The implementation of an enterprise communication platform like Whispir follows a structured methodology to ensure seamless integration and alignment with specific business objectives. The total duration is highly variable, generally ranging from 4 to 12 weeks, depending on the complexity of required integrations, the number of internal systems involved, and the scope of custom workflow development.
Overview
The process typically begins with understanding the client's current communication landscape and defining success metrics. This is followed by technical configuration, setting up necessary integrations, extensive testing, and training. The project concludes with the launch and a post-implementation review to ensure the solution is operating optimally and delivering the expected value. The greatest variable in duration is the complexity of data migration and the number of custom API integrations with existing enterprise software (e.g., CRM, ERP, HR systems).
Bullet Points
Discovery and Planning (1-2 Weeks): Kick-off meetings, requirement gathering, defining use cases (e.g., crisis communications, service updates), establishing success criteria, and mapping out required data flows and integrations.
Platform Configuration and Setup (2-4 Weeks): Setting up the environment, configuring user roles and permissions, establishing communication channels (SMS, email, voice, WhatsApp), and creating initial branded templates using the Message Builder.
Integration and Development (2-6 Weeks): Connecting the platform to existing core business systems via APIs or pre-built connectors. Developing and testing complex, automated Workflows and communication triggers.
User Acceptance Testing (UAT) and Training (1-2 Weeks): Comprehensive testing of all configured workflows and integrations by client teams. Providing end-user and administrator training to ensure proficiency and adoption.
Go-Live and Post-Implementation Review (Ongoing): Final deployment, continuous monitoring, and optimization of the platform based on early performance Reporting and feedback.
Customisation
The platform allows for deep customization primarily through its Automated Workflows engine and its extensive Integration capabilities. Users can design intricate, multi-channel communication flows that are triggered by specific events within their existing systems (e.g., a service outage, an appointment change, or a marketing segment reaching a threshold). Furthermore, the Message Builder enables complete brand consistency across all channels, ensuring every message aligns with the corporate identity and tone of voice. This focus on tailored workflows and robust integration is central to its enterprise-grade functionality.
Bullet Points
Custom Automated Workflows: Ability to build unique, multi-step communication logic that automatically sends alerts, updates, or requests for action based on defined triggers and conditions, such as sending an SMS, waiting for a response, and then escalating via a voice call or email.
API and Connector Integration: Customization through integrating the platform with virtually any existing enterprise system (CRM, ERP, ticketing systems, etc.) using RESTful APIs or specific connectors, allowing for seamless data exchange.
Branding and Template Customization: The Message Builder allows for the creation of fully branded and mobile-responsive communication assets, including emails, landing pages, and forms, ensuring consistency across all outbound communications.
User Access and Role Configuration: Customizing user access levels and roles to align with organizational structure and safety/compliance requirements, ensuring only authorized personnel can manage specific communication campaigns or access sensitive data.
Additional Costs
In addition to the core subscription or licensing fee—which is often based on the number of users, communication volume, or features included—clients should expect separate costs related to initial implementation and ongoing usage. The most common additional costs are a Setup/Implementation Fee to cover professional services and configuration, and potential Usage/Consumption Charges for high-volume communications (e.g., SMS messages, voice calls) that exceed a bundled allowance. While Maintenance and Standard Support are generally included in the subscription fee for SaaS platforms, premium support or advanced maintenance may incur extra charges.
Bullet Points
Setup/Implementation Fee: A one-time charge covering the cost of professional services, which includes project management, platform configuration, initial technical integration with existing systems, and dedicated end-user training. This fee is mandatory for complex enterprise rollouts.
Usage/Consumption Charges: Fees applied when the client's communication volume (e.g., number of SMS, voice minutes, or rich messaging interactions) exceeds the monthly allocation included in their subscription tier. This makes the total monthly bill variable.
Premium Support and Service Level Agreements (SLAs): While standard 24/7 technical support is usually part of the subscription, clients may opt for an uplifted service, such as a dedicated Technical Account Manager, faster response times, or enhanced System Status monitoring, for an additional recurring fee.
Custom Development and Maintenance: Additional costs may be incurred for developing highly specialized, one-off integrations or complex custom features not covered by the standard platform functionality, as well as the ongoing maintenance of such custom code.
Training
Training typically begins during the platform's initial implementation phase, focusing on the client administrators. The goal is to make the platform's drag-and-drop, low-code/no-code interface easy to master. Support is multi-tiered, ranging from self-service resources to direct, professional assistance for immediate operational issues. This approach ensures both foundational knowledge transfer and rapid resolution of live problems.
Detailed Bullet Points
Dedicated Client Administrator Training: Client administrators are the primary focus of initial training. They receive in-depth instruction on platform configuration, setting up permissions, managing distribution lists, and designing both standard and custom workflows, enabling them to support internal users.
Online Support and Knowledge Base: Access to an online Resource Library, a comprehensive Knowledge Base, and a Support & FAQ portal provides self-service assistance, offering documentation and how-to guides for common tasks and features.
Professional Services and Account Management:Whispir consultants and dedicated Account Management teams work with clients to tailor the platform and maximize its value. Solutions Architecture services are also available to assist with complex use cases and long-term innovation strategy.
Template Library and Out-of-the-Box Solutions: New users gain immediate access to a large library of pre-built templates based on industry best practices and common use cases, allowing them to quickly launch effective communications without needing to build workflows from scratch.
Direct Technical Support: Standard technical support is provided, typically accessible via dedicated phone lines and help desks, with the primary service being directed to the trained client administrators for issue resolution.
Security Measures
The security architecture relies on an ISO 27001-certified program, which mandates continuous security controls and audits. Key measures include encrypting data both while it is being transmitted and while it is stored, strict access controls based on the principle of least privilege, and comprehensive incident response plans. Data sovereignty options also allow customers to select the geographic region for their data storage, meeting specific regulatory requirements.
Detailed Bullet Points
Data Encryption (In-Transit and At-Rest): Data is secured during transmission using industry-standard protocols, typically TLS 1.2 or higher. Data at rest (stored data) is protected using strong encryption standards like AES-256.
Access Control and Least Privilege: Access to customer data and production environments is strictly limited to a small number of authorized staff who demonstrate a documented "need-to-access." Passwords are never stored in plain text but are hashed and stored securely.
Compliance and Independent Audit: The company maintains a comprehensive information security program aligned with standards like ISO 27001, which is independently audited. It also conducts security assessments, such as the one validated by CyberGRX/KPMG, to assure customers of its security posture.
Vulnerability Management and Penetration Testing: A proactive vulnerability management program uses regular host and web application scanning, as well as penetration testing conducted before significant IT changes, to identify and remediate security flaws quickly.
Data Sovereignty: Customers have the option to choose the specific region or territory where their Whispir account is hosted. Once a customer is "homed" to a region, their data does not leave that jurisdiction, aiding in compliance with regional data residency laws.
Security Incident Response: Processes are aligned with established frameworks like NIST guidelines for incident handling, ensuring a dedicated security team can effectively manage, coordinate, and respond to any security breach.
Updates
Updates are typically managed centrally by the vendor and deployed continuously. For security-related patches, updates can occur several times a day as necessary to counter evolving cyber threats. For new features and larger functional releases, a regular cadence is maintained, often monthly or quarterly. The nature of SaaS ensures that all customers are running the latest version, which simplifies maintenance and ensures rapid access to new capabilities.
Detailed Bullet Points
Continuous Security and Patch Updates: Security patches and minor bug fixes are deployed frequently, often in a continuous delivery model, sometimes multiple times a day, to immediately address vulnerabilities and ensure system stability.
Regular Feature Releases: The platform releases major feature updates on a predictable and regular cadence, which may be monthly or quarterly. These updates typically introduce new functionalities in areas like Automated Workflows, new channel support (e.g., a new messaging app), or enhancements to the Reporting engine.
Centralized Management: All updates are managed, tested, and deployed by the vendor. Because it is a cloud platform, no installation or downtime is typically required on the client side, ensuring a seamless user experience.
Client Notifications and Documentation: Customers, particularly client administrators, are informed of upcoming feature updates through release notes, documentation updates in the Resource Library, and internal communications to ensure they can take advantage of the new capabilities.
Version Control for Custom Assets: Key features, such as the Rich Message Studio, often include versioning capabilities, allowing administrators to manage and roll back changes to their custom templates and assets independently of the core platform updates.
Data Ownership and Portability
Data ownership is unequivocally with the customer, who is considered the data controller. The company commits to not using, selling, or disclosing the customer's personal information outside of the direct business relationship and the defined purposes of providing the service. In terms of portability, the policy aligns with major regulations like GDPR, ensuring customers and individuals can obtain their personal data in a usable, machine-readable format to transfer it to another service provider. This approach prevents vendor lock-in and promotes data sovereignty.
Detailed Bullet Points
Customer Data Ownership: The customer, not the software vendor, retains full legal rights and ownership of all customer-provided data, including contact details, message content, and communication history.
Role as Data Processor: The software acts as a data processor, handling and processing the data solely according to the customer's instructions and the terms of the service agreement, while adhering to all relevant data protection laws.
Compliance with Portability Rights: The policy is structured to meet the requirements of the Right to Data Portability under regulations like GDPR, which grants individuals the right to receive their personal data in a structured, commonly used, and machine-readable format.
Data Export Facilitation: The software supports the transfer of data, either directly to the individual or, where technically feasible, to another data controller/service provider, thereby avoiding unnecessary hindrance to the data's movement.
Data Use Limitation: The company explicitly commits to not selling, renting, or otherwise communicating customer personal information to third parties for monetary or other valuable consideration, except as necessary to deliver the service.
Scaling Up / Down
Scaling the platform, both up and down, is managed through adjustments to the customer's service agreement, which typically involves consumption-based components (like message volume or API usage) and fixed components (like user licenses and platform modules). Scaling up is generally an immediate process to meet increased demand, while scaling down is usually handled with a more structured approach, often aligned with contract renewal periods. This structure allows the platform to support everything from unexpected emergency communications to sustained organizational growth.
Detailed Bullet Points
Modular Subscriptions and Feature Scaling: Customers subscribe to a core platform and can add or remove additional modules (e.g., Maps, Events, Voice capabilities) as their operational needs change, allowing for feature-based scaling.
Volume and Usage Adjustments (Scaling Up): Scaling up, often needed for rapid growth or unexpected high-volume events (like crisis communications), is typically immediate by increasing message quotas, contact numbers, or API capacity, with billing adjusted accordingly.
User License Adjustment: The organization can scale the number of authorized users (Company Administrators, Company Members, etc.) up or down to reflect changes in workforce size or functional roles requiring platform access, with licensing costs adjusted on a per-user basis.
Contractual Review for Scaling Down: Scaling down fixed contractual elements (like core modules or subscription tiers) is handled through a review of the service agreement, often requiring negotiation or execution at the next contractual renewal date to ensure compliance with minimum commitments.
"Pay-as-You-Grow" Model: The underlying cloud-based architecture and associated pricing models support a "pay-as-you-grow" approach for consumption elements, allowing for efficient cost management that aligns with actual usage, such as message volume across channels (SMS, Email, Voice).
The terms & conditions for contract renewal and cancellation
The core of the agreement is the Committed Term, after which the contract may either be renewed or continue indefinitely. The key mechanism for avoiding automatic renewal is a written notice of non-renewal that must be provided within a specified period (e.g., 30 days) before the end of the Committed Term. If a customer wishes to cancel after the Committed Term has passed, the contract typically reverts to an indefinite term that requires a similar written termination notice. Termination outside of these terms is often reserved for material breaches of contract by either party.
Detailed Bullet Points
Committed Term: All service agreements begin with a defined minimum commitment period, which is set out in the initial application or contract form.
Non-Renewal Notice: To prevent the automatic continuation of the contract beyond the Committed Term, written notice of non-renewal must be provided to the company by the customer (or vice versa) a specified number of days (e.g., at least 30 days) prior to the expiration date of the current term.
Automatic Continuation: If neither party provides the required non-renewal notice, the agreement does not expire and typically continues on an indefinite basis (e.g., month-to-month or a new fixed term).
Indefinite Term Termination: Once the contract is in an indefinite term, either party can terminate the agreement by providing the other party with a specified period of written notice (e.g., 30 days written notice).
Cancellation for Cause: Either the customer or the software provider can typically terminate the agreement immediately upon written notice to the other party in the event of a material breach of the contract that is not remedied within a certain timeframe.
Notice of Cancellation: All official notices for non-renewal or termination must be submitted in writing, often to a dedicated email address or official company address designated for cancellations.
Compliance
The software meets a range of international and regional compliance standards, which demonstrates its commitment to operating a secure and privacy-respecting platform. The key compliance achievements are centered on international standards for information security management and adherence to major global data privacy regulations, which is critical for its customer base that often handles sensitive communications across multiple jurisdictions.
Detailed Bullet Points
ISO/IEC 27001 Certification: The software maintains certification for ISO/IEC 27001, the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This ensures systematic management of information security risks.
ISO/IEC 27018 Certification: It also holds certification for ISO/IEC 27018, a code of practice for the protection of Personally Identifiable Information (PII) in public clouds acting as PII processors. This is crucial for its role in managing customer data.
EU General Data Protection Regulation (GDPR) Compliance: The platform's policies and operational practices are aligned with the GDPR, ensuring the lawful, fair, and transparent processing of personal data for users in the European Union and the European Economic Area.
California Consumer Privacy Act (CCPA) Compliance: The software commits to meeting the obligations outlined in the CCPA, addressing the privacy rights of California consumers.
Australian Privacy Act 1988 Compliance: The company adheres to the requirements of the Australian Privacy Act, which governs the handling of personal information in Australia.
Singapore Personal Data Protection Act (PDPA) Compliance: The platform's operations also align with the PDPA, addressing the protection of personal data in Singapore.