers the platform your agent runs on, not a promise about what we keep, which is why the retention settings above matter more to your risk register.
If your procurement process needs the underlying certificates and our cross-border arrangements documented, ask us and we will take your compliance team through them.
Is zero retention suitable for all businesses, or just regulated industries?
Most businesses don't need full zero retention. If you're running outbound campaigns for real estate or retail, our standard encryption and security controls work fine.
Zero retention suits organisations handling genuinely sensitive data: healthcare providers, law firms, financial services, and businesses with strict data sovereignty requirements.
How does PII redaction work alongside zero retention?
They're complementary layers. PII redaction strips sensitive identifiers from transcripts before storage. Zero retention prevents storage entirely.
Use PII redaction alone if you need transcripts for QA but can't retain personal details. Or combine both: webhook-streamed transcripts with PII already redacted, stored on your own servers.
For the full security picture, read how Waboom secures voice AI.
Leonardo Garcia-Curtis
Founder & CEO at Waboom AI. Building voice AI agents that convert.
Ready to Build Your AI Voice Agent?
Let's discuss how Waboom AI can help automate your customer conversations.
Book a Free Demo


