Scope and roles
This Data Processing Addendum (the “DPA”) forms part of the Terms of Service between the member (the “Controller” or “you”) and Minutes Network FZ-LLC (the “Processor” or “we”). It applies whenever we process personal data on your behalf in providing the Platform and data protection law, including the UK GDPR and the EU GDPR, applies to that processing. Terms defined in the GDPR have the same meaning here.
It does not cover personal data about you and your team as account holders, which we handle as a controller under our Privacy Policy.
The DPA applies without a signature. If you need a signed copy for your records, contact support@packetexchange.io.
Details of the processing
| Item | Details |
|---|---|
| Subject matter | Providing the Platform under the Terms: carrying, routing, rating and billing calls and messages, and hosting the content you store. |
| Duration | While you use the Platform, then until the data is deleted under section 9. |
| Nature and purpose | Transmission, switching, storage, retrieval, real-time speech and AI processing for AI voice agents you enable, and deletion, only to provide the Platform. |
| Data subjects | People you call or message and who call or message you; your customers and their users on the Switch; people in contact lists you upload; people recorded on your numbers. |
| Personal data | Phone numbers and caller IDs; call times, duration and routing; IP addresses and signalling; SMS content; call recordings and voicemails; contact list data you upload; AI voice call audio, processed in real time. |
| Special category data | Not needed for the Platform. Do not upload it unless you have a lawful basis to process it. |
Your instructions
We process the personal data only on your documented instructions, which are the Terms, this DPA and the way you use and configure the Platform, unless the law requires otherwise. In that case we tell you first, unless the law forbids it. If we believe an instruction breaks data protection law, we tell you.
You are responsible for having a lawful basis for the processing you instruct, including consent for calls, messages, recordings and AI voice calls where the law requires it.
Our obligations
- People we authorise to process the data are bound by confidentiality.
- We maintain the security measures in section 6.
- Taking into account the nature of the processing, we help you respond to requests from data subjects and meet your obligations on security, breach notification, impact assessments and prior consultation.
- We do not sell the data or use it for our own purposes, except to keep the Platform and the telephone network secure, prevent fraud, meet legal obligations and produce statistics that identify no one.
Sub-processors
You authorise us to use sub-processors to provide the Platform. Each is bound by written terms that protect the data at least as well as this DPA, and we remain responsible for their work. The categories we use today are:
| Service | What it does | Data involved | Where |
|---|---|---|---|
| Data centre hosting | Runs the Platform’s servers and databases | All data held on the Platform | Germany |
| Phone numbers and messaging | Provides phone numbers and carries the calls and SMS on them | Phone numbers, call and message records, SMS content, and registration documents for numbers that need them | European Union |
| Speech processing | Turns speech into text and text into speech for AI voice agents | Live call audio and the words spoken | United States |
| AI models | Powers AI voice agents and assistants, and reads uploaded rate sheets and contact lists | Conversation text, questions and the content of uploaded files | United States |
| Email delivery | Sends account, billing, security, number activity and status emails | Email addresses, names and the content of the emails | United States |
| Caller ID testing | Places test calls to real handsets and reports the caller ID received | The caller ID and route under test | Worldwide |
Carriers and route sellers that carry your traffic receive the signalling needed to connect each call and message. They act under their own telecoms obligations rather than as our sub-processors.
The named list is available on request at support@packetexchange.io. We tell account owners by email at least 30 days before a new sub-processor starts processing their data. You can object on reasonable data protection grounds in that time. If we cannot resolve the objection, you can stop using the affected feature or close your account, and we refund the unused part of any Switch subscription period.
Security measures
- TLS encryption for the website, dashboard and API.
- Passwords stored as bcrypt hashes and API keys as SHA-256 hashes.
- Two-factor authentication and role-based permissions for team members.
- Production servers in access-controlled data centres in Germany, with administrative access limited to authorised staff using key-based authentication.
- Private networking between servers and databases, replicated databases, and audit trails of account and administrative actions.
- Automated fraud and traffic controls, and automatic deletion of signalling traces, request logs and expired recordings.
- Staff access to member data only where needed for support, billing, security or legal reasons.
Calls and messages cross public carrier networks that may not encrypt them. You are responsible for securing your own credentials, systems and SIP and SMPP endpoints, and for the security settings you choose on the Platform.
Personal data breaches
We tell you without undue delay, and aim to do so within 48 hours, after becoming aware of a personal data breach affecting data we process for you. We share what we know about what happened, the data affected and what we are doing about it, and keep you updated as we learn more.
International transfers
Platform servers are in Germany, and Minutes Network FZ-LLC is established in the United Arab Emirates, which has no adequacy decision from the UK or the European Union. So where you transfer personal data to us from the UK or the European Economic Area, Module Two (controller to processor) of the European Commission’s Standard Contractual Clauses, with the UK Addendum where relevant, is incorporated into this DPA. Where a sub-processor processes the data in another country without an adequacy decision, the transfer is covered by the same clauses or another mechanism the law recognises.
Return and deletion
While your account is open, you can export call records and delete recordings, voicemails, contact lists and other content from your dashboard. Recordings and voicemails are also deleted automatically on the retention period you set for each number.
Before closing your account, export anything you want to keep. After closure, we delete the recordings, voicemails, message content and contact lists we hold for you within 30 days of your request to support@packetexchange.io. Call records and financial records are kept where the law, billing, tax, fraud prevention or an open dispute requires, and stay protected under this DPA for as long as we keep them.
| Record | How long we keep it |
|---|---|
| Signalling traces for each call | 7 days, then deleted automatically |
| API request logs | 90 days, then deleted automatically |
| Call recordings and voicemails | The period the member sets for each number (30 days by default), then deleted automatically |
| Call and message records | While needed for billing, disputes, fraud prevention and legal obligations |
| SMS message content | While the member’s account is open, and after closure until deleted on request |
| Account details | While the account is open. Name, email address, company, phone number and country are removed when it is closed |
| Financial records | For as long as tax and accounting law requires, including after the account is closed |
Audits
We provide the information reasonably needed to show that we meet this DPA, including answers to security questionnaires. If that is not enough, or a regulator requires it, you may audit our compliance once a year, with at least 30 days’ notice, during business hours and at your cost, under confidentiality and without access to other members’ data.
Liability and precedence
Liability under this DPA is subject to the limits in the Terms, as far as the law allows. On data protection, this DPA takes precedence over the Terms, and the Standard Contractual Clauses take precedence over both where they apply.
Contact
- Legal notices, privacy, abuse reports, law enforcement requests and support
- support@packetexchange.io