Data Controller
SIPSTACK Inc. acts as the data controller for personal data we collect from customers and users of our services. As a data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring such processing complies with the General Data Protection Regulation (GDPR).
Our principal place of business is in Canada (Toronto, Ontario). We serve customers worldwide including in the European Economic Area (EEA), United Kingdom, and Switzerland. We are committed to protecting the privacy and rights of all individuals regardless of location.
For customers in the EEA and UK, we have appointed a Data Protection Officer (DPO) who oversees our GDPR compliance efforts and serves as the point of contact for data protection authorities and individuals exercising their rights under GDPR.
We process personal data only for specified, explicit, and legitimate purposes. We collect only the data necessary to provide our services and do not process data in ways that are incompatible with the original purposes for which it was collected.
Legal Basis for Processing
We process personal data under several legal bases depending on the context and nature of processing:
Performance of Contract (Article 6(1)(b)): We process your personal data to provide the telecommunications and AI services you have contracted for. This includes account management, billing, service delivery, technical support, and all activities necessary to fulfill our contractual obligations.
Legitimate Interests (Article 6(1)(f)): We may process data based on our legitimate business interests, such as fraud prevention, network security, service improvement, and internal business operations. We conduct legitimate interests assessments to ensure such processing does not override your fundamental rights and freedoms.
Legal Obligations (Article 6(1)(c)): We process certain data to comply with legal requirements including telecommunications regulations (CRTC, FCC where applicable), tax laws, law enforcement requests, and data retention requirements mandated by applicable laws.
Consent (Article 6(1)(a)): For certain processing activities such as marketing communications, analytics cookies, and optional AI improvement features, we rely on your explicit consent. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
Vital Interests (Article 6(1)(d)): In emergency situations involving E911 services, we may process location and contact data to protect the vital interests of a person.
Our Products and Data Processing
The following table sets out the personal data processed by each SIPSTACK product, its legal basis under GDPR, and the categories of data involved.
Nova PBX
| Processing Activity | Personal Data | Legal Basis | |---|---|---| | SIP registration and call routing | SIP credentials, IP address, user-agent, device MAC | Contract | | Call recordings (where enabled) | Voice audio, caller/callee identity | Contract + Consent (recording notice) | | Voicemail storage | Voice audio, caller identity, timestamps | Contract | | AI transcription (all tiers) | Voice audio, transcript text | Contract | | Sentiment analysis (Nova Ultra; Enterprise where enabled) | Transcript text, sentiment scores | Contract | | Call summarization/diarization (Nova Ultra; Enterprise where enabled) | Transcript text, speaker segments, summaries | Contract | | Call Detail Records | Numbers, duration, timestamps, direction | Contract + Legal obligation | | Feature configuration | Extension numbers, IVR menus, routing rules | Contract |
Retention: Call recordings and voicemail: Nova Core 30 days, Nova Pro 180 days, Nova Ultra 365 days (auto-purged). CDRs: active subscription + 12 months post-cancellation. AI data (Nova Ultra; Enterprise where enabled): 180 days.
Flare SMS
| Processing Activity | Personal Data | Legal Basis | |---|---|---| | Contact management | Names, phone numbers, custom fields | Contract | | Message delivery and logging | Phone numbers, message content, timestamps | Contract | | Campaign delivery | Contact lists, message content, delivery status | Contract | | Opt-out suppression | Phone numbers, opt-out timestamps | Legal obligation (TCPA/CASL) | | Webhook delivery | Endpoint URLs, message payloads | Contract |
Aura AI
| Processing Activity | Personal Data | Legal Basis | |---|---|---| | Real-time voice processing (ASR) | Voice audio (processed in-memory, not retained unless recording enabled) | Contract | | LLM response generation | Conversation context | Contract | | Text-to-speech output | Generated audio (session only) | Contract |
Note: Aura AI audio is processed by self-hosted models on SIPSTACK Canadian infrastructure. Audio is not retained beyond the call session unless call recording is independently enabled.
SARA AI
| Processing Activity | Personal Data | Legal Basis | |---|---|---| | Inbound email processing | Email content, sender identity, message history | Contract | | SMS auto-reply processing | SMS message content, sender phone number, conversation history | Contract | | RAG embedding generation | Email and SMS content, support knowledge base | Contract | | LLM response drafting | Support email, portal chat and SMS content + RAG context (via Together AI, US) | Contract | | Conversation history | Email threads, SMS conversations, generated responses | Contract | | Knowledge base learning | Generalized Q&A from resolved tickets (PII stripped, human-reviewed) | Legitimate interests (Art. 6(1)(f)) — RAG improvement; enterprise opt-out available |
Important: SARA text inference — support email, portal chat and SMS — is routed to Together AI (United States) for LLM processing; Together AI is the primary language model for those surfaces. Only the Aura AI voice agent runs on a self-hosted model. We intend to replace this with self-hosted GPU infrastructure and have not committed to a date. Together AI does not retain data for model training per our data processing agreement. See the Sub-Processor List below.
Pulse (Mobile)
| Processing Activity | Personal Data | Legal Basis | |---|---|---| | Authentication | JWT tokens (stored in device secure storage) | Contract | | VoIP session management | WebRTC session data, SIP credentials (encrypted) | Contract | | Push notifications | Device push tokens | Contract + Consent |
Switchboard
| Processing Activity | Personal Data | Legal Basis | |---|---|---| | Account management | User profiles, email addresses, roles | Contract | | Session management | Session tokens, login timestamps | Contract | | Audit logging | User actions, timestamps, IP addresses | Legitimate interests + Legal obligation | | Billing | Payment method tokens (via Stripe), invoice history | Contract + Legal obligation |
Sub-Processor List
SIPSTACK uses the following sub-processors to deliver our services. All sub-processors are bound by data processing agreements requiring GDPR-compliant protections.
Canada has received an EU adequacy decision, meaning transfers to SIPSTACK's Canadian infrastructure do not require additional safeguards.
| Sub-Processor | Location | Purpose | Data Shared | Transfer Mechanism | |---|---|---|---|---| | Together AI | United States | Primary LLM inference for SARA AI text responses (support email, portal chat, SMS) | Message content, RAG context | Standard Contractual Clauses (SCCs) | | Stripe | United States | Payment processing | Billing information, payment method tokens | SCCs + Stripe DPA | | Bandwidth | United States | Voice/SMS carrier | Phone numbers, message content, voice routing metadata | SCCs | | Wasabi Technologies | Canada (ca-central-1) / United States (us-east-1) | Object storage (recordings, voicemail, media) | Call recordings, voicemail, media files | Adequacy decision (CA) / SCCs (US) | | Cloudflare | Global (CDN nodes) | CDN, DDoS protection, DNS | Web traffic, IP addresses | SCCs | | Sentry | United States | Error monitoring and crash reporting | Error messages, stack traces, session context | SCCs | | HyperDX | United States | Application logging and observability | Application and server access logs, error diagnostics, request/response metadata, IP addresses | SCCs | | AWS Polly | United States | Text-to-Speech (optional feature) | Text content submitted for synthesis | SCCs | | Google Cloud TTS | United States | Text-to-Speech (optional feature) | Text content submitted for synthesis | SCCs | | Expo / EAS | United States | Mobile app build and distribution | Build artifacts, app metadata | SCCs |
Self-hosted infrastructure (no transfer): The following AI/ML systems run entirely on SIPSTACK-owned servers in Canada and involve no third-party data transfer:
- Parakeet-TDT-CTC-1.1B — Real-time ASR
- WhisperX large-v3 — Post-call transcription and diarization
- Kokoro / Fish Speech — Text-to-Speech
- Ollama / vLLM — LLM inference for the Aura AI voice agent
- pgvector — RAG embeddings
- GLiNER / spaCy / BERTopic — NLP classification and topic modeling
Data Subject Rights
Under GDPR, you have the following rights regarding your personal data:
Right of Access (Article 15): You can request confirmation of whether we process your personal data and obtain a copy. We will provide this in a structured, commonly used, and machine-readable format within 30 days.
Right to Rectification (Article 16): If your personal data is inaccurate or incomplete, you have the right to request correction. We will update your data promptly.
Right to Erasure — "Right to be Forgotten" (Article 17): You can request deletion of your personal data when it is no longer necessary, when you withdraw consent, or when processing is unlawful. This right is subject to legal retention obligations (e.g., billing records, audit logs).
Right to Restriction (Article 18): You may request that we restrict processing in certain circumstances, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
Right to Object (Article 21): You can object to processing based on legitimate interests or for direct marketing purposes. We will stop such processing unless we demonstrate compelling legitimate grounds.
Rights Related to Automated Decision-Making (Article 22): You have the right not to be subject to decisions based solely on automated processing that produce significant legal or similar effects, unless such processing is necessary for a contract or you have provided explicit consent.
Self-Serve Rights Exercise
Many GDPR rights can be exercised directly through your Switchboard account without contacting the DPO:
Data Export (Right of Access + Portability)
Navigate to: Switchboard → Account → Privacy → Request Data Export
Your export ZIP includes: organization profile, provisioned phone numbers, PBX configuration, contacts and message logs, call detail records (12 months), voicemail and media files, and invoice history. One export is permitted per organization per 24-hour period. Download links are valid for 7 days.
Data Deletion Requests (Right to Erasure)
Navigate to: Switchboard → Account → Privacy → Request Data Deletion
Available deletion scopes:
- PBX configuration (extensions, IVR menus, ring groups, queues)
- Messages and campaign data
- Call recordings and voicemail
- AI voice processing data (Enterprise tier)
Billing records, CDRs required for legal compliance, and audit logs cannot be deleted self-serve — submit a formal request to [email protected] for review.
Account Cancellation
Self-serve cancellation via Switchboard → Account → Billing → Cancel Subscription initiates a 30-day data retrieval period. After 30 days, call recordings, voicemail and other stored media are deleted. Records we are required to retain — billing and payment records, call detail records, and audit trails — are kept for their statutory periods with direct identifiers removed or replaced; that process is pseudonymization, and the pseudonymized records remain personal data. Backup and disaster-recovery archives rotate on their own schedule, so a copy may persist for a limited period after deletion from the live system.
Cookie Preferences
Update consent preferences at any time via the Cookie Settings link in the website footer. We implement Consent Mode v2 with all non-essential cookies denied by default.
Marketing Opt-Out
Use the one-click unsubscribe link in any marketing email (List-Unsubscribe header). For SMS, reply STOP to any message — automatic suppression list enforcement prevents future sends.
For rights requests that cannot be fulfilled self-serve, contact [email protected]. We respond within 30 days (extendable to 60 days for complex requests, with notice).
Data Protection Impact Assessments
SIPSTACK conducts DPIAs for processing activities that pose elevated risks to the rights and freedoms of individuals. Completed assessments include:
Aura AI Voice Processing: Assessed real-time ASR and LLM response generation for inbound/outbound voice calls. Key findings: audio not retained beyond session; self-hosted infrastructure; no third-party data transfer. Risk classification: low-medium.
SARA AI Text Processing (Together AI): Assessed routing of SARA message content to Together AI (US) for LLM inference. Key findings: Together AI is the primary language model for SARA text responses across support email, portal chat, and SMS; content sent is the inbound message plus the RAG retrieval context. Risk classification: medium-high. Mitigations relied upon: SCCs, the provider's no-training commitment, and a roadmap to eliminate the transfer by moving inference to self-hosted GPU infrastructure (no committed date).
Call Recording and AI Analysis: Assessed Nova PBX recording, transcription, sentiment, and summarization pipeline. Key findings: tier-based retention with enforced auto-purge; customer-configurable recording announcements; recordings stored in regionally appropriate Wasabi S3. Risk classification: medium.
New DPIAs are conducted for any material change to processing activities involving sensitive personal data or new technologies.
Data Processing
We process personal data in accordance with GDPR principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
All personal data processing activities are documented in our Records of Processing Activities (RoPA), which includes the purposes of processing, categories of data subjects, types of personal data, recipients of data, international transfers, retention periods, and security measures.
Our employees and contractors who have access to personal data are subject to confidentiality obligations and receive training on data protection principles and GDPR requirements. Access to personal data is granted on a need-to-know basis.
International Transfers
When we transfer personal data from the EEA, UK, or Switzerland to countries outside those jurisdictions, we ensure appropriate safeguards are in place:
Canada — Adequacy Decision: Canada has received an EU adequacy decision under GDPR. Transfers to SIPSTACK's Canadian infrastructure (primary data center, self-hosted AI/ML, Wasabi ca-central-1 for CAD organizations) require no additional safeguards.
United States — Standard Contractual Clauses: For transfers to US-based sub-processors (Together AI, Stripe, Bandwidth, Sentry, HyperDX, Wasabi us-east-1 for USD organizations), we rely on the European Commission's approved Standard Contractual Clauses (2021 SCCs) supplemented by transfer impact assessments.
Data Processing Agreements: All third-party processors who handle personal data on our behalf are bound by DPAs requiring GDPR-compliant protections.
We conduct transfer impact assessments (TIAs) for transfers to the United States and implement supplementary measures where necessary.
Breach Notification
In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
If the breach is likely to result in high risk to individuals, we will also notify affected data subjects without undue delay. Notifications will include the nature of the breach, likely consequences, measures taken or proposed to address the breach, and contact information for our DPO.
We maintain incident response procedures including breach detection, containment, investigation, notification, and remediation. All security incidents are logged and reviewed.
DPO Contact
Our Data Protection Officer oversees GDPR compliance and serves as the primary contact for all data protection matters. Contact our DPO to exercise your rights, ask questions about data processing, or raise concerns.
Data Protection Officer Email: [email protected] Mail: SIPSTACK Inc., Data Protection Officer, 575-3093 Bathurst St., Toronto, ON M6A 2A3, Canada Response Time: All DPO inquiries are acknowledged within 72 hours; substantive responses within 30 days.
The DPO works independently and reports directly to senior management. The DPO has authority to escalate data protection issues to executive leadership.
For general privacy questions, you may also contact: [email protected]