Privacy Policy
Effective 10 May 2026.
This privacy policy explains how Silux Telecom Ltd (“Silux Call”, “we”) collects, uses, stores and shares personal data when you use the Silux Call platform, our marketing site, our mobile and desktop softphones, and any related services.
1. Who we are
Silux Telecom Ltd is the data controller for the personal data processed about visitors to our website and tenants who hold accounts on our platform. We are registered in England & Wales. You can contact our Data Protection Officer at dpo@siluxcall.co.uk.
2. What we collect
- Account data — name, email, password (bcrypt-hashed), tenant slug.
- Identity data — billing address, VAT number, telephone number for OTP/2FA.
- Usage data — call detail records (CDR): caller, called, duration, disposition, recording reference.
- Recordings & transcripts — when you enable call recording, audio is stored under your retention policy. Transcripts are generated by Whisper (self-hosted) under your transcription policy.
- Device data — IP address, user-agent, device push tokens for incoming-call wake-up.
- Referral / affiliate data — if you reach us via an affiliate link, the referral code, a first-party visitor ID, approximate IP, browser, landing page and UTM tags, so we can credit the introducing partner. See our Cookies Policy and Affiliate Programme Terms.
- Cookies — see Cookies Policy.
3. Lawful bases (UK GDPR Art. 6)
- Contract — to provide the service you have signed up for.
- Legitimate interest — to keep our service secure, prevent fraud, and run analytics for product improvement.
- Legal obligation — for tax records, lawful interception requests under RIPA / IPA, and HMRC reporting.
- Consent — for marketing emails (where required), call recording where two-party consent is needed, and cookies that are not strictly necessary.
4. Sharing
We do not sell personal data. We share with sub-processors strictly to deliver the service: AWS / Hetzner (hosting), Stripe (billing), Brevo (transactional email), upstream UK PSTN carriers for call termination, optional Twilio / Vonage for SMS, Whisper-self-host for transcription. A current list of sub-processors is at /legal/dpa#subprocessors.
5. International transfers
Personal data is hosted within the UK and EEA. Where transfers outside the UK are unavoidable (for example, an iOS push goes through APNS in the United States), we rely on the UK International Data Transfer Agreement (IDTA) and the EU Standard Contractual Clauses, plus appropriate technical safeguards (TLS 1.3, encryption at rest).
6. Retention
- Account records — life of account + 6 years (HMRC).
- CDR — life of account + 12 months (default), configurable.
- Call recordings — per the tenant's retention setting (default 90 days, HIPAA mode locks 2,190 days).
- Transcripts — match recording retention.
- Marketing email opt-ins — until you unsubscribe.
7. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict processing, port, and object. Email dpo@siluxcall.co.uk; we respond within 30 days. You may also complain to the Information Commissioner’s Office at ico.org.uk.
8. Security
We follow ISO 27001-aligned controls. Recordings encrypted at rest with KMS where enabled, TLS 1.2/1.3 in transit, SRTP+TLS available per-tenant. Penetration testing once per year; results summarised at /legal/security.
9. Children
Silux Call is a B2B service. We do not knowingly collect data from anyone under 18.
10. Changes
We post material changes here and email tenant admins with 30 days’ notice.
Silux Telecom Ltd is a company registered in England & Wales. UK GDPR / Data Protection Act 2018 controller: Silux Telecom Ltd. ICO registration: pending.