Roles and responsibility
The Customer is controller and decides how telephony, recording, FAX, chat, PCAP and diagnostics are used. RelayPBX acts as processor for Managed and support data. A licence, button or configuration capability is not caller consent or legal authority.
Before enabling a feature, the Customer assesses each jurisdiction, purpose, necessity, notice, consent or other basis, access, retention, transfer and individual rights.
CDR and call metadata
CDR and flow can include numbers, names, tenant, endpoints, times, status, routing, account code, carrier and technical identifiers. They support call handling, billing, security, diagnostics and reporting. Tenant CDR retention, minimum scope and roles require periodic review.
Call recording
The Customer chooses always-on, on-demand, selective or disabled recording and supplies any required announcement, tone, consent or other authority before recording, plus a process for people who decline. Recordings must not be used for unlawful employee monitoring or capture payment-card data without approved pause or masking.
Playback and download need a separate role, links are not public, downloads are audited and Recording Policy controls retention. Exported files become the responsibility of the Customer.
Voicemail and prompts
Voicemail may contain private or sensitive content. The Customer configures PIN, user access, notifications, retention and lawful prompts. PINs must not be sent in tickets or email. Deleted messages may remain until encrypted backup rotation ends.
FAX, chat and phonebook
FAX and chat may contain confidential data. The Customer assigns mailboxes, restricts viewing, verifies recipients and sets retention. Phonebook data must be lawfully obtained and shared.
Delivery or read status is technical information, not proof of recipient identity or formal legal service.
Call Capture, SIP/SDP and PCAP
Call Capture is off by default and requires an entitlement, plan module, role and host setting. SIP/SDP without RTP is preferred when audio is unnecessary. Full PCAP may contain media, addresses, numbers, protocol tokens and secrets.
Capture needs a defined purpose, scope and duration. Access, download and deletion are audited; node policy enforces retention and storage limits. Continuous surveillance without documented need and authority is prohibited.
Remote diagnostics and support
Remote logs operate only after Customer enablement for an agreed scope and period. Bundles should redact passwords, tokens, keys, PINs and unnecessary content. The Customer reviews attachments before sending. Support opens data only for a case, logs access and deletes working copies after purpose.
Never send full card data, private keys or active secrets in a ticket.
Caller ID and SIP headers
Caller ID, PAI, Diversion and X-Headers must match Customer rights, forwarding scenario, carrier contract and local law. Saving a value does not prove number ownership. Support may request evidence and block spoofing.
Location and emergency calls
Emergency location must be accurate, current and linked to the proper number and user. Access is restricted and change-audited. Testing follows the procedure of the carrier and must not create false alarms. Law may require longer retention or disclosure.
Retention, legal hold and deletion
Tenant policy separately controls CDR, recordings, voicemail, FAX, chat and audit; PCAP uses node policy. A missing expiry is flagged as a gap, not indefinite consent. Shortening retention may be irreversible.
A documented legal hold pauses deletion within scope. Normal retention resumes after release. Backups delete expired data through rotation and are not used for ordinary access.
Individual rights and incidents
The Customer verifies and handles access, correction, restriction and erasure; RelayPBX assists under the DPA. Suspected unauthorised listening, download, misdirected FAX, PCAP disclosure or cross-tenant access must be reported immediately to security@relaypbx.com while preserving identifiers without spreading content.