This is a launch draft, provided for review. It becomes binding at go-live after the operator's sign-off.
1. What we process
VoipFlow is multi-tenant cloud infrastructure orchestration software. To provide the service we process: tenant configuration data, certificate material (handled by the automation layer, not by humans in normal operation), signaling metadata (headers, timing, status — not media content), account and billing data, and the support messages you send us.
2. What we don't process
We do not process the content of your calls. Media flows encrypted (SRTP) between endpoints and the edge; we handle orchestration, not transcription, recording, or analytics of call content. We don't sell data — our pricing is flat and published, and data brokerage isn't a business we're in.
3. Where data lives
Tenant workloads run on our five edge nodes (Atlanta, Silicon Valley, Frankfurt, London, Sydney). EU-tenant workloads can be pinned to EU nodes (Frankfurt, London) on request.
4. Subprocessors
Infrastructure and CDN providers for hosting, and the ACME certificate authority (Let's Encrypt) for certificate issuance per tenant domain. Current list is available on request.
5. Retention
Account data for the life of the account; signaling metadata for operational troubleshooting windows (30 days); support messages for the life of the account plus 90 days. Backups rotate on a 35-day cycle.
6. Your rights
Access, correction, export, and deletion of account data — the tenant portal covers export and deletion directly. EU data pinning is honored on request as noted above.
7. Contact
Privacy questions go through the contact page. An engineer answers.