Objectives and success criteria: define what you want LiveCall to achieve (e.g., better lead capture, proactive calling, appointment scheduling, chat-to-call routing).
Stakeholders and roles: product, marketing, sales, IT, compliance.
Dedicated account management: for large teams, often part of enterprise packages.
Training and enablement
Training bundles: live training sessions, on-site or virtual, usually priced separately if not included.
Training
Training options
Onboarding training (live): guided sessions for admins and end-users covering setup, integrations, routing, and best practices.
Product tours and in-app guidance: step-by-step prompts, checklists, and contextual tips within the UI.
Webinars and group trainings: scheduled sessions focusing on features like chat widgets, click-to-call, scheduling, and reporting.
Self-service resources: a knowledge base, FAQs, API docs, and release notes.
Role-based training tracks: separate content for admins, agents, and supervisors.
Playbooks and best practices: templates for call scripts, qualification criteria, and escalation paths.
** certifications or competency checks**: optional quizzes or badges to verify proficiency.
Support options
Included support levels: standard support with business hours, access to knowledge base, and community forums.
Response-time SLAs: defined targets (e.g., P0 defects within 1–2 hours, P1 within 4–8 hours) depending on plan.
Premium/support add-ons: 24/7, priority response, or dedicated account management.
Support channels: email, chat, phone, and a support portal with ticket tracking.
Health checks and success reviews: periodic check-ins to review adoption, usage metrics, and ROI.
Technical onboarding: assistance with integrations (CRM, helpdesk, analytics), data mapping, and migration support.
User enablement materials: playbooks, training videos, and quick-start guides.
Change management and enablement
New feature training with release notes and impact guidance.
Change impact communications: advance notice for major updates, deprecation notices, and migration guidance.
Optional enablement sprints: focused sessions to implement new capabilities or reconfigure workflows.
Security Measures
Data protection and access control
Role-based access control (RBAC): granular permissions by role (admin, supervisor, agent, viewer).
Multi-factor authentication (MFA): to secure admin and user accounts.
Single Sign-On (SSO): SAML or OIDC integration for centralized authentication.
Data transmission and storage
Encryption in transit: TLS 1.2+ for data transmitted between users, browsers, and services.
Encryption at rest: data stored in encrypted form, with key management practices
Secure call handling: protections around recording data, access controls, and in-transit protection for audio data.
Compliance and governance
Data retention policies: configurable retention periods for recordings, transcripts, and logs.
Data minimization and access logging: audit trails of who accessed what data and when.
Do-Not-Call and consent management: synchronization with consent lists and compliance flags.
Data export and deletion rights: ability to export data for compliance requests and to delete data per policy or regulatory requirements.
Privacy and security practices
Regular security assessments: vulnerability scans, penetration testing, and third-party audits.
Incident response: defined process and SLAs for security incidents.
Backup and disaster recovery: data backups, RPO/RTO targets, and recovery plans.
Network security: isolated environments (sandbox/production), IP allowlists, and anomaly detection.
Updates
Update cadence
Regular release cycles: monthly or quarterly minor releases with bug fixes and small features.
Major releases: less frequent, typically announced in advance with deprecation timelines.
Emergency patches: critical fixes deployed as soon as they’re ready.
Change management and communicatio
Release notes: detailed documents outlining new features, improvements, fixed issues, and any breaking changes.
Backward compatibility considerations: guidance on how updates affect existing workflows and integrations.
Deprecation notices: advance notice for sunset of features or APIs, with migration guidance.
Deployment and testing
Staging/sandbox environment: separate environment to test updates before production.
Pilot programs: optional early access for a subset of customers to validate changes.
Rollback plan: defined procedure to revert if an update causes issues.
Customer impact and planning
Maintenance windows: scheduled times for updates to minimize disruption.
Impact assessment: documentation on how updates affect integrations, workflows, and data mappings.
Support during updates: enhanced support channels around release days.
Data Ownership and Portability
Data ownership
You own your data: In most cases, customers retain ownership of all data generated within the platform (contacts, leads, chats, call recordings, transcripts, analytics data, etc.).
Vendor holds data on behalf of customer: The platform acts as a data processor/holding service for the customer’s data.
Data access and control
Data access rights: Customers typically have access to their own data via the UI and API, subject to RBAC.
Data export rights: Most agreements include the right to export your data upon request, including export formats (CSV, JSON, etc.) and full data exports of key objects (contacts, leads, calls, transcripts, recordings, chat transcripts).
Data deletion rights: Customers can request deletion of personal data or complete data erasure in compliance with data retention policies and regulatory requirements (e.g., GDPR, CCPA).
Data portability
Standard data formats: Data should be exportable in standard formats for interoperability with other systems.
API access: Ongoing API access to retrieve data, subject to rate limits and authentication.
Data retention after termination: Clear policy on how long data remains accessible post-termination, and how it is securely deleted after that period.
Data retention and deletion
Retention policies: Configurable retention periods for recordings, transcripts, logs, and messages.
Secure deletion: Shredding or cryptographic deletion processes to ensure data is unrecoverable after retention period or upon customer request.
Scaling Up / Down
Scaling up (growth scenarios)
User seats and licenses: Add more seats/users; pricing adjusts accordingly.
Feature tiers: Access to higher-tier features (advanced routing, more extensive analytics, larger call volumes).
Capacity considerations: Increased concurrent sessions, call minutes, recording storage, and API usage.
Implementation impact: Potential onboarding time for new teams, additional training, and possible integration expansion.
Scaling down (downsizing scenarios)
Flexible licensing: Reduce number of seats, agents, or channels; prorated adjustments where applicable.
Data retention adjustments: Shorten retention periods if data volume must be reduced.
Resource optimization: Decommission unused integrations or widgets to lower costs.
The terms & conditions for contract renewal and cancellation
Renewal type: auto-renewal by default unless canceled; renewal notice period required (e.g., 30–90 days).
Pricing at renewal: Known, historical, or market-based pricing; any cap or escalation (e.g., "no more than 5% YoY" or standard CPI-based adjustments).
Term length at renewal: Same term as initial, or option to adjust term length.
SLA and support alignment: Renewed SLAs and support levels, possibly with updated terms.
Cancellation/termination
Notice period: Required advance notice to terminate (e.g., 30–90 days before renewal date).
Termination for convenience vs. for cause: Whether you can cancel without cause and any notice window; termination for cause (breach) with cure period.
Data export rights on termination: Timeline and method to export data after termination.
Data deletion on termination: How and when data is securely deleted post-termination, and any retention for compliance purposes.
Outstanding obligations: Payment of any remaining balance, final invoicing, and handling of prorations.
Transition support: Availability of transition assistance (e.g., data export services, onboarding for a new provider) during/after termination.
Compliance
ISO/IEC 27001: Information security management system (often accompanied by ISO 27018 for cloud privacy).
ISO/IEC 27017: Cloud-specific security controls (sometimes bundled with 27001).
SOC 2 Type II (and SOC 3): Security and availability controls, often with a focus on the Trust Service Criteria (CC, CC1–CC9 variants).
SOC 2 Type I vs Type II: Type II covers operating effectiveness over a period; many customers require Type II.
HIPAA/HITECH (if applicable): For healthcare-related data; requires business associate agreements (BAA) and specific safeguards.
GDPR compliance measures: Data processing agreements, data subject rights handling, data localization where applicable, and DPIAs.
CCPA/CPRA readiness (if applicable): Consumer rights and data handling in California.
PCI DSS (if handling payment data): Not always applicable unless payments are processed or stored.
Privacy certifications: EU-US/Swiss-US Privacy Shield (note: shield frameworks evolved; rely on GDPR-compliant transfers and SCCs for data transfers).