RelayPBX
ProductSolutionsFeaturesEditionsDeployResourcesSupport
LanguageEnglish⌄
EnglishEN✓PolskiPLहिन्दीHIPortuguês (Brasil)PT
Customer portalGet started
ProductSolutionsFeaturesEditionsDeployResourcesSupport
LanguageEnglish⌄
EnglishEN✓PolskiPLहिन्दीHIPortuguês (Brasil)PT
Customer portalGet started
Data protection

RelayPBX Privacy Notice

This notice explains the personal data we control, why we need it, who receives it, how long it is retained and how individuals can exercise their rights.

Version: 2026-08-04Effective: 2026-08-04
On this page01Controller and contact02Controller and processor roles03Data categories04Purposes and legal bases05Sources and required data06Recipients and processors07Transfers outside the EEA08Retention09Individual rights10Automated decisions11Security and breaches12Cookies, analytics and marketing13Children and changes
01

Controller and contact

The business below controls website, account, sales, security and support data. Requests: privacy@relaypbx.com. Security reports: security@relaypbx.com.

9ne.pl Jarosław Starońul. Starobielawska 32a, 54-061 Wrocław, PolandNIP 8942787122 · VAT-UE PL8942787122 · REGON 363646399contact@relaypbx.comRelayPBX seller and service provider
02

Controller and processor roles

RelayPBX is controller for visitors, account holders, buyers, contacts and installation administrators. For Managed Communications Data and remote support content, RelayPBX may act only on behalf of the Customer as processor under the DPA. The Customer remains controller and provides notices to its users and callers.

03

Data categories

  • account and identity data, including name, email, organisation, roles, SSO and MFA identifiers;
  • buyer and commerce data, including legal name, country, tax identifier, orders, subscriptions, invoices, payments and refunds, but not full card data;
  • technical and security data, including login events, security-log IP address, device, browser, audit and diagnostics;
  • support tickets, messages, attachments, screen recordings and voluntarily supplied logs;
  • public-site path, referrer domain, coarse country and device, named click target and Web Vitals, without raw IP, form content, replay or persistent identifier;
  • Communications Data processed for Customers: CDR, SIP identifiers, chat, voicemail, FAX, recordings, PCAP and diagnostics.
04

Purposes and legal bases

  • contract and pre-contract steps: account, quote, payment, licence, provisioning, portal, support and billing;
  • legal obligation: tax, accounting, complaints, authority requests and breach duties;
  • legitimate interests: security, abuse prevention, audit, legal claims, quality and aggregated analytics without persistent tracking, after balancing;
  • consent: only where expressly requested, such as optional marketing or non-essential technology, and withdrawable prospectively;
  • vital interests or legal task: exceptionally where safety or a binding request requires it.

A checkout acknowledgement of this notice is not consent to contractually or legally necessary processing.

05

Sources and required data

Data comes from the individual, their organisation, tenant administrator, identity provider, payment provider, PBX installation and security infrastructure. Required fields are necessary for account, contract, tax or security; without them the relevant service may not be available.

06

Recipients and processors

Access is limited to authorised RelayPBX personnel and necessary providers: OVHcloud and infrastructure providers, Cloudflare/Sites for site delivery and storage, RelayPBX Identity/Keycloak, PayU for PLN payments, Stripe for international sales and the billing portal, wFirma for invoicing, transactional email and SMTP providers, backup services, advisers and authorities where law requires.

RelayPBX does not sell personal data. Providers receive only data needed for their function and are bound by contract, confidentiality and security.

07

Transfers outside the EEA

RelayPBX prefers EEA processing. Where a provider or support access transfers data to a country without adequacy, RelayPBX uses an appropriate mechanism such as Standard Contractual Clauses, a transfer assessment and supplementary safeguards. Information can be requested from privacy@relaypbx.com, subject to security and confidentiality redactions.

08

Retention

  • orders, invoices and accounting records for statutory tax/accounting periods and limitation periods;
  • account and contract data for the relationship plus necessary closure, security and claims periods;
  • authentication session records until active expiry and up to 30 days after expiry or revocation;
  • detailed public-site analytics for 180 days, followed only by non-identifying aggregates where retained;
  • newsletter records: unconfirmed requests for up to 30 days, active subscriptions until consent is withdrawn, and a minimal suppression record after opt-out to prevent unintended resubscription;
  • migration assessment requests for up to 180 days when no customer relationship or longer claims duty follows;
  • support content for handling and claims, or shorter after secure deletion;
  • PBX data according to tenant policies for CDR, recordings, voicemail, FAX, audit and chat; Call Capture according to node settings;
  • backups until rotation completes unless a documented legal hold applies.
09

Individual rights

Depending on context, individuals may request access, copy, correction, erasure, restriction, portability, objection and consent withdrawal at privacy@relaypbx.com. Identity is verified proportionately and RelayPBX generally responds within one month. Processor-held data requests are referred to or handled with the Customer controller.

Individuals may complain to the Polish UODO at uodo.gov.pl or their competent local supervisory authority.

10

Automated decisions

RelayPBX does not make solely automated decisions about individuals with legal or similarly significant effects. Automated fraud, payment, licence and security checks may pause a workflow for review and can be challenged through support.

11

Security and breaches

Controls include encryption in transit, access control, MFA, tenant isolation, audit, minimisation, restore-tested backups, secret management, release scanning and monitoring. No control removes all risk.

As controller, RelayPBX assesses and documents incidents, notifies the authority without undue delay and where feasible within 72 hours when required, and informs individuals for high risk. As processor, RelayPBX informs the Customer without undue delay under the DPA.

12

Cookies, analytics and marketing

Strictly necessary cookies protect sign-in, OIDC state and language preference. RelayPBX public analytics uses no cookie or persistent identifier and respects Do Not Track. See the Cookie Notice.

Electronic marketing uses an appropriate legal basis and easy opt-out. Transactional account, security, billing and service messages are not marketing.

13

Children and changes

RelayPBX is an organisational product for adults and is not directed to children. Unauthorised child accounts are addressed when discovered.

This notice may change for law, function, supplier or risk. Material changes affecting active accounts are communicated appropriately and every published version carries its date.

Related documents
TermsDPACookiesCommunications Data
RelayPBX

A precise control plane for business telephony, contact centers and service-provider voice infrastructure.

Version 1.0 · Cloud, Dedicated Cloud and Self-hosted
ProductOverviewBusiness PBXCloud PBXContact CenterMulti-tenant PBXSelf-hosted PBXPBX migrationPlan advisorCapabilities & roadmapEditionsDeployment
ResourcesVideo guidesCommunityDocumentationKnowledge baseFAQSupportCustomer portalCustomer docs
CompanyContactSecurityStatusPartners
RelayPBX newsletterReleases, practical field notes and important changes.
Secure payments accepted
stripePayPalVISAmastercard
© 2026 RelayPBX. All rights reserved.
PrivacyTermsDPAAcceptable useCookiesResponsible disclosure