VirPhone

Company Data Privacy Policy

Last Updated: July 2025

1. Introduction

At VirPhone, we are committed to protecting the company data entrusted to us by our business customers. This Company Data Privacy Policy specifically addresses how we collect, process, store, and protect data belonging to business customers and their organizations when utilizing our cloud communications services, enterprise accounts, and related infrastructure. This document operates alongside our general Privacy Policy to provide specific clarity for our B2B customers.

2. Definitions

To ensure clarity throughout this policy, we define the following key terms:

  • Company Data: Any business data transmitted, stored, or processed through VirPhone services. This includes call records, voicemails, recordings, contact directories, and technical configurations.
  • Customer: The business entity or organization that holds an account with VirPhone.
  • Authorized Users: Employees, contractors, or agents using VirPhone services on behalf of the Customer.
  • ConnectOne™: VirPhone's proprietary mobile and desktop application.

3. Company Data We Process

In order to provide our comprehensive enterprise communication services, we process the following types of Company Data:

  • Call Detail Records (CDRs): Call timestamps, durations, source, and destination numbers.
  • Voicemail and Call Recordings: Audio files and metadata (only when explicitly enabled and configured by the Customer).
  • System Configurations: Auto attendant routing rules, IVR menus, and call queue settings.
  • Contact Directories: Company-wide contact lists and user address books.
  • User Account Information: Names, extensions, role assignments, and permission tiers.
  • Billing Information: Payment details and invoicing history.
  • Network Data: Device configuration data, IP addresses, and quality-of-service metrics.
  • Messaging Data: Chat and SMS/MMS messaging transcripts (if applicable to the Customer's service plan).

4. How We Use Company Data

VirPhone processes Company Data solely for the following business purposes:

  • Service delivery, operation, and maintenance of our cloud PBX/UCaaS platform.
  • Accurate billing, invoicing, and account management.
  • Providing technical support, troubleshooting, and customer service.
  • Monitoring network optimization, security, and quality of service.
  • Complying with mandatory legal and regulatory obligations, including CPNI rules, E911 routing, and lawful intercept requirements.
  • Service improvements and feature development (utilizing aggregated and de-identified data only).

5. Data Ownership

The Customer retains full and absolute ownership of all their Company Data. VirPhone processes Company Data strictly as a service provider on behalf of the Customer. We do not sell, rent, or trade your Company Data to any third parties. Furthermore, VirPhone strictly prohibits the use of Company Data for advertising or marketing to third parties.

6. Data Storage and Security

We maintain stringent security controls to protect Company Data:

  • Hosting: Data is hosted in SOC 2 compliant, geo-redundant data centers located within the United States.
  • Encryption: Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.
  • Voice/Video Security: Active voice and video streams are encrypted utilizing Secure Real-time Transport Protocol (SRTP).
  • Access Controls: VirPhone personnel access is governed by strict role-based access controls (RBAC) and principle-of-least-privilege methodologies.
  • Monitoring: We conduct regular security audits, vulnerability assessments, and maintain 24/7 intrusion detection and monitoring systems.
  • Incident Response: Formalized incident response procedures are in place to address potential security events swiftly.

7. Data Retention

Our data retention policies are designed to balance service functionality with security:

  • CDRs: Call Detail Records are retained according to the Customer's account settings, with a default retention period of 12 months.
  • Voicemails and Recordings: Retained strictly according to the Customer's configuration and storage limits.
  • Service Termination: Upon termination of service, Company Data remains available for export by the Customer for 30 days. Following this period, it is permanently deleted from our active and backup systems within 90 days.
  • Legal Holds: Certain data may be retained for longer periods if mandated by law, regulation, or active legal proceedings.

8. Data Access and Control

We provide Customers with comprehensive control over their Company Data:

  • Customers can access, export, and delete their Company Data directly through the VirPhone administrative portal.
  • Customers have total control over user permissions, role assignments, and access levels within their own organization.
  • VirPhone personnel access Company Data only when strictly necessary for technical support (with Customer authorization) or for legal compliance.
  • Customers may request a full, structured data export at any time during their active service period.

9. Sub-processors and Third Parties

To deliver our enterprise services, VirPhone utilizes trusted sub-processors for underlying infrastructure, payment processing, and core service delivery. All sub-processors are rigorously vetted and bound by strict data protection agreements that match or exceed the commitments in this policy. A complete list of current sub-processors is available upon request. We will notify Customers of any material changes to our sub-processor list.

10. CPNI Compliance

Customer Proprietary Network Information (CPNI) relates to the quantity, technical configuration, type, destination, location, and amount of use of a telecommunications service. VirPhone strictly complies with Federal Communications Commission (FCC) regulations regarding the protection of CPNI. CPNI is utilized exclusively for providing, maintaining, and marketing related telecommunications services to you. Customers maintain the right to restrict the use of their CPNI at any time by contacting our support team.

11. Breach Notification

In the unlikely event of a security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Company Data, VirPhone will notify affected Customers without unreasonable delay (and within 72 hours of incident confirmation). Notification will detail the nature of the breach, the specific data affected, immediate remediation steps taken, and a designated point of contact for further inquiries. VirPhone maintains comprehensive cyber insurance and a tested incident response plan.

12. ConnectOne™ Mobile App

When Authorized Users utilize the ConnectOne™ mobile application, they may access Company Data such as contacts, call history, and voicemail. All Company Data accessed or transmitted via ConnectOne™ operates under the exact same stringent protections described in this policy. Data synced to mobile devices is encrypted locally and can be remotely wiped by the Customer's administrator via the VirPhone portal if a device is lost or an employee departs. For comprehensive details regarding device permissions and app-specific data collection, please refer to Section 9 of our general Privacy Policy.

13. Changes to This Policy

We may update this Company Data Privacy Policy from time to time to reflect changes in our operational practices, new features, or evolving regulatory requirements. We will notify Customers of any material changes by updating the "Last Updated" date at the top of this document, and for significant changes, by providing notice via the VirPhone administrative portal or email.

Questions About Your Company's Data?

Our compliance and security teams are available to address any concerns regarding how we protect your organization's information.

Contact Our Privacy Team

VirPhone
7659 Mall Road, STE 1174, Florence, KY 41042
1-844-684-9222

Ready to modernize your communications?Talk to our experts today.