DATA PRIVACY • CPNI SAFEGUARDS • ZERO DATA SELLING • AES-256 ENCRYPTION
Effective Date: August 24, 2026 | Last Updated: August 24, 2026
COMEXCEL is committed to safeguarding the privacy, security, and confidentiality of the personal information, telecommunications data, and customer content entrusted to us by small businesses, multi-location companies, enterprise organizations, remote/hybrid workforces, PBX administrators, IT teams, and individual VoIP users. This Privacy Policy explains our practices regarding the collection, processing, protection, retention, and disclosure of information across our Business VoIP Phone Service & Cloud PBX Solutions, SIP trunking, 2-way business SMS/MMS, mobile and desktop softphones, CRM integrations, and artificial intelligence communications tools.
Privacy at a Glance
- What We Collect: Account credentials, billing details, Customer Proprietary Network Information (CPNI), voice call recordings, SMS/MMS messages, AI speech transcripts, and softphone diagnostic telemetry.
- How We Protect It: Multi-layered enterprise security including TLS signaling, SRTP voice stream encryption, AES-256 data storage at rest, multi-factor authentication (MFA), and role-based access controls (RBAC).
- Strict 10DLC & Messaging Rule: We do not sell, rent, or share mobile numbers, SMS opt-in consent records, or messaging originator data with third parties or affiliates for marketing or promotional purposes.
- Telecommunications Compliance: Full adherence to FCC CPNI rules, E911 emergency routing, TCPA/CTIA messaging standards, and HIPAA-compliant data transmission frameworks.
Scope & Services Covered
This Privacy Policy forms an integral part of the COMEXCEL Legal & Compliance Hub and applies to all interactions across our platform ecosystem. It governs data collected from:
- Account Administrators & IT Teams: Business representatives purchasing, provisioning, and administering enterprise telecom networks.
- Authorized End Users & Remote Workforces: Employees, contractors, and hybrid staff utilizing provisioned extensions, softphones, and mobile applications.
- Communications Participants: External callers and messaging recipients interacting with businesses hosted on the COMEXCEL network.
- Website Visitors & Prospects: Individuals browsing our corporate website, reading documentation, or submitting quote requests.
Information We Collect
We collect information necessary to provide, operate, bill, and secure enterprise communications:
- Account & Administrative Data: Legal business name, corporate address, administrator contact information, employee extension assignments, and role-based permissions.
- Billing & Transaction Details: Payment transaction tokens, subscription tiers ($18, $22, $25/user/month), usage metrics ($0.015/SMS), and invoices processed through PCI-DSS Level 1 payment gateways.
- Telecommunications Service Data: Call Detail Records (CDRs), originating/terminating numbers, call timestamps, connection durations, SIP routing data, and network telemetry.
Customer Proprietary Network Information (CPNI) & E911 Data
As an interconnected VoIP provider, COMEXCEL protects Customer Proprietary Network Information (CPNI) under FCC regulations (47 CFR Part 64):
- What Constitutes CPNI: CPNI includes technical configurations, destination phone numbers, call frequency, duration, and telephony billing metadata.
- CPNI Safeguards: We never sell or disclose CPNI for non-telecommunications marketing without explicit prior consent. Access is restricted behind multi-factor authentication (MFA) and granular permissions.
- E911 Emergency Location Data: Physical dispatch addresses provided by administrators are transmitted directly to local Public Safety Answering Points (PSAPs) during emergency 911 calls as required by FCC Part 9 mandates.

Voice Communications, Voicemail & Call Recordings
- Voice Media Streams: Active phone calls are encrypted using Secure Real-time Transport Protocol (SRTP) to safeguard against interception.
- Customer-Controlled Call Recording: Call recording capabilities are controlled solely by account administrators. Stored audio files are encrypted at rest using AES-256. Legal Notice: Customers are legally responsible for complying with federal and state one-party or all-party call recording consent laws prior to recording conversations.
- Voicemail Storage: Voicemail audio files and voicemail-to-email notifications (.mp3/.wav files) are routed and stored through encrypted channels and managed according to customer-configured retention policies.
AI Transcription, Summaries & Voice Intelligence
When customers activate AI Voice Intelligence features:
- Processing Scope: Voice audio is processed solely to generate private real-time transcripts, sentiment insights, and executive summaries for your account.
- No Public Foundation Model Training: COMEXCEL does not sell, publish, or utilize private customer call audio or transcripts to train public, generalized AI foundation models.
- Data Ownership: AI-generated notes remain the proprietary property of the customer and can be permanently purged by account administrators at any time.
Business SMS, MMS & 10DLC Messaging Governance
- 10DLC Brand & Campaign Registration: COMEXCEL registers customer messaging campaigns with The Campaign Registry (TCR) to ensure carrier-approved throughput across U.S. wireless networks.
- Automated Opt-Out Processing: Our messaging platform automatically detects and enforces standard carrier opt-out keywords (STOP, END, CANCEL, QUIT, UNSUBSCRIBE).
- Strict Non-Sharing Policy: Mobile information, opt-in consent verification records, and SMS campaign data are never sold, rented, or shared with third parties, affiliates, or lead aggregators for marketing purposes.
CRM & Third-Party Integrations
When linking COMEXCEL with third-party software (such as Salesforce, HubSpot, Zoho, Google Workspace, or Microsoft 365):
- Data Synchronized: Depending on customer configuration, the platform synchronizes call logs, contact profiles, recording links, SMS threads, and AI summaries into the connected CRM timeline.
- Authentication Security: Integrations connect via OAuth 2.0 credentials and encrypted REST API webhooks. Third-party systems process data under their respective service agreements and privacy policies.
Email & Automated Service Communications
- Transactional Service Alerts: We send essential system notifications regarding billing invoices, password resets, number porting updates, security alerts, and regulatory disclosures.
- Marketing Communications: Account contacts can opt out of promotional newsletters and product feature announcements at any time using the “Unsubscribe” link in the email footer.
Mobile & Desktop Softphone Telemetry
Our native desktop (Windows, macOS) and mobile (iOS, Android) applications collect essential operational telemetry:
- Permissions: Microphone access for voice calling, push notification tokens for inbound call signaling, and optional local contact directory access.
- Diagnostic Telemetry: Device hardware models, OS versions, IP addresses, app release tags, and crash diagnostics collected to optimize voice packet delivery and troubleshoot jitter.
Remote & Hybrid Workforce Data Handling
- Extension Privacy: Softphone apps route business calls through corporate PBX caller IDs, keeping employee personal cell phone numbers completely private.
- Administrative Oversight: Administrators can review enterprise call logs, queue metrics, and presence status associated with provisioned extensions in alignment with workplace governance standards.
Cookies, Tracking & Website Technologies
- Strictly Necessary Cookies: Essential for portal authentication, session security, and account management.
- Performance Cookies: Anonymous, aggregated analytical telemetry used to understand website navigation flow and improve interface performance.
- Browser Controls: Visitors can disable non-essential cookies through standard browser settings without impacting core PBX operations.
How We Use Business & Communications Data
We process collected information strictly for legitimate commercial and telecommunications purposes:
- Provisioning and maintaining Cloud PBX extensions, softphone credentials, and SIP trunks.
- Routing PSTN calls, toll-free traffic, and SMS/MMS across carrier interconnects.
- Managing zero-downtime business number porting and DID inventory assignments.
- Generating Call Detail Records (CDRs) and billing statements.
- Mitigating robocall spoofing, toll fraud, and cyber abuse under FCC STIR/SHAKEN rules.
- Complying with federal telecommunications statutes and lawful court orders.
How We Disclose Information & Subprocessors
COMEXCEL does not sell customer personal data. Disclosures occur strictly with trusted subprocessors required for telecommunications delivery:
- Tier-1 Telecommunications Carriers: Underlying PSTN carriers and SMS aggregators required to route voice traffic, deliver 10DLC texts, and complete number ports.
- Cloud Infrastructure Providers: Geo-redundant Tier-IV data centers hosting encrypted application servers and database clusters.
- Payment Gateways: PCI-DSS Level 1 payment processors handling billing transactions.
- Law Enforcement: Regulatory agencies or law enforcement authorities only when compelled by valid court orders, subpoenas, or statutory mandates.
Business & Enterprise Customer Data (Controller vs. Processor)
- COMEXCEL as Data Controller: We act as a Controller for direct customer account records, administrative billing contacts, and commercial relationship data.
- COMEXCEL as Data Processor: When hosting voice calls, SMS payloads, call recordings, voicemail files, and CRM records on behalf of enterprise subscribers, COMEXCEL acts strictly as a Data Processor. The subscribing organization remains the Data Controller responsible for lawful end-user notices and consent.
Healthcare (HIPAA/BAA) & Regulated Data
- HIPAA Technical Architecture: COMEXCEL supports Health Insurance Portability and Accountability Act (HIPAA) compliance for medical clinics, dental practices, and healthcare organizations.
- Business Associate Agreements (BAAs): We execute formal BAAs with eligible healthcare accounts, implementing TLS/SRTP transmission encryption, role-based access restrictions, and administrative audit logging for protected health information (PHI).
Data Security & Cryptographic Standards
- In-Transit Encryption: Voice signaling is protected via TLS 1.3, and voice media streams are encrypted via SRTP.
- At-Rest Encryption: Stored call recordings, voicemails, AI transcripts, and databases are protected using AES-256 bit encryption.
- Infrastructure Redundancy: Tier-IV geo-redundant data center nodes engineered for 99.999% SLA availability and automated sub-second failover.
- Access Controls: Multi-factor authentication (MFA), role-based permissions (RBAC), and continuous administrative audit logging.

Data Retention & Deletion Schedules
- Call Detail Records (CDRs): Retained for billing validation, tax reporting, and FCC compliance records.
- Call Recordings & Voicemails: Stored according to custom retention schedules established by account administrators, after which they are permanently deleted from server disks.
- Account Records: Retained for the duration of the active service subscription plus standard statutory periods required for corporate tax and regulatory compliance.
U.S. State Privacy Rights & California (CCPA/CPRA) Notice
Eligible U.S. residents (under the CCPA/CPRA and similar state frameworks in VA, CO, CT, and UT) have specific rights regarding their personal data:
- Right to Access & Portability: Request details regarding categories of personal data collected, stored, and processed.
- Right to Correction & Deletion: Request correction of inaccurate records or deletion of personal data, subject to statutory telecommunications retention mandates.
- Non-Discrimination: We do not discriminate against any customer or user for exercising lawful privacy rights.
- No Sale of Personal Information: COMEXCEL does not sell personal information or share personal data for cross-context behavioral advertising.
International Data & Cross-Border Transfers
COMEXCEL telecommunications infrastructure and data centers are located in the United States. If accessing our services internationally, your data is transferred to, stored, and processed securely in the United States subject to standard contractual clauses and robust technical safeguards.
Security Incident Response & Breach Protocols
COMEXCEL maintains an active Computer Security Incident Response Plan (CSIRP). In the event of a verified security incident affecting customer data or CPNI, we will notify affected account administrators and regulatory authorities without unreasonable delay in accordance with federal and state data breach notification statutes.
Your Privacy Choices & Opt-Out Controls
- Account Portal: Manage user permissions, reset passwords, update extension routing, and adjust call recording retention directly within the administrative console.
- SMS Opt-Out: Reply STOP to any automated or business text message to immediately discontinue SMS communications.
- Email Preferences: Manage marketing preferences via the unsubscribe link in non-transactional communications.
- Formal Privacy Inquiries: Submit data access or deletion requests to our compliance team.
Policy Updates & Regulatory Contact
COMEXCEL may periodically update this policy to reflect platform updates or evolving regulatory requirements. When material changes occur, we will update the “Last Updated” date at the top of this document and notify account administrators via portal announcements or email.
COMEXCEL Legal & Compliance Department
- Company: COMEXCEL Communications
- Privacy & CPNI Inquiries: [email protected]
- Security & Incident Response: [email protected]
- Mailing Address: COMEXCEL Legal Department, 2800 Marina Mile Blvd, Suite 118, Fort Lauderdale, FL 33312
- Support & Telephony Inquiries: [email protected]
Frequently Asked Questions (FAQ)
Does COMEXCEL sell or share business CPNI or customer contact lists?
No. COMEXCEL strictly complies with FCC Customer Proprietary Network Information (CPNI) regulations and does not sell, rent, monetize, or disclose call detail records, messaging metadata, or customer lists to third-party advertisers or marketers.
How are voice call recordings, voicemails, and AI transcripts secured?
All stored media files, call recordings, voicemail audio, and speech-to-text transcripts are encrypted at rest using enterprise AES-256 encryption and protected in transit via TLS 1.3 cryptographic protocols with multi-factor authentication (MFA) access controls.
Does COMEXCEL use customer voice data or messaging content to train public AI models?
No. All conversational audio, transcription payloads, and automated call summaries processed by COMEXCEL AI tools are strictly siloed to your dedicated account and are never fed into public foundation models or shared across multi-tenant boundaries.
How does COMEXCEL handle SMS opt-in consent data under 10DLC rules?
In compliance with CTIA messaging guidelines and carrier 10DLC registries, mobile numbers, opt-in consent verification records, and SMS campaign data are never shared or transferred to third parties or affiliates for promotional purposes.
Is COMEXCEL compliant with HIPAA and SOC 2 data protection standards?
Yes. COMEXCEL provides technical architectures supporting HIPAA compliance for healthcare providers, executes formal Business Associate Agreements (BAAs), and maintains enterprise data center security safeguards.
What is the difference between COMEXCEL as a Data Controller and Data Processor?
COMEXCEL acts as a Data Controller for direct customer account logins, billing contacts, and commercial contracts. When hosting voice calls, SMS payloads, call recordings, and CRM data on behalf of enterprise subscribers, COMEXCEL acts strictly as a Data Processor.
How long are Call Detail Records (CDRs) and call recordings retained?
CDRs are retained in compliance with FCC telecommunications accounting and tax regulations. Voice recordings and voicemails are retained strictly according to the custom lifecycle schedules configured by your account administrator.
How can I exercise my privacy rights or request data deletion?
Authorized account administrators can manage or purge recordings, transcripts, and contact records directly inside the management portal, or submit a formal data request by contacting [email protected].
Have Questions About Your Telecommunications Privacy?
Whether you need to review our CPNI governance protocols, submit an enterprise data export or deletion request, or speak directly with our compliance team, we are here to help.
