Who we are and scope
This Policy describes how Herous Futurus OÜ, operating as OpenPhonex, handles personal data across our websites, accounts, dashboards, APIs, phone numbers, calls, messages, recordings, transcripts, AI-agent connections, and support (the "Service").
Herous Futurus OÜ, Estonia. Contact us at [email protected].
Our privacy roles
We decide why and how to process account registration, KYC, billing, fraud prevention, security, support, website, and service-improvement data. For recordings, transcripts, prompts, knowledge, messages, tool data, and other content a customer routes through OpenPhonex, the customer normally decides the purpose and means of processing.
If you are a caller, message recipient, employee, or contact of an OpenPhonex customer, that customer is normally responsible for its privacy notice, legal basis, AI disclosure, recording consent, and response to your rights request. You may contact the customer directly; we will assist it as required.
Data we collect
- Account and contact data: name, email, organization, role, login provider, settings, language, and communications with us.
- Verification data: identity, age, address, company, beneficial-owner, use-case, and supporting-document data required by us, a verification provider, carrier, or authority.
- Telecom data: phone numbers, caller and recipient numbers, routing, SIP and room events, timestamps, duration, delivery status, carrier, country, IP address, device, and call or message metadata.
- Customer Content: audio, recordings where enabled, transcripts, summaries, prompts, responses, messages, knowledge sources, tool calls, tool results, and agent configuration.
- Billing data: plan, orders, wallet balance and ledger, usage, invoices, tax and payment status. Payment-card details are handled by our payment processor rather than stored by OpenPhonex.
- Technical and security data: API and audit events, authentication records, logs, diagnostics, abuse signals, consent records, and approximate location derived from IP or number.
- Website and support data: pages and interactions, cookie choices, analytics identifiers where permitted, masked session replay of site and workspace interaction where you have accepted optional browser analytics, support chats, contact-form submissions, and feedback.
Where data comes from
We receive data from you; your account administrators and users; callers and message participants; connected agents, tools, applications, and identity providers; carriers and number providers; identity-verification and payment providers; security and analytics systems; public or government sources used for compliance; and devices or browsers that access the Service.
Why we use data and our legal bases
- Contract: create accounts; provision numbers; route calls and messages; run configured AI agents and tools; provide recordings, transcripts, usage, billing, support, and requested features.
- Legal obligation: telecom registration, KYC, sanctions checks, tax, accounting, lawful requests, consumer protection, and records we must keep.
- Legitimate interests: secure and operate the Service, prevent fraud and abuse, troubleshoot, enforce our terms, manage providers, understand performance, and improve reliability. We balance these interests against your rights.
- Consent: optional analytics or marketing cookies and other processing where consent is the appropriate basis. You may withdraw consent without affecting earlier lawful processing.
- Customer instructions: process Customer Content to provide the Service as a processor or service provider under our Terms and the customer's configuration.
AI, voice, and automated processing
At a customer's direction, we send the data needed to selected speech-to-text, language-model, text-to-speech, and tool providers to generate live agent responses, transcripts, summaries, or actions. Provider choice can affect processing location and retention. Customers should avoid sending sensitive data unless their configuration and legal basis are appropriate.
When a customer uses Knowledge Bases, OpenPhonex stores the uploaded source file in private service storage and creates derived search chunks. Google Gemini may process source text and a hosted agent's search query to provide that feature. A source is available only to the hosted agents the customer attaches to its knowledge base; it is not made public or automatically sent to every call.
We may use automated risk signals to detect fraud, account takeover, prohibited traffic, or unusual spending. Where applicable law gives you rights concerning a decision with legal or similarly significant effects, you may request information and human review. We do not use customer call content to train a general-purpose OpenPhonex model unless we separately obtain the permission required by law.
Who receives data
We share only what is reasonably needed with:
- telecom carriers and number providers, including DIDWW and downstream networks;
- cloud infrastructure and communications systems, including DigitalOcean and our LiveKit-based media stack;
- AI and media providers selected for an agent, which may include Deepgram, Google Gemini, and ElevenLabs. Google Gemini may also process the source text and search query needed when a customer enables Knowledge Bases;
- identity-verification, payment, authentication, support, email, security, and professional-service providers, which may include Didit, Stripe, Google, GitHub, and Chatwoot;
- analytics providers, including PostHog for minimized operational product telemetry and, only after browser consent, PostHog for optional browser analytics and masked session replay and Google Analytics for optional browser analytics;
- authorities, courts, carriers, advisers, or affected parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or establish legal claims; and
- a buyer, investor, or successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice.
Providers can change as the Service evolves. We require providers handling personal data for us to protect it and use it only for the agreed services. Our current material providers, purposes, locations, and change process are in the Subprocessor register below.
International transfers
We are established in Estonia and use providers and telecom networks around the world. Data may therefore be processed outside your country, including outside the EEA, United Kingdom, or Switzerland. Where required, we rely on adequacy decisions, the European Commission's standard contractual clauses, the UK addendum or equivalent safeguards, and supplementary measures appropriate to the risk. Telecom routing may necessarily pass through the destination or originating country.
How long we keep data
We keep data only as long as needed for the purposes above, customer instructions, and legal requirements. Retention depends on the data and account configuration:
- Customer Content follows the customer's configured retention where available. Unless a different setting or order applies, the current default for stored call recordings is 90 days.
- Account, number, call-detail, message, audit, and support records are kept while the account is active and for a reasonable period afterward for service delivery, disputes, fraud prevention, and legal compliance.
- Accounting and transaction records are generally kept for seven years where Estonian law requires it.
- KYC and telecom registration data is kept for the provider or statutory period that applies to the number, account, or transaction.
- Security logs and backups expire on rolling schedules unless an incident, dispute, legal hold, or lawful request requires longer retention.
Deletion from live systems and backups may occur at different times. We may retain de-identified or aggregated information that can no longer reasonably identify a person.
Cookies, browser storage, and your choices
We use necessary cookies or local storage for authentication, security, language, one-time secret display, and your privacy preference. These support a service you request and are not controlled by the optional analytics choice:
- Authentication and security: signed session, email-challenge, short-lived secret-display, anti-abuse, and request-security state.
- Language: the NEXT_LOCALE cookie remembers the locale selected by you or negotiated by the site.
- Privacy preference: openphonex_cookie_consent in local storage remembers whether optional browser analytics are allowed. openphonex_cookie_consent is the preference we read; where PostHog is configured and has been started, its own SDK additionally keeps that choice in local storage under a __ph_opt_in_out_ key.
- Temporary product state: narrowly scoped cookies may display a newly created API key, gateway token, or webhook secret once and then expire it.
When enabled, optional browser analytics help us understand page and product interaction, performance, and feature adoption. Browser-side PostHog uses memory-only persistence, so it writes no analytics cookie and no device or visitor identifier of its own; the accept-or-decline flag described above is the only thing its SDK stores. Where it is configured, it also records a masked session replay of your interaction with the site and workspace, and only while your saved privacy preference is “Accept”. Outside the blocked elements described next, every value you type is masked before a replay leaves your browser, and so is every word displayed anywhere except our public marketing pages — the signed-in workspace and our internal operator views included — so a replay of the product shows layout, pointer movement and navigation rather than words, and a phone number on screen reaches us only as placeholder characters. On the public pages — the home, pricing, contact, legal and sign-in pages — the visible text is our own copy and is recorded as shown; the exception there is the live demo on the home page, whose conversation is masked because the words in it are yours. Masking reaches text and typed values, not element attributes or media addresses, so those surfaces are handled by blocking the element from capture altogether — it is omitted from the recording and leaves only an empty box, with nothing inside it recorded at all. Blocked are: the one-time display of a new API key, gateway token or webhook secret; call transcripts and message bodies; call-recording players and download links; the caller-ID element used across the workspace; every hidden input field; and the tooltips that would otherwise carry a number or an agent name. Network request and response bodies, request headers, and browser console output are never recorded. Interaction events record which element you used — its type, position, and styling classes — and not the text it displayed or the attributes on it. Google Analytics may set _ga and related _ga_* cookies. We do not use advertising cookies on the current public Service.
We separately record a small set of authenticated server-side product outcomes for service operation, reliability, security, and feature adoption. Those events do not depend on browser cookies, can use an account identifier, and are processed under our legitimate interests. We minimise event properties and do not use call audio, transcripts, messages, knowledge content, or tool payloads for this telemetry.
Where it is configured, we also collect error reports when our own software fails — in your browser, in the API, and in the software that runs a call. These are processed under our legitimate interest in a working and secure Service and are not part of the optional analytics choice above: they write no cookie and no identifier of their own, they describe a fault in our code rather than your behaviour, and an error report that only arrived from people who had already accepted analytics would not tell us the Service was broken. A report carries the fault — the error type and message, the file and line inside our code, the page or route, and the browser or release version — together with a short trail of the interactions and requests immediately before it. Before a report is sent we remove phone numbers, email addresses, SIP addresses, credentials and API keys from every part of it, discard the contents of local variables, and blank the fields that carry call transcripts, message bodies and prompts. The receiving service additionally records the network address a report arrived from, truncated so that its final segment is removed; we do not use it to identify you, and it is the only part of an error report we do not control from the sending side. Reports go to our own error-tracking instance on the hosting infrastructure named in the register above; no new recipient receives them.
The Chatwoot support client is loaded only after you choose a Support entry. It may then use browser storage needed to maintain that conversation. Do not include call content, credentials, identity documents, or other sensitive data unless our support team requests it through an appropriate secure channel.
Use the control below or “Cookie settings” in the footer at any time to accept or withdraw optional browser analytics. Withdrawal stops further optional browser analytics and removes Google Analytics cookies visible to this origin. Your choice is browser- and device-specific; necessary storage cannot be disabled through this control.
Security and responsible disclosure
OpenPhonex operates a telecom and AI control plane where call content, credentials, identity information, and provider actions require different trust boundaries. We use safeguards proportionate to those risks, including tenant-bound authorization, narrowly scoped credentials, TLS in transit, protected service secrets, separated runtime roles, audit records, monitoring, backups, incident procedures, and reviewed image/release gates. No system is completely secure and this summary is not a certification or guarantee.
Customers must protect account and API credentials, remove former users, scope tools and provider keys, secure connected systems, review agent behavior, configure lawful recording and retention, and report suspected compromise promptly. Never send secrets in ordinary support chat or email.
Act in good faith and avoid privacy violations, service disruption, social engineering, persistence, data destruction, high-volume scanning, or access beyond what is needed to demonstrate the issue. Give us a reasonable opportunity to investigate before public disclosure. We will acknowledge reports and coordinate remediation based on severity, but we do not currently promise a bounty. We investigate suspected incidents and notify affected customers or authorities when applicable law or the DPA below requires it.
Your privacy rights
Depending on your location and our role, you may have the right to access, correct, delete, restrict, or receive a copy of your data; object to certain processing; withdraw consent; opt out of certain profiling, sale, sharing, or targeted advertising; and appeal a denied request.
Email [email protected] with "Privacy request" in the subject and identify the account, phone number, or customer relationship relevant to the request without sending passwords, full identity documents, recordings, or other unnecessary sensitive data. We may verify your identity and authority through a safer channel, and applicable exceptions may limit a request. Authorized agents may submit requests where local law permits. We will respond without undue delay and normally within one month under the GDPR, subject to a permitted extension for complex or numerous requests. We will not discriminate against you for exercising a privacy right.
If OpenPhonex processes your data only for a customer, send the request to that customer first. We will support the customer's response. EEA residents may complain to the Estonian Data Protection Inspectorate or their local supervisory authority.
United States privacy notice
For residents of US states with applicable privacy laws, the categories described in section 3 are the categories we collected during the preceding 12 months. We use and disclose them for the business and commercial purposes in sections 5 and 7 and retain them as described in section 9.
We do not sell call recordings, transcripts, message content, KYC documents, or payment data for money. We do not knowingly sell or share personal data of people under 18. If an optional analytics activity is legally treated as a sale, sharing, or targeted advertising in your state, we will provide the notice and choice required by that law. You can exercise applicable rights using the process in section 12.
Children
The Service is not directed to children, and account holders must be at least 18. We do not knowingly collect personal data directly from a child to create an account. A customer must not use the Service to collect children's data unless it has a lawful, appropriately configured use case and all required parental or guardian permissions.
Business Data Processing Addendum
Parties, roles, and processing details
Customer is the controller, or a processor appointing OpenPhonex as a subprocessor. OpenPhonex is the processor or subprocessor. Terms such as personal data, processing, controller, processor, data subject, and supervisory authority have the meanings in applicable data-protection law.
- Subject and purpose: provide, secure, support, and troubleshoot customer-configured phone numbers, calls, messages, agents, tools, knowledge, recordings, transcripts, and related features.
- Duration: the Agreement plus limited deletion, backup, legal-hold, dispute, and statutory-retention periods described in this Policy and the Service configuration.
- Data subjects: Customer users, staff, callers, recipients, contacts, and people represented in Customer Content.
- Data and operations: identifiers, phone numbers, audio, recordings, transcripts, messages, prompts, knowledge, tool inputs/results, and interaction/routing metadata that OpenPhonex collects, transmits, routes, hosts, records where enabled, transcribes, retrieves, generates, secures, deletes, returns, or discloses to authorized providers.
Instructions and responsibilities
OpenPhonex processes personal data only on documented Customer instructions in the Agreement, account configuration, API or tool calls, and lawful written requests, unless Union or Member State law requires otherwise. We will inform Customer before legally required processing unless prohibited. We will promptly tell Customer if, in our reasonable opinion, an instruction infringes applicable data-protection law and may suspend that instruction.
Customer is responsible for a lawful basis, required notices and consents, data accuracy, authorized users, configured retention, and the legality of calls, messages, recording, AI use, knowledge, and connected tools.
Confidentiality, security, and assistance
Authorized personnel are bound by confidentiality. Taking account of the state of the art, cost, nature, scope, context, purposes, and risk, OpenPhonex maintains measures designed to protect personal data, including:
- tenant- and scope-based access controls, authentication, least-privilege service credentials, and secret-management boundaries;
- encryption in transit, protected storage and backups where configured, network isolation, and provider access controls;
- audit and security logging, monitoring, incident response, vulnerability and dependency management, and tested release controls;
- data minimisation, bounded customer-facing collections, retention and deletion controls, and restrictions on production access.
No measure eliminates every risk. Customer must secure its credentials, devices, connected systems, tools, and provider accounts and choose settings appropriate to its use case.
- We provide reasonable technical and organizational assistance for data-subject requests.
- We notify Customer without undue delay after confirming a personal-data breach affecting Customer Content and provide information available to support Customer’s obligations.
- We provide reasonable assistance with security obligations, data-protection impact assessments, and prior consultation, considering information available to us.
- We make information reasonably necessary to demonstrate compliance available and permit a proportionate audit no more than annually, or when required by a competent authority or material incident, subject to advance notice, confidentiality, security, non-disruption, and reasonable cost allocation.
Subprocessors and restricted transfers
Customer gives general written authorization for the subprocessors in the register below. We impose written data-protection obligations appropriate to their services and remain responsible for their performance to the extent required by applicable law. We provide reasonable advance notice of a new material subprocessor. Customer may object within 15 days on reasonable data-protection grounds. The parties will seek a reasonable alternative; if none is available, either party may discontinue or terminate the affected Service without penalty beyond charges already incurred.
Where GDPR personal data is transferred to a country without an applicable adequacy decision, the European Commission Standard Contractual Clauses adopted by Decision 2021/914 are incorporated by reference. Module Two or Module Three applies as appropriate; Option 2 general authorization and the optional docking clause apply; supervisory authority and governing Member State are determined under the Clauses, with Estonia used where a selection is required; and Estonian courts have jurisdiction under Clause 18. The applicable UK International Data Transfer Addendum and Swiss adaptations supplement those Clauses where required.
Return, deletion, and priority
During the Service, Customer may use available export and deletion features or request reasonable assistance. After termination, and on Customer’s request within 30 days, we will return or delete Customer Content where technically feasible unless law requires retention. Remaining copies are deleted according to normal retention and backup cycles, subject to legal hold, security, and dispute requirements.
DPA questions may be sent to [email protected].
Subprocessors and service providers
A subprocessor processes personal data on our behalf when OpenPhonex acts as a processor for a customer. Some listed organizations may instead act as an independent controller for a particular activity, such as telecom compliance or payment processing. AI providers process Customer Content only when the customer selects or enables that provider or feature.
DigitalOcean
- Purpose
- Cloud hosting, managed database, object storage, networking, and backups
- Data
- Account data, Customer Content, call artifacts, logs, and configuration
- Location
- Customer-selected service region; support and corporate operations may be global
DIDWW and downstream telecom networks
- Purpose
- Phone numbers, identity/registration delivery, and call/message routing
- Data
- Identity and registration data, phone numbers, communications metadata, and routed content
- Location
- Ireland/EEA and the countries or networks needed to originate or terminate a communication
Deepgram
- Purpose
- Customer-selected speech-to-text processing
- Data
- Live call audio and resulting transcript
- Location
- Provider processing locations and transfer terms applicable to the selected service
Google (Gemini and related AI services)
- Purpose
- Customer-selected language-model processing and enabled Knowledge Base search
- Data
- Prompts, transcripts, tool context, knowledge source text, and queries
- Location
- Provider processing locations and applicable transfer safeguards
ElevenLabs
- Purpose
- Customer-selected text-to-speech processing
- Data
- Text to synthesize, voice configuration, and generated audio
- Location
- Provider processing locations and applicable transfer safeguards
Didit
- Purpose
- Identity and business verification
- Data
- Verification identifiers, documents, images, and decision metadata
- Location
- Provider processing locations and applicable transfer safeguards
Stripe
- Purpose
- Payments, invoices, fraud controls, and payment status
- Data
- Account, billing, transaction, tax, and payment metadata; card data goes directly to Stripe
- Location
- EEA, United States, and other provider locations under applicable safeguards
PostHog
- Purpose
- Minimized product and service analytics, and masked session replay, when configured
- Data
- Operational event, account or pseudonymous identifier, device/page metadata, and masked session replay of site and workspace interaction; every value you type is masked before capture, the words displayed in the signed-in workspace and in our internal operator views are masked before capture, the text of our public marketing pages is recorded as shown, and the elements that reveal secrets, transcripts, message bodies and call recordings are blocked from it entirely
- Location
- Configured EU analytics endpoint where enabled
GlitchTip (self-hosted)
- Purpose
- Error and crash reporting for our own software
- Data
- Error type and message, the file and line inside our code, page path, browser version, the software release for our server-side components, a truncated network address recorded on receipt, and a short trail of interactions and requests before the failure; phone numbers, addresses, credentials, local variables and the fields carrying transcripts, message bodies and prompts are removed before a report is sent
- Location
- Our own instance on the hosting infrastructure listed above; no new recipient
Google Analytics
- Purpose
- Optional public-site and product browser analytics
- Data
- Cookie/device identifiers and page or interaction metadata after consent
- Location
- Provider locations under applicable transfer safeguards
- Open-source LiveKit components and Chatwoot currently operated on OpenPhonex-controlled infrastructure do not by themselves create a separate vendor recipient. If a hosted vendor service is enabled, we will update this register before relying on it for Customer Content.
- Customer-controlled providers, SIP trunks, models, tools, webhooks, or knowledge sources are governed by the customer's direct relationship with that provider and are not appointed by OpenPhonex as our subprocessor.
- Google and GitHub may act as authentication providers when a user chooses their sign-in option. Their own privacy terms apply to that direct interaction.
We update this register before a new material subprocessor begins processing Customer Content and provide reasonable advance notice through the account contact or Service where the change materially affects customer processing. Send notice subscriptions, questions, or objections to [email protected].
Changes and contact
We may update this Policy as the Service, providers, and laws change. We will post the new version here and give additional notice when a change materially affects your rights or our use of personal data.
Questions, complaints, or requests can be sent to [email protected]. Herous Futurus OÜ, Estonia. Customer processing is also governed by the Data Processing Addendum above.