Panoramic enterprise cybersecurity visual showcasing COMEXCEL data protection controls, encrypted telecom streams, and regulatory compliance shields.

COMEXCEL Privacy Policy & Telecommunications Data Governance

Safeguarding business VoIP, cloud PBX, CPNI, and messaging data with enterprise-grade encryption and regulatory compliance.

Effective Date: September 10, 2026 | Last Updated: September 10, 2026

COMEXCEL Privacy Policy and Telecommunications Data Governance Statement establishes binding technical standards, statutory privacy protections, and lifecycle management protocols across all enterprise communications services. COMEXCEL is committed to safeguarding personal information, telecommunications metadata, and customer payloads entrusted to us by multi-location enterprises, healthcare networks, financial institutions, and remote workforces. This statement details our operational practices regarding collection, processing, cryptographic protection, retention schedules, and statutory disclosure across our Business VoIP Phone Service & Cloud PBX Solutions, SIP trunking, 2-way business SMS/MMS, desktop/mobile softphones, CRM integrations, and artificial intelligence communications engines.

Privacy at a Glance

  • What We Collect: Account credentials, billing details, Customer Proprietary Network Information (CPNI), voice call recordings, SMS/MMS messages, AI speech transcripts, and softphone diagnostic telemetry.
  • How We Protect It: Multi-layered enterprise security including TLS signaling, SRTP voice stream encryption, AES-256 data storage at rest, multi-factor authentication (MFA), and role-based access controls (RBAC).
  • Strict 10DLC & Messaging Rule: We do not sell, rent, or share mobile numbers, SMS opt-in consent records, or messaging originator data with third parties or affiliates for marketing or promotional purposes.
  • Telecommunications Compliance: Full adherence to FCC CPNI rules, E911 emergency routing, TCPA/CTIA messaging standards, and HIPAA-compliant data transmission frameworks.

Scope & Services Covered

This Privacy Policy forms an integral component of the master COMEXCEL Legal & Compliance Hub and applies to all interactions across our platform ecosystem. It governs data processed from:

  • Account Administrators & IT Teams: Business representatives purchasing, provisioning, and administering enterprise telecom networks.
  • Authorized End Users & Remote Workforces: Employees, contractors, and hybrid staff utilizing provisioned extensions, softphones, and mobile applications.
  • Communications Participants: External callers and messaging recipients interacting with businesses hosted on the COMEXCEL network.
  • Website Visitors & Prospects: Individuals browsing our corporate website, reading documentation, or submitting quote requests.

Information We Collect

We collect and process only the categories of information strictly required to deliver, bill, secure, and optimize enterprise communications services:

Data ClassificationSpecific Data Elements CollectedLawful Basis / Purpose
Account & ProfileLegal corporate name, physical address, admin email, provisioned extension directory, and user login credentials.Contractual Necessity (Art. 6(1)(b) GDPR) / Account Administration
Financial & BillingTokenized payment hashes, billing addresses, invoice history, and monthly service tiers.Statutory Obligation & Contractual Execution / Tax Mandates
Telephony Metadata (CDRs)Originating/terminating phone numbers, connection timestamps, call duration, SIP status codes, and network IP hops.Legal Mandate (FCC CPNI Regulations) / Carrier Routing & Billing
Customer Communications PayloadStored call recordings, voicemail audio files, business SMS/MMS text bodies, and AI speech transcripts.Subscribing Customer Direct Authorization / Service Delivery
Device & Endpoint DiagnosticsHandset models, firmware builds, client OS versions, round-trip latency, jitter, and packet loss metrics.Legitimate Interest / Network QoS Optimization & Troubleshooting

Customer Proprietary Network Information (CPNI) & E911 Data

As an interconnected VoIP service provider, COMEXCEL protects Customer Proprietary Network Information (CPNI) in strict compliance with FCC regulations (47 CFR Part 64, Subpart U):

  • What Constitutes CPNI: CPNI encompasses technical configurations, destination phone numbers, call frequency, duration, timestamps, and telephony billing metadata generated by customer network use. It excludes subscriber directory listings (name, phone number, and physical office address).
  • CPNI Non-Disclosure Guarantee: COMEXCEL never sells, trades, or discloses CPNI to external parties for marketing, advertising, or lead-generation purposes. Access is restricted behind multi-factor authentication (MFA) and granular, role-based access permissions.
  • E911 Emergency Location Transmission: In compliance with FCC Part 9 mandates, Kari’s Law, and the RAY BAUM’S Act, registered physical dispatchable addresses are transmitted directly to local Public Safety Answering Points (PSAPs) during emergency 911 calls. Review complete subscriber obligations in our dedicated E911 & Emergency Services Disclosure.
Technical architecture diagram illustrating the secure separation, encryption, and FCC-compliant handling of CPNI and E911 location data.

Voice Communications, Voicemail & Call Recordings

  • Voice Media Streams: Active phone calls are encapsulated using Secure Real-time Transport Protocol (SRTP) with AES-256 encryption, preventing unauthorized sniffing across public transit pathways.
  • Customer-Controlled Call Recording: Call recording capabilities are controlled solely by account administrators. Stored audio files are encrypted at rest using AES-256 ciphers.
  • Compliance with Recording Laws: Customers are legally responsible for complying with federal and state one-party or all-party call recording consent statutes prior to activating automated or on-demand recording features.
  • Voicemail Storage & Voicemail-to-Email: Voicemail audio files and voicemail-to-email notifications (.mp3/.wav files) are routed and stored through encrypted channels and managed according to customer-configured retention policies.

AI Transcription, Summaries & Voice Intelligence

When organizations activate COMEXCEL AI Voice Intelligence and automated transcription features:

  • Dedicated Processing Scope: Voice audio payloads are processed solely to generate real-time transcripts, sentiment insights, and executive summaries for your authenticated organization.
  • Zero Public Foundation Model Training: COMEXCEL does not sell, license, or utilize customer call audio, transcripts, or call summaries to train public foundation models or LLMs.
  • Absolute Customer Ownership: All generated transcripts and summaries remain the proprietary property of the customer and can be purged at any time by account administrators.

Business SMS, MMS & 10DLC Messaging Governance

  • 10DLC Brand & Campaign Registration: COMEXCEL registers customer messaging campaigns with The Campaign Registry (TCR) to ensure carrier-approved throughput across Tier-1 U.S. wireless networks.
  • Automated STOP Opt-Out Suppression: Our messaging infrastructure enforces standard carrier opt-out keywords (STOP, END, CANCEL, QUIT, UNSUBSCRIBE) directly at the carrier gateway level.
  • Strict Non-Sharing Policy: Mobile information, opt-in consent verification records, and SMS campaign data are never sold, rented, or shared with third parties, affiliates, or lead aggregators for marketing purposes. For operational campaign rules, review our 10DLC & Messaging Policy.

CRM & Third-Party Integrations

When customers integrate COMEXCEL with third-party software (such as Salesforce, HubSpot, Zoho, Google Workspace, or Microsoft 365):

  • Data Synchronized: The platform synchronizes call logs, contact profiles, recording links, SMS threads, and AI summaries into the connected CRM timeline based on customer configuration.
  • Authentication Security: Integrations connect via OAuth 2.0 credentials and encrypted REST API webhooks. Third-party systems process data under their respective service agreements and privacy policies.

Email & Automated Service Communications

  • Transactional Service Alerts: We transmit essential system notifications regarding billing invoices, password resets, number porting updates, security alerts, and regulatory disclosures. These communications cannot be disabled while maintaining an active account.
  • Marketing Communications: Account contacts can opt out of promotional newsletters and product feature announcements at any time using the “Unsubscribe” link in the email footer.

Mobile & Desktop Softphone Telemetry

Our native desktop (Windows, macOS) and mobile (iOS, Android) applications collect operational telemetry strictly to ensure call continuity:

  • Required Device Permissions: Microphone access for voice calling, push notification tokens for inbound call signaling, and optional local contact directory access.
  • Diagnostic Telemetry: Device hardware models, OS versions, IP addresses, app release tags, and crash diagnostics collected to optimize voice packet delivery and troubleshoot jitter.

Remote & Hybrid Workforce Data Handling

  • Extension Privacy: Softphone apps route business calls through corporate PBX caller IDs, keeping employee personal cell phone numbers completely private.
  • Administrative Oversight: Administrators can review enterprise call logs, queue metrics, and presence status associated with provisioned extensions in alignment with workplace governance standards.

Cookies, Tracking & Website Technologies

COMEXCEL employs web technologies to authenticate sessions, safeguard portals, and analyze site performance. We automatically honor Global Privacy Control (GPC) signals sent by browsers. Complete tracking categories, subprocessor cookies, and consent management tools are outlined in our Cookie & Tracking Technologies Policy.

How We Use Business & Communications Data

We process collected information strictly for legitimate commercial and telecommunications operations:

  • Provisioning and maintaining Cloud PBX extensions, softphone credentials, and SIP trunks.
  • Routing PSTN calls, toll-free traffic, and SMS/MMS across carrier interconnects.
  • Managing zero-downtime business number porting and DID inventory assignments.
  • Generating Call Detail Records (CDRs) and billing statements.
  • Mitigating robocall spoofing, toll fraud, and cyber abuse under FCC STIR/SHAKEN rules.
  • Complying with federal telecommunications statutes and lawful court orders.

How We Disclose Information & Subprocessors

COMEXCEL never sells customer personal data. Disclosures occur strictly with trusted subprocessors required for telecommunications delivery:

Subprocessor CategoryOperational FunctionData TransferredSecurity Controls
Tier-1 PSTN CarriersCall termination, nationwide PSTN routing, number portingE.164 phone numbers, SIP signaling metadataEncrypted carrier interconnections
10DLC Aggregators & TCRBrand verification, carrier campaign vetting, SMS routingCorporate EIN, brand identity, campaign sample templatesHTTPS / TLS REST API integrations
Cloud Data CentersApplication hosting, switching infrastructure, database vaultsEncrypted database snapshots, call logs, media filesSOC 2 Type II certified, AES-256 disk encryption
Payment GatewaysSubscription billing, invoice processingPayment tokens, billing addressesPCI-DSS Level 1 compliant
Law Enforcement AuthoritiesStatutory compliance pursuant to subpoenas, warrants, or CALEATransactional records or intercepted media strictly as orderedSubject to validation under our Law Enforcement Guidelines

Business & Enterprise Customer Data (Controller vs. Processor)

  • COMEXCEL as Data Controller: We act as a Controller for direct customer account records, administrative billing contacts, and commercial relationship data.
  • COMEXCEL as Data Processor: When hosting voice calls, SMS payloads, call recordings, voicemail files, and CRM records on behalf of enterprise subscribers, COMEXCEL acts strictly as a Data Processor. The subscribing organization remains the Data Controller responsible for lawful end-user notices and consent.

Healthcare (HIPAA/BAA) & Regulated Data

COMEXCEL supports Health Insurance Portability and Accountability Act (HIPAA) compliance for healthcare providers, medical clinics, and covered entities. We execute binding Business Associate Agreements (BAAs), implementing TLS/SRTP transmission encryption, role-based access restrictions, and administrative audit logging for protected health information (PHI). Review complete healthcare architectures in our HIPAA Compliance Statement.

Data Security & Cryptographic Standards

  • In-Transit Encryption: Voice signaling is protected via TLS 1.3 with Perfect Forward Secrecy, and live voice media streams are encrypted via SRTP with AES-256.
  • At-Rest Encryption: Stored call recordings, voicemails, AI transcripts, and multi-tenant databases are protected using AES-256 encryption managed via Hardware Security Modules (HSMs).
  • Infrastructure Redundancy: Tier-IV geo-redundant data center nodes engineered for 99.999% SLA availability and automated sub-second failover.
  • Identity Governance: Multi-factor authentication (MFA), role-based permissions (RBAC), and continuous administrative audit logging.
  • Explore complete architectural blueprints in our Security & Trust Center.
Architectural flowchart detailing TLS signaling, SRTP voice encryption, and AES-256 at-rest storage across Tier-IV data centers.

Data Retention & Deletion Schedules

Customer records, communications metadata, and media archives are retained only as long as necessary to satisfy service delivery, contractual agreements, and statutory record-keeping rules. Production databases are purged within 30 days of verified cancellation, and rotational backups overwrite within 30 to 60 days. Detailed retention windows and self-service mobile app deletion protocols are detailed in our Data Retention & Account Deletion Policy.

U.S. State Privacy Rights & California Notice

Residents of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA) hold statutory rights regarding their personal information:

Statutory Privacy RightOperational Scope & Execution
Right to Know & AccessRequest details regarding categories of personal data collected, stored, and subprocessed.
Right to Rectification & CorrectionCorrect inaccurate account profiles, billing details, or user directory assignments.
Right to Erasure & DeletionRequest permanent purging of personal data, subject to telecommunications CPNI, tax, and E911 statutory exceptions.
Right to Non-DiscriminationCOMEXCEL does not alter pricing, service quality, or platform SLAs if you exercise lawful privacy rights.
Zero Selling or SharingCOMEXCEL does not sell personal records or share data for cross-context behavioral advertising.

International Data & Cross-Border Transfers

COMEXCEL telecommunications infrastructure and primary switching facilities are situated within the United States. If accessing services internationally, personal data and communications telemetry are transferred to, stored, and processed securely in the United States under Standard Contractual Clauses (SCCs) and robust technical safeguards.

Security Incident Response & Breach Protocols

COMEXCEL maintains an active Computer Security Incident Response Plan (CSIRP). In the event of a verified security incident affecting customer records or CPNI, we will notify affected account administrators and appropriate regulatory authorities without unreasonable delay in accordance with federal and state data breach notification statutes.

Your Privacy Choices & Opt-Out Controls

  • Management Portal: Configure user permissions, update extension routing, and adjust call recording retention directly within the administrative console.
  • SMS Opt-Out: Reply STOP to any automated or business text message to immediately discontinue SMS communications.
  • Email Preferences: Manage marketing communications via the unsubscribe link in non-transactional emails.
  • Formal Data Requests: Submit verified statutory privacy requests directly to our privacy desk.

Policy Updates & Regulatory Contact

COMEXCEL periodically updates this policy to reflect platform updates and evolving regulatory frameworks. When material changes occur, we update the “Last Updated” date at the top of this document and notify administrators via portal alerts or email.

COMEXCEL Legal & Compliance Department

Frequently Asked Questions (FAQ)

Does COMEXCEL sell or share business CPNI or customer contact lists?

No. COMEXCEL strictly complies with FCC Customer Proprietary Network Information (CPNI) regulations and does not sell, rent, monetize, or disclose call detail records, messaging metadata, or customer lists to third-party advertisers or marketers.

How are voice call recordings, voicemails, and AI transcripts secured?

All stored media files, call recordings, voicemail audio, and speech-to-text transcripts are encrypted at rest using enterprise AES-256 encryption and protected in transit via TLS 1.3 cryptographic protocols with multi-factor authentication (MFA) access controls.

Does COMEXCEL use customer voice data or messaging content to train public AI models?

No. All conversational audio, transcription payloads, and automated call summaries processed by COMEXCEL AI tools are strictly siloed to your dedicated account and are never fed into public foundation models or shared across multi-tenant boundaries.

How does COMEXCEL handle SMS opt-in consent data under 10DLC rules?

In compliance with CTIA messaging guidelines and carrier 10DLC registries, mobile numbers, opt-in consent verification records, and SMS campaign data are never shared or transferred to third parties or affiliates for promotional purposes.

Is COMEXCEL compliant with HIPAA and SOC 2 data protection standards?

Yes. COMEXCEL provides technical architectures supporting HIPAA compliance for healthcare providers, executes formal Business Associate Agreements (BAAs), and maintains enterprise data center security safeguards.

What is the difference between COMEXCEL as a Data Controller and Data Processor?

COMEXCEL acts as a Data Controller for direct customer account logins, billing contacts, and commercial contracts. When hosting voice calls, SMS payloads, call recordings, and CRM data on behalf of enterprise subscribers, COMEXCEL acts strictly as a Data Processor.

How long are Call Detail Records (CDRs) and call recordings retained?

CDRs are retained in compliance with FCC telecommunications accounting and tax regulations. Voice recordings and voicemails are retained strictly according to the custom lifecycle schedules configured by your account administrator.

How can I exercise my privacy rights or request data deletion?

Authorized account administrators can manage or purge recordings, transcripts, and contact records directly inside the management portal, or submit a formal data request by contacting [email protected].

Have Questions About Your Telecommunications Privacy?

Whether you need to review our CPNI governance protocols, submit an enterprise data export or deletion request, or speak directly with our compliance team, we are here to help.