Privacy Policy
Last Updated: July 2026
Your privacy is our priority. This Privacy Policy explains how we collect, use, and protect your data in compliance with GDPR, CCPA, NDPR, and other privacy laws.
1. Introduction
Ring0S ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and retain information from users of our cloud phone system platform.
This Privacy Policy applies to: • Workspace Administrators & Users: Individuals who create accounts or use our platform • Call Parties & Message Recipients: Individuals whose communications are processed through the platform • Data Subjects: Anyone whose personal data we collect in connection with providing our Service
2. Information We Collect
Account Information: When you create a Ring0S account or workspace, we collect: • Full name, email address, and phone number • Organization name and type • Workspace configuration and preferences • Billing address and payment method (securely tokenized) • Authentication credentials
Communication Data: We collect and process: • Call records: Phone numbers, timestamps, duration, call status, routing information • Message content: SMS text body, sender/recipient numbers, timestamp, delivery status • Recordings: Audio files of calls (if you enable recording) • Transcriptions: AI-generated text from recordings (if you use transcription features) • Metadata: VOIP codecs, network quality metrics, call transfers, conference participants
Usage & Analytics: • Features used and frequency • Login times and locations (IP address, browser, device) • API call frequency and endpoints accessed • Workspace activity logs • Error logs and debugging information
Device & Browser Data: • IP address and browser information • Cookies and similar tracking technologies • Device identifiers and operating system
3. How We Use Your Information
To Provide the Service: • Provisioning and managing phone numbers • Routing calls and messages through carriers • Processing transcriptions via AI providers • Recording and storing calls and messages • Managing user access and workspace permissions • Providing customer support
Billing & Account Management: • Calculating usage-based charges • Generating and processing invoices • Detecting and preventing fraud • Resolving billing disputes
Legal & Regulatory Compliance: • Complying with law enforcement requests • Enforcing our Terms of Service • Detecting and addressing fraud or security issues • Meeting data retention requirements
Service Improvement & Analytics: • Analyzing anonymized usage patterns • Monitoring Service performance • Identifying usage trends • Improving features and carrier selection
Security & Abuse Prevention: • Detecting unauthorized access and fraud • Monitoring for policy violations • Analyzing access patterns for suspicious behavior • Preventing denial-of-service attacks
4. Legal Basis for Processing
Contract Performance: We process personal data necessary to provide the Service, billing, customer support, and account management.
Legal Obligation: We comply with law enforcement requests, regulatory requirements, and telecommunications laws.
Legitimate Interest: • Preventing fraud, abuse, and security threats • Improving our Service • Enforcing our Terms of Service
Consent: • Marketing communications (opt-in only) • Non-essential analytics or tracking • Optional features
EU Users (GDPR): You have the right to object to processing based on legitimate interest. See the Your Data Subject Rights section for how to exercise these rights.
6. Data Retention
Active Account Data: • Account & user information: Lifetime of workspace • Billing records: 7 years (tax compliance) • Call records & metadata: Default 90 days (customizable) • Recordings: Default 90 days (max 1 year) • Messages & SMS: Default 90 days • Usage logs: 1 year
After Account Termination: • Call records: 90 days (for dispute resolution, compliance) • Recordings: 90 days (then permanently deleted) • Messages: 90 days • Account information: 30 days (then anonymized) • Billing records: 7 years (tax and legal requirement)
Right to Deletion: You may request deletion of your data subject to legal retention requirements and unresolved disputes. See the Your Data Subject Rights section for how to exercise deletion rights.
7. Your Data Subject Rights
GDPR Rights (EU/UK Users): • Access: Right to access all personal data we hold about you • Correction: Right to correct inaccurate or incomplete data • Deletion: Right to delete personal data, subject to legal exceptions • Portability: Right to obtain your data in a structured, machine-readable format • Restrict Processing: Right to restrict our processing of your data • Object: Right to object to processing based on legitimate interest • Withdraw Consent: Right to withdraw consent at any time • Lodge a Complaint: Right to lodge a complaint with your Data Protection Authority
CCPA Rights (California Users): • Right to Know: Request what personal information we collect, use, and share • Right to Delete: Request deletion of personal information • Right to Opt-Out: Opt out of "sale" or "sharing" of personal information • Right to Correct: Request correction of inaccurate personal information • Right to Limit: Limit use of sensitive personal information • Right to Appeal: Appeal our decision on your rights request
How to Exercise Your Rights: Email privacy@ring0s.com with: • Your name, email, and workspace ID (if applicable) • Specific request (access, deletion, correction, etc.)
Response Timeline: • We will respond within 30 days for GDPR • We will respond within 45 days for CCPA • No fee for reasonable requests (one per 12 months)
8. Data Security & Encryption
Security Measures: • Encryption in Transit: TLS/SSL encryption (HTTPS) for all data transmission • Encryption at Rest: AES-256 for recordings, messages, sensitive data • Access Control: Role-based access; employees access data on need-to-know basis • Authentication: Multi-factor authentication (MFA) available for user accounts • Auditing: Regular security audits and penetration testing • Monitoring: 24/7 security monitoring and alerting
Data Breach Notification: If we experience a data breach affecting your personal data: • EU/UK users: Notification within 72 hours per GDPR Article 33 • California users: Notification without unreasonable delay per CCPA • Nigeria users: Notification without delay per NDPR
We investigate immediately and notify you with full details of what happened, affected data, and steps you can take.
Important: No security is perfect. We implement reasonable measures, but cannot guarantee absolute security. We recommend maintaining backups of critical data.
Last Updated: July 2026 • Version 1.0
Compliant with GDPR, CCPA, CPRA, NDPR, and other privacy laws