Privacy Policy

Last Updated: July 20, 2026

1. Introduction

Welcome to [Company Name] ("Company," "we," "our," or "us"). We respect your privacy and are committed to protecting the personal and telecommunications data of our website visitors, customers, and business partners.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website ([Website URL]) or use our telecommunication products and services, including Cloud PBX, Direct Inward Dialing (DIDs), Voice over IP (VoIP), SIP Trunking, and Wholesale Telecommunication Services (collectively, the "Services").

2. Information We Collect

Because of the technical nature of telecommunication services, we collect both general personal data and specific Telecommunications Service Data.

A. Information You Provide Directly

  • Account & Contact Data: Name, business name, email address, phone number, billing address, and job title when you register for an account, request a quote, or purchase services.
  • Payment & Financial Data: Credit card details, bank account information, tax ID numbers, and billing history processed securely via our payment processors.
  • Support & Identity Verification: Identification documents (e.g., passport, national ID, business registration certificates) required for legal compliance, regulatory Know Your Customer (KYC) verification, or DID registration.

B. Telecommunications & Traffic Data (CDR)

When you utilize our VoIP, SIP Trunking, Cloud PBX, or Wholesale services, our networks process Call Detail Records (CDRs) and metadata, which may include:

  • Source and destination phone numbers (IP endpoints, SIP URIs, DIDs).
  • Call duration, timestamps, call status, and routing paths.
  • Technical diagnostics (IP addresses, media formats, packet loss, jitter, latency).
  • Call Content: By default, call media flows through our network unrecorded. If you utilize optional features like Cloud PBX Call Recording, audio files are recorded and stored solely on your instruction as a Data Controller.

C. Automatically Collected Web Data

  • Device and browser type, IP address, operating system, and browsing activity on our website collected via cookies and log files.

3. How We Use Your Information

We process your data for the following core purposes:

  • Service Delivery & Provisioning: To route voice calls, allocate DIDs, manage Cloud PBX systems, configure SIP trunks, and maintain network connectivity.
  • Billing & Account Management: Processing payments, issuing invoices, monitoring credit limits, and managing wholesale settlements.
  • Regulatory & Legal Compliance: Fulfilling legal requirements related to phone number assignment, emergency service routing (e.g., e911 / 112), anti-fraud monitoring, and lawful intercept requests from authorized authorities.
  • Network Integrity & Security: Detecting, preventing, and mitigating fraudulent call routing, SIP attacks, spam, or unauthorized access.
  • Customer Support: Diagnosing call quality issues, troubleshooting network faults, and responding to inquiries.
  • Marketing: Sending service updates, policy changes, and promotional communications (you may opt out at any time).

4. Legal Basis for Processing

Depending on your region (e.g., under the EU GDPR), we rely on the following legal bases:

  1. Contractual Necessity: To perform our obligations under our Terms of Service.
  2. Legal Obligation: To comply with telecom regulations, tax laws, and KYC identity verification requirements for DID assignment.
  3. Legitimate Interests: To secure our network against fraud, manage wholesale call routing, and improve our platform.
  4. Consent: Where you have explicitly opted in (e.g., for direct marketing or specific cookie usage).

5. Sharing and Disclosure of Information

We do not sell your personal data. We share your information only in the following circumstances:

  • Upstream Carriers & Wholesale Partners: To complete call routing and number porting, traffic data and destination numbers are transmitted to partner carriers, tier-1 operators, and local exchange carriers.
  • Third-Party Service Providers: Trusted vendors providing hosting, payment processing, fraud detection, and customer support tooling under strict confidentiality agreements.
  • Legal & Regulatory Authorities: When required by law, subpoena, court order, or telecom regulatory bodies to comply with legal processes or emergency assistance requirements.
  • Business Transfers: In connection with any merger, sale of company assets, financing, or acquisition.

6. Data Retention

We retain personal and telecommunication data only for as long as necessary to fulfill the purposes outlined in this policy:

  • Account & Billing Data: Retained for the duration of your contract plus statutory tax and accounting retention periods (typically 5 to 10 years).
  • Call Detail Records (CDRs): Retained for billing, fraud management, and legal compliance for a standard period (typically [e.g., 6 to 12 months]), after which they are purged or anonymized.
  • Call Recordings (Cloud PBX): Managed directly according to customer account settings and deleted upon customer deletion or contract termination.

7. Security of Your Data

We implement robust administrative, physical, and technical security measures designed to protect your data, including:

  • Transport Layer Security (TLS) and Secure Real-time Transport Protocol (SRTP) encryption support.
  • Network firewalls, intrusion detection systems (IDS), and continuous anti-fraud monitoring.
  • Access controls and strict authentication protocols for administrative access.

8. Your Data Protection Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal information we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure ("Right to be Forgotten"): Request deletion of your data, subject to legal and regulatory retention mandates.
  • Restriction & Objection: Object to or restrict certain processing activities (e.g., direct marketing).
  • Data Portability: Request transfer of your data to another service provider in a structured format.

To exercise any of these rights, please contact our Data Protection Officer (DPO) at [Email Address].

9. International Data Transfers

As a global telecom and wholesale provider, your data may be transferred to and processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or adequacy decisions, to protect cross-border data transfers.

10. Third-Party Links & Integration Services

Our website or Cloud PBX platform may contain links or API integrations to third-party services (e.g., CRM integrations, webhooks). We are not responsible for the privacy practices or content of third-party platforms.

11. Updates to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our services, legal requirements, or operational practices. We will notify you of material changes by posting the updated policy with a revised "Last Updated" date or through direct account notifications.