Scope and roles
This policy explains how we handle personal data in connection with our web-based dialer and call-center platform (the Service) and our website. "We", "us" and "our" mean the company named on this page. Our customers are the businesses that create workspaces on the Service.
We handle personal data in two different roles:
- As a processor, for the data our customers put into the Service or create with it: their contacts, lead lists, call records, notes, recordings and voicemails, and the activity of their own staff. The customer is the controller of that data and decides why and how it is used. We process it only on the customer's instructions.
- As a controller, for the data we need to run our business: the people who sign up and manage accounts, billing contacts, visitors to our website, and people who write to us.
If you received a call from a business that uses the Service, that business is responsible for your data. The section below on people our customers call explains what you can do.
Data we process for our customers
When a customer uses the Service, we process the following on their behalf:
- Contacts and lists: names, phone numbers, email addresses, companies, notes, time zones, consent status and source, custom fields the customer defines, and do-not-call entries.
- Call records: the numbers involved, direction, times, durations, queue or campaign, outcome, disposition, notes, callbacks, and a log of events during the call.
- Recordings and voicemails: audio of calls the customer chooses to record, voicemail messages left for the customer, and prerecorded messages the customer uploads.
- Staff activity: the customer's users and their roles, agent states and break times, and supervisor actions such as listening to or joining a call.
We use this data only to provide the Service to that customer: to place and route calls, show the wallboard and reports, store and play recordings, run campaigns, send the webhooks the customer configures, and support the customer when they ask. We do not sell it, and we do not use it for our own marketing. Our staff access a customer's workspace only to provide support, investigate abuse or keep the Service running, and that access is recorded.
Requests from data subjects
Because our customers control the data about their contacts, requests to access, correct or delete that data are handled by the customer. The Service gives customers the tools to do so. Contacts can be edited and exported, and the erasure tool permanently deletes a contact and removes their details from call records, notes, recordings and voicemails. Where the number is on a do-not-call list, only the do-not-call entry is kept, so that the person is not called again.
If we receive a request about data a customer controls, we pass it to that customer and help them respond.
Data we control
As a controller, we collect:
- Account data: names, email addresses, usernames, roles, password hashes and multi-factor authentication settings for the people who use the Service.
- Business and verification data: your company's details and the information you submit for business verification and caller-ID registration, such as legal name, tax identifier, address, website, authorised representative and use case.
- Billing data: billing contacts, plan, seats, invoices and payment status. Card details are collected and held by our payments processor. We receive only limited details, such as the card brand and last four digits.
- Usage and cost data: minutes, call counts, phone numbers in use and the carrier cost of your traffic, which we use for billing, usage limits and abuse monitoring.
- Security and agreement records: sign-in times, IP addresses, audit logs of sensitive actions, and records of your acceptance of our Terms and Acceptable Use Policy, including version, time, IP address and user.
- Website and enquiries: what you send us through the contact form (name, work email, company, team size, phone number and message) or when you subscribe to updates, and the messages you send to our support team.
The application uses cookies that are needed to sign you in and keep your session secure.
How we use the data we control
We use it to:
- create and run your account and provide the Service;
- bill you, apply usage allowances and warn owners as limits approach;
- verify businesses and meet carrier and caller-ID requirements;
- detect and prevent fraud and abuse, including automated monitoring of outbound traffic patterns;
- send service messages, such as invitations, password resets, billing notices, usage warnings and notices that outbound calling has been paused;
- answer enquiries and, where the law allows, tell business contacts about our products, with an option to opt out at any time;
- comply with legal obligations and enforce our terms.
Where data protection law requires a legal basis, we rely on performing our contract with you, our legitimate interests in running and securing the Service, compliance with legal obligations, and consent where we ask for it.
Subprocessors
We use a small number of service providers to run the Service. They process personal data only on our instructions and under written terms that protect it:
- Telephony provider: carries calls between browsers and the phone network, provides phone numbers, and stores recordings until they are deleted.
- Payments processor: collects payments, holds card details and issues receipts.
- Hosting provider: runs our application servers and databases.
We keep an up-to-date list of subprocessors and their locations, available on request, and we tell customers before we add or replace one.
International transfers
We and our subprocessors may process personal data in the United States and in other countries. Where the law requires it, we protect transfers with appropriate safeguards, such as standard contractual clauses.
Retention
- Call records are kept for 25 months, and detailed call event logs for 13 months.
- Recordings are kept for the retention period of the customer's plan, or a shorter period the customer sets, and are then deleted automatically. Customers can delete recordings sooner.
- Contacts erased with the erasure tool are deleted at once, apart from any do-not-call entry described above.
- After a workspace is cancelled, owners can export data for 30 days. The workspace's data becomes eligible for permanent deletion 90 days after cancellation and is then deleted.
- Billing records are kept for as long as tax and accounting law requires.
- Backups are overwritten on our normal backup cycle.
Security
We protect personal data with technical and organisational measures appropriate to the risk. Among them: passwords are stored only as salted hashes; sessions and API keys are stored only as hashes; multi-factor authentication is available to every user and required for our own administrators; traffic is encrypted in transit; recordings are played only through authenticated access to the Service and are never exposed through public links; and sensitive actions, such as joining a live call, overriding a compliance warning or accessing a workspace as support, are recorded in audit logs.
No system is perfectly secure. If a breach affects personal data, we will notify affected customers without undue delay and help them meet their own obligations.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export the personal data we control about you, to object to or restrict certain uses, and to withdraw consent. To exercise these rights, contact us using the privacy contact shown on this page. You may also complain to your data protection authority.
For data a customer controls, such as a record of a call you received, please contact that business. We will pass on any request we receive.
People our customers call
If a business called you using the Service, that business decides whom to call and what to keep. You can ask the business to stop calling you. During many campaign calls, you can also press 9 when prompted to be added to that business's do-not-call list. To access or delete your data, contact the business directly. If you contact us instead, we will forward your request to them.
Children
The Service is a business tool and is not intended for children. We do not knowingly collect personal data from children.
Changes to this policy
The date of this policy is shown on this page. If we make material changes, we will tell workspace owners in advance and update the date.
Contact
Questions about this policy, or requests about data we control, can be sent to the privacy contact and address shown on this page.