Effective date: [DATE TO BE SET ON PUBLICATION] Data controller: [LEGAL ENTITY NAME AND REGISTERED ADDRESS TO BE COMPLETED] Contact: privacy@cloudyvoice.com

1. Scope

This policy explains how CloudyVoice handles personal data when you visit our website, create an account, or use our voice services.

It does not cover personal data you transmit through the Services as part of your own calling operations. For that data you are the controller and we act as processor — see section 8.

2. What we collect

Data you provide

DataPurposeLawful basis
Name, email, company, phoneAccount creation and supportContract
Password (stored as a scrypt hash)AuthenticationContract
Enquiry messagesResponding to youLegitimate interests
Traffic profile for route reviewAssessing lawful useLegal obligation / legitimate interests

Data generated by use

DataPurposeLawful basis
Call detail records (numbers, time, duration, cost)Billing, fraud prevention, dispute resolutionContract / legal obligation
Payment records and transaction hashesCrediting balance, accountingContract / legal obligation
Session and CSRF tokensKeeping you logged in securelyContract
IP address at signup and loginFraud and abuse preventionLegitimate interests
Server logsSecurity and diagnosticsLegitimate interests

What we do not collect

  • We do not use third-party analytics, advertising, or tracking cookies.
  • We do not sell personal data. We have never done so and will not.
  • We do not record the content of your calls. Recording is a function of your own systems, and any recordings you make are yours to control.

3. Cookies

We set a single essential cookie holding your session token, used to keep you logged in. It is HttpOnly, SameSite=Lax, and Secure in production.

We do not set analytics, advertising, or third-party cookies, which is why you are not being shown a consent banner.

4. How long we keep data

CategoryRetention
Account recordsDuration of the account, plus [PERIOD TO BE SET]
Call detail records[PERIOD TO BE SET — check local telecoms retention law]
Payment and invoice recordsAs required by applicable accounting and tax law, typically 6-7 years
Enquiry messages[PERIOD TO BE SET]
Session recordsUntil expiry or logout
Server logs[PERIOD TO BE SET]

5. Who we share with

We share personal data only where necessary:

RecipientWhatWhy
Upstream carriersCalled number, originating number, durationTo route your calls
Blockchain networksPublic wallet addresses and transaction dataInherent to cryptocurrency payment
Email delivery providerEmail address, message contentPassword reset delivery
Hosting providerData stored on our infrastructureTo operate the service
Professional advisersAs neededLegal and accounting
AuthoritiesAs legally requiredCompliance with valid legal process

Note that blockchain transactions are public and permanent by design. Wallet addresses and transaction amounts are visible to anyone and cannot be erased by us or by you.

6. International transfers

Personal data may be processed outside your country. Where data subject to UK or EU GDPR is transferred outside the UK or EEA, we rely on [TRANSFER MECHANISM TO BE COMPLETED — typically Standard Contractual Clauses or an adequacy decision].

7. Your rights

Depending on where you are, you may have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase data, where no overriding legal obligation to retain it applies
  • Restrict or object to processing based on legitimate interests
  • Portability — receive your data in a machine-readable format
  • Withdraw consent, where processing is based on consent
  • Complain to a supervisory authority

Exercise any of these at privacy@cloudyvoice.com. We respond within one month.

Note that some data cannot be erased on request — billing records subject to statutory retention, and blockchain transactions, which are outside anyone's control.

8. When you are the controller

When you use the Services to call your own contacts, you determine the purposes and means of that processing. You are the controller; we are your processor.

In that role:

  • We process transmission data only as needed to route and bill your calls.
  • You are responsible for having a lawful basis to contact those individuals.
  • You are responsible for honouring their rights, including objection to direct marketing.
  • A data processing agreement under Article 28 GDPR is available on request and is required before processing personal data subject to UK or EU GDPR.

9. Security

  • Passwords are hashed with scrypt. We cannot read them.
  • Sessions are database-backed with CSRF protection on state-changing requests.
  • Transport is HTTPS with HSTS in production.
  • A strict Content Security Policy is enforced.
  • Rate limiting applies to authentication endpoints.
  • Access to production systems is restricted to personnel who require it.

No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform you where the risk is high.

10. Children

The Services are not directed at children and we do not knowingly collect their data.

11. Changes

Material changes will be notified by email or through the portal. The last-updated date above always reflects the current version.

12. Contact and complaints

Data protection enquiries: privacy@cloudyvoice.com Supervisory authority: [TO BE COMPLETED — e.g. the ICO in the UK]