Effective date: [DATE TO BE SET ON PUBLICATION] Data controller: [LEGAL ENTITY NAME AND REGISTERED ADDRESS TO BE COMPLETED] Contact: privacy@cloudyvoice.com
1. Scope
This policy explains how CloudyVoice handles personal data when you visit our website, create an account, or use our voice services.
It does not cover personal data you transmit through the Services as part of your own calling operations. For that data you are the controller and we act as processor — see section 8.
2. What we collect
Data you provide
| Data | Purpose | Lawful basis |
|---|---|---|
| Name, email, company, phone | Account creation and support | Contract |
| Password (stored as a scrypt hash) | Authentication | Contract |
| Enquiry messages | Responding to you | Legitimate interests |
| Traffic profile for route review | Assessing lawful use | Legal obligation / legitimate interests |
Data generated by use
| Data | Purpose | Lawful basis |
|---|---|---|
| Call detail records (numbers, time, duration, cost) | Billing, fraud prevention, dispute resolution | Contract / legal obligation |
| Payment records and transaction hashes | Crediting balance, accounting | Contract / legal obligation |
| Session and CSRF tokens | Keeping you logged in securely | Contract |
| IP address at signup and login | Fraud and abuse prevention | Legitimate interests |
| Server logs | Security and diagnostics | Legitimate interests |
What we do not collect
- We do not use third-party analytics, advertising, or tracking cookies.
- We do not sell personal data. We have never done so and will not.
- We do not record the content of your calls. Recording is a function of your own systems, and any recordings you make are yours to control.
3. Cookies
We set a single essential cookie holding your session token, used to keep you logged in. It is HttpOnly, SameSite=Lax, and Secure in production.
We do not set analytics, advertising, or third-party cookies, which is why you are not being shown a consent banner.
4. How long we keep data
| Category | Retention |
|---|---|
| Account records | Duration of the account, plus [PERIOD TO BE SET] |
| Call detail records | [PERIOD TO BE SET — check local telecoms retention law] |
| Payment and invoice records | As required by applicable accounting and tax law, typically 6-7 years |
| Enquiry messages | [PERIOD TO BE SET] |
| Session records | Until expiry or logout |
| Server logs | [PERIOD TO BE SET] |
5. Who we share with
We share personal data only where necessary:
| Recipient | What | Why |
|---|---|---|
| Upstream carriers | Called number, originating number, duration | To route your calls |
| Blockchain networks | Public wallet addresses and transaction data | Inherent to cryptocurrency payment |
| Email delivery provider | Email address, message content | Password reset delivery |
| Hosting provider | Data stored on our infrastructure | To operate the service |
| Professional advisers | As needed | Legal and accounting |
| Authorities | As legally required | Compliance with valid legal process |
Note that blockchain transactions are public and permanent by design. Wallet addresses and transaction amounts are visible to anyone and cannot be erased by us or by you.
6. International transfers
Personal data may be processed outside your country. Where data subject to UK or EU GDPR is transferred outside the UK or EEA, we rely on [TRANSFER MECHANISM TO BE COMPLETED — typically Standard Contractual Clauses or an adequacy decision].
7. Your rights
Depending on where you are, you may have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase data, where no overriding legal obligation to retain it applies
- Restrict or object to processing based on legitimate interests
- Portability — receive your data in a machine-readable format
- Withdraw consent, where processing is based on consent
- Complain to a supervisory authority
Exercise any of these at privacy@cloudyvoice.com. We respond within one month.
Note that some data cannot be erased on request — billing records subject to statutory retention, and blockchain transactions, which are outside anyone's control.
8. When you are the controller
When you use the Services to call your own contacts, you determine the purposes and means of that processing. You are the controller; we are your processor.
In that role:
- We process transmission data only as needed to route and bill your calls.
- You are responsible for having a lawful basis to contact those individuals.
- You are responsible for honouring their rights, including objection to direct marketing.
- A data processing agreement under Article 28 GDPR is available on request and is required before processing personal data subject to UK or EU GDPR.
9. Security
- Passwords are hashed with scrypt. We cannot read them.
- Sessions are database-backed with CSRF protection on state-changing requests.
- Transport is HTTPS with HSTS in production.
- A strict Content Security Policy is enforced.
- Rate limiting applies to authentication endpoints.
- Access to production systems is restricted to personnel who require it.
No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform you where the risk is high.
10. Children
The Services are not directed at children and we do not knowingly collect their data.
11. Changes
Material changes will be notified by email or through the portal. The last-updated date above always reflects the current version.
12. Contact and complaints
Data protection enquiries: privacy@cloudyvoice.com Supervisory authority: [TO BE COMPLETED — e.g. the ICO in the UK]