Governance
Proof of Consent
This statement explains how Qytherion AI captures, verifies, stores, and furnishes proof of consent for Qytherion AI automations, call center workflows, workspace provisioning, billing, and customer communications.
Why proof of consent matters
Qytherion AI orchestration, campaign execution, and billing changes are gated by authorization events. Proof of consent creates a verifiable chain showing who approved what, when approval occurred, and which system state was in effect at that moment.
A reliable consent ledger protects customer autonomy, reduces dispute friction, and supports lawful operations when audits, provider reviews, or regulatory inquiries occur.
Consent checkpoints we record
- Workspace onboarding: Identity verification events, owner confirmation, accepted legal terms version, and onboarding approval timestamps.
- Automation launches: Approver identity, workflow snapshot hash, selected agent(s), queue context, launch window, and any policy gates passed at submit time.
- Call/SMS campaign authorization: Consent-source references, campaign channel, opt-in/opt-out state, and suppression checks used before contact attempts.
- Billing and plan changes: Payment intent confirmation, add-on authorizations, seat expansion approvals, invoice acknowledgements, and related account events.
- Privacy and marketing preferences: Email/SMS/analytics preferences with immutable history of opt-in, opt-out, and preference-change events.
- Delegated admin actions: Approvals made by authorized admins are logged with actor identity and privilege scope at time of action.
Evidence model and chain-of-custody
Consent evidence is stored in a controlled audit datastore with integrity safeguards designed for traceability and review.
- Event schema: Each event contains actor, action, target object, timestamp, channel, and correlation identifiers.
- Context capture: We attach relevant context such as IP address, user agent, account role, and workflow metadata where available and permitted.
- Integrity controls: Records are append-only in the audit stream; modifications are tracked as superseding events rather than silent overwrite.
- Access controls: Audit access is limited to authorized personnel with logged access and role-based permissions.
How to request proof of consent
Authorized requesters can obtain a consent evidence packet for operational, compliance, or dispute purposes.
- Submit a request from the account dashboard or by emailing [email protected] with subject line "Proof of Consent Request."
- We verify requester authority (account owner, authorized admin, or regulator/partner with documented entitlement).
- We define scope: workspace, campaign, invoice, contact channel, and date range.
- We compile consent events and supporting metadata, then apply legally required redactions.
- We deliver the packet as signed PDF and/or structured JSON bundle based on request needs.
Standard response targets: acknowledgement within 1 business day and delivery within 5 business days for routine scopes.
Complex, multi-workspace, or regulator-bound requests may require additional time; we provide status updates and expected delivery timing.
Packet contents and delivery formats
Proof packages are tailored to the requested scope and may include:
- Consent event timeline with UTC timestamps
- Approver identity and role at time of approval
- Approval channel (dashboard, email confirmation, API event, integration callback)
- Workflow/campaign identifiers and snapshot references
- Contact preference or opt-in/opt-out history where relevant
- Billing or invoice-linked approval references where applicable
Delivery options include signed PDF summary, machine-readable JSON bundle, and scoped CSV extracts for audit reconciliation. Sensitive attributes may be masked where legally required.
Retention schedule
Consent records are retained while a workspace is active and for a minimum of two (2) years after closure. Longer retention may apply when required by financial, contractual, telecom-provider, dispute, or regulatory obligations.
Where no legal hold applies, qualified accelerated deletion requests may be processed after reconciliation, subject to limitations described in our Data Retention policy.
Backup copies may persist for the backup retention window before final expiry.
Use in disputes and regulator requests
When consent events are requested for dispute resolution or regulator response, we provide scoped records and supporting metadata sufficient to validate authorization history.
Where lawful and contractually permitted, we may provide attestation letters confirming extraction scope, event source, and delivery timestamp.
Contact
Need a copy of your consent log or have questions about a specific approval event? Contact [email protected] with subject line "Proof of Consent Request" and include the relevant workspace email, campaign identifier, or invoice number.
For full process details, visit the Consent Requests guide for checklist, request templates, timelines, and delivery formats.