Legal

Privacy Policy

Voice traffic generates unusually sensitive data — who called whom, from where, for how long, and sometimes what was said. This policy explains exactly what Telecorenetwork collects, why we collect it, how long we keep it and what you can ask us to do with it.

Last updated: 11 August 2026

Who we are and the scope of this policy

Telecorenetwork ("Telecorenetwork", "we", "us") provides enterprise VoIP and cloud communications services, including SIP trunking, hosted PBX, DID numbers, wholesale voice termination, contact centre software, voice APIs and A2P messaging. Our registered address is Forum One, 8000 W Interstate 10, Suite 1011, San Antonio, TX 78230, United States, and we operate 42 points of presence supporting customers in more than 190 countries.

This policy covers personal data we process through our public website, our customer portal, our APIs and our voice and messaging network. It does not cover the websites of other companies you may reach through links from ours, and it does not replace any data processing agreement you have signed with us — where a signed DPA and this policy conflict, the DPA governs.

Our role depends on the data. For your account, billing and support relationship with us, Telecorenetwork is a data controller and decides how that data is used. For the communications your organisation carries across our network — call records, message content, recordings you configure — Telecorenetwork generally acts as a data processor on your instructions, with the exception of the limited processing we must perform as a regulated telecommunications carrier.

Information we collect

We group the data we hold into five categories, because each is collected for a different reason and kept for a different period.

  • Account and contact data. Names, business email addresses, telephone numbers, job titles, company names, billing addresses, tax identifiers, portal usernames, authentication credentials and multi-factor enrolment details, plus the identity documents some regulators require before a number range can be allocated.
  • Call detail records and signalling metadata. Calling and called numbers, timestamps, duration, disposition and release cause, trunk and route identifiers, SIP user agent strings, IP addresses of registering endpoints, codec negotiated, and quality telemetry such as jitter, packet loss, round-trip time and derived MOS.
  • Message records. Sender and recipient numbers, timestamps, delivery receipts, campaign and brand identifiers, and — where your configuration requires us to store it for delivery or regulatory purposes — message content.
  • Call recordings and transcripts, where enabled. Recording is off by default on every Telecorenetwork service. It becomes active only when you switch it on for a trunk, queue, extension or API application. When it is on, we store the audio you have asked us to store and, if you have enabled transcription or voice analytics, the derived text and metadata.
  • Website and product usage data. Pages viewed, referring URL, approximate location derived from IP address, browser and device characteristics, portal actions such as configuration changes and number orders, API request logs, and support interactions including tickets, chat transcripts and — where you are told at the start of the call — support call recordings.

We do not knowingly collect special category data such as health, biometric or political information. If your recordings contain such data because of the nature of your business, you remain responsible for identifying that risk and configuring retention accordingly.

How we use information

The overwhelming majority of what we process exists because a telephone network cannot function without it. Routing a call requires the destination number; billing it requires the duration; investigating poor audio requires the quality telemetry; and defending against toll fraud requires spotting anomalous dialling patterns within seconds rather than at the end of the month.

  • Delivering, routing, terminating and billing voice and messaging traffic
  • Provisioning services, allocating numbers and validating regulatory eligibility for those numbers
  • Detecting and preventing toll fraud, traffic pumping, robocalling abuse and account takeover
  • Monitoring network health, capacity planning and diagnosing faults reported to our 24/7 NOC
  • Providing support, honouring service levels and communicating maintenance and incidents
  • Meeting legal, regulatory, tax and lawful interception obligations in the jurisdictions where we operate
  • Sending service notices, and — only where you have opted in or where permitted for existing business customers — relevant product and industry communications
  • Producing aggregated, de-identified statistics on network performance and industry trends

We do not sell personal data, we do not share it with advertising networks for cross-context behavioural advertising, and we do not use the content of your calls or messages to train models.

Legal bases for processing under GDPR

Where the UK GDPR or EU GDPR applies to our processing, we rely on the following legal bases. Each of them is tied to a specific purpose rather than applied as a blanket justification.

  • Performance of a contract — provisioning services, carrying traffic, invoicing, and providing support to the customer we contract with.
  • Legitimate interests — network security, fraud prevention, service improvement, and business-to-business marketing to existing customers. We document a balancing assessment for each of these and you can object at any time.
  • Legal obligation — retaining billing records for tax purposes, responding to valid law enforcement requests, and meeting carrier obligations such as emergency call handling and caller identity authentication.
  • Consent — non-essential cookies, marketing to prospects who are not customers, and any optional analytics feature you switch on. Consent can be withdrawn without affecting processing carried out beforehand.
  • Vital interests — passing location and callback information to emergency services when an emergency call is placed across our network.

Call recordings and consent

Recording law varies enormously. Some jurisdictions require only that one participant knows the call is being recorded; others require every participant to consent; others require a specific announcement before the conversation begins. Telecorenetwork provides the technical controls — announcements, per-queue and per-extension toggles, pause-and-resume for payment capture, and automatic deletion schedules — but the obligation to obtain lawful consent sits with the organisation that enables recording.

When recording is active on your account, we recommend that you play a recording notice on every affected call, document your lawful basis, restrict who can replay recordings, and use pause-and-resume so that card details are never written to storage in the first place. Our platform supports all four, and PCI-DSS SAQ-D aligned controls apply to the payment-adjacent paths.

Recordings are encrypted at rest with AES-256, access is logged, and every replay or export leaves an audit trail visible to your account administrators.

Data sharing and sub-processors

We share personal data only where it is necessary to deliver the service, meet a legal obligation or protect the network. Every sub-processor is bound by written contract, assessed before engagement and re-assessed at least annually. We describe them by category rather than by name here; the current named list is maintained in the customer portal and we notify account administrators before adding a new sub-processor that materially affects your data.

  • Interconnect and termination carriers — receive the signalling information required to complete a call or deliver a message, including calling and called numbers.
  • Cloud infrastructure and colocation providers — host our media, signalling and portal workloads in the regions you select.
  • Payment processors — handle card and bank transactions. Telecorenetwork does not store full card numbers on its own systems.
  • Support, ticketing and communications tooling — used by our support and NOC teams to manage your requests and send service notices.
  • Number registries, porting administrators and regulators — receive the subscriber information required to allocate, port or maintain numbers in each market.
  • Professional advisers and auditors — receive limited access under confidentiality obligations during SOC 2 Type II, ISO 27001 aligned and financial audits.
  • Law enforcement and courts — only in response to a valid, properly served legal demand, and only to the extent it compels disclosure. We keep a record of such requests and challenge those that are overbroad.

If Telecorenetwork is involved in a merger, acquisition or asset sale, personal data may transfer to the acquiring entity. You will be notified before your data becomes subject to a materially different privacy policy.

International transfers and Standard Contractual Clauses

Voice traffic is inherently international. A call from Frankfurt to Singapore crosses several jurisdictions before it is answered, and our 42 PoPs are distributed across the Americas, Europe, the Middle East, Africa and Asia-Pacific. Some transfers are therefore unavoidable if the call is to complete at all.

Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another approved mechanism. We supplement these with transfer impact assessments, encryption in transit and at rest, and contractual commitments from recipients to notify us of any government access request they are legally permitted to disclose.

Enterprise customers with data residency requirements can pin signalling, media, recording storage and CDR retention to a named region. Ask your account team to enable residency pinning before you provision services rather than after.

Data retention periods

We keep data for as long as it is needed for the purpose it was collected for, plus any period a law or regulator requires. Unless your contract specifies otherwise, our defaults are:

  • Call detail records and signalling metadata — 24 months, then deleted. Billing-relevant summaries are retained for 7 years for tax and audit purposes.
  • Message records — 12 months for delivery metadata; message content is retained for 30 days unless you configure a shorter or longer period.
  • Call recordings and transcripts — 90 days by default, configurable between 1 day and 7 years per queue, trunk or application. Deletion is permanent and irreversible.
  • Quality telemetry (jitter, loss, MOS) — 13 months at full resolution, then retained indefinitely only in aggregated, de-identified form.
  • Account and contract records — for the life of the account plus 7 years after termination.
  • Support tickets and chat transcripts — 36 months from closure.
  • Marketing contact data — 24 months from your last interaction with us, then deleted unless you re-engage.
  • Website analytics — 14 months, held in de-identified form.
  • Security and access logs — 12 months, longer where an investigation is open.

Where a legal hold applies to a specific dataset, deletion is suspended for that dataset only, and resumes as soon as the hold is lifted.

Your rights and how to exercise them

Depending on where you live, you may have some or all of the following rights over the personal data we hold about you as a controller:

  • Access — obtain confirmation that we process your data and receive a copy of it.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have data deleted where we no longer have a lawful reason to keep it.
  • Portability — receive data you provided to us in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests, including direct marketing, which we will stop on request without exception.
  • Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
  • Withdrawal of consent — withdraw any consent you gave, at any time.
  • Complaint — lodge a complaint with your supervisory authority, such as the Information Commissioner's Office in the UK or your national data protection authority in the EEA.

Write to privacy@telecorenetwork.com with the request and enough information for us to identify you. We respond within 30 days and will tell you if we need a further two months for a complex request. We do not charge for these requests unless they are manifestly unfounded or repetitive.

If your data sits inside a customer's account — for example you were the other party to a call carried for one of our customers — we act as a processor and must refer you to that customer, who is the controller. We will help you identify them where we lawfully can.

Security measures

Our security programme is assessed under SOC 2 Type II and built to controls aligned with ISO 27001. That means independent testing, not just internal assertion.

  • TLS 1.3 for signalling and portal traffic; SRTP with AES-256 for media; AES-256 for data at rest
  • Role-based access control, least privilege, mandatory multi-factor authentication for all staff and administrative portal accounts
  • Segregated production environments, hardware-backed key management and quarterly access reviews
  • Continuous fraud monitoring with automatic spend caps, destination allow-lists and anomalous-pattern suspension
  • Annual third-party penetration testing and a coordinated vulnerability disclosure process
  • A documented incident response plan with breach notification to affected controllers without undue delay and, where required, within 72 hours

No system is perfect. If you believe you have found a vulnerability in a Telecorenetwork service, contact support@telecorenetwork.com with the details and we will acknowledge within one business day.

Children's privacy

Telecorenetwork sells to businesses. Our services are not directed at children, we do not knowingly market to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@telecorenetwork.com and we will delete it promptly.

California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and the purposes for which it is used, to request deletion, to request correction, to opt out of sale or sharing, and to limit the use of sensitive personal information. You also have the right not to be discriminated against for exercising any of these rights — we will not degrade your service or change your pricing because you made a request.

Telecorenetwork does not sell personal information and does not share it for cross-context behavioural advertising as those terms are defined by the CPRA. The categories we collect map to the sections above: identifiers, commercial information, internet and network activity, geolocation inferred from IP address, professional information, and — where you enable recording — audio information.

To exercise a California right, email privacy@telecorenetwork.com or call +1 (800) 555-0100. An authorised agent may submit a request on your behalf with written permission that we can verify.

Cookies and tracking

Our website uses a small number of cookies. Strictly necessary cookies keep your session alive, remember your consent choices and protect against cross-site request forgery; these cannot be switched off. Analytics cookies help us understand which pages are useful and are only set once you consent. We do not use third-party advertising cookies or tracking pixels on this site.

You can manage your preferences through the cookie banner or clear cookies through your browser at any time. Blocking strictly necessary cookies will prevent the customer portal from working. We honour Global Privacy Control signals where your browser sends them.

Changes to this policy

We update this policy when our services, sub-processors or legal obligations change. The "last updated" date at the top always reflects the current version. For material changes — a new category of data, a new purpose, or a shorter retention period that affects you — we will notify account administrators by email at least 30 days before the change takes effect, and we keep prior versions available on request.

Contact us

For any privacy question, request or complaint, contact our privacy team first. We would rather resolve an issue directly than have you go to a regulator, and we treat every request as a genuine one.

This document is a template written for the Telecorenetwork website and is provided for informational purposes only. It is not legal advice. Review it with qualified counsel in each jurisdiction where you operate, and align it with your signed data processing agreements, before publishing it as a binding policy.

Questions

Need a DPA, a sub-processor list or a residency commitment?

Our privacy and compliance team will send the current sub-processor register, our standard data processing agreement and the SOC 2 Type II report summary under NDA.

SOC 2 Type II · ISO 27001 aligned · GDPR & UK GDPR · HIPAA-ready · PCI-DSS SAQ-D