Private communications. Built for your business.

LEGAL & TRUST

Customer data-processing overview

The responsibilities and details to establish before Telfron processes communication data on a customer’s behalf.

Effective 8 October 2026 · Last reviewed 8 October 2026
On this page

1. Scope and agreement

This page is an overview, not an executed data-processing agreement, transfer agreement or subprocessor register. Where Telfron processes personal information for a customer, the parties must establish the actual roles and enter the required written terms before that processing begins. A product licence does not settle every data-protection responsibility.

2. Define the processing schedule

  • Identify the customer/controller and Telfron entity/processor, relevant services and authorized contacts.
  • Record the subject matter, duration, nature and purpose of processing, people affected and information categories.
  • Specify documented instructions, permitted access, deployment locations and who configures recording and retention.
  • Identify sensitive information and any processing that needs additional legal conditions or sector safeguards.

3. Document protections and assistance

The agreement should address confidentiality, appropriate technical and organizational measures, assistance with individual rights, incident reporting, assessments and audits, and the handling of unlawful instructions. Measures must describe the service actually delivered, including customer responsibilities. Do not substitute generic claims such as ‘military-grade encryption’ for evidence.

4. Subprocessors and international transfers

The processing agreement should list the relevant subprocessors, service functions, countries and access arrangements. Establish authorization, flow-down obligations and a process for changes and objections where required. Decide the appropriate transfer mechanism and safeguards for each restricted transfer. Request supplier and transfer details for the proposed service; this overview is not a subprocessor register or evidence that a particular agreement has already been executed.

5. AI and communication content

Document whether audio, messages, transcripts, prompts or summaries leave customer infrastructure; which provider receives them; and how provider retention, training use and access are controlled. Define approved knowledge, review, handover and any restrictions on sensitive content. A private PBX deployment can still use an external AI provider if configured that way.

6. Retention, return and deletion

Agree active-record retention, backup rotation, legal holds, export format, return or deletion at service end and any permitted exceptions. Specify verification and assistance arrangements. Do not promise immediate erasure from every backup without a documented and workable process.

7. Request deployment-specific documents

Contact info@telfron.com with the subject ‘Data-processing review’ and your proposed service and deployment. The review should establish the required agreement, processing schedule, measures and supplier/transfer information before processing customer content.

Reference frameworks

References explain relevant frameworks; their inclusion is not a claim of certification or universal compliance.