Company Data Privacy Policy
Last Updated: July 2025
1. Introduction
At VirPhone, we are committed to protecting the company data entrusted to us by our business customers. This Company Data Privacy Policy specifically addresses how we collect, process, store, and protect data belonging to business customers and their organizations when utilizing our cloud communications services, enterprise accounts, and related infrastructure. This document operates alongside our general Privacy Policy to provide specific clarity for our B2B customers.
2. Definitions
To ensure clarity throughout this policy, we define the following key terms:
- Company Data: Any business data transmitted, stored, or processed through VirPhone services. This includes call records, voicemails, recordings, contact directories, and technical configurations.
- Customer: The business entity or organization that holds an account with VirPhone.
- Authorized Users: Employees, contractors, or agents using VirPhone services on behalf of the Customer.
- ConnectOne™: VirPhone's proprietary mobile and desktop application.
3. Company Data We Process
In order to provide our comprehensive enterprise communication services, we process the following types of Company Data:
- Call Detail Records (CDRs): Call timestamps, durations, source, and destination numbers.
- Voicemail and Call Recordings: Audio files and metadata (only when explicitly enabled and configured by the Customer).
- System Configurations: Auto attendant routing rules, IVR menus, and call queue settings.
- Contact Directories: Company-wide contact lists and user address books.
- User Account Information: Names, extensions, role assignments, and permission tiers.
- Billing Information: Payment details and invoicing history.
- Network Data: Device configuration data, IP addresses, and quality-of-service metrics.
- Messaging Data: Chat and SMS/MMS messaging transcripts (if applicable to the Customer's service plan).
4. How We Use Company Data
VirPhone processes Company Data solely for the following business purposes:
- Service delivery, operation, and maintenance of our cloud PBX/UCaaS platform.
- Accurate billing, invoicing, and account management.
- Providing technical support, troubleshooting, and customer service.
- Monitoring network optimization, security, and quality of service.
- Complying with mandatory legal and regulatory obligations, including CPNI rules, E911 routing, and lawful intercept requirements.
- Service improvements and feature development (utilizing aggregated and de-identified data only).
5. Data Ownership
The Customer retains full and absolute ownership of all their Company Data. VirPhone processes Company Data strictly as a service provider on behalf of the Customer. We do not sell, rent, or trade your Company Data to any third parties. Furthermore, VirPhone strictly prohibits the use of Company Data for advertising or marketing to third parties.
6. Data Storage and Security
We maintain stringent security controls to protect Company Data:
- Hosting: Data is hosted in SOC 2 compliant, geo-redundant data centers located within the United States.
- Encryption: Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.
- Voice/Video Security: Active voice and video streams are encrypted utilizing Secure Real-time Transport Protocol (SRTP).
- Access Controls: VirPhone personnel access is governed by strict role-based access controls (RBAC) and principle-of-least-privilege methodologies.
- Monitoring: We conduct regular security audits, vulnerability assessments, and maintain 24/7 intrusion detection and monitoring systems.
- Incident Response: Formalized incident response procedures are in place to address potential security events swiftly.
7. Data Retention
Our data retention policies are designed to balance service functionality with security:
- CDRs: Call Detail Records are retained according to the Customer's account settings, with a default retention period of 12 months.
- Voicemails and Recordings: Retained strictly according to the Customer's configuration and storage limits.
- Service Termination: Upon termination of service, Company Data remains available for export by the Customer for 30 days. Following this period, it is permanently deleted from our active and backup systems within 90 days.
- Legal Holds: Certain data may be retained for longer periods if mandated by law, regulation, or active legal proceedings.
8. Data Access and Control
We provide Customers with comprehensive control over their Company Data:
- Customers can access, export, and delete their Company Data directly through the VirPhone administrative portal.
- Customers have total control over user permissions, role assignments, and access levels within their own organization.
- VirPhone personnel access Company Data only when strictly necessary for technical support (with Customer authorization) or for legal compliance.
- Customers may request a full, structured data export at any time during their active service period.
9. Sub-processors and Third Parties
To deliver our enterprise services, VirPhone utilizes trusted sub-processors for underlying infrastructure, payment processing, and core service delivery. All sub-processors are rigorously vetted and bound by strict data protection agreements that match or exceed the commitments in this policy. A complete list of current sub-processors is available upon request. We will notify Customers of any material changes to our sub-processor list.
10. CPNI Compliance
Customer Proprietary Network Information (CPNI) relates to the quantity, technical configuration, type, destination, location, and amount of use of a telecommunications service. VirPhone strictly complies with Federal Communications Commission (FCC) regulations regarding the protection of CPNI. CPNI is utilized exclusively for providing, maintaining, and marketing related telecommunications services to you. Customers maintain the right to restrict the use of their CPNI at any time by contacting our support team.
11. Breach Notification
In the unlikely event of a security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Company Data, VirPhone will notify affected Customers without unreasonable delay (and within 72 hours of incident confirmation). Notification will detail the nature of the breach, the specific data affected, immediate remediation steps taken, and a designated point of contact for further inquiries. VirPhone maintains comprehensive cyber insurance and a tested incident response plan.
12. ConnectOne™ Mobile App
When Authorized Users utilize the ConnectOne™ mobile application, they may access Company Data such as contacts, call history, and voicemail. All Company Data accessed or transmitted via ConnectOne™ operates under the exact same stringent protections described in this policy. Data synced to mobile devices is encrypted locally and can be remotely wiped by the Customer's administrator via the VirPhone portal if a device is lost or an employee departs. For comprehensive details regarding device permissions and app-specific data collection, please refer to Section 9 of our general Privacy Policy.
13. Changes to This Policy
We may update this Company Data Privacy Policy from time to time to reflect changes in our operational practices, new features, or evolving regulatory requirements. We will notify Customers of any material changes by updating the "Last Updated" date at the top of this document, and for significant changes, by providing notice via the VirPhone administrative portal or email.
Questions About Your Company's Data?
Our compliance and security teams are available to address any concerns regarding how we protect your organization's information.
Contact Our Privacy TeamVirPhone
7659 Mall Road, STE 1174, Florence, KY 41042
1-844-684-9222
