IPPBX Privacy Policy
Effective Date: July 27, 2026
Last Updated: July 27, 2026
IPPBX, LLC, a Delaware limited liability company (“IPPBX,” “we,” “us,” or “our”), provides cloud-based business telephone, communications, artificial intelligence, automation, customer-management, workforce, and related technology services.
This Privacy Policy explains how IPPBX collects, uses, processes, stores, and discloses information through:
- The IPPBX website and Customer Portal;
- Cloud PBX and business telephone services;
- Mobile, desktop, browser, and connected applications;
- Calling, voicemail, SMS, MMS, fax, recording, and transcription services;
- AI receptionists, AI callers, AI assistants, AI Workforce capabilities, and automated workflows;
- CRM, customer records, knowledge bases, documents, tasks, scheduling, marketing, workforce, finance, and operational modules;
- Equipment, installation, onboarding, support, and professional services; and
- Other services that link to this Privacy Policy.
This Privacy Policy applies to business customers, prospective customers, administrators, authorized users, website visitors, and individuals who communicate with an IPPBX customer through the Services.
IPPBX services are intended for business, commercial, nonprofit, and governmental use. They are not offered as residential or personal consumer telephone services.
1. Our Role
Depending on the situation, IPPBX may act in different privacy roles.
Information IPPBX Controls
IPPBX generally determines how and why it processes:
- Website visitor information;
- Prospect and sales information;
- Customer account and administrator information;
- Billing and transaction records;
- Support communications;
- Security and fraud-prevention information; and
- Information needed to operate and improve the IPPBX platform.
For this information, IPPBX generally acts as a business, controller, or similar responsible party under applicable privacy laws.
Customer-Controlled Information
When a customer submits, creates, connects, records, or processes information through the Services, the customer generally determines why that information is processed and how the Services are configured.
For Customer Content, IPPBX generally acts as a service provider, contractor, or processor on behalf of the customer.
Customers are responsible for:
- Providing legally required privacy notices;
- Establishing a lawful basis for processing;
- Obtaining required permissions and consents;
- Configuring recordings, transcripts, AI tools, and automations appropriately;
- Responding to requests from their employees, customers, patients, donors, members, callers, message recipients, and other individuals; and
- Ensuring that their use of the Services complies with applicable law.
An individual who has a privacy question about information controlled by an IPPBX customer should normally contact that customer first. IPPBX may refer the request to the applicable customer.
2. Information We Collect
The information collected depends on which Services are used and how the customer configures them.
A. Account and Contact Information
We may collect:
- Business and organization names;
- Individual names and job titles;
- Business addresses;
- Email addresses;
- Telephone and mobile numbers;
- Billing and technical contacts;
- Authorized administrators and users;
- Account credentials and authentication information;
- Electronic signatures;
- Order forms, quotes, contracts, and acceptance records; and
- Customer support preferences.
B. Billing and Transaction Information
We may collect or receive:
- Billing addresses;
- Selected plans, extensions, numbers, modules, and equipment;
- Invoice, payment, and account-balance information;
- Payment status and transaction identifiers;
- Limited payment-method details;
- Tax, regulatory, carrier, usage, shipping, and equipment charges;
- Chargeback and collection information; and
- Records associated with refunds, credits, disputes, and account adjustments.
Full payment-card or banking information may be collected and processed by third-party payment processors. IPPBX may receive limited payment information and transaction status from those providers.
C. Telephone and Communications Information
Depending on the Services and customer settings, we may process:
- Telephone numbers;
- Caller ID and CNAM information;
- Calling and called-party information;
- Call-detail records;
- Call date, time, duration, routing, disposition, and status;
- Extension, queue, department, device, and user information;
- Call recordings;
- Voicemails and voicemail recordings;
- SMS and MMS messages;
- Fax content and transmission information;
- Email or connected-channel communications;
- Call transfers, routing rules, and interactive voice response selections;
- Contact lists and communication history;
- Opt-in, opt-out, suppression, and Do Not Call records; and
- Carrier delivery, filtering, rejection, and error information.
D. Customer Content and Business Information
Customers may submit or connect:
- Contact and company records;
- Customer, member, donor, patient, employee, vendor, or prospect information;
- CRM records;
- Account and billing history;
- Notes and communication history;
- Tasks, activities, tickets, and assignments;
- Appointments, calendars, and schedules;
- Sales opportunities, quotes, orders, and service requests;
- Uploaded documents;
- Porting and number-authorization documents;
- Scripts, templates, prompts, instructions, and business rules;
- Company policies and knowledge-base materials;
- Marketing, campaign, and lead information;
- Workforce, attendance, scheduling, and operational information;
- Information retrieved through authorized integrations; and
- Information generated from workflows or customer-authorized actions.
E. AI Processing Information
When AI features are used, we may process information such as:
- Live or recorded audio;
- Voice input and generated voice output;
- Call recordings and voicemails;
- Transcripts;
- Messages and documents;
- Prompts, instructions, scripts, and company knowledge;
- Customer and account context;
- Conversation history;
- AI-generated responses;
- Summaries and classifications;
- Sentiment or intent indicators;
- Extracted names, telephone numbers, email addresses, dates, requests, and other entities;
- Suggested actions and follow-up;
- Workflow requests and automation results;
- Tool and integration outputs;
- Quality, performance, latency, and error information;
- Safety, abuse, and security indicators; and
- User corrections, approvals, rejection, and feedback.
AI processing may combine a communication with information that the customer has authorized the AI feature to access, such as customer history, billing status, open requests, appointments, notes, company policies, and assigned employees.
F. Device, Network, and Technical Information
We may collect:
- IP addresses;
- Browser and application type;
- Device identifiers;
- Operating system;
- Login activity;
- Session and authentication information;
- SIP, network, and connection information;
- Approximate location derived from IP address;
- Device configuration;
- Application permissions;
- Diagnostic information;
- Crash, performance, and error logs;
- Security events; and
- Records of administrative changes.
G. Website and Cookie Information
We may use cookies and similar technologies to collect:
- Pages visited;
- Referring pages;
- Interaction with forms and buttons;
- Browser and device information;
- Session information;
- Website preferences;
- Analytics information; and
- Advertising or campaign attribution information.
H. Support, Installation, and Professional-Service Information
We may collect:
- Support requests and ticket history;
- Recorded or transcribed support calls;
- Screenshots and diagnostic files;
- Device, network, and configuration information;
- Remote-support activity;
- Installation and shipping information;
- Training participation;
- Customer instructions and approvals; and
- Communications with authorized representatives.
I. Information From Other Sources
We may receive information from:
- The customer and its authorized users;
- Individuals communicating with the customer;
- Carriers and telecommunications providers;
- Numbering and porting providers;
- Payment processors;
- Equipment vendors and shipping companies;
- Cloud, AI, software, and integration providers;
- Identity, fraud, and security providers;
- Publicly available business sources;
- Authorized marketing or lead sources; and
- Government agencies or legal processes.
3. How We Use Information
We may use information to:
- Establish and manage customer accounts;
- Verify identity and authority;
- Provision numbers, extensions, applications, equipment, and Services;
- Route, connect, complete, and manage communications;
- Deliver voicemail, SMS, MMS, fax, recording, and transcription features;
- Provide AI receptionists, AI callers, assistants, summaries, recommendations, and workflow actions;
- Connect communications with authorized business information;
- Operate CRM, support, scheduling, marketing, workforce, finance, and operational tools;
- Process orders and payments;
- Calculate usage, taxes, fees, and carrier charges;
- Provide onboarding, migration, configuration, training, support, and maintenance;
- Detect fraud, toll fraud, spam, spoofing, abuse, security threats, and unauthorized access;
- Protect customers, recipients, networks, carriers, vendors, and IPPBX;
- Troubleshoot, test, monitor, maintain, and improve the Services;
- Enforce agreements and policies;
- Comply with legal, regulatory, carrier, and law-enforcement obligations;
- Respond to privacy and legal requests;
- Maintain business, tax, accounting, audit, and compliance records;
- Communicate about the account, Services, security, billing, and support;
- Provide service announcements and legally permitted marketing; and
- Complete a merger, acquisition, financing, reorganization, or sale of assets.
4. AI Processing and Automated Features
AI systems are probabilistic and may generate incomplete, incorrect, or inappropriate results.
Customers control which AI features are activated, which information those features may access, which instructions they receive, and which actions may be performed automatically or require human approval.
IPPBX may process Customer Content through IPPBX systems and authorized AI, cloud, transcription, voice, telecommunications, and automation providers to deliver the requested feature.
IPPBX does not sell Customer Content for third-party advertising. IPPBX does not use call recordings, transcripts, CRM information, or connected business records to target third-party advertising to the individuals described in those records.
Unless expressly authorized by the customer, IPPBX does not permit a third party to use Customer Content to create advertising profiles unrelated to providing the Services.
Customers should use human review before relying on AI output for decisions involving:
- Employment;
- Credit or lending;
- Housing;
- Insurance;
- Healthcare;
- Legal rights;
- Public benefits;
- Safety;
- Financial transactions; or
- Other decisions that may have significant effects on an individual.
5. Call Recording, Monitoring, and Transcription
The Services may allow customers to record, monitor, transcribe, summarize, analyze, or store calls and other communications.
The customer—not IPPBX—decides whether these features are enabled and is responsible for:
- Providing required notices;
- Obtaining legally sufficient consent;
- Determining whether one-party or all-party consent applies;
- Complying with employment and workplace-monitoring laws;
- Configuring recording and retention settings;
- Restricting access to recordings and transcripts; and
- Using the resulting information lawfully.
A recording announcement or technical setting provided by IPPBX does not guarantee that a customer has satisfied every legal requirement.
6. Customer Proprietary Network Information
To the extent telecommunications information handled by IPPBX qualifies as Customer Proprietary Network Information or is subject to similar communications-privacy requirements, IPPBX uses and discloses that information as permitted to:
- Provide and bill for the Services;
- Protect customers and network integrity;
- Prevent fraud and abuse;
- Respond to customer requests;
- Maintain and improve related service categories; and
- Comply with applicable legal requirements.
IPPBX may require authentication before discussing account, call, number, or usage information.
7. Cookies and Similar Technologies
IPPBX may use:
- Essential cookies for login, security, account functions, and website operation;
- Preference cookies to remember selections and settings;
- Analytics cookies to understand website and application performance; and
- Advertising or attribution technologies to measure marketing effectiveness where permitted.
Browser settings may allow users to block or delete cookies. Blocking essential cookies may prevent portions of the website or Customer Portal from operating.
Where required, IPPBX will provide cookie choices or recognize legally required browser-based opt-out preference signals.
8. How We Disclose Information
IPPBX may disclose information to the following categories of recipients.
Service Providers
We may use providers supporting:
- Telecommunications and carriers;
- Telephone numbers and porting;
- Cloud hosting and infrastructure;
- AI, speech recognition, voice generation, and transcription;
- Security, fraud prevention, and monitoring;
- Software, APIs, and integrations;
- Payment processing;
- Customer support;
- Email and messaging;
- Analytics;
- Equipment, shipping, and installation;
- Accounting, legal, insurance, and professional services; and
- Data storage, backup, and disaster recovery.
These providers may process information only as necessary to perform services for IPPBX or as otherwise permitted by contract and law.
Customers and Authorized Users
Information may be made available to the customer organization, its administrators, and users according to the permissions and configurations selected by that customer.
Carriers and Communication Providers
We may disclose information necessary to route, deliver, register, filter, troubleshoot, or bill calls, messages, fax transmissions, numbers, and related services.
Legal and Safety Disclosures
We may disclose information when we reasonably believe it is necessary to:
- Comply with law, regulation, court order, subpoena, or legal process;
- Respond to lawful government or law-enforcement requests;
- Protect the rights, property, safety, and security of IPPBX or others;
- Investigate fraud, spam, abuse, security incidents, or policy violations;
- Protect telecommunications networks and carriers; or
- Establish, exercise, or defend legal claims.
Business Transactions
Information may be transferred in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable confidentiality and legal requirements.
With Direction or Consent
We may disclose information when directed by the customer or when the relevant individual has provided consent.
9. No Sale of Customer Content or Mobile Opt-In Data
IPPBX does not sell Customer Content for monetary consideration.
IPPBX does not share mobile-originator information, SMS opt-in data, or messaging consent with third parties for their own unrelated marketing or promotional purposes.
Mobile information may be disclosed to telecommunications providers, messaging vendors, and other service providers solely as necessary to deliver, support, secure, and administer the messaging Services.
Text-message opt-in and consent information will not be sold or transferred for unrelated third-party marketing.
10. Data Retention
IPPBX retains information according to the type of information, customer configuration, selected package, contractual requirements, security needs, and applicable law.
Information may be retained:
- While an account is active;
- For the period necessary to provide a requested Service;
- According to customer-selected recording or message settings;
- For billing, tax, accounting, audit, and dispute purposes;
- To meet carrier, porting, fraud-prevention, and regulatory requirements;
- To investigate abuse or security incidents;
- To enforce agreements;
- To preserve legal claims; and
- For legitimate backup and disaster-recovery periods.
After termination, IPPBX may delete, disable, archive, anonymize, or restrict access to Customer Content according to its retention practices and legal obligations.
Deleted information may remain temporarily in backups, security logs, fraud records, legal holds, or systems operated by third-party providers.
IPPBX is not required to retain information that has expired, been overwritten, been deleted under customer settings, or is no longer available from a third-party system.
11. Security
IPPBX uses administrative, technical, and physical safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure.
Safeguards may include:
- Access controls and authentication;
- Role-based permissions;
- Encryption where appropriate;
- Network and system monitoring;
- Logging and security review;
- Backup and recovery measures;
- Vendor and personnel controls;
- Fraud and abuse detection; and
- Incident-response procedures.
No internet, telecommunications, cloud, or storage system is completely secure. IPPBX cannot guarantee that every communication will be encrypted end-to-end or that information will never be intercepted, delayed, lost, accessed, or compromised.
Customers are responsible for maintaining secure passwords, administrator access, user permissions, devices, networks, applications, integrations, and account configurations.
12. Regulated and Sensitive Information
Customers may not submit specially regulated information unless the applicable Service is designed for that information and IPPBX has expressly agreed in writing to the required terms.
This may include:
- Protected health information;
- Payment-card data outside an approved payment process;
- Social Security numbers;
- Government identification documents;
- Biometric identifiers;
- Government-classified information;
- Export-controlled information;
- Criminal-justice information;
- Student records;
- Precise geolocation;
- Highly sensitive financial information; and
- Other information subject to specialized legal safeguards.
A customer requiring HIPAA, financial-services, government, education, or other regulated-data handling must obtain any required addendum, including a Business Associate Agreement where applicable, before submitting regulated information.
13. International Data Transfers
IPPBX is based in the United States. Information may be processed in the United States and in other countries where IPPBX or its service providers operate.
Where applicable law requires additional safeguards for international transfers, IPPBX may use contractual protections or other legally recognized transfer mechanisms.
14. Privacy Rights
Depending on location and applicable law, an individual may have the right to:
- Confirm whether personal information is being processed;
- Access personal information;
- Correct inaccurate information;
- Delete certain information;
- Obtain a portable copy of certain information;
- Opt out of the sale of personal information;
- Opt out of targeted advertising;
- Opt out of certain profiling or automated decision-making;
- Limit certain uses of sensitive information;
- Withdraw consent;
- Object to or restrict certain processing;
- Appeal a denied privacy request; and
- Receive equal service without unlawful discrimination for exercising privacy rights.
IPPBX does not sell Customer Content or use Customer Content for unrelated third-party targeted advertising.
Submitting a Request
Requests may be submitted by contacting:
- Email: info@ippbx.com
- Subject: Privacy Request
The request should include:
- The requester’s name;
- The organization or IPPBX customer involved;
- The email address or telephone number associated with the information;
- The privacy right being requested; and
- Sufficient information for IPPBX to locate the relevant records.
IPPBX may take reasonable steps to verify identity and authority before completing a request.
When IPPBX processes information on behalf of a customer, IPPBX may refer the request to that customer or assist the customer in responding.
Authorized agents may submit requests where permitted by law, subject to verification of the agent’s authority.
If a request is denied, the response will explain available appeal procedures where required.
Certain information may be exempt from a request, including information needed for security, fraud prevention, billing, legal claims, regulatory compliance, or delivery of requested Services.
15. Communications Choices
Customers and prospects may opt out of promotional emails by using the unsubscribe option or contacting IPPBX.
Service, security, billing, legal, support, and account communications are not promotional and may continue while an account or obligation remains active.
Recipients of customer-generated calls and messages should direct opt-out requests to the customer responsible for the communication. IPPBX may also take steps to suppress or block communications when necessary to enforce law, carrier requirements, or the Acceptable Use Policy.
16. Children
The Services are intended for business use and are not directed to children under 18.
IPPBX does not knowingly create accounts for children or intentionally collect personal information directly from children for independent marketing purposes.
Customers that use the Services to communicate with or process information about minors are responsible for obtaining required parental, institutional, or legal authorization.
17. Changes to This Privacy Policy
IPPBX may update this Privacy Policy to reflect changes in the Services, technology, vendors, law, or business practices.
The updated version will identify its effective date. Material changes may also be communicated through email, the Customer Portal, an invoice notice, or another reasonable method.
Continued use of the Services after an updated Privacy Policy becomes effective constitutes acknowledgment of the updated policy to the extent permitted by law.
18. Contact Information
Questions, complaints, and privacy requests may be directed to:
IPPBX, LLC
3500 South DuPont Hwy
Dover, Delaware 19901
United States
Email: info@ippbx.com
Telephone: 877-821-8371
Operational office:
1270 Avenue of the Americas, 7th Floor
New York, New York 10020