Legal

Privacy Policy

Last updated: 27 July 2026. This page is maintained by VoxioTelecom Ltd.

1. Who we are

VoxioTelecom Ltd. is the data controller for personal data processed through our website, portal and voice services. Contact: privacy@voxiotelecom.com.

2. What we collect

  • Account data: company name, contact email, country, billing email.
  • Authentication data: hashed password, session tokens.
  • Traffic metadata (CDRs): A-number, B-number, timestamp, duration, disposition, source IP. Required by law for the retention period below.
  • Payment metadata: crypto transaction hashes, deposit amounts. We do not store payment card details; crypto processing is handled by Plisio.
  • Support content: the text of tickets you submit.

We do not record call audio.

3. Why we process it

  • To provide the voice service and portal (contract).
  • To bill you and issue invoices (contract, legal obligation).
  • To detect fraud, spoofed CLI and unlawful traffic (legitimate interest, legal obligation).
  • To comply with telecom regulation and lawful requests from competent authorities (legal obligation).

4. Retention

Account data: for the life of your account plus 6 years for tax and accounting purposes. Traffic metadata (CDRs): 12 months, or as required by the applicable data-retention regulation in the routing jurisdiction. Support tickets: 3 years.

5. Sub-processors

We rely on the following sub-processors to deliver the Service:

  • Supabase — authentication and application database (EU region).
  • Plisio — cryptocurrency payment processing.
  • Cloudflare — DNS and edge protection.
  • MagnusBilling — self-hosted class-4 softswitch and billing engine.

6. International transfers

Data is primarily processed within the European Economic Area. Where a sub-processor is located outside the EEA, transfers rely on Standard Contractual Clauses.

7. Your rights

Under GDPR you have the right to access, rectify, erase, restrict, port and object to processing of your personal data. Contact privacy@voxiotelecom.com to exercise these rights. You may also lodge a complaint with your local supervisory authority.

8. Security

Passwords are hashed. Portal traffic is TLS-encrypted. SIP signalling and media may be optionally protected with TLS/SRTP. Access to production systems is restricted and logged.

9. Cookies

We use only strictly necessary cookies for authentication and session management. We do not use advertising or cross-site tracking cookies.

10. Changes

Material changes to this policy will be notified by email at least 30 days before they take effect.