1. Introduction
YUSUF IT SERVICES LIMITED ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our website, Cloud PBX platform, DID number services, and related telecommunications services (the "Services"). This policy complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003.
2. Information We Collect
2.1 Information You Provide
- Account registration: Name, email address, phone number, company name, billing address.
- Identity verification: Passport/ID copies, proof of address, and company registration documents (required for DID numbers in certain countries — see Legal Requirements).
- Payment information: Credit/debit card details, PayPal account, billing address. Payment card data is processed by our PCI-compliant payment processors and is not stored on our servers.
- Support communications: Emails, chat transcripts, and phone calls with our support team.
2.2 Information Collected Automatically
- Usage data: Call records (CDRs), call duration, caller/callee numbers, timestamps.
- Technical data: IP address, browser type, operating system, device information, referring URLs.
- Cookies & analytics: See Section 8 below.
2.3 Call Recordings
If you enable call recording on your PBX, recordings are stored encrypted on our servers. You are responsible for informing callers and obtaining consent for recording as required by applicable law.
3. How We Use Your Data
| Purpose | Legal Basis (UK GDPR) |
|---|---|
| Providing and managing Services | Performance of contract (Art. 6(1)(b)) |
| Processing payments | Performance of contract |
| Identity verification for DID numbers | Legal obligation (Art. 6(1)(c)) |
| Customer support | Legitimate interest (Art. 6(1)(f)) |
| Service improvements & analytics | Legitimate interest |
| Marketing communications (with consent) | Consent (Art. 6(1)(a)) |
| Fraud prevention & security | Legitimate interest |
| Compliance with legal obligations | Legal obligation |
4. Data Sharing
We do not sell your personal data. We may share it with:
- Telecommunications carriers: To provision DID numbers and route calls. This may include sharing identity documents with local carriers as required by law.
- Payment processors: To process transactions securely.
- Cloud infrastructure providers: For hosting and data storage (servers located in the UK and EU).
- Law enforcement: When required by law, court order, or to prevent fraud.
- Professional advisors: Lawyers, auditors, and accountants as necessary.
5. International Transfers
Some of our carriers and service providers operate outside the UK. Where personal data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the ICO, adequacy decisions, or binding corporate rules.
6. Data Retention
- Account data: Retained for the duration of your account plus 6 years.
- Call detail records: Retained for 12 months after generation.
- Call recordings: Retained per your plan settings (default: 90 days). You may delete recordings from the dashboard.
- Identity documents: Retained for the duration of number ownership plus 12 months.
- Payment records: Retained for 7 years (legal/tax requirements).
7. Your Rights
Under the UK GDPR, you have the right to:
- Access your personal data (Subject Access Request).
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), subject to legal obligations.
- Restrict processing in certain circumstances.
- Data portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interests or direct marketing.
- Withdraw consent at any time (where consent is the legal basis).
To exercise your rights, email [email protected]. We will respond within 30 days.
8. Cookies
We use the following types of cookies:
- Strictly necessary: Required for the website and dashboard to function (session, authentication).
- Analytics: Help us understand how visitors use our site (e.g., Google Analytics). These are anonymised.
- Functional: Remember your preferences (e.g., language, timezone).
You can manage cookie preferences through your browser settings. Disabling cookies may affect functionality.
9. Security
We implement appropriate technical and organisational measures to protect your data, including:
- TLS encryption for all data in transit.
- AES-256 encryption for stored call recordings and sensitive data.
- Multi-factor authentication option for dashboard access.
- Regular security audits and penetration testing.
- Access controls and staff training.
10. Children's Privacy
Our Services are not directed at individuals under 18 years of age. We do not knowingly collect data from children. If we become aware that we have collected data from a minor, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and/or a prominent notice on our website at least 30 days before they take effect.
12. Complaints
If you are unhappy with how we handle your data, you may lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
13. Contact Us
For privacy-related enquiries:
- Email: [email protected]
- Address: International House, 22-28 Wood Street, Doncaster, United Kingdom, DN1 3LW
- Phone: +44 800 743 2835