Privacy Policy
Last updated: 14 July 2026 Effective date: 14 July 2026
This Privacy Policy explains how Umney Connect (“Umney”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you visit umneyconnect.com, create an account, or use the Umney Connect cloud PBX, CRM, and related products (the “Service”).
It is written for enterprise and SMB customers evaluating cloud communications platforms and for individual users of those Organisations.
1. Who we are and roles
Controller for website visits, marketing, account administration, billing identity, and platform security logs: Umney Connect (contact: privacy@umneyconnect.com).
For Customer Data that your Organisation stores in the Service (contacts, call metadata, recordings if enabled, tickets, CRM fields), your Organisation is typically the controller and Umney acts as a processor / service provider processing data on your documented instructions. A Data Processing Addendum is available on request for enterprise customers.
2. Scope
This Policy covers:
- Visitors to our marketing and legal pages
- Account holders, administrators, and agents using the dashboard or softphone
- Individuals whose data appears in an Organisation’s tenant (employees, customers, callers) — Organisations remain responsible for providing their own notices to those individuals where required
3. Personal data we collect
3.1 Data you provide
- Identity and contact data: name, email, phone, job title, organisation name
- Account credentials and authentication events
- Billing and payment method references (card/bank details are typically processed by Stripe, Paystack, or similar processors — we do not store full card numbers)
- Support communications and feedback
- Configuration data: SIP trunks, routing rules, IVR settings, user roles
3.2 Telephony and product usage data
- Call detail records (CDR): timestamps, direction, duration, numbers/extensions, disposition, tenant identifiers
- Softphone registration and session diagnostics (device/browser metadata, edge region, error codes)
- Webhook and provider events needed to complete calls (Twilio, Telnyx, SIP providers you configure)
- Optional call recordings, voicemail, and transcriptions when your Organisation enables those features
- CRM records, notes, chat/widget interactions, and AI assistant prompts/outputs where those modules are used
3.3 Technical and security data
- IP address, user agent, approximate location derived from IP, cookies and similar technologies
- Application logs, request IDs, rate-limit counters, and abuse-prevention signals
- Performance and availability telemetry for service reliability
3.4 Data from third parties
Telephony Providers, payment processors, single sign-on providers (if enabled), and publicly available business registries may supply data needed to operate the Service.
4. Purposes and legal bases (GDPR / UK GDPR)
We process personal data to:
- Provide and administer the Service (contract / legitimate interests)
- Authenticate users and secure multi-tenant isolation (legitimate interests / legal obligation)
- Bill and collect fees (contract / legal obligation)
- Prevent fraud, toll fraud, and platform abuse (legitimate interests / legal obligation)
- Improve reliability, features, and documentation (legitimate interests; where required, consent)
- Communicate service notices and (with consent or soft opt-in where allowed) product updates
- Comply with law enforcement and regulatory requests where legally compelled
Where we rely on consent (for example certain cookies or marketing), you may withdraw consent at any time without affecting prior lawful processing.
5. How we use Customer Data as a processor
We process Customer Data only to provide the Service to your Organisation, including hosting, routing, storage, backup, support (with least privilege), and security monitoring. We do not sell Customer Data. We do not use Customer Content to train public foundation models for unrelated third parties. Limited product analytics may use aggregated or de-identified metrics.
Organisations control retention of recordings and CRM records within plan limits and product settings, subject to our backup windows and legal holds.
6. Sharing and processors
We share personal data with:
- Infrastructure providers (for example Cloudflare for edge compute, DNS, and security; database and object storage providers for durable Customer Data)
- Telephony Providers you configure or that power Umney-hosted SIP features
- Payment processors (Stripe, Paystack, or successors)
- Email delivery providers for transactional mail (password reset, invoices, alerts)
- Professional advisers and auditors under confidentiality
- Authorities when required by valid legal process
We require processors to implement appropriate security and use data only for contracted purposes. A current sub-processor list can be requested from privacy@umneyconnect.com.
International transfers: where data is transferred outside your region, we use appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms.
7. Retention
- Account and billing records: retained for the life of the account and thereafter as required for tax, accounting, and dispute resolution (typically up to 7 years where mandated)
- Security logs: retained for a rolling period appropriate to incident response (often 30–180 days unless investigating an incident)
- CDR and product logs: retained per Organisation plan settings and platform defaults; purged or anonymised after retention windows
- Recordings/voicemail: retained until deleted by the Organisation or until plan retention expires
- Backups: may persist for a limited additional period after deletion for disaster recovery
8. Security measures
Measures include TLS encryption in transit, logical tenant isolation, role-based access control, secrets management for Worker and platform credentials, monitoring/alerting, vulnerability management, and least-privilege operational access. Customers remain responsible for strong passwords, MFA where offered, correct RBAC assignments, and securing SIP credentials.
9. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, object, port data, and withdraw consent. You may lodge a complaint with a supervisory authority.
- End users of an Organisation should contact that Organisation first (they control the tenant data)
- Site visitors and account owners may contact privacy@umneyconnect.com
- We will respond within timelines required by applicable law (for example one month under GDPR, subject to extensions)
We may need to verify identity before fulfilling requests.
10. Cookies and similar technologies
We use:
- Strictly necessary cookies for authentication, security, and load balancing
- Preferential/functional cookies to remember settings
- Analytics cookies (if enabled) to understand product and marketing usage
You can control cookies via browser settings. Blocking essential cookies may prevent login.
11. Children’s privacy
The Service is directed to businesses and is not intended for children under 16 (or higher age required locally). We do not knowingly collect children’s data.
12. Automated decision-making
Routing, fraud scoring, and optional AI assistants may automate or assist decisions. These features are intended to support human agents and administrators; Organisations remain responsible for outcomes affecting individuals (for example hiring, credit, or similarly significant automated decisions under Article 22 GDPR) and for enabling human review where required.
13. Changes to this Policy
We may update this Privacy Policy. Material changes will be posted with a new “Last updated” date and, where appropriate, notified to administrators. Continued use after changes constitute acceptance where permitted by law.
14. Contact
Privacy and data-protection requests: privacy@umneyconnect.com Security incidents: security@umneyconnect.com General support: support@umneyconnect.com Postal / registered details: available on request for enterprise contracting Website: https://umneyconnect.com