Privacy Policy
Applies to all services provided by Lux Telecom. If you have bought service from us, the version in force is the one published on the date of your order. Contact us with any question about this document.
This policy explains what personal data Lux Telecom handles, why, and for how long. It covers our website, the customer portal and the voice services we provide.
1. Who is responsible
Lux Telecom is the controller for the personal data described here. For anything in this policy, including a request to exercise your rights, contact us and mark your message for the attention of the data protection contact.
2. Data we handle
- Account and verification data — names and contact details of your staff, company registration and ownership information, identity documents where we are required to collect them, and payment instrument details.
- Call detail records (CDRs) — calling and called numbers, date, time, duration, routing and disposition of each call. CDRs are personal data in most jurisdictions, because a telephone number identifies a person. This is the least obvious and most sensitive category we handle, and it is treated accordingly.
- Technical data — SIP signalling and registration logs, IP addresses, and platform access logs.
- Billing data — invoices, payments, credits and disputes.
- Website data — pages requested, and the cookies described in section 8.
We do not record the content of calls, and we do not listen to or transcribe your traffic.
3. Why we handle it, and on what basis
- To perform the contract — provisioning numbers, routing calls, rating usage, invoicing, support.
- To comply with legal obligations — anti-money-laundering checks, tax and accounting records, lawful requests from a competent authority, and numbering and telecoms regulatory duties.
- For our legitimate interests — preventing fraud and abuse, protecting the platform, monitoring quality, and pursuing unpaid Charges. We balance these against your interests and use the least intrusive means that works.
- With consent — where consent is the correct basis, for example optional marketing. You can withdraw it at any time without affecting service.
4. How long we keep it
These are the periods we apply unless a longer period is required by law or a shorter one is possible:
- CDRs — 12 months for billing, dispute resolution and fraud investigation, then deleted or aggregated so individuals are no longer identifiable.
- Invoices and accounting records — the period required by the applicable tax law, which is commonly six or seven years.
- Verification and AML records — the statutory retention period following the end of the relationship.
- Technical and access logs — up to 12 months.
- Account contact data — for the life of the relationship and a reasonable period afterwards for legal claims.
5. Who we share it with
Delivering a call inherently discloses signalling data to other networks. We share personal data with upstream and terminating carriers and numbering providers to the extent needed to originate, route and terminate traffic and to investigate faults and fraud; with payment providers to take payment; with professional advisers, auditors and insurers; with regulators, law enforcement and courts where we are lawfully required; and with suppliers who process data on our behalf under written terms. We do not sell personal data.
6. International transfers
Voice traffic is international by nature, so data will be transferred to countries other than the one you are in. Where we transfer personal data out of a jurisdiction that restricts such transfers, we rely on an adequacy decision where one exists, or on standard contractual clauses with appropriate safeguards.
7. Your rights
Subject to the law that applies to you, you may ask for access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, and to object to processing based on legitimate interests. We will respond within the period the applicable law allows. Where we cannot comply — for example because a retention obligation overrides a deletion request — we will explain why. You can also complain to your data protection supervisory authority.
Note that where you are our business customer, personal data about your own end users is generally handled by you as controller and by us as processor on your instructions. Requests from your end users should be directed to you.
8. Cookies
We use cookies that are strictly necessary for the site and portal to work, including session and security cookies, and cookies that remember your cart. These do not require consent. Where we use any analytics or preference cookie that is not strictly necessary, it is set only with your consent and can be withdrawn.
9. Security
We apply access controls, encryption of data in transit, network segregation, logging and least-privilege administration. SIP credentials are treated as secrets. No system is perfectly secure; if a breach affects your data and the law requires notification, we will notify you and the relevant authority within the required timeframe.
10. Changes
We will update this policy when our processing changes and will tell you about material changes through the portal or by email.