> ## Documentation Index
> Fetch the complete documentation index at: https://docs.quarterzip.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

Quarterzip uses secure and robust design principles to provide best in class security features for our customers.

Quarterzip is ISO/IEC 27001 certified, demonstrating our commitment to internationally recognized standards for information security management.

## Consent Approval Process

When starting a call users can decide which part of their screen and what audio they would like to share with Quarterzip. You can decide what the default share option should be in your agent settings.

<Frame>
  <img src="https://mintcdn.com/quarterzip/PSl6c2veDx83I2-l/images/image-2.png?fit=max&auto=format&n=PSl6c2veDx83I2-l&q=85&s=b87064335d169671079e7348f4bdb149" alt="Image" width="621" height="592" data-path="images/image-2.png" />
</Frame>

User have three different options:

1. Share a single tab in their browser.
2. Share a single application window.
3. Share an entire screen.

The agent can only see their screen after the user has made a specific choice about what to share with the agent. By default most web browsers will ask permission the first time a website wants to see your screen.

If a user doesn't wish to share their screen the agent may still continue with the call ans guide the user with audio assistance only.

Similar to the screen the user must provide permission to the webpage to access the microphone.

<Frame>
  <img src="https://mintcdn.com/quarterzip/PSl6c2veDx83I2-l/images/image-3.png?fit=max&auto=format&n=PSl6c2veDx83I2-l&q=85&s=067c369bfa6633bb7c9197820aa2ac08" alt="Image" width="333" height="403" data-path="images/image-3.png" />
</Frame>

The agent can only hear the user after permission to access the microphone is given.

## Authorization Using Google Identity

Quarterzip sessions are authenticated using [Google Identity Anonymous Auth](https://docs.cloud.google.com/identity-platform/docs/concepts-authentication). When the SDK is initialised inside a webpage it creates an anonymous identity that is stored locally in the session. This identity is used across calls on the same domain to maintain memory and call context.

When starting a call with the SDK you can provide an email, display name, and external identifier

## Model Training

By default Quarterzip does not use your data for foundational model training. Quarterzip does use recordings of calls (if enabled) to provide fine tuning of the knowledge base and agent guide.

## Data Processing and Retention

Data retention durations can be found in our [Security and Trust Overview](https://www.quarterzip.ai/legal/security-and-trust-overview) page, customer can opt-in to 90, 180, or 365 days of retention.

### Internal Testing Call: Visual Data

**Description of Processing:** For quality assurance and to monitor agent performance, a random sample of interactions has its raw media (audio and images) temporarily stored.

**Definition of Data Type:** Visual Data refers to video or image data taken from the user's screen, transmitted from a user's device during live communication sessions used by workspace users (Onboarding agent builders) to develop and train the agent. This does not pertain to video from the user's camera.

**Collection Enabled:** Opt-Out

**Retention:** If opted-in, the Customer may configure this to; 90, 180, 365 or indefinite

### End User Calls: Visual Data

**Description of Processing:** For quality assurance and to monitor agent performance, a random sample of interactions has its raw media (audio and images) temporarily stored.

**Definition of Data Type:** Visual Data refers to video or image data taken from the user's screen, transmitted from a user's device during live communication sessions for your customer's users (regarded as external end users). This does not pertain to video from the user's camera.

**Collection Enabled:** Opt-in

**Retention:** If opted-in, the Customer may configure this to; 90, 180, 365 or indefinite

### Audio and Transcripts

**Description of Processing:** Audio from interactions is processed into text transcripts. These transcripts serve as the direct input for Insight generation. They are stored temporarily to allow for reprocessing or support inquiries if needed.

**Definition of Data Type:** Call Audio and Artefacts include voice recordings, call transcripts, and content representative of the audio during the communication session.

**Collection Enabled:** Opt-Out

**Retention:** If opted-in, the Customer may configure this to; 90, 180, 365 or indefinite

### Analytics

**Description of Processing:** The transcripts and interaction metadata are distilled into the actionable Insights and Analytics that you see and interact with. This includes performance metrics, sentiment analysis, key topic identification, and trend data. This is the primary representation of your data within the Quarterzip platform.

**Definition of Data Type:** Analytics Data comprises operational metadata, usage information, system-generated events, and derived or insights associated with the use of the service. This includes identifiers, anonymised insights, timestamps, performance metrics, and aggregated interaction patterns visible within product interfaces. We create anonymised statistical data from Your Data and usage of our Services (for example, through aggregation). Once anonymised, we own that data and may use it for our own purposes, such as to provide and improve our Services, to develop new services or product offerings, to identify business trends, and for other uses we communicate to you. This may include making such anonymised data publicly available, provided it is not compiled using a sample size small enough to make underlying portions of Your Data identifiable.

**Collection Enabled:** Required

**Retention:** Indefinite
