Do Not Call
Settings → Compliance → Do Not Call list is the org-wide blocklist. Numbers here are blocked across every program. Opt-outs captured on a call propagate within about 60 seconds and block in-flight retries. Anyone who has opted out is not contacted again.Audit log
Settings → Compliance → Audit log is a seven-year record of compliance-relevant events — opt-ins, opt-outs, and policy edits. You can export it as CSV.HIPAA and your BAA
Handling protected health information requires a signed Business Associate Agreement between your organization and Rivvi. A BAA is included — it is not an upsell. The gate is a signed BAA (signed on file), not the presence of a PDF. PHI outreach — most notably Echo referral calling — stays off until that signature is in place. Connecting tools and asking questions in chat still work.
You can:
- Complete the BAA during Teach Rivvi
- Download the current agreement from Compliance
- Upload a signed PDF, DOC, or DOCX (up to 25 MB) with an attestation. Uploads are encrypted, visible to org admins, and written to the audit log.
Data and security
On the same Compliance page:- Storage region — US East (Virginia)
- Encryption — AES-256 at rest, TLS 1.3 in transit
- Retention schedules and the vendor list that can touch PHI — Trust Center. Request the sub-processor list under NDA from there.
Web search
Admins can let the coworker look up public web pages during chat. It is off by default and lives on Compliance.Outreach guardrails (always on)
- You approve every launch. Nothing dials until you click the launch card. See Runs.
- Opt-outs are respected — captured on a call, they land on the Do Not Call list.
- Calling hours are enforced from Settings → Calling.