PRIVACY POLICY

applicable from February 1, 2024

Introduction

Contacter PG TELECOM Spolka z o.o.:

PG TELECOM Spolka z o.o. Address: ul. Stefana Batorego 18/108, 02-591 Warsaw

Email: info@sipsim.com

Tel: +336 44 55 55 55

https://sipsim.com/

General Info

SipSim acts as a Data Controller when processing your Personal Data in the following scenarios

  1. If you utilize SipSim products and services that necessitate an account (referred to as an "OurCompany User"), we process some of your Personal Data as a Data Controller in specific situations outlined below. An OurCompany User is typically a representative or employee of an OurCompany Customer or a prospective customer (a company in the process of becoming an OurCompany Customer) who acts on behalf of our customer. If you are an OurCompany User, Sections 1 and 5-12 pertain to SipSim handling of your Personal Data. Additionally, SipSim may process your Personal Data for other purposes as a Data Processor. For more information on such processing and to exercise your rights related to Personal Data Processing, please contact the corresponding OurCompany Customer.
  2. If you visit our website without logging into your SipSim account, and you are also an OurCompany User, Sections 2 and 5-12 apply to the processing of your Personal Data by SipSim.
  3. If you express interest in SipSim products or services and/or agree to be included in our marketing database (referred to as a "Lead"), Sections 3 and 5-12 apply to SipSim handling of your Personal Data.
  4. If you initiate contact with SipSim or have been contacted by our go-to-market teams, including our support, sales, or customer success agents (referred to as an "OurCompany Contact"), and you may have contacted us via phone through one of our customer support lines. If you are also a Lead or an OurCompany User, Sections 4 and 5-12 govern SipSim processing of your Personal Data.

SipSim is a worldwide service provider, and as such, we gather Personal Data from individuals across the globe in various locations. Consequently, different privacy and personal data protection laws are applicable to SipSim use of your Personal Data. SipSim is committed to upholding the highest standards in safeguarding your personal data while also respecting the variations in local regulations. This Privacy Policy is applicable to SipSim handling of Personal Data on a global scale.

Unless expressly stated otherwise in this document, all terms beginning with a capital letter shall have the definitions provided in SipSim Terms of Use.

1. Personal Data processing

The entity within SipSim that acts as the Data Controller for SipSim User's Personal Data is the specific SipSim entity that is the contracting party with the Customer associated with your SipSim account.

The table provided below outlines the various purposes for which your Personal Data may be processed when you are an SipSim User, with SipSim serving as the Data Controller. It also includes information on the different categories of data, the legal basis for processing, the recipients' categories, and details regarding the retention period for each specific processing purpose. Additionally, aside from the purposes mentioned below, Sipsim may also process personal data as required by relevant legal obligations.

Purpose and included processing activities

In the context of ensuring the satisfaction of our valued customers, we engage in the following activities:

  1. Analytics of User Behavior within SipSim Product: We analyze user behavior within SipSim product to gain insights and improve the overall user experience. This analysis helps us identify areas where we can enhance the functionality and usability of our services.
  2. Manual Analysis of Customer Usage of SipSim Product: Our speciallists conduct in-depth manual analysis of how customers utilize SipSim product. This personalized approach allows us to better understand individual customer needs and tailor our services accordingly.
  3. Communication with Customers by SipSim representatives: Our service and sales managers engage in direct communication with customers. This ensures that we address their specific requirements, answer any queries they may have, and offer guidance to maximize the benefits of using SipSim product.

These practices are fundamental to our commitment to delivering exceptional customer experiences and continuously improving the value we provide to our users.

Categories of Personal Data:

  • Customer account data
  • Customer financial/payment data
  • Information about the user
  • Customer contact data (from contact list)
  • Additional call-related data (notes, tags, insight cards)

Legal Basis:

  • The processing of this data is deemed necessary for the legitimate interests pursued by SipSim. This includes providing SipSim services to Customers, enhancing the user experience, and continually improving, developing, and administering SipSim products and services.

Categories of Recipients:

  • Hosting provider
  • Providers of infrastructure services
  • CRM providers
  • Telecommunication carriers and operators

Retention Period:

  • Data is retained for the duration of the Customer relationship.

Processing Customer Requests and Coordinating User Inquiries

At SipSim, we take customer service seriously, and as part of our commitment to providing outstanding support, we engage in the following activities:

  1. Handling Customer Requests: We diligently process and address customer requests, ensuring that we meet their needs promptly and efficiently.
  2. Coordinating User Inquiries: We coordinate and manage inquiries submitted by both Customers and SipSim Users through our Customer Support Portal on the SipSim website. This involves tracking, organizing, and prioritizing inquiries to provide timely responses and resolutions.

Our goal is to provide responsive and effective support, ensuring that our customers and users receive the assistance they need when using our services.

Categories of Personal Data:

  • Customer account data
  • Customer financial/payment data
  • Information about the user
  • Customer contact data (from contact list)
  • Call/SMS metadata
  • Additional call-related data (notes, tags, insight cards)

Legal Basis:

  • The processing of this data is deemed necessary for the legitimate interests pursued by SipSim. This includes providing SipSim services to Customers, enhancing the user experience, and continually improving, developing, and administering SipSim products and services.

Categories of Recipients:

  • Hosting provider
  • Providers of ticketing solutions
  • Providers of CRM systems

Retention Period:

  • Data is retained for a maximum of up to 3 years following the request.

Ensuring Security and Integrity of OurCompany Systems and Infrastructure

At SipSim, safeguarding the security and integrity of our systems and infrastructure is a top priority. To achieve this, we engage in the following activities:

  1. Analysis of Registration, Usage, Access, and Metrics: We conduct detailed analysis of various aspects, including user registration, system usage, access patterns, and other metrics across SipSim systems. This proactive approach helps us identify trends and potential vulnerabilities.
  2. Detection of Suspicious Activity: Our vigilant monitoring allows us to detect any suspicious activity that may indicate fraudulent use of our services or account takeover. Examples of such activity include repetitive use of information for registration, unusual outbound call destinations, or a sudden increase in account activity.
  3. Implementation of Security Measures: Based on our analysis and the identification of suspicious activity, we promptly implement both proactive and reactive security measures. These measures are designed to protect our systems, infrastructure, and user accounts from potential threats.

By actively monitoring and responding to security-related events, we ensure that our customers and users can confidently rely on the security and reliability of SipSim services.

Categories of Personal Data:

  • Customer account data
  • Information about the user
  • Customer contact data (from contact list)
  • Call/SMS metadata
  • Additional call-related data (notes, tags, insight cards)

Legal Basis:

  • The processing of this data is deemed necessary for the legitimate interests pursued by SipSim. These interests include securely providing SipSimServices as contracted between SipSim and its Customers, ensuring lawful use, and preventing fraudulent activities on the SipSim platform.

Categories of Recipients:

  • Hosting provider
  • Providers of infrastructure services
  • Fraud detection tool provider

Retention Period:

  • Data is retained for the duration of the Customer relationship.

Invoicing

As part of our standard business operations, we engage in the following activity:

Preparation of Invoices based on Customer's Usage of the SipSim Product:

To ensure transparent and accurate billing, we prepare invoices that reflect our customers' usage of the SipSim product. These invoices are generated based on the services rendered and the usage data collected, allowing us to maintain a clear record of charges in line with our contractual agreements.

Our commitment to accurate invoicing helps establish trust and transparency in our billing processes, ensuring that our customers are billed correctly for the services they have utilized.

Categories of Personal Data:

  • Customer account data
  • Call/SMS metadata

Legal Basis:

  • The processing of this data is considered necessary for the legitimate interests pursued by SipSim. These interests include the ability to bill SipSim Services accurately based on the usage of SipSim services, as stipulated in the contract between SipSim and the Customer.

Categories of Recipients:

  • Providers of billing management tools

Retention Period:

  • Data is retained for a maximum of up to 3 month following the completion of the SipSim communication services.

Cash Collection and Billing Administration

In our commitment to efficient financial operations, we engage in the following activities:

Administration of Billing and Cash Collection:

We oversee the entire billing process and cash collection to ensure the smooth financial operation of our services. This includes:

  1. Handling Customer Requests: Our team is available to assist customers with any inquiries or requests related to payments, invoices, or any other billing-related matters. We aim to provide timely and helpful responses to ensure a seamless billing experience.
  2. Invoice Management: We manage the issuance of invoices, ensuring that they accurately reflect the charges for the services provided.
  3. Cash Collection: We facilitate the collection of payments from customers, making sure that transactions are processed efficiently and securely.

Our dedication to efficient cash collection and billing administration contributes to a streamlined financial process, benefiting both our customers and SipSim.

Categories of Personal Data:

  • Customer account data
  • Customer financial/payment data

Legal Basis:

  • The processing of this data is deemed necessary for the legitimate interests pursued by SipSim. These interests include the ability to claim payment for outstanding invoices as per the terms and agreements between SipSIm and the Customer.

Categories of Recipients:

  • Providers of billing management tools
  • Providers of payment solutions

Retention Period:

  • Data is retained for a maximum of up to 6 months following the issuance of the invoice to the customer.

Protection of SipSim Rights and Interests

In our commitment to safeguarding our legal rights and interests, we engage in the following activities:

Personal Data Storage for Potential Disputes, Claims, Questions, or Disagreements:

To ensure the protection of SipSim rights and interests, we may retain personal data in anticipation of potential disputes, claims, questions, or disagreements. This data may be used if and when such situations arise, including but not limited to legal proceedings or resolution of contractual matters.

Our proactive approach in storing relevant personal data allows us to maintain a comprehensive record that can be utilized, if necessary, to address disputes or claims and ensure a fair and lawful resolution.

Categories of Personal Data:

  • Customer account data
  • Information about the user
  • Additional call-related data (notes, tags, insight cards)
  • Call/SMS/MMS/Mobile data metadata

Legal Basis:

  • The processing of this data is considered necessary for the legitimate interests pursued by SipSim. These interests include the ability to initiate or respond to claims and questions that may arise in the context of the Customer relationship.

Categories of Recipients:

  • None

Retention Period:

  • Data is retained for a maximum of up to 1 year following the termination of the Customer relationship.

Ensuring SipSim Compliance and Responding to Law Enforcement Requests under Applicable Telecommunications Laws

As a telecommunications service provider, SipSim is bound by the laws of specific countries to fulfill the following obligations:

  1. Collection and Storage of Identity Verification Data: We are required to collect information for the purpose of verifying the identity of the customer when provisioning phone numbers and to retain such data for a specified duration.
  2. Disclosure to Law Enforcement Authorities: In response to a binding request, which may include information requests or lawful interception requests, we may be obligated to disclose data to law enforcement authorities.

To fulfill these legal obligations, we collect and store the necessary data for the prescribed period. During our service tenure, we utilize a validation stamp generated from previously provided information to facilitate the provisioning of additional phone numbers within the same geographic location.

Categories of Personal Data:

  • Call/SMS/MMS/Mobile Data metadata
  • Customer account data
  • Customer-provided documentation
  • Customer identity verification data

Legal Basis:

  • The processing of this data is necessary to comply with legal obligations imposed on SipSim. Additionally, it is deemed necessary for the legitimate interests pursued by SipSim to simplify the number provisioning process for customers and ensure the efficient provision of our services.

Categories of Recipients:

  • None

Retention Period:

  • Data is retained as required by applicable law, with retention periods ranging from 1 to 6 years.

2. Processing of Site Visitor's Personal Data

If you visit our website as a Site Visitor, we process your Personal Data in the form of cookies and similar online identifiers, collectively referred to as "cookies."

It's important to note that the information provided in this section pertains solely to SipSim use of cookies on the website. If you are an SipSim User and access SipSim Services through a web browser while signed in to your Sipsim User account, please refer to Section 1 of this Privacy Policy (Processing of SipSim User's Personal Data), as the cookie usage described in Section 2 does not apply in that context.

Data Controller of Site Visitor's Cookies: The entity responsible for managing Site Visitor's cookies is SipSim.

About Cookies: Cookies are alphanumeric identifiers or trackers that are transmitted to the device you use to access our services via your web browser. They serve various purposes, including making websites function correctly or more efficiently, providing additional features for an enhanced user experience, and offering valuable information to site owners.

Types of Cookies Used by OurCompany and Their Functions:

  1. Strictly Necessary (Technical) Cookies: These cookies are essential for the proper operation of our website. Without them, the website would not function as intended.
  2. Statistics Cookies: These cookies gather information about your website usage, such as the pages you visited and the links you clicked on. They help us understand how our website is used and improve its content and functionality.
  3. Marketing Cookies: Marketing cookies track your online activity to assist advertisers in delivering more relevant advertisements or limiting the frequency of ad displays.

Your Consent and Cookie Choices: Please note that you have the option to manage your cookie preferences when visiting our website. You can choose to accept or reject certain types of cookies.

At SipSim, we value your privacy and strive to provide transparency about our use of cookies to enhance your online experience.

3. Processing of Lead's Personal Data For Sales and Marketing Purposes

When it comes to the processing of your Personal Data as a Lead for our sales and marketing activities, please note the following key details:

Data Controllers: The Data Controllers for these activities is SIPSIM Limited liability company (SIPSIM, LLC).

Data Collection: We collect your contact details for our database from various sources, including SipSim internal customer database, forms on the SipSim.com, SipSim.fr web sites, social networks (such as LinkedIn, Facebook), campaigns co-organized by SipSim and its partners, and data-enrichment tools and providers (subject to compliance with applicable laws).

Opting Out: If you wish to stop receiving marketing emails from us, you can use the "Unsubscribe" link provided in every marketing email. Please allow up to 3 working days for processing your "Unsubscribe" request. For phone calls related to our outbound sales development activities, you can inform our representative that you no longer wish to be contacted in this manner.

Personal Data Used: As a Lead, we may process some or all of the following Personal Data, depending on your specific circumstances: name, email, phone number, company and job title, region/country, and/or IP address. We may also use certain data related to your company, such as company size, CRM, and whether you or your company is a SipSim Customer.

Purposes of Processing and Legal Basis:The table below outlines the different purposes for which your Personal Data as a Lead may be processed by SipSim, the legal basis for the processing, categories of recipients, and retention periods for each specific processing purpose.

At SipSim, we value your privacy and provide options for you to control your contact preferences to ensure you receive the information that matters most to you.

Conducting Email Marketing Campaigns for Brand Awareness

As part of our efforts to promote brand awareness and keep you informed about our products and services, we conduct email marketing campaigns. These campaigns encompass a range of promotional content related to the SipSim product and services, including new features, integration partnerships, surveys, event invitations, and content such as guides or e-books.

Email Marketing Content: Our email marketing content may include:

  • Promotions related to SipSim products and services, including updates and new features.
  • Requests to complete surveys or questionnaires to gather valuable feedback.
  • Invitations to events, such as webinars hosted by SipSim or in which SipSim participates.
  • Promotion of content created by SipSim, either exclusively or in collaboration with our partners, such as guides and e-books.

Digital Marketing Approach: Our digital marketing efforts utilize internet and online-based digital technologies, encompassing various devices like desktop computers and mobile phones, as well as other digital media and platforms to effectively promote SipSim products and services.

At SipSim , we respect your preferences and ensure that you have the option to control your participation in our email marketing campaigns. Your privacy and preferences are important to us, and we aim to provide you with valuable and relevant information.

Legal Basis:

  • If you are an EU resident and an SipSim Customer, we rely on our legitimate interest to contact you within our email marketing campaigns. We believe that, as a Customer, you benefit from staying informed about news related to our product and services.
  • If you are not an SipSim customer, we typically rely on your consent, as required by applicable law (such as the ePrivacy Directive and derived national laws). Therefore, we only contact you via email if you have given us explicit consent (opt-in).

Categories of Recipients:

  • E-mail automatisation suppliers
  • CRM partners

Retention Period:

  • If you are not SipSIm customer, we retain your consent-based data for 3 years after you provide your consent.
  • If you are or were a SipSim customer, we retain your data for 1 year following the termination of the customer relationship.

Outbound Sales

In our pursuit of connecting with companies whose needs align with SipSim products and services, we may engage in outbound sales development activities. This can involve our outbound sales representatives reaching out to you via email and/or phone to introduce and discuss our offerings in relation to your company's requirements.

At SipSim, we approach outbound sales development with the intention of providing valuable solutions that cater to your company's specific needs. We value your privacy and aim to establish meaningful connections based on the potential benefits our products and services can offer your organization.

Legal Basis:

  • Our engagement in outbound sales development activities is based on our legitimate interest. These activities encompass a form of direct marketing where we carefully evaluate the potential benefits of SipSim products and services for your company. We believe that your company could derive value from our communication.

Categories of Recipients:

  • Please refer to Section 5 in our policy for information about other recipients.

Retention Period:

  • If you consent to our outreach, we will retain your data for a maximum of 3 years following the date you provide us with your consent.

Targeting Our Products, Services, and Marketing Activities

To continually enhance our ability to meet your needs, we conduct internal data analysis. This analysis provides us with comprehensive, aggregate statistics about our Customers and Leads, as well as valuable insights into the market. This enables us to better tailor our communication and align our products and services with your specific requirements.

At SipSim, we are committed to delivering products and services that cater to your specific requirements. Our internal data analysis empowers us to better understand and address your needs, ultimately ensuring that you receive the most valuable and relevant information from us.

Legal Basis:

  • Our engagement in internal data analysis is rooted in our legitimate interest. We strongly believe that by improving our ability to target our communication and align our products and services with your needs, you will ultimately derive even greater benefit from them.

Categories of Recipients:

  • In this context, your Personal Data is not shared with any third-party recipients.

Retention Period:

  • We retain your data for this purpose for as long as we process your Personal Data for conducting email marketing campaigns for the promotion of brand awareness or outbound sales development.

4. Processing SipSim Contact's Personal Data: Enhancing Our Product and Performance

Purpose: The table provided below outlines the specific objectives for which we may process your Personal Data as an SipSim Contact, along with the legal basis for this processing, the types of recipients involved, and the duration for which we retain your Personal Data for each purpose.

Enhancing Our Product and Performance

To continually enhance the performance of our product at SipSim, we engage in the analysis of product performance, particularly in the context of your interactions with our agents. This process involves activities such as testing new features, troubleshooting, identifying and rectifying bugs, as well as exploring and implementing methods to enhance overall performance. Some of these activities may also incorporate machine learning and the optimization of artificial intelligence technologies.

At SipSim, we are dedicated to delivering an exceptional product experience to all our users. Our commitment to product enhancement is aimed at ensuring that everyone who engages with the SipSim product benefits from continuous improvements and the introduction of new features.

Categories of Personal Data:

  • Contact data of the SipSim Contact
  • Content of communication exchanged between SipSim and the SipSim Contact

Legal Basis:

  • This data processing is rooted in our legitimate interests. We firmly believe that all individuals interested in the SipSim product ultimately benefit from ongoing improvements in its performance, including the introduction of new features.

Categories of Recipients:

  • No specific recipient categories are applicable in this context.

Retention Period:

  • We retain this data for a maximum of 1 year following the date of communication.

5. Other Recipients of Collected Personal Data

The Personal Data we collect is accessible to specific parties in accordance with the following guidelines:

  1. Our Personnel: Authorized individuals within our organization who require access to Personal Data for legitimate business purposes.
  2. Control Services: External auditors or other services responsible for regulatory compliance and data protection oversight.
  3. Recipient Subcontractors: Subcontractors who are involved in providing services or support related to our operations.

Additionally, please be aware that Personal Data may be disclosed in response to lawful requests from government agencies or public authorities. This can include requests from public officers or debt collection organizations, and such disclosure may be necessary to satisfy national security, law enforcement, or other legal requirements.

It's important to note that depending on your location, we may be obligated to adhere to local regulations and requirements. In some cases, using a local phone number may necessitate the verification of a customer's identity and the collection and storage of specific user details, such as first and last names and addresses. This procedure may be triggered in response to official requests from competent local authorities.

At SipSim, we are committed to compliance with applicable regulations and the responsible handling of Personal Data, ensuring that it is disclosed only as required by law and in line with relevant legal and security requirements.

6. Retention of Personal Data

At SipSIm, we adhere to the following principles when it comes to the retention of Personal Data:

  1. We retain Personal Data for as long as we have a valid legal basis to do so. Once that legal basis ceases to exist, we take the necessary steps to either delete the data, aggregate it, or, if deletion is not immediately feasible (e.g., due to data stored in backup archives), securely isolate it from any further processing until deletion becomes possible.
  2. In some cases, we may retain Personal Data to fulfill our legal or regulatory obligations. However, once these obligations are no longer in effect or have been lifted, we promptly remove the Personal Data from our systems and records, as well as those of our subcontractors if applicable. Alternatively, we may archive or anonymize the data to ensure that it can no longer be identified.

Our commitment is to ensure the responsible and compliant management of Personal Data, aligning our data retention practices with legal requirements and best practices in data protection.

7. European Personal Data Transfers

At SipSim we understand the importance of safeguarding the transfer of Personal Data to countries located outside the European Economic Area, Switzerland, or the United Kingdom (referred to collectively as "Europe"). Such transfers can also involve the processing of Personal Data by individuals located outside Europe who are employed by us or by our trusted service providers, acting as Data Processors.

To ensure the secure and compliant transfer of Personal Data outside Europe, we have implemented appropriate safeguards in accordance with relevant regulations, notably the General Data Protection Regulation (GDPR). We place a strong emphasis on ensuring that importers of Personal Data adhere to the GDPR's security requirements.

Our approach to such transfers involves the execution of suitable contractual arrangements, including the use of standard contractual clauses approved by the Commission of the European Union. Additionally, we may implement further measures as required, following a comprehensive assessment, in accordance with the European Data Protection Board’s (EDPB) Recommendation no. 1/2020.

Furthermore, SipSim remains vigilant in monitoring legislative developments and staying up-to-date with the latest guidance related to the transfer of Personal Data outside Europe. We are committed to cooperating with EU data protection authorities (DPAs) and adhering to the advice provided by these authorities.

Our dedication to data protection and compliance ensures that the transfer of Personal Data outside Europe is carried out with the utmost care and in accordance with applicable regulations and best practices. Your trust in our commitment to data security is of paramount importance to us.

8. Web-site links

Our Site and Services may feature links to websites belonging to our partners, advertisers, and affiliates. If you choose to click on a link that directs you to any of these external websites, please be aware that these companies maintain their own privacy policies. It's important to note that SipSim bears no responsibility or liability for how these third parties handle Personal Data. We strongly advise that you review the privacy policies of these websites before visiting them.

Your privacy and data security are our priorities. We encourage you to exercise caution and due diligence when navigating external websites, ensuring that your data is handled in a manner consistent with your expectations and preferences.

9. Security

At SipSim, we are dedicated to implementing a comprehensive set of precautions, organizational measures, and advanced technical safeguards. Our objective is to ensure the security, integrity, and confidentiality of Personal Data. We prioritize measures to prevent any unauthorized modification or damage to this data and to thwart access by unauthorized third parties.

For instance, we place strong emphasis on security for our employees' accounts, including the use of robust passwords. Additionally, all our staff members are bound by strict confidentiality obligations. We employ encryption for all data, both during transit and while it's at rest.

We recognize the critical importance of your trust, and we remain unwavering in our commitment to upholding the highest standards of data security and preserving your privacy.

10. Your Rights and Choices

When SipSim processes your Personal Data as a Data Controller, you have the following rights:

  1. Access and Copy: You have the right to access and obtain a copy of the Personal Data we process.
  2. Rectification: You can request the rectification of inaccuracies or outdated information in your Personal Data, as well as the addition of missing details.
  3. Objection: You may object to the processing of Personal Data that relies on legitimate interests.
  4. Erasure and Right to Be Forgotten: You have the right to request the erasure of your Personal Data, also known as the right to be forgotten.
  5. Consent Withdrawal: You can withdraw your consent at any time for processing that is solely based on your consent.
  6. Portability: You have the right to move, copy, or transmit your Personal Data.
  7. Restriction: You can request the restriction or limitation of the processing of your Personal Data.
  8. Guidelines for Posthumous Data Use: You have the ability to set guidelines for the use of your Personal Data after your passing.

11. Amendments

SipSim reserves the right to make amendments to the terms of this Privacy Policy periodically. If you do not agree with the updated version of the Privacy Policy, we recommend discontinuing your use of the Services or, as applicable, refraining from visiting our website. All revised terms will automatically take effect on the day when a new Privacy Policy is published on the Site.

In cases where we introduce new consent-based processing of Personal Data, we will ensure to obtain your consent before processing such Personal Data. This may involve, for instance, the inclusion of a checkbox for you to select, indicating your consent.