Skip to content
All posts

Before the AI interviewer calls

A practical consent record for AI customer interviews: what to capture before contact, disclose during the call, retain afterwards, and do when someone opts out.

The Nosie teamHouse byline
Nosie article card reading Before the AI interviewer calls

The dangerous sentence in automated customer research is short: "They agreed to be contacted."

Who is they? Agreed where? To a phone call or an email? About this study or about product updates generally? Did the notice say an AI interviewer would be speaking? How long ago was it? What happens when the person changes their mind?

If the answer lives in somebody's memory, a spreadsheet note, or a generic terms-of-service checkbox, it is not a reliable consent boundary. It is a story the organisation tells itself after the number has already entered the dialling queue.

An AI voice interview needs something stronger: a consent receipt that can be checked before contact, explained at the start of the conversation, and revoked without argument.

This article is a practical design checklist, not legal advice. Consent and calling rules differ by purpose, channel, and jurisdiction. Get advice for the countries and kinds of contact you actually use.

Consent has three separate jobs

Teams often use one word for three decisions.

Permission to contact answers whether this person agreed to hear from you, through this channel, for this purpose.

Transparency at contact answers whether they understand who is calling, that the interviewer is AI, what the conversation is for, and what will happen to what they say.

Permission to continue answers whether now is still a good time. A person can have agreed last Tuesday and decline today. The old permission does not make the new no negotiable.

All three have to work. A perfect opening cannot repair a contact list gathered without permission. A valid signup checkbox does not excuse an automated caller that conceals its identity. A clear disclosure does not entitle the agent to continue after "not interested."

Start with a receipt, not a boolean

A field called consent: true records a conclusion and discards the evidence behind it. When the purpose changes, or somebody asks why they were called, the useful part is gone.

A workable consent receipt should let you answer these questions:

QuestionWhat to record
Who agreed?The person or account the permission belongs to
Who collected it?The organisation and, where useful, the operator or system
When and where?Timestamp, source, and collection method
What was the purpose?A specific research purpose, not "business communications"
Which channels?Phone, SMS, email, or another named channel
What kind of caller?Whether an automated or AI-generated voice was disclosed
What notice did they see?The wording or a versioned copy of it
How long will the result be kept?The retention period disclosed before collection
How can they stop?The revocation path and where that suppression propagates

This is not paperwork for its own sake. Each field closes a real ambiguity.

If the receipt says email but the queue wants to dial, the call stops. If the receipt says onboarding research but the campaign is a sales promotion, the call stops. If nobody can recover the notice that was shown, the team knows it has an evidence problem before a participant has to discover it for them.

The receipt should be immutable as evidence. Correct a mistake with a new event or a new grant, not by silently rewriting what supposedly happened in the past.

Tell people before the interesting part

The first ten seconds matter more than a privacy-policy link in the footer.

A useful opening answers six things in plain language:

  1. Who is calling?
  2. Is the interviewer AI or human?
  3. Why is the call happening?
  4. Could the conversation be recorded and shared with service providers?
  5. How long will it take?
  6. Is now a good time?

For example:

Hi, I'm an AI interviewer calling for Acme. This is a short conversation about your first month using the product. This conversation may be recorded and shared with the service providers that run it. It should take about three minutes. Is now a good time?

That is not the whole privacy notice. It is the information needed to decide whether to continue. A longer written notice can explain recipients, storage, access and correction rights, and contact details without forcing the voice agent to read a legal page aloud.

The New Zealand Office of the Privacy Commissioner says organisations using generative AI should explain in plain language how, when, and why the tool is being used before collecting personal information. Its transparency guidance also recommends a contextual, "just-in-time" notice when a full policy is impractical at the point of collection. An opening disclosure is that idea applied to a voice call.

The provider boundary matters too. ElevenLabs' current disclosure requirements require notice immediately before an interaction that the user is dealing with AI rather than a human and that the conversation may be recorded and shared with service providers. A customer's consent form and a provider's required disclosure are related, but neither substitutes for the other.

Indirect collection changes the transparency problem

In customer research, the platform often receives a person's name and contact details from its customer before it hears anything from the person themselves. That is indirect collection.

New Zealand's Information Privacy Principle 3A came into force on 1 May 2026. Unless an exception applies, an organisation collecting personal information indirectly must take reasonable steps to make sure the person knows that collection happened, why it happened, who will receive the information, who collects and holds it, and how to exercise access and correction rights.

The important operational lesson is not "add another paragraph to the terms." It is to know which organisation is doing which job.

A SaaS company may choose the cohort and supply contact details. An interview platform may process them on the company's behalf. Voice, telephony, and language-model providers may handle parts of the conversation. Your notices and contracts should describe that chain accurately enough that a person can understand it. Do not assume that displaying one company's privacy policy somewhere in the process has informed the participant about all the others.

The Office of the Privacy Commissioner notes that a service provider acting only on behalf of its customer may leave the customer responsible for notification. That allocation still needs evidence. "We assumed the other party told them" is not evidence.

Purpose is a boundary, not a label

"Customer research" is usually too broad to govern a real call.

Compare these purposes:

  • Understand why new accounts did not complete payroll setup in their first 30 days.
  • Gather product feedback.
  • Improve our services.

Only the first one gives the participant and the interviewer a useful boundary. It says which experience is in scope and makes several tempting questions obviously out of scope.

Purpose also separates research from marketing. A person who agrees to discuss onboarding friction has not necessarily agreed to hear a sales pitch, join a newsletter, or be contacted about an unrelated product. If the interview changes purpose halfway through, the original receipt cannot stretch to cover it.

This improves the research itself. A narrow purpose produces better questions, less unnecessary personal information, and outputs that can be mapped to an actual decision. It is the consent version of choosing one step in the funnel rather than investigating "onboarding".

A later no outranks an earlier yes

Revocation is not feedback. It is a state transition.

The voice agent should recognise a plain refusal, acknowledge it once, and end the conversation. It should not negotiate, offer a shorter version, or ask the person to explain. If the person asks for no further contact, the system then has to suppress future attempts before another worker, retry, channel, or study can reach the same person under the same scope.

That last part is where polite policies fail. The call ends correctly, but an already queued SMS still goes out. Or the person is suppressed in one study and added again to the next. Or the interview platform records the opt-out while the customer's CRM keeps treating the contact as eligible.

Design the revocation path across systems:

  1. Cancel active and scheduled attempts.
  2. Mark the person unavailable for the agreed scope.
  3. Refuse later enrolment that would bypass the suppression.
  4. Emit an event for downstream systems.
  5. Keep only the minimal evidence needed to honour the opt-out.

Do not delete the suppression marker as part of a general data purge. Forgetting that somebody opted out is how a deletion request turns into a second unwanted call.

Retention is part of the promise

A voice interview workflow can involve several records across customer, interview-platform, telephony, and voice-provider systems: contact metadata, call-routing events, audio, a transcript, a summary, structured attributes, and billing or audit evidence. They do not all need the same retention period.

Start with the purpose and work backwards. If the study needs a transcript for 90 days and aggregated findings after that, say so before interviewing anyone. Do not collect indefinitely because storage is cheap. Do not extend the period after interviews begin without revisiting the promise participants received.

Provider defaults deserve particular attention. ElevenLabs documents separate retention controls for transcripts and audio, and says its default conversation retention is two years. Its audio-saving documentation says audio saving is enabled by default and must be disabled per agent when recordings are not needed.

A policy that says "we do not keep audio" is only true when the provider setting, deletion path, and operational checks agree with it. Configuration is part of the product promise.

The same applies to model training. The Office of the Privacy Commissioner cautions against putting sensitive or confidential information into a generative-AI service unless retention and disclosure are understood, and specifically warns about information being used to train models. Review the provider's current data-use setting rather than relying on what it was called when the account was opened.

The ten-point preflight

Before an AI interviewer contacts a real cohort, verify these ten things:

  • The research purpose names the experience and decision in scope.
  • Every person has an attributable, timestamped consent receipt.
  • The permitted channel includes the one about to be used.
  • The notice covered an automated or AI-generated voice where required.
  • The opening identifies the caller, purpose, AI, recording and provider sharing, duration, and choice to continue.
  • Calling hours are evaluated in the participant's local time.
  • A verbal decline ends the call; a request for no further contact suppresses later attempts.
  • Downstream systems receive and honour the opt-out.
  • Audio, transcript, derived data, and provider retention settings match the notice.
  • A person can request access, correction, or deletion through a real monitored path.

Then test the refusal path before the happy path. A successful interview proves the questions can run. A successful decline proves the boundary can hold.

Consent makes the interview better

Consent is sometimes treated as the friction added before the useful part. In research, it is part of the useful part.

A participant who knows who is calling and why can answer the actual question instead of spending the opening minute deciding whether the call is a scam. A precise purpose keeps the interviewer from fishing. A visible timebox gives the person a real choice. A clean way to stop makes the answers that remain more trustworthy.

The goal is not to turn a three-minute interview into a legal ceremony. It is to make the system able to answer a simple challenge: why was this person contacted, what did they agree to, and what happened when they said no?

If the answer requires reconstructing intent from three databases and somebody's memory, the call was not ready to be made.


Where Nosie fits

Nosie requires a recorded consent attestation before a contact can be added to a study. Contact methods are explicit, calling hours are evaluated locally, and a refusal ends the interview. Opt-out is enforced across every study of the same project and delivered to connected systems as a signed contact.opted_out webhook.

Study retention is chosen before interviews begin and can be shortened later, but not extended once interviews exist. Nosie stores transcripts and structured results for the study period. Call audio is retained by the voice provider for seven days for quality review, alongside a seven-day provider transcript/PII retention setting; Nosie keeps no separate audio archive. The details, including access, correction, and deletion rights, are in the privacy policy.

If you want to hear the opening and refusal path before involving a customer, try the interview on yourself. The first self-test is free and does not consume a billable interview.

  • consent
  • privacy
  • ai-voice
  • customer-research
  • outbound-research
  • new-zealand

Newsletter

New posts, about once a month

What we learn building voice interviews — onboarding research, consent, and the odd engineering note. No product announcements dressed up as insight, and one click to leave.