{"id":1294,"date":"2024-10-07T07:46:30","date_gmt":"2024-10-07T07:46:30","guid":{"rendered":"https:\/\/corvum.io\/?page_id=1294"},"modified":"2026-03-23T22:41:39","modified_gmt":"2026-03-24T05:41:39","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/corvum.io\/ca\/privacy-policy\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"1294\" class=\"elementor elementor-1294\" data-elementor-post-type=\"page\">\n\t\t\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-fdace83 e-flex e-con-boxed e-con e-parent\" data-id=\"fdace83\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3e4b575 elementor-widget elementor-widget-heading\" data-id=\"3e4b575\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Privacy Policy<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cd08a65 elementor-widget elementor-widget-text-editor\" data-id=\"cd08a65\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"p2\"><em><b>Last updated March 20, 2026<\/b><\/em><\/p><p class=\"p2\"><b>1. Introduction and Scope<\/b><\/p><p class=\"p3\"><b>CloudPBX Inc. (d.b.a. Corvum) (\u201cCorvum,\u201d \u201cwe,\u201d \u201cus,\u201d or \u201cour\u201d) provides cloud-based Voice over Internet Protocol (VoIP) and Cloud PBX communications services to law firms and legal professionals in Canada and the United States (\u201cServices\u201d). We are committed to protecting the privacy and confidentiality of personal information in a manner consistent with the highest professional standards.<\/b><\/p><p class=\"p3\"><b>This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use our Services, visit our website at corvum.io, or otherwise interact with us. It applies to all customers, users, and individuals whose personal information we process in connection with our Services, regardless of whether they are located in Canada or the United States.<\/b><\/p><p class=\"p3\"><b>Given that our customers are law firms, we understand that communications processed through our platform may involve solicitor-client privileged information. We have designed our systems and practices with this sensitivity in mind.<\/b><\/p><p class=\"p2\"><b>2. Legal Framework and Compliance<\/b><\/p><p class=\"p5\"><b>Corvum operates in accordance with applicable privacy legislation in the jurisdictions where we and our customers operate. Our compliance framework covers both Canadian and U.S. law, including:<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">The Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial equivalents;<\/li><li class=\"li6\">The Canadian Anti-Spam Legislation (CASL);<\/li><li class=\"li6\">Applicable provincial legislation including British Columbia\u2019s Personal Information Protection Act (PIPA), Alberta\u2019s PIPA, and Quebec\u2019s Law 25 (Act respecting the protection of personal information in the private sector);<\/li><li class=\"li6\">Applicable telecommunications regulations under the CRTC and Telecommunications Act.<\/li><li class=\"li6\">The U.S. Electronic Communications Privacy Act (ECPA) and Stored Communications Act (SCA), which govern the interception of and access to wire, oral, and electronic communications, including VoIP calls;<\/li><li class=\"li6\">The U.S. Communications Act and applicable FCC regulations, including CALEA obligations for VoIP providers;<\/li><li class=\"li6\">Applicable U.S. state privacy laws where Corvum\u2019s services are provided to customers in those states, including the California Consumer Privacy Act \/ California Privacy Rights Act (CCPA\/CPRA) and equivalent laws in other U.S. states with comprehensive privacy legislation (see Section 10 for U.S. Customer Rights);<\/li><li class=\"li6\">U.S. state wiretapping and all-party consent laws, which impose requirements additional to federal law in California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, and Washington.<\/li><\/ul><p class=\"p6\">Where our customers\u2019 law firms serve clients in other jurisdictions, our contractual data processing terms address applicable cross-border obligations. Corvum acts as a service provider (U.S.) \/ data processor (Canada) under applicable privacy laws; our U.S. law firm customers remain the controllers \/ businesses responsible for their own compliance obligations to their employees and clients.<\/p><p class=\"p8\"><b>3. Information We Collect<\/b><\/p><p class=\"p9\"><b>3.1 Account and Registration Information<\/b><\/p><p class=\"p10\"><b>When you register for our Services, we collect information necessary to establish and manage your account, including:<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Business name, address, and contact details;<\/li><li class=\"li6\">Names and contact information of authorized users and administrators;<\/li><li class=\"li6\">Billing and payment information (processed through PCI-DSS compliant payment processors; we do not store full payment card numbers);<\/li><li class=\"li6\">Username, password credentials, and security settings;<\/li><li class=\"li11\">Service configuration preferences and feature settings.<\/li><\/ul><p class=\"p9\"><b>3.2 Communications Data<\/b><\/p><p class=\"p10\"><b>In providing VoIP and Cloud PBX services, we necessarily process certain communications-related data, including:<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Call detail records (CDRs): originating and terminating numbers, call duration, timestamps, and call routing data;<\/li><li class=\"li6\">Voicemail data, call recordings (where enabled and configured by the customer);<\/li><li class=\"li6\">Fax transmission metadata;<\/li><li class=\"li6\">Directory and contact list entries entered by users;<\/li><li class=\"li6\">Device provisioning data including MAC addresses for IP phone hardware.<\/li><li class=\"li6\">Where AI Features are enabled by the Customer: AI-generated call transcripts and call summaries (see Section 12 and the AI Features Addendum (Version 2.0)).<\/li><\/ul><p class=\"p11\">Important: Corvum does not listen to, review, or use the content of your voice communications except where you have specifically provided permission to do so, or as compelled by lawful authority. The content of calls is not used for advertising or commercial profiling purposes.<\/p><p class=\"p9\"><b>3.3 Technical and Device Data<\/b><\/p><p class=\"p10\"><b>We automatically collect certain technical data when you use our Services or infrastructure, including:<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">IP addresses and network information;<\/li><li class=\"li6\">SIP registration data and session metadata;<\/li><li class=\"li6\">Mobile application usage data, device identifiers, and operating system information;<\/li><li class=\"li6\">System logs, error reports, and diagnostic data;<\/li><li class=\"li11\">Authentication and access logs.<\/li><\/ul><p class=\"p9\"><b>3.4 Support and Communications Data<\/b><\/p><p class=\"p10\"><b>When you contact our support team or communicate with us, we collect:<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Support ticket contents, correspondence, and resolution history;<\/li><li class=\"li6\">Information you provide when reporting issues or requesting assistance;<\/li><li class=\"li11\">Survey responses and feedback.<\/li><\/ul><p class=\"p9\"><b>3.5 Information We Do Not Collect<\/b><\/p><p class=\"p10\"><b>We do not intentionally collect or process:<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">The substantive content of solicitor-client (Canada) or attorney-client (United States) privileged communications;<\/li><li class=\"li6\">Personal health information;<\/li><li class=\"li6\">Financial account information beyond what is necessary for billing;<\/li><li class=\"li6\">Information about individuals who are not users or administrators of our Services, except as incidentally contained in CDRs or voicemail data.<\/li><\/ul><p class=\"p2\"><b>4. How We Use Personal Information<\/b><\/p><p class=\"p11\"><b>We use personal information only for the purposes for which it was collected or as otherwise permitted by law. Our primary purposes include:<\/b><\/p><p class=\"p13\"><b>4.1 Service Delivery<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Provisioning, operating, and maintaining VoIP and Cloud PBX services;<\/li><li class=\"li6\">Routing, completing, and logging telephone calls and communications;<\/li><li class=\"li6\">Authenticating users and securing account access;<\/li><li class=\"li6\">Providing mobile and desktop applications;<\/li><li class=\"li11\">Hardware provisioning and configuration.<\/li><\/ul><p class=\"p13\"><b>4.2 Account and Billing Management<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Processing payments and issuing invoices;<\/li><li class=\"li6\">Managing service plans, upgrades, and renewals;<\/li><li class=\"li11\">Communicating material service changes, scheduled maintenance, or outages.<\/li><\/ul><p class=\"p13\"><b>4.3 Customer Support<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Responding to support requests and resolving service issues;<\/li><li class=\"li6\">Investigating and diagnosing technical problems;<\/li><li class=\"li11\">Maintaining support history to improve service continuity.<\/li><\/ul><p class=\"p13\"><b>4.4 Security and Fraud Prevention<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Detecting, preventing, and investigating fraud, unauthorized access, and security incidents;<\/li><li class=\"li6\">Monitoring for toll fraud, SIP abuse, and other telecommunications fraud;<\/li><li class=\"li6\">Maintaining audit logs for security purposes;<\/li><li class=\"li11\">Complying with our obligations under Canadian telecommunications regulations and, where applicable, U.S. federal telecommunications law including CALEA and FCC regulations.<\/li><\/ul><p class=\"p13\"><b>4.5 Service Improvement<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Analyzing aggregated, de-identified usage patterns to improve service performance and reliability;<\/li><li class=\"li6\">Identifying and resolving systemic issues;<\/li><li class=\"li6\">AI Features: where enabled, processing call audio and transcripts through LLM sub-processors to generate transcripts and summaries for Customer use. Call content is never used to train AI models. See Section 12 and the AI Features Addendum for full details.<\/li><li class=\"li11\">Developing new features and capabilities.<\/li><\/ul><p class=\"p13\"><b>4.6 Legal Compliance<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Complying with applicable laws, regulations, and lawful government or judicial requests;<\/li><li class=\"li6\">Enforcing our Terms of Service and contractual obligations;<\/li><li class=\"li6\">Establishing, exercising, or defending legal claims.<\/li><\/ul><p class=\"p6\">We do not sell personal information. We do not use personal information to serve third-party advertising.<\/p><p class=\"p2\"><b>5. Disclosure of Personal Information<\/b><\/p><p class=\"p11\"><b>We do not sell, rent, or trade personal information. We may disclose personal information in the following limited circumstances:<\/b><\/p><p class=\"p9\"><b>5.1 Service Providers and Sub-Processors<\/b><\/p><p class=\"p10\"><b>We engage trusted third-party service providers who process personal information on our behalf under contractual obligations consistent with this Policy. These include:<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Cloud infrastructure and data centre providers (Canadian and U.S. providers under appropriate data processing agreements);<\/li><li class=\"li6\">Payment processors (PCI-DSS compliant);<\/li><li class=\"li6\">Customer support and ticketing platforms;<\/li><li class=\"li6\">Telecommunications carriers and interconnect partners for call routing.<\/li><\/ul><p class=\"p11\">We require all service providers to maintain appropriate data security and to use personal information only for the purposes for which it was disclosed.<\/p><p class=\"p9\"><b>5.2 Legal and Regulatory Requirements<\/b><\/p><p class=\"p10\"><b>We may disclose personal information when required to do so by law, including:<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">In response to valid court orders, subpoenas, or judicial warrants;<\/li><li class=\"li6\">In response to lawful requests by law enforcement or regulatory authorities under applicable Canadian law;<\/li><li class=\"li6\">As required by CRTC regulations or the Telecommunications Act;<\/li><li class=\"li6\">To prevent imminent harm, fraud, or serious illegal activity.<\/li><\/ul><p class=\"p11\">Where permitted by law, we will notify affected customers of compelled disclosures. For U.S. law enforcement and government access requests, including under the ECPA, Stored Communications Act, and CALEA, see Section 10.5.<\/p><p class=\"p9\"><b>5.3 Business Transactions<\/b><\/p><p class=\"p11\"><b>In the event of a merger, acquisition, sale of assets, or other corporate transaction, personal information may be transferred as part of that transaction, subject to the receiving party assuming equivalent privacy obligations. We will notify customers of any material change in ownership or control that affects how their information is handled.<\/b><\/p><p class=\"p9\"><b>5.4 With Your Consent<\/b><\/p><p class=\"p11\"><b>We may disclose personal information for other purposes with your express consent, which you may withdraw at any time.<\/b><\/p><p class=\"p2\"><b>6. Data Security<\/b><\/p><p class=\"p5\"><b>Corvum implements administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold, including:<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Encryption of data in transit using TLS\/SRTP and equivalent protocols;<\/li><li class=\"li6\">Encryption of sensitive data at rest;<\/li><li class=\"li6\">Role-based access controls and the principle of least privilege;<\/li><li class=\"li6\">Multi-factor authentication for administrative access;<\/li><li class=\"li6\">Network segmentation and firewall controls;<\/li><li class=\"li6\">Regular security assessments and vulnerability management;<\/li><li class=\"li6\">Intrusion detection and security monitoring;<\/li><li class=\"li6\">Employee security awareness training.<\/li><\/ul><p class=\"p6\">No method of transmission over the internet or method of electronic storage is 100% secure. In the event of a data breach involving personal information, we will notify affected individuals and relevant authorities as required under applicable law, including: (a) within the timeframes prescribed by PIPEDA and applicable Canadian provincial laws; and (b) in the case of U.S. customers, within the timeframes required by applicable U.S. state breach notification laws, which vary by state but generally require notification within 30 to 90 days of discovery. CloudPBX Inc. (d.b.a. Corvum) maintains a breach response plan and will cooperate with affected customers to meet their own notification obligations to their clients and employees. In the event of a breach involving AI-generated transcripts or summaries, the sensitivity of that content will be taken into account in assessing risk and notification obligations; see the AI Features Addendum (Version 2.0), Section 5.<\/p><p class=\"p2\"><b>7. Data Retention<\/b><\/p><p class=\"p5\"><b>We retain personal information for as long as necessary to fulfill the purposes for which it was collected, to maintain the Services, and to comply with our legal obligations. Our general retention practices include:<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Account and billing information: retained for the duration of the customer relationship and for a minimum of seven (7) years following termination to meet tax and regulatory requirements;<\/li><li class=\"li6\">Call detail records: retained for a minimum of six (6) months and up to seven (7) years depending on regulatory requirements and customer contractual terms;<\/li><li class=\"li6\">Call recordings: retained for a minimum of six (6) months and up to twenty-four (24) months, depending on customer choice and agreement;<\/li><li class=\"li6\">Voicemail messages: retained for a minimum of three (3) months and up to twelve (12) months.<\/li><li class=\"li6\">Support records: retained for five (5) years following resolution;<\/li><li class=\"li6\">Security logs: retained for a minimum of twelve (12) months;<\/li><li class=\"li6\">Marketing communications consent records: retained for three (3) years following the end of the consent relationship;<\/li><\/ul><p class=\"p16\">AI-generated call transcripts and summaries (where AI Features are enabled): subject to Customer-configured retention periods; default ninety (90) days from date of generation. See the AI Features Addendum (Version 2.0), Section 6, for full details.<\/p><p class=\"p6\">When personal information is no longer required, we securely delete or anonymize it in accordance with our data destruction procedures.<\/p><p class=\"p2\"><b>8. Cross-Border Data Transfers<\/b><\/p><p class=\"p3\"><b>Corvum is a Canadian company and our primary data processing occurs in Canada. We provide services to customers in both Canada and the United States. For U.S.-based customers, personal information is processed primarily in Canada and may also be processed within the United States by our sub-processors. For Canadian customers, personal information may also be processed in the United States by certain sub-processors, as described below.<\/b><\/p><p class=\"p3\"><b>Where personal information is transferred outside Canada, we ensure that appropriate safeguards are in place, including contractual protections consistent with PIPEDA and applicable provincial requirements. Customers in Quebec should be aware that, where required under Law 25, we conduct privacy impact assessments before transferring personal information outside Quebec.<\/b><\/p><p class=\"p3\"><b>Canadian customers: By using our Services, you acknowledge that your information may be processed in Canada and, where sub-processors operate in the United States, in the United States under the safeguards described above.<\/b><\/p><p class=\"p3\"><b>U.S. customers: By using our Services, you acknowledge that your information will be processed primarily in Canada and may also be processed within the United States. Transfers to Canada are not subject to U.S. state cross-border transfer requirements. Canada has been recognized as providing an adequate level of data protection, and PIPEDA is acknowledged under a number of international adequacy frameworks. Canadian-based processing therefore does not require additional cross-border transfer mechanisms under most U.S. state privacy laws.<\/b><\/p><p class=\"p2\"><b>9. Your Privacy Rights \u2014 Canadian Customers<\/b><\/p><p class=\"p11\"><b>This section describes privacy rights available to Canadian customers under PIPEDA and applicable provincial legislation. U.S. customer rights are described in Section 10. Subject to applicable law and reasonable verification of your identity, you have the following rights with respect to your personal information:<\/b><\/p><p class=\"p9\"><b>9.1 Right of Access<\/b><\/p><p class=\"p11\"><b>You may request access to the personal information we hold about you, including information about the purposes for which it is used and to whom it has been disclosed.<\/b><\/p><p class=\"p9\"><b>9.2 Right to Correction<\/b><\/p><p class=\"p11\"><b>If personal information we hold about you is inaccurate or incomplete, you may request that we correct or update it.<\/b><\/p><p class=\"p9\"><b>9.3 Right to Withdraw Consent<\/b><\/p><p class=\"p11\"><b>Where we rely on consent as the legal basis for processing, you may withdraw that consent at any time, subject to legal or contractual restrictions. Withdrawal of consent for processing that is necessary to provide the Services may affect our ability to continue providing those Services.<\/b><\/p><p class=\"p9\"><b>9.4 Right to Challenge Compliance<\/b><\/p><p class=\"p11\"><b>You have the right to challenge our compliance with this Policy and applicable privacy legislation. We will investigate all complaints and respond in a timely manner.<\/b><\/p><p class=\"p9\"><b>9.5 Right to Complain to a Regulator (Canadian Customers)<\/b><\/p><p class=\"p11\"><b>If you are not satisfied with our response to a privacy concern, you have the right to make a complaint to the Office of the Privacy Commissioner of Canada (OPC) at <a href=\"http:\/\/www.priv.gc.ca\" rel=\"nofollow\">http:\/\/www.priv.gc.ca<\/a>, or to the applicable provincial privacy commissioner.<\/b><\/p><p class=\"p11\"><b>Customer administrators should note that employee and end-user privacy rights should be addressed in the customer\u2019s own privacy policies, which should be consistent with how Corvum\u2019s Services are deployed. U.S.-based law firm customers should ensure their own privacy policies address the rights of their employees and clients under applicable U.S. state privacy laws.<\/b><\/p><p class=\"p2\"><b>10. Your Privacy Rights \u2014 U.S. Customers<\/b><\/p><p class=\"p11\"><b>This section describes privacy rights available to U.S.-based customers and individuals. The specific rights available to you depend on the state in which you are located. Corvum is committed to honoring these rights to the extent applicable and will not discriminate against you for exercising them.<\/b><\/p><p class=\"p9\"><b>10.1 Rights Under U.S. State Privacy Laws<\/b><\/p><p class=\"p11\"><b>As of 2025, nineteen U.S. states have enacted comprehensive consumer privacy laws. The rights under these laws vary by state, but commonly include the following, subject to applicable thresholds and exemptions:<\/b><\/p><ul class=\"ul1\"><li class=\"li11\"><b><\/b><b>Right to Know \/ Access: You may request that we disclose the categories and specific pieces of personal information we collect, use, disclose, and sell about you.<\/b><\/li><li class=\"li11\"><b><\/b><b>Right to Deletion: You may request deletion of personal information we have collected from or about you, subject to exceptions where retention is required by law or necessary to complete a transaction or provide a requested service.<\/b><\/li><li class=\"li11\"><b><\/b><b>Right to Correct: You may request correction of inaccurate personal information we maintain about you (available under most, but not all, state laws).<\/b><\/li><li class=\"li11\"><b><\/b><b>Right to Opt Out of Sale or Sharing: Corvum does not sell personal information and does not share personal information for cross-context behavioral advertising. This right is therefore not applicable to Corvum\u2019s practices, and no \u201cDo Not Sell or Share\u201d mechanism is required.<\/b><\/li><li class=\"li11\"><b><\/b><b>Right to Limit Use of Sensitive Information: Where we process sensitive personal information (such as the content of communications or account login credentials), we use it only to provide the Services and as otherwise described in this Policy. We do not use sensitive information for secondary purposes that would require a limitation mechanism.<\/b><\/li><li class=\"li11\"><b><\/b><b>Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.<\/b><\/li><\/ul><p class=\"p9\"><b>10.2 California-Specific Disclosures (CCPA\/CPRA)<\/b><\/p><p class=\"p11\"><b>For California residents, the following additional disclosures apply under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA\/CPRA):<\/b><\/p><ul class=\"ul1\"><li class=\"li11\"><b><\/b><b>Categories of personal information collected: identifiers (names, email addresses, IP addresses); commercial information (billing and service records); internet or electronic network activity (usage logs, authentication records); audio and electronic communications (call recordings, voicemail, and where AI Features are enabled, transcripts and summaries); professional and employment information (customer firm details, user roles). See Section 3 for full details.<\/b><\/li><li class=\"li11\"><b><\/b><b>Business or commercial purpose for collection: Service delivery, account management, billing, security and fraud prevention, customer support, and legal compliance. See Section 4 for full details.<\/b><\/li><li class=\"li11\"><b><\/b><b>Sale or sharing of personal information: Corvum does not sell personal information and does not share personal information for cross-context behavioral advertising as defined under the CCPA\/CPRA.<\/b><\/li><li class=\"li11\"><b><\/b><b>Retention: We retain each category of personal information for the periods described in Section 7.<\/b><\/li><li class=\"li11\"><b><\/b><b>Sensitive personal information: To the extent we process sensitive personal information as defined under the CCPA\/CPRA (including the content of communications and account credentials), we use it solely to provide the Services and do not use it for purposes that would require a \u201cLimit the Use of My Sensitive Personal Information\u201d mechanism.<\/b><\/li><\/ul><p class=\"p9\"><b>10.3 How to Submit a U.S. Privacy Rights Request<\/b><\/p><p class=\"p11\"><b>U.S. customers may submit privacy rights requests by contacting us at support@corvum.io. Please identify the right you wish to exercise and provide sufficient information to verify your identity and your relationship with Corvum. We will respond within the timeframe required by applicable state law (45 days under most state laws, with an extension of up to an additional 45 days where reasonably necessary). We will not charge a fee for a reasonable rights request unless it is excessive or manifestly unfounded.<\/b><\/p><p class=\"p11\"><b>Note: Because Corvum provides services exclusively to business customers (law firms), Corvum acts as a service provider \/ data processor under applicable U.S. state privacy laws rather than as a business \/ controller. Many U.S. state privacy rights requests regarding personal information processed by Corvum on behalf of a law firm should therefore be directed to the relevant law firm as the data controller. Corvum will assist law firm customers in fulfilling their own obligations to respond to such requests upon written request from the law firm.<\/b><\/p><p class=\"p9\"><b>10.4 U.S. Wiretapping and Recording Consent<\/b><\/p><p class=\"p11\"><b>U.S. federal law (ECPA \/ Wiretap Act) permits recording of calls with the consent of one party. However, the following U.S. states require the consent of all parties to a telephone or VoIP call before it may be recorded or intercepted: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, and Washington.<\/b><\/p><p class=\"p11\"><b>Law firm customers in these all-party consent states are solely responsible for ensuring that all parties to calls processed through Corvum\u2019s Services (including call recording and AI Features) have provided legally sufficient consent before processing begins. Corvum strongly recommends that these customers deploy an automated call announcement on all applicable lines. The obligation to comply with state wiretapping laws rests with the Customer; Corvum does not monitor, verify, or enforce customer compliance with state-specific recording consent requirements. See the AI Features Addendum (Version 2.0), Section 4.2 and Section 4.5, for specific guidance on all-party consent obligations and U.S. legal framework disclosures applicable to AI-assisted call transcription and summarization.<\/b><\/p><p class=\"p9\"><b>10.5 U.S. Law Enforcement and Government Access<\/b><\/p><p class=\"p11\"><b>As a VoIP provider, Corvum is subject to lawful interception obligations under the Communications Assistance for Law Enforcement Act (CALEA), which requires that our network infrastructure be capable of facilitating lawful interception by U.S. law enforcement pursuant to a valid court order or other legal authority. Corvum will not disclose the existence of a lawful interception order to the extent prohibited by law.<\/b><\/p><p class=\"p11\"><b>U.S. law enforcement may also seek access to stored communications under the Stored Communications Act (SCA), including AI-generated transcripts and summaries stored on the Corvum platform. Corvum will review any such requests for legal validity before responding and will notify affected customers where permitted by applicable law. Customers with concerns about government access to their communications data should contact support@corvum.io. See the AI Features Addendum (Version 2.0), Section 4.5, for further details on CALEA and SCA obligations as they apply to AI Features.<\/b><\/p><p class=\"p2\"><b>11. Cookies and Online Tracking<\/b><\/p><p class=\"p11\"><b>Our website (corvum.io) uses cookies and similar tracking technologies to improve user experience and understand how visitors use our site.<\/b><\/p><p class=\"p13\"><b>11.1 Types of Cookies We Use<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Essential cookies: Required for the website and customer portal to function properly. These cannot be disabled without affecting core functionality.<\/li><li class=\"li6\">Analytical cookies: Used to understand aggregate traffic patterns and improve our website. We use privacy-respecting analytics tools.<\/li><li class=\"li11\">Preference cookies: Used to remember your settings and preferences.<\/li><\/ul><p class=\"p9\"><b>11.2 Managing Cookies<\/b><\/p><p class=\"p11\"><b>You can control and manage cookies through your browser settings. Disabling certain cookies may affect the functionality of our website and customer portal. We do not use cookies for third-party advertising.<\/b><\/p><p class=\"p2\"><b>12. AI-Powered Features<\/b><\/p><p class=\"p3\"><b>Corvum offers optional AI-powered call transcription and summarization features (\u201cAI Features\u201d). These features are enabled by default (with customers onboarded after September 1st, 2025), and to be changed must be explicitly requested by a Customer. When enabled, call audio or transcript text is processed by third-party large language model (LLM) API services to generate transcripts and\/or summaries for the Customer\u2019s authorized users.<\/b><\/p><p class=\"p3\"><b>The collection, use, disclosure, and retention of personal information in connection with AI Features is governed by the CloudPBX Inc. (d.b.a. Corvum) AI Features Addendum (Version 2.0), which forms part of this Privacy Policy and is available at corvum.io\/legal. The Addendum should be read together with Section 10.4 of this Policy (U.S. Wiretapping and Recording Consent) and Sections 10.2\u201310.3 (U.S. Customer Rights). The following is a summary of key commitments applicable to AI Features:<\/b><\/p><ul class=\"ul1\"><li class=\"li3\"><b><\/b><b>AI Features are optional and on by default; they can be configure by the Corvum support team;<\/b><\/li><li class=\"li3\"><b><\/b><b>Call content processed through AI Features is transmitted to third-party LLM sub-processors under contractual terms that prohibit retention, training use, and any secondary use of the data;<\/b><\/li><li class=\"li3\"><b><\/b><b>Call content is never used to train, fine-tune, or improve any LLM model, whether by Corvum or its sub-processors;<\/b><\/li><li class=\"li3\"><b><\/b><b>LLM sub-processors do not retain call audio, transcripts, or summaries after returning the processed output to Corvum;<\/b><\/li><li class=\"li3\"><b><\/b><b>Customers are responsible for ensuring that call parties are informed of and consent to AI-assisted transcription and summarization, including compliance with applicable Canadian and U.S. consent requirements and law society or bar association professional obligations;<\/b><\/li><li class=\"li3\"><b><\/b><b>Customers may disable AI Features and request deletion of all AI-generated content at any time.<\/b><\/li><\/ul><p class=\"p3\"><b>Law firm customers should review the AI Features Addendum carefully with respect to solicitor-client privilege considerations and professional obligations before enabling AI Features. The Addendum includes specific guidance on privilege risk, recommended call announcements, and customer responsibilities.<\/b><\/p><p class=\"p2\"><b>13. Minors<\/b><\/p><p class=\"p3\"><b>Our Services are intended for use by businesses and legal professionals. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected personal information from a minor, we will take prompt steps to delete it.<\/b><\/p><p class=\"p2\"><b>14. Changes to This Privacy Policy<\/b><\/p><p class=\"p5\"><b>We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:<\/b><\/p><ul class=\"ul1\"><li class=\"li6\">Post the updated Policy on our website with a new effective date;<\/li><li class=\"li6\">Notify existing customers by email or through the customer portal at least thirty (30) days before the changes take effect;<\/li><li class=\"li6\">Where required by law, obtain renewed consent.<\/li><\/ul><p class=\"p6\">Your continued use of our Services after the effective date of a revised Policy constitutes your acceptance of the updated terms. We encourage you to review this Policy periodically.<\/p><p class=\"p2\"><b>15. Contact and Privacy Officer<\/b><\/p><p class=\"p3\"><b>CloudPBX Inc. (d.b.a. Corvum) has designated a Privacy Officer responsible for overseeing compliance with this Policy and applicable privacy legislation. If you have questions, concerns, or requests regarding this Policy or our privacy practices, please contact:<\/b><\/p><p class=\"p18\"><b>Privacy Officer<\/b><\/p><p class=\"p3\"><b>CloudPBX Inc. (d.b.a. Corvum)<\/b><\/p><p class=\"p3\"><b>916 &#8211; 470 Granville Street<\/b><\/p><p class=\"p3\"><b>Vancouver, BC V6C 1V5<\/b><\/p><p class=\"p3\"><b>Email: support@corvum.io<\/b><\/p><p class=\"p3\"><b>Website: corvum.io<\/b><\/p><p class=\"p3\"><b>We will acknowledge receipt of privacy inquiries within five (5) business days and will respond substantively within thirty (30) days. Where a more complex investigation is required, we will advise you of the expected timeline.<\/b><\/p><p class=\"p19\"><b><i>CloudPBX Inc. (d.b.a. Corvum) \u2014 Privacy Policy<span class=\"Apple-converted-space\">\u00a0 <\/span>|<span class=\"Apple-converted-space\">\u00a0 <\/span>Effective March 23, 2026<\/i><\/b><\/p><p>\u00a0<\/p><p class=\"p1\"><b>AI FEATURES ADDENDUM<\/b><\/p><p class=\"p2\">To the CloudPBX Inc. (d.b.a. Corvum) Privacy Policy<\/p><p class=\"p3\"><i>Effective Date: March 23, 2026<\/i><\/p><p class=\"p3\"><i>Last Reviewed: March 23, 2026<\/i><\/p><p class=\"p3\"><i>Version: 2.0<\/i><\/p><p class=\"p4\"><span class=\"s1\"><b>LEGAL VERTICAL NOTICE:<span class=\"Apple-converted-space\">\u00a0 <\/span><\/b><\/span><i>This Addendum addresses AI processing of communications that may contain solicitor-client privileged information (Canada) or attorney-client privileged information (United States). Law firm customers in both Canada and the United States must review this Addendum carefully and ensure their own clients are informed of AI-assisted transcription and summarization services prior to enabling these features.<\/i><\/p><p class=\"p7\"><b>Preamble and Relationship to Privacy Policy<\/b><\/p><p class=\"p8\"><b>This AI Features Addendum (\u201cAddendum\u201d) supplements and forms part of the CloudPBX Inc. (d.b.a. Corvum) Privacy Policy. It governs the collection, processing, use, disclosure, and retention of personal information in connection with Corvum\u2019s optional AI-powered call transcription and summarization features (\u201cAI Features\u201d) for customers in both Canada and the United States. Capitalized terms not defined in this Addendum have the meanings given to them in the CloudPBX Inc. (d.b.a. Corvum) Privacy Policy.<\/b><\/p><p class=\"p8\"><b>In the event of any conflict between this Addendum and the core Privacy Policy with respect to AI Features, this Addendum governs.<\/b><\/p><p class=\"p8\"><b>AI Features are entirely optional, but are enabled by default for all customers onboarded on or after September 1st, 2025. They can be configured or disabled by the Corvum support team, reachable via support@corvum.io.<\/b><\/p><p class=\"p7\"><b>1. Description of AI Features<\/b><\/p><p class=\"p10\"><b>Corvum offers the following optional AI-powered features to subscribing law firm customers in Canada and the United States:<\/b><\/p><p class=\"p11\"><b>1.1 AI Call Transcription<\/b><\/p><p class=\"p10\"><b>When enabled, audio from calls routed through the Corvum platform is processed to generate a text transcript of the conversation. Transcription is performed using a large language model (LLM) API service. The transcript is returned to the Corvum platform and made available to authorized users of the Customer\u2019s account.<\/b><\/p><p class=\"p11\"><b>1.2 AI Call Summarization<\/b><\/p><p class=\"p10\"><b>When enabled, the transcript generated under Section 1.1 (or audio directly, depending on configuration) is processed by a second LLM API service to generate a structured summary of the call. Summaries may include key topics discussed, action items, and a brief narrative overview. The summary is returned to the Corvum platform and made available to authorized users of the Customer\u2019s account.<\/b><\/p><p class=\"p11\"><b>1.3 Feature Independence<\/b><\/p><p class=\"p10\"><b>Call Transcription and Call Summarization may be enabled independently. Summarization may be configured to process the transcript output of the Transcription feature, or may operate as a separate pipeline depending on Customer configuration. Both features can be enabled or disabled at any time by the Customer\u2019s account administrator.<\/b><\/p><p class=\"p10\"><span class=\"s1\"><b>NOTE:<span class=\"Apple-converted-space\">\u00a0 <\/span><\/b><\/span><b><i>Depending on configuration, these features may operate in real-time with or without Customer configuration to that effect. Customers may configure features to apply to, specific inbound\/outbound\/internal calls or on an on-demand basis. Review your account configuration to confirm how these features are applied.<\/i><\/b><\/p><p class=\"p7\"><b>2. AI Sub-Processors<\/b><\/p><p class=\"p8\"><b>Corvum uses two third-party LLM API services as sub-processors to power AI Features. These services process call audio and\/or transcript text on Corvum\u2019s behalf under contractual terms described in this section.<\/b><\/p><table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"td1\" valign=\"middle\"><p class=\"p13\"><b>Sub-Processor Role<\/b><\/p><\/td><td class=\"td2\" valign=\"top\"><p class=\"p3\">Transcription LLM (Primary)<\/p><\/td><\/tr><tr><td class=\"td3\" valign=\"middle\"><p class=\"p13\"><b>Service Description<\/b><\/p><\/td><td class=\"td4\" valign=\"top\"><p class=\"p3\">Processes call audio to generate text transcripts<\/p><\/td><\/tr><tr><td class=\"td5\" valign=\"middle\"><p class=\"p13\"><b>Provider<\/b><\/p><\/td><td class=\"td6\" valign=\"top\"><p class=\"p3\">Groq Inc.<span class=\"Apple-converted-space\">\u00a0 <\/span>(note: not the more infamous \u2018Grok\u2019)<\/p><\/td><\/tr><tr><td class=\"td3\" valign=\"middle\"><p class=\"p13\"><b>Processing Location<\/b><\/p><\/td><td class=\"td4\" valign=\"top\"><p class=\"p3\">United States<\/p><\/td><\/tr><tr><td class=\"td7\" valign=\"middle\"><p class=\"p13\"><b>Data Retention by Provider<\/b><\/p><\/td><td class=\"td8\" valign=\"top\"><p class=\"p3\">Zero \u2014 no audio or transcript data is retained by the provider after processing<\/p><\/td><\/tr><tr><td class=\"td9\" valign=\"middle\"><p class=\"p13\"><b>Training Use<\/b><\/p><\/td><td class=\"td10\" valign=\"top\"><p class=\"p3\">Prohibited by contract \u2014 call content is never used to train or improve the provider\u2019s models<\/p><\/td><\/tr><tr><td class=\"td1\" valign=\"middle\"><p class=\"p13\"><b>DPA in Place<\/b><\/p><\/td><td class=\"td2\" valign=\"top\"><p class=\"p3\">No DPA in effect other than service contract<\/p><\/td><\/tr><\/tbody><\/table><table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"td1\" valign=\"middle\"><p class=\"p13\"><b>Sub-Processor Role<\/b><\/p><\/td><td class=\"td2\" valign=\"top\"><p class=\"p3\">Summarization LLM (Secondary)<\/p><\/td><\/tr><tr><td class=\"td3\" valign=\"middle\"><p class=\"p13\"><b>Service Description<\/b><\/p><\/td><td class=\"td4\" valign=\"top\"><p class=\"p3\">Processes transcript text to generate structured call summaries<\/p><\/td><\/tr><tr><td class=\"td5\" valign=\"middle\"><p class=\"p13\"><b>Provider<\/b><\/p><\/td><td class=\"td6\" valign=\"top\"><p class=\"p3\">Openai Inc.<\/p><\/td><\/tr><tr><td class=\"td3\" valign=\"middle\"><p class=\"p13\"><b>Processing Location<\/b><\/p><\/td><td class=\"td4\" valign=\"top\"><p class=\"p3\">United States<\/p><\/td><\/tr><tr><td class=\"td7\" valign=\"middle\"><p class=\"p13\"><b>Data Retention by Provider<\/b><\/p><\/td><td class=\"td8\" valign=\"top\"><p class=\"p3\">Zero \u2014 no transcript or summary data is retained by the provider after processing<\/p><\/td><\/tr><tr><td class=\"td9\" valign=\"middle\"><p class=\"p13\"><b>Training Use<\/b><\/p><\/td><td class=\"td10\" valign=\"top\"><p class=\"p3\">Prohibited by contract \u2014 call content is never used to train or improve the provider\u2019s models<\/p><\/td><\/tr><tr><td class=\"td1\" valign=\"middle\"><p class=\"p13\"><b>DPA in Place<\/b><\/p><\/td><td class=\"td2\" valign=\"top\"><p class=\"p3\">No DPA in effect other than service contract<\/p><\/td><\/tr><\/tbody><\/table><p class=\"p8\"><span class=\"s2\"><b>COMMITMENT:<span class=\"Apple-converted-space\">\u00a0 <\/span><\/b><\/span><b><i>Corvum contractually prohibits both AI sub-processors from retaining, storing, or using any call audio, transcript, or summary content for any purpose other than returning the processed output to Corvum. This prohibition expressly includes model training, product improvement, benchmarking, and any other secondary use.<\/i><\/b><\/p><p class=\"p8\"><b>Corvum will notify customers of any material change to the identity or data processing practices of AI sub-processors at least thirty (30) days before such change takes effect, and will update this Addendum accordingly.<\/b><\/p><p class=\"p14\"><b>3. Data Flows and Processing Details<\/b><\/p><p class=\"p11\"><b>3.1 Transcription Data Flow<\/b><\/p><p class=\"p15\"><b>The following describes how call audio is processed when Call Transcription is enabled:<\/b><\/p><ul class=\"ul1\"><li class=\"li16\">Call audio is captured by the Corvum platform at the point of call termination or during the call, depending on Customer configuration.<\/li><li class=\"li16\">Audio for each call channel is transmitted over an encrypted connection (TLS) to the Transcription LLM API.<\/li><li class=\"li16\">The Transcription LLM processes each audio channel separately, and returns a text transcript to Corvum.<\/li><li class=\"li16\">The audio sent to the LLM is not retained by the LLM provider after the API response is returned.<\/li><li class=\"li16\">Corvum assembles the separate transcripts into a single cohesive transcript.<\/li><li class=\"li16\">The transcript is stored by Corvum and made available to the Customer\u2019s authorized users through the account portal or API.<\/li><li class=\"li10\">The original call audio is retained separately, subject to the Customer\u2019s call recording retention configuration.<\/li><\/ul><p class=\"p11\"><b>3.2 Summarization Data Flow<\/b><\/p><p class=\"p15\"><b>The following describes how transcript content is processed when Call Summarization is enabled:<\/b><\/p><ul class=\"ul1\"><li class=\"li16\">The transcript (from Section 3.1) or call audio is transmitted over an encrypted connection (TLS) to the Summarization LLM API.<\/li><li class=\"li16\">The Summarization LLM processes the input and returns a structured summary to Corvum.<\/li><li class=\"li16\">The input data sent to the LLM is not retained by the LLM provider after the API response is returned.<\/li><li class=\"li16\">The summary is stored by Corvum and made available to the Customer\u2019s authorized users.<\/li><li class=\"li10\">Transcripts and summaries are stored separately and may have different retention periods as configured by the Customer.<\/li><\/ul><p class=\"p11\"><b>3.3 What Is and Is Not Sent to LLM Providers<\/b><\/p><p class=\"p10\"><b>For certainty, the following table describes what data is and is not transmitted to LLM sub-processors:<\/b><\/p><table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"td11\" valign=\"top\"><p class=\"p18\"><b>Data Element<\/b><\/p><\/td><td class=\"td12\" valign=\"top\"><p class=\"p18\"><b>Transcription LLM<\/b><\/p><\/td><td class=\"td12\" valign=\"top\"><p class=\"p18\"><b>Summarization LLM<\/b><\/p><\/td><\/tr><tr><td class=\"td13\" valign=\"top\"><p class=\"p3\">Call audio (voice)<\/p><\/td><td class=\"td14\" valign=\"top\"><p class=\"p19\">Yes \u2014 for transcription<\/p><\/td><td class=\"td14\" valign=\"top\"><p class=\"p20\">No (transcript is sent, not audio)<\/p><\/td><\/tr><tr><td class=\"td15\" valign=\"top\"><p class=\"p3\">Transcript text<\/p><\/td><td class=\"td16\" valign=\"top\"><p class=\"p20\">No<\/p><\/td><td class=\"td16\" valign=\"top\"><p class=\"p19\">Yes \u2014 for summarization<\/p><\/td><\/tr><tr><td class=\"td13\" valign=\"top\"><p class=\"p3\">Caller ID \/ phone numbers<\/p><\/td><td class=\"td14\" valign=\"top\"><p class=\"p20\">No \u2014 stripped before API call<\/p><\/td><td class=\"td14\" valign=\"top\"><p class=\"p20\">No<\/p><\/td><\/tr><tr><td class=\"td17\" valign=\"top\"><p class=\"p3\">Account identifiers or user IDs<\/p><\/td><td class=\"td18\" valign=\"top\"><p class=\"p20\">No<\/p><\/td><td class=\"td18\" valign=\"top\"><p class=\"p20\">No<\/p><\/td><\/tr><tr><td class=\"td19\" valign=\"top\"><p class=\"p3\">Customer name or firm name<\/p><\/td><td class=\"td20\" valign=\"top\"><p class=\"p20\">No<\/p><\/td><td class=\"td20\" valign=\"top\"><p class=\"p20\">No<\/p><\/td><\/tr><tr><td class=\"td21\" valign=\"top\"><p class=\"p3\">Call metadata (duration, timestamps)<\/p><\/td><td class=\"td22\" valign=\"top\"><p class=\"p20\">No<\/p><\/td><td class=\"td22\" valign=\"top\"><p class=\"p20\">No<\/p><\/td><\/tr><tr><td class=\"td19\" valign=\"top\"><p class=\"p3\">Stored transcripts or prior summaries<\/p><\/td><td class=\"td20\" valign=\"top\"><p class=\"p20\">No<\/p><\/td><td class=\"td20\" valign=\"top\"><p class=\"p20\">No<\/p><\/td><\/tr><\/tbody><\/table><p class=\"p14\"><b>4. Consent and Disclosure Requirements<\/b><\/p><p class=\"p11\"><b>4.1 Customer\u2019s Responsibility<\/b><\/p><p class=\"p10\"><b>The Customer (the subscribing law firm) is responsible for ensuring that all parties to calls processed through AI Features have been appropriately informed and, where required by law, have consented to AI-assisted transcription and summarization. This obligation exists independently of Corvum\u2019s own privacy obligations.<\/b><\/p><p class=\"p15\"><b>Corvum strongly recommends that law firm customers (in both Canada and the United States):<\/b><\/p><ul class=\"ul1\"><li class=\"li16\">Update their own client intake and engagement letter processes to disclose the use of AI call transcription and summarization tools where calls with clients may be processed;<\/li><li class=\"li16\">Obtain informed consent from clients prior to enabling AI Features on lines used for solicitor-client communications;<\/li><li class=\"li16\">Consider whether Law Society rules (Canada) or State Bar \/ ABA Model Rules (United States) in their jurisdiction require disclosure of AI tool usage in client communications, and comply accordingly \u2014 multiple U.S. state bars have issued formal guidance on AI use in legal practice;<\/li><li class=\"li10\">Implement a call announcement (see Section 4.3) on all lines where AI Features are active; and consult Section 10.4 of the CloudPBX Inc. (d.b.a. Corvum) Privacy Policy for the definitive list of U.S. all-party consent states.<\/li><\/ul><p class=\"p11\"><b>4.2 All-Party Consent Considerations<\/b><\/p><p class=\"p10\"><b>Canadian federal law (under PIPEDA and the Criminal Code\u2019s interception provisions) generally permits recording of calls with the consent of one party. U.S. federal law (ECPA) also operates on a one-party consent basis at the federal level. However, the following U.S. states require the consent of all parties before a telephone or VoIP call may be recorded, transcribed, or otherwise intercepted: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, and Washington. Where calls involve parties located in any of these all-party consent states, explicit disclosure and consent from all parties is legally required before AI Features process those calls. Given recent class-action litigation against AI transcription vendors (see, e.g., Brewer v. Otter.ai, 2025), Corvum strongly advises Customers to treat all-party consent requirements as a compliance priority.<\/b><\/p><p class=\"p10\"><b>Corvum provides configurable tools to assist with consent compliance. Customers are responsible for deploying and configuring these tools appropriately.<\/b><\/p><p class=\"p11\"><b>4.3 Recommended Call Announcement<\/b><\/p><p class=\"p10\"><b>Corvum recommends that Customers enable an automated call announcement played at the outset of calls processed by AI Features. A suitable announcement might read:<\/b><\/p><p class=\"p10\"><b><i>\u201cThis call may be recorded, transcribed, and summarized using AI-powered tools for the internal use of [Firm Name]. If you do not consent to this, please inform the staff member you are speaking with.\u201d<\/i><\/b><\/p><p class=\"p10\"><b><i>For customers in U.S. all-party consent states (California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, and Washington), a stronger announcement is legally required. We recommend the following variant for those jurisdictions:<\/i><\/b><\/p><p class=\"p10\"><b><i>\u201cThis call will be recorded, transcribed, and summarized using AI-powered tools for the internal use of [Firm Name]. By continuing this call, you consent to this recording and AI processing. If you do not consent, please say so now and we will proceed without recording.\u201d<\/i><\/b><\/p><p class=\"p10\"><b>This announcement should be customized to reflect the firm\u2019s actual practices and reviewed by the firm\u2019s own legal counsel for compliance with applicable law in the relevant jurisdiction(s).<\/b><\/p><p class=\"p11\"><b>4.4 Corvum\u2019s Role<\/b><\/p><p class=\"p10\"><b>Corvum acts as a data processor (Canada) and service provider (United States) with respect to personal information processed through AI Features. The Customer is the data controller (Canada) or business (United States) for purposes of applicable privacy legislation. Corvum processes personal information through AI Features solely on the Customer\u2019s instructions and in accordance with this Addendum. U.S. law firm customers remain the controller \/ business responsible for their own compliance obligations to their employees and clients under applicable U.S. state privacy laws, including the CCPA\/CPRA and equivalent state laws.<\/b><\/p><p class=\"p11\"><b>4.5 U.S. Customers: ECPA, CALEA, and State Law Disclosure<\/b><\/p><p class=\"p10\"><b>U.S. customers enabling AI Features should be aware of the following additional legal context:<\/b><\/p><ul class=\"ul1\"><li class=\"li10\"><b><\/b><b>ECPA \/ Wiretap Act: The Electronic Communications Privacy Act prohibits the intentional interception of wire, oral, or electronic communications without consent. Corvum\u2019s transmission of call audio to LLM sub-processors for transcription is conducted under the service provider exception (18 U.S.C. \u00a7 2511(2)(a)(i)) and pursuant to Customer consent obtained through the act of enabling AI Features. Customers are responsible for obtaining consent from call parties as required under applicable federal and state law.<\/b><\/li><li class=\"li10\"><b><\/b><b>CALEA: As a VoIP provider, Corvum is subject to the Communications Assistance for Law Enforcement Act, which requires that Corvum\u2019s network be capable of facilitating lawful interception pursuant to a valid court order or other legal authority. AI-generated transcripts and summaries stored on the Corvum platform may be subject to lawful access requests under the Stored Communications Act (SCA). Corvum will review any such requests for legal validity before responding.<\/b><\/li><li class=\"li10\"><b><\/b><b>U.S. State Privacy Laws: AI-generated transcripts and summaries may constitute personal information or sensitive personal information under applicable U.S. state privacy laws (including the CCPA\/CPRA, which categorizes audio recordings as sensitive personal information). Corvum processes this data solely as a service provider on the Customer\u2019s instructions. U.S. law firm customers are responsible for disclosing AI Features in their own privacy notices and providing any required opt-out or consent mechanisms to their employees and clients.<\/b><\/li><li class=\"li10\"><b><\/b><b>Third-Party AI Vendor Liability: Recent U.S. litigation has examined whether generic \u201ccall may be recorded\u201d disclosures are sufficient when third-party AI vendors process call content, particularly under state wiretapping laws such as California\u2019s CIPA. Customers are advised to implement explicit disclosures naming AI transcription and summarization at the start of applicable calls, and to review this approach with qualified legal counsel.<\/b><\/li><\/ul><p class=\"p7\"><b>5. Security Measures for AI Features<\/b><\/p><p class=\"p22\"><b>In addition to the security measures described in the core Privacy Policy, Corvum implements the following controls specifically for AI Features:<\/b><\/p><ul class=\"ul1\"><li class=\"li16\">All audio and transcript data transmitted to LLM sub-processors is encrypted in transit using TLS 1.2 or higher;<\/li><li class=\"li16\">Transcripts and summaries stored on the Corvum platform are encrypted at rest;<\/li><li class=\"li16\">Access to transcripts and summaries is restricted to authorized users of the Customer\u2019s account, as configured by the Customer administrator;<\/li><li class=\"li16\">LLM sub-processor API calls use dedicated enterprise API credentials that are isolated from consumer or general-purpose service tiers;<\/li><li class=\"li16\">Corvum does not log the full content of audio or transcripts in system logs; only metadata (call ID, processing status, timestamp) is logged for operational purposes;<\/li><li class=\"li16\">Corvum\u2019s LLM sub-processor agreements include security requirements consistent with industry standards for enterprise API services.<\/li><\/ul><p class=\"p14\"><b>6. Retention and Deletion of AI-Generated Content<\/b><\/p><p class=\"p11\"><b>6.1 Customer-Controlled Retention<\/b><\/p><p class=\"p10\"><b>Customers control the retention period for transcripts and summaries generated through AI Features. Account administrators may configure retention periods through the account portal. Upon expiry of the configured retention period, transcripts and summaries are permanently deleted from the Corvum platform.<\/b><\/p><p class=\"p11\"><b>6.2 Default Retention<\/b><\/p><p class=\"p15\"><b>Where a Customer has not configured a specific retention period, the following defaults apply:<\/b><\/p><ul class=\"ul1\"><li class=\"li16\">Call transcripts: retained for one hundred eighty (180) days from the date of generation;<\/li><li class=\"li16\">Call summaries: retained for one hundred eighty (180) days from the date of generation;<\/li><li class=\"li10\">Operational metadata (call ID, processing status, timestamp): retained for (12) months.<\/li><\/ul><p class=\"p11\"><b>6.3 LLM Provider Retention<\/b><\/p><p class=\"p10\"><b>As described in Section 2, neither LLM sub-processor retains call audio, transcript text, or summary content after returning the processed output to Corvum. Corvum contractually verifies this commitment and conducts periodic reviews of sub-processor compliance.<\/b><\/p><p class=\"p11\"><b>6.4 Deletion on Request<\/b><\/p><p class=\"p10\"><b>Customers may request deletion of specific transcripts or summaries, or all AI-generated content associated with their account, at any time through the account portal or by contacting support@corvum.io. Deletion requests are processed within five (5) business days.<\/b><\/p><p class=\"p7\"><b>7. Privilege Considerations (Solicitor-Client \/ Attorney-Client)<\/b><\/p><p class=\"p8\"><span class=\"s1\"><b>IMPORTANT NOTICE TO LAW FIRM CUSTOMERS:<span class=\"Apple-converted-space\">\u00a0 <\/span><\/b><\/span><b><i>This section addresses specific considerations for law firms using AI Features in connection with solicitor-client (Canada) or attorney-client (United States) privileged communications. Law firm administrators should review this section with their firm\u2019s own privacy counsel before enabling AI Features.<\/i><\/b><\/p><p class=\"p11\"><b>7.1 Privilege Risk<\/b><\/p><p class=\"p15\"><b>Call content processed through AI Features is transmitted to third-party LLM sub-processors. While Corvum has taken contractual and technical steps to minimize risk (including zero-retention commitments and prohibitions on training use), law firms in both Canada and the United States should be aware that:<\/b><\/p><ul class=\"ul1\"><li class=\"li16\">Transmission of privileged communications to a third-party processor may, in some circumstances, be argued to constitute a waiver or potential waiver of solicitor-client privilege (Canada) or attorney-client privilege (United States), depending on the jurisdiction and applicable rules of professional conduct;<\/li><li class=\"li16\">AI-generated transcripts and summaries of privileged communications may not themselves attract privilege protection unless they reflect the exercise of legal judgment;<\/li><li class=\"li10\">Law society rules in some Canadian jurisdictions have issued guidance or are developing guidance on the use of AI tools in legal practice; U.S. firms should consult applicable State Bar rules and any formal ethics opinions on AI use in legal practice issued in their jurisdiction. Both Canadian and U.S. firms should consult current guidance from their relevant law society or bar association.<\/li><\/ul><p class=\"p11\"><b>7.2 Risk Mitigation<\/b><\/p><p class=\"p15\"><b>To mitigate privilege risk, law firm customers are advised to:<\/b><\/p><ul class=\"ul1\"><li class=\"li16\">Enable AI Features only on lines and extensions used for non-privileged communications (e.g., reception, scheduling, administrative calls), unless the firm has conducted a privilege risk assessment and obtained appropriate client consent for privileged call lines;<\/li><li class=\"li16\">Obtain explicit informed consent from clients prior to using AI Features on lines used for substantive legal advice \u2014 for U.S. firms, consider whether this consent must be documented in the client engagement letter under applicable state bar rules;<\/li><li class=\"li16\">Review AI-generated transcripts and summaries before relying on them and apply appropriate legal judgment;<\/li><li class=\"li16\">Implement access controls so that AI-generated content is available only to the professionals who need it;<\/li><li class=\"li10\">Consider whether AI-generated content should be labeled as privileged or work product in the firm\u2019s document management system.<\/li><\/ul><p class=\"p11\"><b>7.3 Corvum\u2019s Limitation<\/b><\/p><p class=\"p10\"><b>Corvum is not a law firm and does not provide legal advice. The considerations in this Section 7 are provided for informational purposes only. Law firm customers are solely responsible for compliance with their professional obligations, including confidentiality, privilege (solicitor-client in Canada; attorney-client in the United States), and applicable law society or bar association rules. Corvum recommends that each firm seek independent legal advice before enabling AI Features.<\/b><\/p><p class=\"p7\"><b>8. Accuracy of AI-Generated Content<\/b><\/p><p class=\"p22\"><b>AI-generated transcripts and summaries are produced by automated systems and may contain errors, inaccuracies, omissions, or \u201challucinations\u201d (content that was not present in the source audio). Specifically:<\/b><\/p><ul class=\"ul1\"><li class=\"li16\">Transcripts may mis-transcribe words, names, legal terminology, numbers, or other content, particularly in low-audio-quality calls or calls with multiple simultaneous speakers;<\/li><li class=\"li16\">Summaries are AI-generated interpretations of the transcript and may omit nuance, mischaracterize positions, or incorrectly attribute statements;<\/li><li class=\"li16\">Neither transcripts nor summaries should be treated as verbatim or authoritative records of a call without review and verification by an authorized user.<\/li><\/ul><p class=\"p16\">Corvum makes no warranty, express or implied, as to the accuracy, completeness, or fitness for purpose of AI-generated transcripts or summaries. Law firm customers in particular must exercise independent professional judgment when reviewing AI-generated content.<\/p><p class=\"p7\"><b>9. Customer Obligations<\/b><\/p><p class=\"p22\"><b>By enabling AI Features, the Customer agrees to:<\/b><\/p><ul class=\"ul1\"><li class=\"li16\">Ensure that all call parties on lines processed by AI Features are appropriately informed of and, where legally required, consent to AI-assisted transcription and summarization prior to or at the start of the call;<\/li><li class=\"li16\">Update the firm\u2019s own privacy policy, client intake processes, and retainer \/ engagement letter agreements to reflect the use of AI call processing tools where applicable, including in any CCPA-required privacy notice for California-based law firms;<\/li><li class=\"li16\">Comply with all applicable laws, including consent, recording, and data protection requirements in all jurisdictions where calls are placed or received \u2014 for U.S. customers, this expressly includes compliance with the ECPA, applicable U.S. state wiretapping and all-party consent laws, and U.S. state privacy laws such as the CCPA\/CPRA;<\/li><li class=\"li16\">Ensure that access to AI-generated content is appropriately restricted within the firm;<\/li><li class=\"li16\">Not use AI Features to process calls involving individuals who have explicitly objected to recording or AI processing;<\/li><li class=\"li16\">Promptly notify Corvum if the Customer becomes aware of any unauthorized access to or disclosure of AI-generated content;<\/li><li class=\"li16\">Review and comply with any updated versions of this Addendum as published by Corvum.<\/li><\/ul><p class=\"p7\"><b>10. Disabling AI Features and Data Deletion<\/b><\/p><p class=\"p8\"><b>AI Features may be disabled at any time by Corvum support staff.<span class=\"Apple-converted-space\">\u00a0 <\/span>Disabling AI Features will immediately stop the processing of new calls through the AI pipeline. Existing transcripts and summaries will be retained until deleted by the Customer or until the applicable retention period expires.<\/b><\/p><p class=\"p8\"><b>Upon termination of the Customer\u2019s Corvum account, all transcripts and summaries associated with the account will be deleted within thirty (30) days, subject to any legal hold obligations. Customers may request earlier deletion by contacting support@corvum.io.<\/b><\/p><p class=\"p7\"><b>11. Updates to This Addendum<\/b><\/p><p class=\"p8\"><b>Corvum may update this Addendum from time to time, including to reflect changes to the AI sub-processors used, data flow architecture, or applicable legal requirements. Where changes are material, Corvum will provide at least thirty (30) days\u2019 notice to Customers before the updated Addendum takes effect, by email or through the customer portal.<\/b><\/p><p class=\"p8\"><b>Continued use of AI Features following the effective date of an updated Addendum constitutes acceptance of the updated terms.<\/b><\/p><p class=\"p7\"><b>12. Contact<\/b><\/p><p class=\"p8\"><b>Questions or concerns about this Addendum or the AI Features described herein should be directed to:<\/b><\/p><p class=\"p26\"><b>Privacy Officer \u2014 CloudPBX Inc. (d.b.a. Corvum)<\/b><\/p><p class=\"p8\"><b>Email: support@corvum.io<\/b><\/p><p class=\"p8\"><b>Website: corvum.io<\/b><\/p><p class=\"p27\"><b><i>CloudPBX Inc. (d.b.a. Corvum) AI Features Addendum<span class=\"Apple-converted-space\">\u00a0 <\/span>|<span class=\"Apple-converted-space\">\u00a0 <\/span>Effective March 23, 2026<span class=\"Apple-converted-space\">\u00a0 <\/span>|<span class=\"Apple-converted-space\">\u00a0 <\/span>Version 2.0<\/i><\/b><\/p><p>\u00a0<\/p><p class=\"p15\"><b><i>\u00a0<\/i><\/b><\/p><p>\u00a0<\/p><p class=\"p15\"><b><i>\u00a0<\/i><\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Privacy Policy Last updated March 20, 2026 1. Introduction and Scope CloudPBX Inc. (d.b.a. Corvum) (\u201cCorvum,\u201d \u201cwe,\u201d \u201cus,\u201d or \u201cour\u201d) provides cloud-based Voice over Internet Protocol (VoIP) and Cloud PBX communications services to law firms and legal professionals in Canada and the United States (\u201cServices\u201d). We are committed to protecting the privacy and confidentiality of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"elementor_header_footer","meta":{"inline_featured_image":false,"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"footnotes":""},"class_list":["post-1294","page","type-page","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/corvum.io\/ca\/wp-json\/wp\/v2\/pages\/1294","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/corvum.io\/ca\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/corvum.io\/ca\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/corvum.io\/ca\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/corvum.io\/ca\/wp-json\/wp\/v2\/comments?post=1294"}],"version-history":[{"count":27,"href":"https:\/\/corvum.io\/ca\/wp-json\/wp\/v2\/pages\/1294\/revisions"}],"predecessor-version":[{"id":3362,"href":"https:\/\/corvum.io\/ca\/wp-json\/wp\/v2\/pages\/1294\/revisions\/3362"}],"wp:attachment":[{"href":"https:\/\/corvum.io\/ca\/wp-json\/wp\/v2\/media?parent=1294"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}