Skip to main content

Help us improve the Digital Marketplace - send your feedback

ARVATO LIMITED

Zoom Virtual Agent (ZVA) by ArvatoConnect

Zoom Virtual Agent (ZVA) 2.0 is an agentic conversational AI-powered self-service solution that uses natural language understanding to automate customer interactions across chat and voice channels. It resolves common to complex enquiries, integrates with backend systems, and seamlessly escalates to live agents where needed, improving efficiency and customer experience.

Features

  • AI-powered natural language understanding for accurate customer intent recognition
  • Powerful integration capability enabling self-service for common to complex enquiries
  • Omnichannel support ensuring consistent experiences across voice and digital channels
  • Seamless escalation to live agents with full conversation context
  • Conversation analytics revealing customer intent, trends, and deflection rates
  • Low-code bot design for rapid flow journey creation and updates
  • Knowledge base integration delivering consistent, approved responses
  • Multilingual support serving diverse customer populations effectively
  • Continuous learning improving accuracy through interaction feedback
  • Integration with many contact centre platforms for unified CX management

Benefits

  • Enables 24/7 service availability and supports business continuity
  • Supports scalable service during peak demand periods
  • Reduces customer effort and increases first-contact resolution for various enquiries
  • Enhances agent experience by reducing repetitive workload
  • Ensures consistent, compliant responses across all customer channels
  • Delivers measurable ROI through reduced contact volumes across channels
  • Accelerates CX improvement through improved customer intent and trends insight

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at richard.husband@arvatoconnect.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 6 6 3 7 0 3 9 5 3 1 3 1 8 8

Contact

ARVATO LIMITED Richard Husband
Telephone: 07867464428
Email: richard.husband@arvatoconnect.co.uk

About your service

Service categories

Application Development and Deployment

Application platforms

  • Model driven application platforms
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Zoom Contact Center
Cloud deployment model
Public cloud
Service constraints
No
System requirements
  • Internet connection; broadband wired or wireless (3G or 4G/LTE)
  • Ability to embed code into website (ZVA 2.0 chat)

User support

Email or online ticketing support
Yes, at extra cost
Support response times
Our standard support hours are 07:00-22:00 7 days a week. The Service Desk will allocate a priority to the incident or request, which will then determine the target response and time required to resolution.

P1 Critical, Response within 30 minutes, Resolution Target 4 hours P2 High, Response within 1 hour, Resolution Target 8 hours
P3 Medium, Response within 4 hours, Resolution Target 3 days
P4 Low, Response within 8 hours, Resolution Target 8 days
P5 Service Request, Response within 16 hours, Resolution Target As agreed in response

Extended support hours will be discussed on a client by client basis.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
ArvatoConnect provide a standard support level, 07:00-22:00 7 days a week. A premium support level with extended hours can be discussed on a client by client basis.
P1 Critical, Response Time within 30 minutes, Resolution Target 4 hours
P2 High, Response Time within 1 hour, Resolution Target 8 hours
P3 Medium, Response Time within 4 hours, Resolution Target 3 days
P4 Low, Response Time within 8 hours, Resolution Target 8 days
P5 Standard, Response Time within 16 hours, Resolution Target As agreed in response
Our Service Desk are the single point of contact for all Zoom Contact Center support and service requests, with an established escalation path.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
ArvatoConnect support new Zoom Virtual Agent (ZVA) users primarily through consultancy, deployment support, configuration, and ongoing expert guidance. Our role is to ensure the Zoom platform is aligned with each organisation’s systems, goals, and operational needs. We provide end-to-end project management and delivery, including design (customer journeys, omni-channel flows, integrations, security/RBAC, agentic AI, quality, analytics and reporting), build, SAT/UAT and tailored training across roles for rapid enablement. Zoom make their Customer Success Advisors available throughout the process. There is also the Zoom Learning Center and various support guides organisations can use anytime to get started with learning and expanding their platform knowledge.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Upon contract termination, Zoom deactivates all user IDs related to the customer account and any saved data is deleted. ArvatoConnect will work with our client to download any recordings and transcripts prior to the termination date by visiting their online user profile, navigating to their recordings/transcriptions and downloading selected items to an alternate source of our clients choice.
End-of-contract process
Upon termination of the contract, Zoom will deactivate all user IDs associated to that billing account and delete any saved recordings and transcripts. Ahead of this, ArvatoConnect will work with our client to extract all recordings/transcripts and data required. Zoom has a data retention standard that details how data is deleted when a customer terminates service (i.e., purged on day 31) and how Zoom must sanitise media following purge.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Zoom offers consolidated administration through the Zoom web portal, allowing account administrators to efficiently manage a geographically distributed organization from a single interface. End users can also access their setting via the same portal, which administrators can configure with granular controls. Customers often choose Zoom for the simplicity and intuitiveness of the Zoom web portal, enabling IT teams to quickly adopt automated workflows and integrate seamlessly with existing systems.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Zoom conducts accessibility testing for new features through an in-house team of dedicated accessibility professionals.
API
Yes
What users can and can't do using the API
The Zoom API is the primary means for developers to access a collection of resources from Zoom. Apps can read and write to the resources and mirror some of the most popular features available in Zoom Web Portal such as creating a new meeting, creating, adding and removing users, viewing reports and dashboards on various usage, and so on using the Zoom API. Depending on your app’s use case, you can choose from our various APIs and implement the features accordingly. All APIs under the Zoom API are based on REST architecture and are accessed via HTTPS at specified URLs. The base URL for all requests is https://api.zoom.us/v2/. The complete URL varies depending on the endpoint of the resource being accessed. For instance, you can list all users on an account via a GET request to this URL: https://api.zoom.us/v2/users/. Within our API reference pages, you can send test requests and view responses. You can also view the code for the request in various languages such as Python, Node, Java and more. With each release, we add additional APIs and enhancements to meet the needs of our customers.
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
ArvatoConnect are experts in Customer journeys, enhancing experience through service customisation and integrations. Zoom also offers a number of opportunities to customise the service. Zoom’s App Marketplace brings together integrations, apps, and bots built by Zoom, third-party developers, and oftentimes our own customers, making it easy for Zoom users to extend the power of Zoom for any business need. The Zoom App Marketplace hosts over 2,500 apps and integrations for our solutions. In addition, Zoom’s APIs allow for a robust extension of the core Zoom product and apps can read and write to the resources and mirror some of the most popular features available in the Zoom Web Portal such as creating, adding and removing users, viewing reports and dashboards on various usage, and so on. Experienced developers can choose to leverage Zoom’s SDKs to incorporate the Zoom experience into their own application. Lastly, role-based access control enables the creation of custom user roles that have a set of permissions that allows access only to the pages a user needs to view or edit.

Scaling

Independence of resources
Zoom’s unique architecture allows to quickly and easily scale to meet demand. Zoom maintain excess capacity in all aspects of their infrastructure to accommodate growing business, healthcare, and education needs and to meet peak usage requirements. Zoom's proven infrastructure supports billions of meeting minutes a month and the architecture is built to handle growing levels of activity, as the unified communications platform is architected from the ground up to address the most technologically difficult aspect of communications: video. Zoom's modern cloud architecture gives the platform its trademark reliability, quality, and scalability.

Analytics

Service usage metrics
Yes
Metrics types
Zoom’s CX Analytics is an enhanced analytics and reporting framework that provides real-time and historical insights into Zoom Virtual Agent (ZVA) performance, including ZVA metrics, containment rate, engagement outcomes, queue trends, and operational dashboards. It supports custom real-time dashboards, default and tailored reports, granular filtering, subscription-based reporting delivery, and engagement logs for deeper performance and quality analysis. Role-based permissions ensure data access is appropriately controlled.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Zoom

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Reports, logs, recordings and transcripts can be exported via the Zoom web portal as required. ArvatoConnect also offer our Microsoft Azure Data Lake Storage (ADLS) Gen2 solution, hosted in the UK, and designed to provide secure, scalable analytics capabilities, ingesting client data from multiple platforms, delivering a customer 360 view.
Data export formats
  • CSV
  • Other
Other data export formats
  • MP4
  • MP3
  • VTT
  • API
  • M4A
  • JSON
Data import formats
  • CSV
  • Other
Other data import formats
SAML

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
Zoom’s infrastructure for real-time video, audio, and data runs on dedicated servers within SSAE 16 and SOC 2 compliant data centres. Zoom sessions are temporary, operating similarly to mobile conversations over public networks. Data in transit between Zoom clients and data centres is secured using Secure Real-time Transport Protocol for media and TLS 1.2 with 256-bit AES-GCM encryption. Data at rest within Zoom’s data centres is protected with 256-bit AES-GCM encryption, ensuring end-to-end security, confidentiality, and integrity across all communications and stored content.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection within supplier network
Zoom follows OWASP standards to maintain robust internal security processes.

Availability and resilience

Guaranteed availability
SLAs are addressed in Zoom's Master Services Agreement (MSA) and may include 99.9% uptime, excluding excused downtime (maintenance).
Approach to resilience
Zoom web services leverage AWS high availability infrastructure with multi-region configuration operating in Active/Standby mode. For real-time communications, Zoom leverages multiple Tier 1 data centres running in Active/Active mode.
Outage reporting
Zoom posts any general incident announcement and other announcements including scheduled maintenance, outages, updates, through their status page at https://www.zoomstatus.com/. For incidents affecting a specific customer, Zoom will notify the account owner and administrator(s) through email or as specified in fully executed agreement.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Management interfaces are accessed via user name and password derived from integration via SSO or user name and password stored in a salted hash. Interfaces are accessed based upon role based access control (RBAC).
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Other
Description of management access authentication
Microsoft PAM

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
ArvatoConnect - Cyber Essentials, Cyber Essentials Plus, GDPR, FCA

Zoom - Cyber Essentials, Cyber Essentials Plus, SOC Type 2, GDPR, Truste Certified Privacy
Information security policies and processes
ArvatoConnect's and Zoom's security policies are derived from ISO 27001 framework
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Change triggers for unique processes and controls are: Code, Database, Infrastructure, Data.

Weekly meetings held to request changes that need to be performed during maintenance windows. Change requests are presented, validated, and scheduled. Changes are approved by the Change Manager. Implementation in production should not be by the same individual who developed the change. When staffing levels do not permit this separation, management oversight and approval of the change and testing process ensure appropriate processes are followed. Dev and test environments are physically and logically segregated from production. No customer data is used in testing.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Zoom has a formal Vulnerability Management Plan in place. Zoom performs monthly vulnerability and web application scanning using an external party (Qualys). Scan reports are reviewed by our Security and technical teams and discussed with the engineering and development teams. Validated findings are tracked in our JIRA system throughout remediation.

Zoom has a monthly patch cadence. Zoom will patch all applications, workstations, and servers (virtual or physical) with all current operating system, database, and application patches deployed in our computing environment according to a schedule predicated on the criticality of the patch. Maintenance/patching typically will have no service downtime.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Zoom has monthly vulnerability and web application scans. Findings are reviewed and validated by their technical and engineering team. Vulnerability is rated on severity level and tracked using JIRA. Vulnerability fixes are released from Zoom's engineering team and follow Zoom's formal change management process for deployment to production. Zoom also has DDoS monitoring and Managed service in place. Affected traffic is diverted and filtered through a scrubbing centre.

Zoom responds to incidents as defined within its SOC2 report available upon execution of a mutual NDA.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Zoom communicates the incident response policy to internal and external users and instructs users to contact their supervisor and the information security representative if they become aware of a possible security breach. When a potential security incident is detected, a defined incident management process is initiated by authorised personnel. Incidents are tracked through Zoom's tracking application, which includes the corrective actions implemented in accordance with the defined policies and procedures.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Wednesday 7 September 2022
What the ISO/IEC 27001 doesn’t cover
While it is not practicable to list exclusions in isolation, our ISO 27001 certification supports all contracted services to ArvatoConnect customers, including contact centre, back-office and IT services.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Monday 16 January 2023
What the ISO 9001 doesn’t cover
While it is not practicable to list exclusions in isolation, our ISO 9001 certification supports business process outsourcing, delivering a comprehensive range of front and back office services. This includes customer experience services and administrative services.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Fbb5c636-5561-4d78-b819-3360c25ffe07
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
A774e5a5-9ad4-4cbf-a7a3-e47ea2c0ef05
Other security certifications
Yes
Any other security certifications
  • Tisax
  • ISO 20000-1:2018

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at richard.husband@arvatoconnect.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.