Home / Legal & Governance / Privacy Policy

Privacy Policy

Our transparent operational commitment to confidential client workflows, HIPAA-certified Protected Health Information (PHI) safeguards, zero-retention AI pipelines, and international cross-border data protection.

Effective Date: January 1, 2026
Last Updated: September 2026
Standards: SOC 2 • HIPAA • CCPA

Zero AI Model Training

Your proprietary data and call recordings are never used to train public or commercial LLMs.

HIPAA Certified (BAA)

Full Business Associate Agreement execution and strict ePHI isolation for health payors.

Cryptographic Isolation

AES-256 encryption at rest and TLS 1.3 across all telephony, APIs, and databases.

100% Data Sovereignty

Full client data ownership, instant data export reports, and certified deletion on demand.

Section 01

1. Scope, Commitment & Legal Framework

Rocket Multi Services Inc. ("Rocket Multi Services," "we," "us," or "our") is a U.S.-managed corporate provider delivering intelligent nearshore business process outsourcing (BPO), customer support (CX), telemarketing, virtual assistance, and autonomous cognitive artificial intelligence workflows.

This Privacy Policy sets forth our mandatory principles regarding the acquisition, protection, compartmentalization, and processing of enterprise data, Protected Health Information (PHI), and Personally Identifiable Information (PII) entrusted to us by client organizations ("Clients") and their end-consumers.

Regulatory Alignment: Our operational infrastructure and bilingual delivery centers comply with United States federal and state legislation (including the California Consumer Privacy Act/CPRA), the Health Insurance Portability and Accountability Act of 1996 (HIPAA/HITECH Omnibus Rule), and international cross-border transfer agreements between the United States and Latin American delivery hubs.

Section 02

2. Categories of Information Collected & Processed

In our capacity as a contracted service provider and Business Associate, we collect and process only data strictly necessary to fulfill executed Statements of Work (SOWs):

Data Classification Examples & Scope Processing Purpose Security Controls
Client Business Data Authorized corporate contacts, billing info, SLAs, SOP documentation, CRM configurations. Account management, operational execution, and invoice generation. Encrypted database storage, RBAC restricted to account directors.
Telephony & Interactions Call audio recordings, chat logs, agent notes, customer sentiment telemetry. Service delivery, Quality Assurance (QA) scoring, dispute resolution. Encrypted dual-channel audio streams, automated PII scrubbing upon request.
Protected Health Information (PHI) Patient demographics, insurance policy IDs, medical billing codes, prior authorization files. Healthcare claims adjudication, member enrollment, and provider verification. Encrypted isolated VLANs, biometric clean-desk delivery rooms, immutable audit logs.
System Diagnostics IP addresses, device telemetry, browser signatures, session latency. Zero-Trust network defense, 99.8% SLA monitoring, DDoS mitigation. SIEM real-time monitoring, 24/7 Security Operations Center (SOC).

Section 03

3. AI Safeguards & Strict Data Isolation

As enterprise organizations scale their operations with conversational AI agents and robotic process automations (RPA), data protection and model governance are of paramount importance.

Our Ironclad AI Confidentiality Commitment

Rocket Multi Services STRICTLY PROHIBITS the training, fine-tuning, or ingestion of any client proprietary documents, customer interaction transcripts, or health records into public, commercial, or third-party Foundation Large Language Models (including public ChatGPT, Claude, or Gemini instances).

  • Tenant-Isolated Virtual Private Clouds (VPC): All AI model inference is executed within dedicated, single-tenant private infrastructure.
  • Volatile In-Memory Processing: Real-time automated agents process operational prompts in volatile RAM with zero prompt retention or model parameter updating.
  • Human-in-the-Loop Oversight: High-stakes actions (such as healthcare claims adjudication or financial transactions) mandate licensed human specialist review before confirmation.

Section 04

4. Enterprise Cryptography & Physical Safeguards

We employ defense-in-depth measures audited under SOC 2 Type II controls to ensure the confidentiality, integrity, and availability of client assets:

Cryptographic Encryption

AES-256 bit hardware-level encryption at rest across all disks, database clusters, and cloud backups. Enforced TLS 1.3 protocol for all data in transit.

Clean-Desk Operational Hubs

Biometric facial access gates, locked-down kiosk thin-clients with disabled USB ports, and a total ban on personal smartphones, cameras, or paper on delivery floors.

Segmented Network VLANs

Enterprise client traffic is logically and physically partitioned on dedicated subnets with next-gen firewall inspection and continuous Data Loss Prevention (DLP) monitoring.


Section 05

5. HIPAA & Protected Health Information Compliance

Rocket Multi Services operates as a legally compliant Business Associate to healthcare payors, health maintenance organizations (HMOs), third-party administrators (TPAs), and hospital systems under the Health Insurance Portability and Accountability Act (HIPAA).

Prior to onboarding healthcare workflows, we execute a comprehensive Business Associate Agreement (BAA) formalizing our administrative, technical, and physical safeguards:

  • Minimum Necessary Standard: Healthcare SDRs and medical billers access only the minimal fields required to complete insurance verification or prior authorization.
  • Annual Workforce Testing: Every team member assigned to healthcare accounts completes mandatory annual HIPAA recertification with background checks.
  • Immediate Breach Notification: Contractual commitment to provide written notice to client Covered Entities within 24 hours of any verified security incident involving ePHI.

Section 06

6. Subprocessors & Third-Party Infrastructure

To maintain 99.8% SLA operational availability, we collaborate with vetted, tier-1 technology partners bound by data protection agreements (DPAs) that match or exceed our own standards:

  • Cloud Infrastructure: AWS (US East & West) and Microsoft Azure for high-availability database replication and redundant compute clusters.
  • Telephony & WebRTC: Certified telecom carriers providing dedicated SIP trunking, TLS-encrypted signaling, and SRTP media streams.
  • Physical Security: Centro Empresarial San Roque (Cajicá/Bogotá) featuring 24/7 armed security patrols, biometric access checkpoints, and industrial backup generators.

Section 07

7. Client Data Sovereignty & Consumer Privacy Rights

Our clients retain absolute sovereignty over their data assets. You maintain the right to:

  • Right of Access & Portability: Request automated exports of all customer records, call transcripts, and performance telemetry in standard JSON/CSV format.
  • Right to Rectification: Request correction of any inaccurate contact or customer demographic records.
  • Right to Erasure ("Right to be Forgotten"): Direct the cryptographically validated purging of customer records in compliance with CCPA and GDPR frameworks.
  • Right to Audit: Request executive summaries of our annual SOC 2 Type II audit attestations, vulnerability scans, and disaster recovery exercise logs.

Section 08

8. Data Retention & Secure Cryptographic Destruction

Client operational records and call audio logs are retained strictly in accordance with client-defined Statements of Work (SOWs) or applicable statutory mandates (e.g., 7-year retention for CMS health insurance records).

Upon expiration or termination of a client contract, all client proprietary files, databases, and encryption keys are securely wiped following DoD 5220.22-M and NIST SP 800-88 sanitization standards, followed by issuance of a formal Certificate of Destruction.


Section 09

9. Data Protection Officer & Regulatory Inquiries

For inquiries regarding our privacy standards, Business Associate Agreements (BAA), or to exercise data sovereignty rights, please contact our Data Governance and Privacy Office:

Data Protection & Compliance Office

Rocket Multi Services Inc.
Legal & Compliance Division
Email: privacy@rocketservicios.com  |  info@rocketservicios.com
Rocket
1