Introduction
SIPSTACK Inc. ("SIPSTACK", "we", "us", or "our") is a telecommunications and AI software company incorporated in Canada with its principal place of business at 575-3093 Bathurst St., Toronto, ON M6A 2A3. This Privacy Policy applies to all SIPSTACK products and services, including Nova PBX, Flare SMS, Aura AI, SARA AI, Pulse, and Switchboard (collectively, the "Services").
This policy explains what personal information we collect, why we collect it, how we use and share it, how long we keep it, and your rights regarding your data. By using our Services, you agree to the collection and use of information in accordance with this policy.
If you have questions, contact our Privacy Officer at [email protected] or our Data Protection Officer (EU/UK matters) at [email protected].
Information We Collect
Information You Provide Directly
When you register for an account, subscribe to our Services, or contact our support team, you may provide:
- Identity information: Name, job title, company name
- Contact information: Email address, phone number, mailing address
- Account credentials: Username, password (stored as a one-way hash — we never store plaintext passwords)
- Billing information: Billing address and payment method details. Payment card data is processed directly by Stripe and is not stored on SIPSTACK servers.
- Support communications: Messages, tickets, and attachments you send to our support team
Information Collected Automatically
When you use our Services, we automatically collect:
- Technical data: IP address, browser type and version, operating system, device identifiers
- Usage data: Pages viewed, features used, time spent, referring URLs, click patterns
- Log data: Server access logs, error logs, API request/response metadata
- Cookies and tracking technologies: See our Cookie Policy for full details
Information Collected Through Our Products
The specific data we collect depends on which SIPSTACK products you use:
Nova PBX
Nova PBX is our cloud phone system. When you use Nova PBX, we collect:
- Call Detail Records (CDRs): Caller/callee phone numbers, call duration, timestamps, call disposition, and routing path
- Call recordings: Audio files of recorded calls (if recording is enabled). Recordings are stored in Wasabi S3 with regional routing based on your billing currency. See Call Recording Disclosure for consent obligations.
- Voicemail: Audio files and, where enabled, transcriptions of voicemail messages
- SIP registration data: Device IP addresses, SIP user agents, registration timestamps, device MAC addresses
- PBX configuration: Extensions, ring groups, IVR menus, queues, time conditions, call routing rules, device provisioning data
- AI-processed data (feature availability varies by tier):
- Transcription: Real-time and post-call transcripts generated from call audio (all tiers)
- Sentiment analysis: AI-generated sentiment scores applied to call transcripts (Nova Ultra; Enterprise where enabled)
- Call summarization: Automated summaries of call content (Nova Ultra; Enterprise where enabled)
- Speaker diarization: Speaker identification in multi-party calls (Nova Ultra; Enterprise where enabled)
- AI data retention: 180 days (Nova Ultra; Enterprise where enabled)
Flare SMS
Flare SMS is our business messaging platform. We collect:
- Contact data: Phone numbers, names, email addresses, custom fields, tags, and list memberships for contacts you import or create
- Message logs: Content, sender/recipient numbers, delivery status, timestamps, and direction (inbound/outbound) for all SMS and MMS messages
- Campaign data: Broadcast content, scheduled times, audience lists, A/B test variants, drip campaign steps, and delivery analytics
- Opt-out records: STOP/UNSUBSCRIBE responses and suppression list memberships to enforce messaging compliance
- Template library: Message templates you create
- Webhook delivery logs: Outbound webhook payloads, delivery attempts, and response codes (HMAC-signed)
Aura AI
Aura AI is our voice agent platform (Enterprise tier). We collect:
- Voice call audio: Real-time audio input processed by our Automatic Speech Recognition (ASR) engine (Parakeet) to generate transcripts during active calls
- Transcripts: Text transcriptions of interactions with AI voice agents
- LLM-generated responses: Outputs from our large language model inference pipeline
- TTS audio: Text-to-speech audio generated to respond to callers
Voice call audio is processed in real time and is not retained beyond the call session unless call recording is separately enabled on the associated Nova PBX extension.
SARA AI
SARA AI is our intelligent auto-responder for email support and SMS conversations. We collect:
- Customer email content: Inbound emails forwarded to SARA for processing, including full message body and headers
- SMS message content: Inbound SMS/MMS messages processed by SARA auto-reply (when enabled on a Flare SMS number), including message body and sender phone number
- Conversation history: Full email thread and SMS conversation context tracked per ticket or conversation, stored in our internal database
- Vector embeddings: Semantic representations of conversation content used for knowledge base retrieval (stored in our self-hosted pgvector database — not shared externally)
- AI-generated draft responses: Draft replies created by SARA for human review before sending (email) or auto-sent based on confidence thresholds (SMS)
Knowledge base learning: When a support ticket is resolved, SARA may extract generalized question-and-answer content from the resolution to add to its knowledge base. This content is generalized to remove personal information (names, account numbers, phone numbers, IP addresses, billing amounts) and must pass a human review and approval process before it becomes available for future knowledge retrieval. This is retrieval-augmented generation (RAG) — not model weight training. No personally identifiable information is retained in the knowledge base. Enterprise customers may opt out by contacting [email protected].
Important note regarding Together AI: When SARA generates a response to a support email, a portal chat message, or an SMS, the message content and the retrieval context assembled for that reply are sent to Together AI's API (a US-based AI inference provider) for large language model inference. Together AI is currently the primary language model for SARA text responses on all three of those surfaces. Our self-hosted models handle voice-agent language processing and all retrieval embeddings, which are not shared externally. We intend to move SARA text inference onto self-hosted GPU infrastructure and eliminate this transfer; we have not committed to a date. See AI Data Processing and Data Sharing and Sub-Processors for full details.
Pulse (Mobile App)
Pulse is our mobile UCaaS application for iOS and Android. We collect:
- Authentication tokens: JWT access tokens (30-day expiry) and refresh tokens (90-day expiry), stored in your device's hardware-backed secure storage (iOS Keychain / Android Keystore via expo-secure-store)
- SIP credentials: Your extension SIP username and password, delivered over HTTPS and stored encrypted
- TURN credentials: Ephemeral ICE/TURN credentials with 5-minute TTL for WebRTC connectivity — not persisted
- Push notification tokens: Device push tokens (APNs/FCM) for incoming call notifications (when push notifications are enabled)
- WebRTC session data: ICE candidates, session description protocol (SDP) used for establishing encrypted media sessions — not stored after session ends
Switchboard (Customer Portal)
Switchboard is the web portal used by administrators and end users to manage their SIPSTACK account. We collect:
- Session data: Authenticated sessions stored in our database with expiry management
- User profiles: Name, email address, role, organization membership, and assigned permissions
- Audit trails: Administrative actions, login history, account changes, and impersonation events (for support purposes)
- Billing interactions: Invoice views, payment method updates, subscription changes
How We Use Your Information
We use the information we collect to:
- Provide and operate the Services: Deliver calls, route messages, process AI tasks, authenticate users, manage subscriptions, and generate invoices
- Maintain and improve the Services: Monitor system performance, diagnose issues, prevent abuse, and develop new features
- Communicate with you: Send transactional notices (receipts, password resets, security alerts, service status updates), and with your consent, marketing communications about new features or products
- Ensure security and prevent fraud: Detect suspicious activity, enforce rate limits, block abusive traffic, and maintain network integrity
- Comply with legal obligations: Respond to lawful requests from authorities, fulfill regulatory reporting requirements, and meet telecommunications regulatory obligations
- Analytics: Generate aggregated, anonymized usage statistics to understand platform adoption and guide product decisions. We do not use individual-level behavioral profiling for advertising purposes.
- AI knowledge base improvement: We may extract generalized, de-identified question-and-answer content from resolved support tickets to add to SARA's retrieval knowledge base. This extraction is generalized by AI and reviewed by a human administrator before it is published. It is used for retrieval-augmented generation (RAG) only — not for training model weights. No raw personal data (names, email addresses, phone numbers, account details) is retained in the knowledge base. Enterprise customers may opt out by contacting [email protected].
Customer Testimonials
If you choose to submit a customer testimonial through your account, we collect the content you provide (your star rating, written testimonial, name, job title, company name, and any logo you upload) along with consent evidence — your identity and the IP address, user-agent, and timestamp of your acceptance. We use this information to publish and promote your testimonial across our marketing surfaces in accordance with the Customer Testimonial & Logo Release you accept at submission. This data may be processed and stored in the United States. If you are a Canadian customer, you may withdraw your consent and request removal of your testimonial from SIPSTACK-controlled marketing surfaces at any time, and we will honor such requests on a forward-looking basis as described in the Release.
Call Recording Disclosure
Nova PBX allows you to enable call recording on your extensions, queues, and inbound routes. Call recording laws vary by jurisdiction. In some jurisdictions (including Canada, and US states such as California, Florida, Illinois, and Pennsylvania), recording a call requires the consent of all parties. You — not SIPSTACK — are responsible for:
- Determining the consent requirements that apply to your calls based on your location and the location of the called party
- Configuring and playing recording announcements to all parties before recording begins
- Obtaining any required consent
SIPSTACK provides configurable recording disclosure announcements through Nova PBX to help you meet these obligations, but the legal responsibility remains with you as the subscriber.
Call recordings are automatically purged after your tier's retention period:
- Lite: 30 days
- Pro: 90 days
- Enterprise: 365 days
AI Data Processing
SIPSTACK operates both self-hosted AI infrastructure and, for specific features, third-party AI services.
Self-Hosted AI (No External Data Transfer)
The following AI services run exclusively on SIPSTACK-owned infrastructure in Canada. No data is transferred to external parties for these functions:
| Service | Model | Function | |---------|-------|----------| | ASR (real-time) | Parakeet-TDT-CTC-1.1B | Real-time call transcription for Nova PBX and Aura AI | | ASR (post-call) | WhisperX large-v3 | Post-call transcription and speaker diarization | | LLM (voice) | Self-hosted open-source LLM | Language model for the Aura AI voice agent | | Text-to-Speech | Kokoro-82M, Fish Speech v1.5 | Voice synthesis for IVR prompts and AI agents | | NLP | GLiNER, spaCy, BERTopic | Entity extraction, text classification, topic modeling | | Embeddings (RAG) | mxbai-embed-large (pgvector) | Semantic search and knowledge base retrieval for SARA |
Third-Party AI Processing
| Provider | Location | Function | Data Sent | Duration | |----------|----------|----------|-----------|----------| | Together AI | United States | Primary LLM inference for SARA AI text responses (support email, portal chat, SMS) | Customer message content + RAG retrieval context | Ongoing; we intend to migrate this to self-hosted infrastructure and have not committed to a date | | AWS Polly | United States | Text-to-Speech (optional feature) | Text strings for synthesis | Only if enabled | | Google Cloud TTS | United States | Text-to-Speech (optional feature) | Text strings for synthesis | Only if enabled |
Together AI processes data under a data processing agreement with SIPSTACK. Together AI does not use data submitted via API for training their models. We are actively working to eliminate this third-party dependency by deploying dedicated self-hosted GPU infrastructure.
Data Sharing and Sub-Processors
We do not sell your personal information to third parties. We do not share personal information for cross-context behavioral advertising. We share your information only with the following categories of parties:
Sub-Processor List
| Sub-Processor | Location | Purpose | Data Categories Shared |
|---|---|---|---|
| Together AI | United States | Primary LLM inference for SARA AI text responses (support email, portal chat, SMS) | Customer message content, RAG retrieval context |
| Stripe | United States | Payment processing and billing | Billing address, payment method details |
| Bandwidth | United States | Voice carrier, SMS carrier, DID provisioning, E911 | Phone numbers, message content (for delivery), voice routing metadata |
| Wasabi Technologies | Canada (sipstack-ca, ca-central-1) and United States (sipstack-us, us-east-1) | Object storage for PBX media, regionally segregated by billing entity | Call recordings, voicemail audio, MOH, TTS, media files |
| Cloudflare R2 | United States (sipstack-wal, sipstack-fleet) | PostgreSQL WAL archive and internal fleet orchestration logs (system data — not user-generated content) | Database WAL segments, internal job stdout/stderr |
| Cloudflare | Global | CDN, DDoS protection, DNS, Turnstile bot protection | Web traffic, IP addresses |
| Sentry | United States | Application error monitoring | Error messages, stack traces, device metadata, and — for errors raised while handling an API request — the request method, query string, body, and session cookie |
| HyperDX | United States | Application logging and observability | Application and server access logs, error diagnostics, API request/response metadata, IP addresses |
| AWS Polly | United States | Text-to-Speech synthesis (optional) | Text content |
| Google Cloud TTS | United States | Text-to-Speech synthesis (optional) | Text content |
| Expo Application Services (EAS) | United States | React Native mobile app build and distribution | App build artifacts, metadata |
Telecommunications Carriers
We share data with our telecommunications carrier partners (including Bandwidth) as technically necessary to complete calls, route messages, and provide interconnection services. This includes caller and callee phone numbers, call routing data, and message content. These transfers are governed by industry regulations and standards.
Legal Requirements
We may disclose your information when required by law, court order, or lawful process from a governmental or regulatory authority. Where legally permitted, we will notify you before complying with such a request.
Business Transfers
In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the successor entity. We will provide notice before your information becomes subject to a different privacy policy.
Data Retention
| Data Type | Retention Period | Notes | |---|---|---| | Call recordings | Nova Core: 30 days · Nova Pro: 180 days · Nova Ultra: 365 days | Automatically purged by retention worker | | Voicemail | Same as call recordings per tier | Automatically purged | | AI data (Nova Ultra; Enterprise where enabled) | 180 days | Transcripts, sentiment scores, call summaries | | SARA conversation history | Duration of subscription + 30-day cooling-off | Email threads, SMS auto-reply conversations, draft responses | | SARA knowledge base | Indefinite (while platform is active) | Generalized Q&A entries; human-reviewed and approved; no raw PII retained | | Call Detail Records (CDRs) | Duration of subscription + 12 months for export | Anonymized after 7 years for cancelled accounts (env-gated) | | SMS / MMS message logs | Duration of subscription | Available in self-serve data export (last 12 months) | | Application audit logs | 2 years (non-financial) | Financial audit records: 7 years | | Billing and payment records | 7 years | Required for tax and accounting compliance | | Account data after cancellation or trial expiry | Retained while dormant; permanently deleted after 12 months of inactivity | Services suspended immediately; reactivate or export anytime before deletion; deletion honored on request. For-cause / AUP terminations: 30-day retrieval period, then deletion. | | Push notification tokens | Duration of active device registration | Deleted on logout or token refresh |
You may request deletion of your data at any time. See Your Rights and Choices for self-serve options.
Where Your Data Is Stored
SIPSTACK operates a regional data model for user-generated content. The region that processes your calls, messages, voicemail, and recordings is determined by your billing entity (Canadian or U.S.). PBX, SIP routing (nexus), and media processing are regionally separated; cross-region session border controllers (SBCs) carry SIP signaling only — no media (voice/MMS) transits an SBC.
Canada
- Wasabi S3
sipstack-ca(ca-central-1, Toronto): Call recordings, voicemail audio, music-on-hold, TTS audio, and other PBX media for organizations billed under the SIPSTACK Canadian entity (CAD). - Nexus CA SIP cluster (
nexus-ca.sipstack.com): SIP registrations and call signaling for Canadian-region tenants. Voice media (RTP) is established directly between endpoints and the regional media gateway and does not transit U.S. infrastructure. - Self-hosted infrastructure (Canadian data center, Hivelocity Toronto): Primary PostgreSQL database (
ss_main), Redis, MinIO (legacy general object storage — being migrated), all self-hosted AI/ML services (Ollama, WhisperX, Parakeet, Kokoro, pgvector, NLP), and transactional email delivery. Application logging and observability are currently provided by a third-party service outside this infrastructure — see the Sub-Processor List.
United States
- Wasabi S3
sipstack-us(us-east-1): Call recordings, voicemail audio, music-on-hold, TTS audio, and other PBX media for organizations billed under the SIPSTACK U.S. entity (USD). - Nexus US SIP cluster (
nexus-us.sipstack.com): SIP registrations and call signaling for U.S.-region tenants. - Cloudflare R2 (U.S. jurisdiction): PostgreSQL write-ahead log (WAL) archive (
sipstack-wal) and internal fleet orchestration logs (sipstack-fleet). These buckets hold system and operational data; they are not used for user-generated voicemail, recordings, SMS/MMS media, or other customer content. WAL segments may contain incidental row-level data from the primary database — see the residency notice below. - Stripe: Payment processing and billing records.
- Bandwidth: Carrier routing metadata; voice traffic and SMS/MMS content in transit (carrier-required).
- Together AI: Primary SARA AI LLM inference for text responses on support email, portal chat, and SMS (see AI Data Processing).
- Sentry: Application error and crash diagnostic data, including the request context (method, query string, body, session cookie) for errors raised while handling an API request.
- HyperDX: Application logging and observability data — server access logs, error logs, and API request/response metadata emitted by our backend services. This is server-side telemetry only; we do not run a HyperDX browser SDK or session-replay recorder in any SIPSTACK application.
Global (CDN)
- Cloudflare: Web traffic and API requests transit Cloudflare's global edge network for CDN delivery and DDoS protection. Cloudflare does not retain request payloads.
Cross-Border Residency Notice (PIPEDA / Quebec Law 25)
Canadian customers' user-generated content (call recordings, voicemail, music-on-hold, TTS, PBX media) stays in Canada via the regional Wasabi bucket described above. A defined set of data flows for Canadian customers does cross the Canada–U.S. border: the PostgreSQL WAL archive (Cloudflare R2, U.S.), Sentry diagnostic data (U.S.), HyperDX application logging and observability data (U.S.), Together AI LLM inference for SARA text replies on support email, portal chat and SMS (U.S.), Stripe billing data (U.S.), and Bandwidth carrier metadata (U.S.). These transfers are subject to contractual safeguards with each sub-processor and are disclosed here in accordance with PIPEDA Principle 4.8 (Openness). Privacy Impact Assessments for these flows (Quebec Law 25, s. 17) have been drafted and are undergoing legal review. Canadian customers requiring a Data Processing Addendum may review our Data Processing Addendum (Canada) or contact [email protected].
Your Rights and Choices
Self-Serve Data Export (GDPR Article 20 / CCPA Right to Know)
You can request a copy of all personal data associated with your organization through the Switchboard portal:
Switchboard → Account → Privacy → Request Data Export
Your export includes: organization profile, provisioned phone numbers, PBX configuration, contacts, SMS CDRs (last 12 months), call CDRs (last 12 months), voicemail metadata, media file inventory, and billing invoices. The export is packaged as a ZIP archive and delivered via a secure 7-day download link. One export per organization per 24 hours.
Self-Serve Data Deletion (GDPR Article 17 / CCPA Right to Delete)
You can request deletion of specific data categories through Switchboard:
Switchboard → Account → Privacy → Request Data Deletion
Available deletion scopes:
- PBX configuration: Extensions, ring groups, IVR menus, queues, routing rules, device records
- Messages: SMS/MMS logs and contact data
- Recordings: Call recordings and voicemail
- AI voice data: AI-generated transcripts, sentiment scores, and call summaries
- SARA AI data: Conversation history, email threads, SMS auto-reply logs, and AI-generated draft responses
Note: Billing records and CDRs are locked from deletion — these are required by telecommunications regulations and tax law. Deletion requests are reviewed by our compliance team within 30 days. You will receive email notifications when your request is approved, rejected, or completed.
Account Cancellation
You can cancel your subscription at any time through Switchboard. After cancellation, your account enters a 30-day cooling-off period during which your data remains accessible for export. After that period, call recordings, voicemail and other stored media are deleted. Records we are required to retain — billing and payment records, call detail records, and audit trails — are kept for the periods set out in Data Retention with direct identifiers removed or replaced; that process is pseudonymization, and the pseudonymized records remain personal information. Backup and disaster-recovery archives rotate on their own schedule, so a copy may persist for a limited period after deletion from the live system.
Cookie Preferences
You can manage your cookie preferences at any time using the Cookie Settings link in the footer of sipstack.com. Our consent banner implements Google Consent Mode v2 — all non-essential cookies are denied by default until you explicitly grant consent. See our Cookie Policy for full details.
SMS Opt-Out
To stop receiving SMS messages from any SIPSTACK customer using Flare SMS, reply STOP to any message. Opt-outs are immediately added to the sender's suppression list and are permanent until you reinstate consent by replying START.
Email Unsubscribe
All marketing emails include a one-click unsubscribe link and a List-Unsubscribe-Post header compliant with RFC 8058 for automated unsubscription. Unsubscribing from marketing emails does not affect transactional or service-related notifications.
Your Privacy Rights by Jurisdiction
Canada — PIPEDA
As a Canadian corporation, we are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. Under PIPEDA, you have the right to:
- Access personal information we hold about you
- Correct inaccurate or incomplete information
- Withdraw consent for non-essential uses (subject to legal or contractual limitations)
- Lodge a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca
To exercise these rights, contact [email protected].
California — CCPA/CPRA
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with the following rights.
Categories of personal information we collect:
| CCPA Category | Examples | |---|---| | Identifiers | Name, email address, phone number, IP address, account ID | | Commercial information | Subscription plan, billing history, invoices | | Internet or electronic network activity | Usage logs, CDRs, message logs, session data | | Audio, electronic, or visual data | Call recordings, voicemail audio | | Professional or employment information | Company name, job title, industry | | Inferences | AI-generated transcripts, sentiment scores, call summaries |
Business and commercial purposes for collection: Service delivery, billing, customer support, security, fraud prevention, aggregated analytics, AI model improvement (anonymized).
Do Not Sell or Share My Personal Information: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.
Your California rights:
- Right to Know: Request the categories and specific pieces of personal information we have collected about you
- Right to Delete: Request deletion of personal information (subject to legal exceptions)
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: We do not sell or share — this right is satisfied by our policy
- Right to Limit Use of Sensitive Personal Information: Request that we limit use of sensitive PI to purposes necessary for providing the Services
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
How to exercise your rights: Contact [email protected] or use the self-serve tools in Switchboard (see Your Rights and Choices). We will verify your identity via your account credentials. Authorized agents may submit requests with written permission from the account holder. We respond to verified requests within 45 days (extendable by an additional 45 days with notice).
European Union and United Kingdom — GDPR
If you are located in the EEA or UK, see our GDPR Compliance page for detailed information on legal bases for processing, your GDPR data subject rights, international transfers, our Data Protection Officer contact, and breach notification procedures.
Children's Privacy
Our Services are not directed at individuals under the age of 13 (or under 16 in jurisdictions where a higher age threshold applies). We do not knowingly collect personal information from children. If we become aware that personal information has been collected from a child without verifiable parental consent, we will take steps to delete that information promptly.
If you are a parent or guardian and believe your child has provided us with personal information, please contact [email protected].
Security
We implement technical and organizational security measures to protect your personal information against unauthorized access, loss, disclosure, or destruction. These measures include:
- Encryption in transit: TLS 1.2 or higher for all API, portal, and SIP traffic
- Encryption at rest: Databases, object storage, and backups are encrypted at rest
- Access controls: Role-based access control, MFA for administrative accounts, principle of least privilege, and access logging
- Security monitoring: Continuous monitoring and alerting, anomaly detection, and security incident response procedures
- Breach notification: In the event of a personal data breach, we will notify affected individuals and relevant supervisory authorities as required by applicable law (72 hours for GDPR; promptly for PIPEDA)
No security system is impenetrable. If you discover a security vulnerability, please report it to [email protected].
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, products, or legal requirements. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Post the revised policy on this page
- Notify you by email to the address associated with your account (for material changes affecting your rights)
- Provide at least 30 days' notice before material changes take effect
Your continued use of our Services after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree to a material change, you may cancel your account before the effective date.
Contact
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Privacy Officer Email: [email protected] Phone: 1-800-277-7578 Mail: SIPSTACK Inc., Privacy Officer, 575-3093 Bathurst St., Toronto, ON M6A 2A3, Canada
Data Protection Officer (EU/UK) Email: [email protected] Response time: We acknowledge all privacy inquiries within 72 hours and respond fully within 30 days.