Who we are and scope
This Policy describes how Herous Futurus OÜ, operating as OpenPhonex, handles personal data across our websites, accounts, dashboards, APIs, phone numbers, calls, messages, recordings, transcripts, AI-agent connections, and support (the "Service").
Herous Futurus OÜ is an Estonian private limited company, registry code 14347121, registered at Katleri tn 19-41, Lasnamäe linnaosa, Tallinn, Harju maakond 13915, Estonia. Contact us at [email protected].
Our privacy roles
We decide why and how to process account registration, KYC, billing, fraud prevention, security, support, website, and service-improvement data. For recordings, transcripts, prompts, knowledge, messages, tool data, and other content a customer routes through OpenPhonex, the customer normally decides the purpose and means of processing.
If you are a caller, message recipient, employee, or contact of an OpenPhonex customer, that customer is normally responsible for its privacy notice, legal basis, AI disclosure, recording consent, and response to your rights request. You may contact the customer directly; we will assist it as required.
Data we collect
- Account and contact data: name, email, organization, role, login provider, settings, language, and communications with us.
- Verification data: identity, age, address, company, beneficial-owner, use-case, and supporting-document data required by us, a verification provider, carrier, or authority.
- Telecom data: phone numbers, caller and recipient numbers, routing, SIP and room events, timestamps, duration, delivery status, carrier, country, IP address, device, and call or message metadata.
- Customer Content: audio, recordings where enabled, transcripts, summaries, prompts, responses, messages, knowledge sources, tool calls, tool results, and agent configuration.
- Billing data: plan, orders, wallet balance and ledger, usage, invoices, tax and payment status. Payment-card details are handled by our payment processor rather than stored by OpenPhonex.
- Technical and security data: API and audit events, authentication records, logs, diagnostics, abuse signals, consent records, and approximate location derived from IP or number.
- Website and support data: pages and interactions, cookie choices, analytics identifiers where permitted, support chats, contact-form submissions, and feedback.
Where data comes from
We receive data from you; your account administrators and users; callers and message participants; connected agents, tools, applications, and identity providers; carriers and number providers; identity-verification and payment providers; security and analytics systems; public or government sources used for compliance; and devices or browsers that access the Service.
Why we use data and our legal bases
- Contract: create accounts; provision numbers; route calls and messages; run configured AI agents and tools; provide recordings, transcripts, usage, billing, support, and requested features.
- Legal obligation: telecom registration, KYC, sanctions checks, tax, accounting, lawful requests, consumer protection, and records we must keep.
- Legitimate interests: secure and operate the Service, prevent fraud and abuse, troubleshoot, enforce our terms, manage providers, understand performance, and improve reliability. We balance these interests against your rights.
- Consent: optional analytics or marketing cookies and other processing where consent is the appropriate basis. You may withdraw consent without affecting earlier lawful processing.
- Customer instructions: process Customer Content to provide the Service as a processor or service provider under our Terms and the customer's configuration.
AI, voice, and automated processing
At a customer's direction, we send the data needed to selected speech-to-text, language-model, text-to-speech, and tool providers to generate live agent responses, transcripts, summaries, or actions. Provider choice can affect processing location and retention. Customers should avoid sending sensitive data unless their configuration and legal basis are appropriate.
We may use automated risk signals to detect fraud, account takeover, prohibited traffic, or unusual spending. Where applicable law gives you rights concerning a decision with legal or similarly significant effects, you may request information and human review. We do not use customer call content to train a general-purpose OpenPhonex model unless we separately obtain the permission required by law.
Who receives data
We share only what is reasonably needed with:
- telecom carriers and number providers, including DIDWW and downstream networks;
- cloud infrastructure and communications systems, including DigitalOcean and our LiveKit-based media stack;
- AI and media providers selected for an agent, which may include Deepgram, Google Gemini, and ElevenLabs;
- identity-verification, payment, authentication, support, email, security, and professional-service providers, which may include Didit, Stripe, Google, GitHub, and Chatwoot;
- analytics providers, including PostHog and Google Analytics, according to our configuration and your cookie choice;
- authorities, courts, carriers, advisers, or affected parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or establish legal claims; and
- a buyer, investor, or successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice.
Providers can change as the Service evolves. We require providers handling personal data for us to protect it and use it only for the agreed services. The current categories and material provider changes will be reflected in this Policy or communicated through the Service.
International transfers
We are established in Estonia and use providers and telecom networks around the world. Data may therefore be processed outside your country, including outside the EEA, United Kingdom, or Switzerland. Where required, we rely on adequacy decisions, the European Commission's standard contractual clauses, the UK addendum or equivalent safeguards, and supplementary measures appropriate to the risk. Telecom routing may necessarily pass through the destination or originating country.
How long we keep data
We keep data only as long as needed for the purposes above, customer instructions, and legal requirements. Retention depends on the data and account configuration:
- Customer Content follows the customer's configured retention where available. Unless a different setting or order applies, the current default for stored call recordings is 90 days.
- Account, number, call-detail, message, audit, and support records are kept while the account is active and for a reasonable period afterward for service delivery, disputes, fraud prevention, and legal compliance.
- Accounting and transaction records are generally kept for seven years where Estonian law requires it.
- KYC and telecom registration data is kept for the provider or statutory period that applies to the number, account, or transaction.
- Security logs and backups expire on rolling schedules unless an incident, dispute, legal hold, or lawful request requires longer retention.
Deletion from live systems and backups may occur at different times. We may retain de-identified or aggregated information that can no longer reasonably identify a person.
Cookies and analytics
We use necessary cookies or local storage for authentication, security, language, and your privacy preferences. Optional analytics help us understand site and product usage. Where consent is required, optional analytics remain disabled until you accept them through our cookie banner.
You can accept or decline optional analytics in the banner and can clear the stored choice in your browser to choose again. Browser settings can also block cookies, although blocking necessary storage may prevent login or other features from working. We do not use advertising cookies on the current public Service.
Security
We use technical and organizational safeguards designed for the sensitivity and risk of the data, including access controls, authentication, encryption in transit, provider controls, logging, isolation, and incident procedures. No system is completely secure. Protect your credentials, use appropriately scoped API keys, and report suspected compromise promptly to [email protected].
Your privacy rights
Depending on your location and our role, you may have the right to access, correct, delete, restrict, or receive a copy of your data; object to certain processing; withdraw consent; opt out of certain profiling, sale, sharing, or targeted advertising; and appeal a denied request.
Email [email protected] with "Privacy request" in the subject. We may verify your identity and authority, and applicable exceptions may limit a request. Authorized agents may submit requests where local law permits. We will not discriminate against you for exercising a privacy right.
If OpenPhonex processes your data only for a customer, send the request to that customer first. We will support the customer's response. EEA residents may complain to the Estonian Data Protection Inspectorate or their local supervisory authority.
United States privacy notice
For residents of US states with applicable privacy laws, the categories described in section 3 are the categories we collected during the preceding 12 months. We use and disclose them for the business and commercial purposes in sections 5 and 7 and retain them as described in section 9.
We do not sell call recordings, transcripts, message content, KYC documents, or payment data for money. We do not knowingly sell or share personal data of people under 18. If an optional analytics activity is legally treated as a sale, sharing, or targeted advertising in your state, we will provide the notice and choice required by that law. You can exercise applicable rights using the process in section 12.
Children
The Service is not directed to children, and account holders must be at least 18. We do not knowingly collect personal data directly from a child to create an account. A customer must not use the Service to collect children's data unless it has a lawful, appropriately configured use case and all required parental or guardian permissions.
Changes and contact
We may update this Policy as the Service, providers, and laws change. We will post the new version here and give additional notice when a change materially affects your rights or our use of personal data.
Questions, complaints, or requests can be sent to [email protected] or Herous Futurus OÜ, Katleri tn 19-41, Tallinn 13915, Estonia.