Who we are
Minutes Network FZ-LLC, registered in the Ras Al Khaimah free zone, United Arab Emirates (Licence No. 47016932), runs the PacketExchange platform (the “Platform”) and is the controller of personal data about account holders, their team members, website visitors and people who contact us. Our UK and EU contact is Minutes Network Limited, Leeds, United Kingdom (company no. 13955776).
When we carry calls and messages for a member, or store recordings, messages and contact lists for them, we act on that member’s behalf as their processor under our Data Processing Addendum. If your question is about how a member uses your data, for example a call you received from them, contact that member. We will help them respond.
For anything in this policy, contact support@packetexchange.io.
What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account details | Name, email address, company, phone number, country, profile photo, tax ID and tax country. | You and your team |
| Sign-in and security | Your password (stored only as a one-way hash), two-factor settings, your Google account ID if you sign in with Google, sign-in times, IP addresses and browser details. | You, your browser and Google |
| Payments | Top-ups, invoices and withdrawals, the wallet address or bank details you give for payouts, and blockchain transaction IDs. Our card payment processor collects card details; we keep only a reference to the card. | You and our payment providers |
| Call and message records | Calling and called numbers, caller ID, times, duration, route, price, IP addresses, call signalling and call quality measurements. | Created as traffic passes through the Platform |
| Message content | The text of SMS messages sent or received through the Platform. | Members and the people they message |
| Content members store | Call recordings, voicemails, call menu prompts and audio files, dialer contact lists, do-not-call lists, AI agent instructions and rate sheets. | Members |
| Activity on the Platform | API requests (endpoint, time, IP address and result) and account actions such as purchases, settings changes and approvals. | Created as you use the Platform |
| Communications | Support requests, emails with us and status page subscriptions. | You |
How we use it
| Purpose | Legal basis under the UK and EU GDPR |
|---|---|
| Providing the Platform: running your account, carrying and billing traffic, storing your content and paying out earnings | Performing our contract with you |
| Protecting the Platform and the telephone network: detecting fraud, artificial traffic and account takeover, blocking abusive traffic and enforcing our policies | Our legitimate interests, and those of other members and carriers, in security and fraud prevention |
| Meeting legal obligations: tax and accounting records, sanctions rules, lawful requests from authorities and US voice compliance | Legal obligation |
| Communicating with you: service, billing and security emails, status updates you subscribe to and replies to support requests | Performing our contract with you, or your consent for status subscriptions |
| Improving the Platform: understanding how features are used, fixing faults and producing market statistics that identify no one | Our legitimate interests in running and developing the Platform |
We do not sell personal data or use it for advertising. We do not use call audio, recordings or message content to train AI models.
AI features
Some features use AI. When you use one, the content it needs is sent to an AI provider to produce the result:
- AI voice agents. The live audio of the call is converted to text, answered by an AI model and converted back into speech.
- Imports. Rate sheets and contact lists you upload are read by an AI model so they can be imported.
- Assistants. The support assistant and the assistants in the dialer and the Switch read your questions and the account information needed to answer them.
None of these features makes decisions about you that have legal or similarly significant effects. Fraud and traffic controls can block calls or hold funds automatically, and a person reviews any suspension or withheld payout if you ask.
Where your data is
The Platform’s servers and databases are in data centres in Germany. The company that runs the Platform is established in the United Arab Emirates, some of our providers, including our email, payment and AI providers, process data in the United States and other countries, and calls and messages cross carrier networks in the countries they connect. When personal data leaves the UK or the European Economic Area for a country without an adequacy decision, the United Arab Emirates included, we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where relevant, or another transfer mechanism the law recognises.
How long we keep it
| Record | How long we keep it |
|---|---|
| Signalling traces for each call | 7 days, then deleted automatically |
| API request logs | 90 days, then deleted automatically |
| Call recordings and voicemails | The period the member sets for each number (30 days by default), then deleted automatically |
| Call and message records | While needed for billing, disputes, fraud prevention and legal obligations |
| SMS message content | While the member’s account is open, and after closure until deleted on request |
| Account details | While the account is open. Name, email address, company, phone number and country are removed when it is closed |
| Financial records | For as long as tax and accounting law requires, including after the account is closed |
Members can delete recordings, voicemails and contact lists from their dashboard at any time, and can set how long recordings are kept for each number.
Your rights
Depending on where you live, you can ask us to give you a copy of your personal data, correct it, delete it, restrict how we use it or transfer it to you in a portable format. You can also object to processing based on our legitimate interests, and withdraw consent where we rely on it.
- Most account details can be changed in your settings, and call records can be exported from your dashboard.
- You can close your account from your settings. We then remove your name, email address, company, phone number, country and two-factor settings, and keep only what the law, billing or an open dispute requires.
- For anything else, email support@packetexchange.io from the address on your account. We reply within one month.
If you are in the UK or the EU, you can complain to your data protection authority. We would welcome the chance to resolve your concern first.
Security
- Connections to the website, dashboard and API are encrypted with TLS.
- Passwords are stored as bcrypt hashes and API keys as SHA-256 hashes, so neither can be read back.
- Two-factor authentication is available on every account, and team members get only the permissions they are given.
- Administrative access to production systems is limited to authorised staff and uses key-based authentication.
If a breach affects your personal data, we tell you and the relevant authorities as the law requires.
Children
The Platform is for businesses and is not directed at anyone under 18. We do not knowingly accept children as account holders.
Changes to this policy
We post updates on this page with a new date and version. If a change materially affects how we use your personal data, we tell account holders by email or in the dashboard before it takes effect.
Contact
- Legal notices, privacy, abuse reports, law enforcement requests and support
- support@packetexchange.io