Personal data at rest encryption controls
User data (in memory)
• Not encrypted by phone application except for passwords stored in memory. Passwords are
only decrypted temporarily during use.
User data (on flash)
• Not Encrypted
Call Logs (on flash)
• Not Encrypted
User Passwords (on flash)
• AES-256 encrypted
• There are no controls available for the type or strength of encryption
User data in logs (on flash)
• Not Encrypted
Personal data in transit encryption controls
User data (in memory)
• TLS 1.2 to send/receive data with servers
User data (on flash)
• TLS 1.2 (HTTPs) to send/receive data with servers
• SSH
Call Logs (on flash)
• TLS 1.2 (HTTPs) to receive data with servers
• Data is never transmitted out of the phone
User Passwords (on flash)
• TLS 1.2 to send/receive data with servers (only the encrypted form is transmitted)
User data in logs (on flash)
• TLS 1.2 (HTTPs) to send data with servers when it is being sent as a phone report
• SSH
Data Privacy Controls Addendum
January 2020 Installing and Administering Avaya 9601/9608/9611G/9621G/9641G/9641GS IP
Deskphones SIP 136
Comments on this document? infodev@avaya.com