RelayPBX
ProductSolutionsFeaturesEditionsDeployResourcesSupport
LanguageEnglish⌄
EnglishEN✓PolskiPLहिन्दीHIPortuguês (Brasil)PT
Customer portalGet started
ProductSolutionsFeaturesEditionsDeployResourcesSupport
LanguageEnglish⌄
EnglishEN✓PolskiPLहिन्दीHIPortuguês (Brasil)PT
Customer portalGet started
GDPR · processing

Data Processing Agreement

This DPA forms part of the Customer contract whenever RelayPBX processes personal data on behalf of the Customer in Managed, support or diagnostics.

Version: 2026-08-04Effective: 2026-08-04
On this page01Parties and precedence02Documented instructions03Subject, duration, nature and purpose04People and data categories05Customer duties06Confidentiality and personnel07Technical and organisational measures08Subprocessors09International transfers10Rights and compliance assistance11Personal data breaches12Return and deletion13Information and audit14Contact, liability and law
01

Parties and precedence

The Customer identified in the order is controller and the provider below is processor. This DPA starts with order acceptance and lasts while RelayPBX processes data for the Customer. It prevails over conflicting general terms for data protection.

9ne.pl Jarosław Starońul. Starobielawska 32a, 54-061 Wrocław, PolandNIP 8942787122 · VAT-UE PL8942787122 · REGON 363646399contact@relaypbx.comRelayPBX seller and service provider
02

Documented instructions

RelayPBX processes data only on documented Customer instructions in the contract, configuration, retention policy, support case or authorised administrator command. Union or Member State law is the exception, with prior notice where legally permitted. RelayPBX informs the Customer if an instruction appears unlawful and may pause it pending clarification.

03

Subject, duration, nature and purpose

Subject: PBX, Managed hosting, support, backup, updates, licensing and diagnostics. Duration: the contract and controlled deletion. Nature: collection, recording, organisation, storage, reading, transfer, restriction, export, deletion and restoration. Purpose: functions selected and configured by the Customer.

04

People and data categories

People may include staff, contractors, customers, callers, agents, administrators, contacts and FAX recipients. Data may include identifiers, contact and phone numbers, call metadata, IP, SIP/SDP, emergency location, chat, voicemail, recordings, FAX documents, PCAP, audit and support data. Special-category data may appear only through Customer-supplied or captured content; the Customer assesses lawfulness and necessity.

05

Customer duties

  • establish legal basis, purpose, scope, retention and transparent notices;
  • ensure recording, monitoring, FAX, PCAP and remote diagnostics are lawful in each jurisdiction;
  • configure roles, MFA, tenants and retention for minimisation;
  • send no excessive data or unlawful instruction;
  • handle individual rights as controller and send RelayPBX verified instructions.
06

Confidentiality and personnel

Authorised RelayPBX personnel are bound by confidentiality and role-based need. Administrative access is logged, reviewed and removed when no longer needed. Support does not inspect communication content without a case, instruction or authorised incident response.

07

Technical and organisational measures

  • TLS, secure credential hashing, secret stores and signed licences/updates;
  • tenant isolation across API, database, files, roles and regression tests;
  • MFA, SSO, RBAC, least privilege, audit and controlled support access;
  • encrypted off-site backups, rotation and automated restore drills;
  • external monitoring, vulnerability management, image scanning, SBOM and controlled releases;
  • tenant retention, legal hold, secure export and controlled erasure;
  • incident, continuity, update, rollback and secure-development procedures.
08

Subprocessors

The Customer gives general authorisation for providers needed by the selected model: infrastructure, site delivery and object storage, identity, email, payment, invoicing, backup and security tooling. These may include OVHcloud, Cloudflare/Sites, PayU, Stripe, wFirma and email providers.

Equivalent data duties flow down. RelayPBX gives notice of material changes. The Customer may object on substantiated data-protection grounds within 14 days. If no solution is possible, the affected service may be terminated with refund of unused future fees.

09

International transfers

Data leaves the EEA only on Customer instruction or under an appropriate mechanism such as adequacy or Standard Contractual Clauses with assessment and supplementary safeguards. RelayPBX provides information needed for the transfer assessment of the Customer.

10

Rights and compliance assistance

Taking account of processing nature, RelayPBX assists with access, correction, erasure, restriction, portability and objection, and with security assessments, breaches, DPIAs and authority consultation using available information. Standard export and deletion are included; excessive custom work may be charged unless caused by RelayPBX breach.

11

Personal data breaches

RelayPBX notifies the Customer without undue delay after confirming a breach of entrusted data, targeting 24 hours where enough facts exist. Available information covers nature, people and records, contact, likely effects and mitigation, and may be supplied in phases.

RelayPBX does not notify authorities or individuals for the Customer unless instructed or legally required. The Customer remains responsible for controller assessment and deadlines.

12

Return and deletion

On termination, the Customer may export data. At the choice of the Customer, RelayPBX returns or deletes entrusted data and deletes copies as backup rotation completes, unless law requires retention. Backups are isolated from normal use. A documented legal hold pauses deletion within scope.

13

Information and audit

RelayPBX provides information needed to demonstrate compliance, including measures, test reports, SBOM and backup status. Once yearly, the Customer may conduct a reasonable documentary audit under confidentiality and notice. On-site audit is available when documents are insufficient or an authority requires it, without access to other customers or service disruption.

The Customer bears unusual audit cost unless it identifies a material RelayPBX breach.

14

Contact, liability and law

Operations: privacy@relaypbx.com; incidents: security@relaypbx.com. Liability follows the Terms to the extent lawful. This DPA follows the law and forum of the main contract without limiting supervisory authority powers or individual rights.

Related documents
TermsPrivacyCommunications Data
RelayPBX

A precise control plane for business telephony, contact centers and service-provider voice infrastructure.

Version 1.0 · Cloud, Dedicated Cloud and Self-hosted
ProductOverviewBusiness PBXCloud PBXContact CenterMulti-tenant PBXSelf-hosted PBXPBX migrationPlan advisorCapabilities & roadmapEditionsDeployment
ResourcesVideo guidesCommunityDocumentationKnowledge baseFAQSupportCustomer portalCustomer docs
CompanyContactSecurityStatusPartners
RelayPBX newsletterReleases, practical field notes and important changes.
Secure payments accepted
stripePayPalVISAmastercard
© 2026 RelayPBX. All rights reserved.
PrivacyTermsDPAAcceptable useCookiesResponsible disclosure