Legal
Privacy policy
Last updated JUN 10 2026
We collect the minimum needed to run support and identity operations for your company — we are a processor of your data, not a marketer. Additional information is set out in the B2B agreement we sign with you during onboarding.
01
What we collect
What we hold depends on which products you run. It falls into four buckets:
- Account data: names, work emails, roles, and billing details for the people who administer your workspace.
- Configuration: phone numbers, routing rules, connected systems, and the workflows you define.
- Marta: call audio when recording is enabled, transcripts, and caller metadata such as number, time, and duration.
- IdentityPilot: the directory and identity records of the systems you connect — names, titles, group memberships, and entitlements.
02
How we use it
Customer content is used to operate the products you have enabled, to keep them secure, and to help you when you ask us to. That is the whole list.
We never use customer content for advertising, and we never train foundation models on it. When our engineers look at your data to resolve a support request, the access is scoped to that request and logged.
03
Call recordings & transcripts
Calls are recorded only when you enable recording, and you enable it per line. Marta can play a disclosure prompt at the start of each call; giving callers legally sufficient notice remains your obligation under the laws that apply where they are.
Recordings and transcripts are retained for 90 days by default. You can shorten that, keep transcripts without audio, or set retention to zero so nothing is stored once the call ends.
04
Identity data
The directory and identity records IdentityPilot touches are processed under your documented instructions, as set out in our data processing agreement (DPA).
Identity data is synced only to the systems you connect. We do not enrich it, cross-reference it between customers, or share it with anyone.
05
Subprocessors
We use a small set of subprocessors to run the services: cloud hosting, a telephony carrier, and transactional email.
On our website we use PostHog (hosted in the EU) for product analytics, and session recording where you allow it, to understand how visitors use the site and improve it. These run only after you consent through our cookie banner, you can withdraw consent at any time from the cookie settings, and this data is never used for advertising or sold.
06
Retention & deletion
When you delete data, close a workspace, or your contract ends, we delete customer content within 30 days of the request or the end date, whichever comes first.
Encrypted backups roll off automatically within a further 35 days. We keep nothing beyond what the law requires us to, such as invoices.
07
Your rights
Under the GDPR, the CCPA, and similar laws you can request access to, correction of, deletion of, or a portable copy of your personal data. Send requests to privacy@jordantech-solutions.net and we will respond within the statutory window.
If you are in the EU or EEA and believe we have processed your data unlawfully, you may also lodge a complaint with your supervisory authority.
08
International transfers
Where customer data moves outside the region it was collected in, the transfer is governed by the European Commission's Standard Contractual Clauses, incorporated into our DPA.
09
Changes
We will post any changes to this policy here and update the date above. For material changes, we email workspace administrators at least 30 days before they take effect.
10
Contact
Privacy questions, data requests, and DPA paperwork all go to the same place.
Data protection inquiries — we reply within two business days.
privacy@jordantech-solutions.net