Controller and contact
The business below controls website, account, sales, security and support data. Requests: privacy@relaypbx.com. Security reports: security@relaypbx.com.
9ne.pl Jarosław Starońul. Starobielawska 32a, 54-061 Wrocław, PolandNIP 8942787122 · VAT-UE PL8942787122 · REGON 363646399contact@relaypbx.comRelayPBX seller and service providerController and processor roles
RelayPBX is controller for visitors, account holders, buyers, contacts and installation administrators. For Managed Communications Data and remote support content, RelayPBX may act only on behalf of the Customer as processor under the DPA. The Customer remains controller and provides notices to its users and callers.
Data categories
- account and identity data, including name, email, organisation, roles, SSO and MFA identifiers;
- buyer and commerce data, including legal name, country, tax identifier, orders, subscriptions, invoices, payments and refunds, but not full card data;
- technical and security data, including login events, security-log IP address, device, browser, audit and diagnostics;
- support tickets, messages, attachments, screen recordings and voluntarily supplied logs;
- public-site path, referrer domain, coarse country and device, named click target and Web Vitals, without raw IP, form content, replay or persistent identifier;
- Communications Data processed for Customers: CDR, SIP identifiers, chat, voicemail, FAX, recordings, PCAP and diagnostics.
Purposes and legal bases
- contract and pre-contract steps: account, quote, payment, licence, provisioning, portal, support and billing;
- legal obligation: tax, accounting, complaints, authority requests and breach duties;
- legitimate interests: security, abuse prevention, audit, legal claims, quality and aggregated analytics without persistent tracking, after balancing;
- consent: only where expressly requested, such as optional marketing or non-essential technology, and withdrawable prospectively;
- vital interests or legal task: exceptionally where safety or a binding request requires it.
A checkout acknowledgement of this notice is not consent to contractually or legally necessary processing.
Sources and required data
Data comes from the individual, their organisation, tenant administrator, identity provider, payment provider, PBX installation and security infrastructure. Required fields are necessary for account, contract, tax or security; without them the relevant service may not be available.
Recipients and processors
Access is limited to authorised RelayPBX personnel and necessary providers: OVHcloud and infrastructure providers, Cloudflare/Sites for site delivery and storage, RelayPBX Identity/Keycloak, PayU for PLN payments, Stripe for international sales and the billing portal, wFirma for invoicing, transactional email and SMTP providers, backup services, advisers and authorities where law requires.
RelayPBX does not sell personal data. Providers receive only data needed for their function and are bound by contract, confidentiality and security.
Transfers outside the EEA
RelayPBX prefers EEA processing. Where a provider or support access transfers data to a country without adequacy, RelayPBX uses an appropriate mechanism such as Standard Contractual Clauses, a transfer assessment and supplementary safeguards. Information can be requested from privacy@relaypbx.com, subject to security and confidentiality redactions.
Retention
- orders, invoices and accounting records for statutory tax/accounting periods and limitation periods;
- account and contract data for the relationship plus necessary closure, security and claims periods;
- authentication session records until active expiry and up to 30 days after expiry or revocation;
- detailed public-site analytics for 180 days, followed only by non-identifying aggregates where retained;
- newsletter records: unconfirmed requests for up to 30 days, active subscriptions until consent is withdrawn, and a minimal suppression record after opt-out to prevent unintended resubscription;
- migration assessment requests for up to 180 days when no customer relationship or longer claims duty follows;
- support content for handling and claims, or shorter after secure deletion;
- PBX data according to tenant policies for CDR, recordings, voicemail, FAX, audit and chat; Call Capture according to node settings;
- backups until rotation completes unless a documented legal hold applies.
Individual rights
Depending on context, individuals may request access, copy, correction, erasure, restriction, portability, objection and consent withdrawal at privacy@relaypbx.com. Identity is verified proportionately and RelayPBX generally responds within one month. Processor-held data requests are referred to or handled with the Customer controller.
Individuals may complain to the Polish UODO at uodo.gov.pl or their competent local supervisory authority.
Automated decisions
RelayPBX does not make solely automated decisions about individuals with legal or similarly significant effects. Automated fraud, payment, licence and security checks may pause a workflow for review and can be challenged through support.
Security and breaches
Controls include encryption in transit, access control, MFA, tenant isolation, audit, minimisation, restore-tested backups, secret management, release scanning and monitoring. No control removes all risk.
As controller, RelayPBX assesses and documents incidents, notifies the authority without undue delay and where feasible within 72 hours when required, and informs individuals for high risk. As processor, RelayPBX informs the Customer without undue delay under the DPA.
Children and changes
RelayPBX is an organisational product for adults and is not directed to children. Unauthorised child accounts are addressed when discovered.
This notice may change for law, function, supplier or risk. Material changes affecting active accounts are communicated appropriately and every published version carries its date.