On this page
1. Scope and agreement
This page is an overview, not an executed data-processing agreement, transfer agreement or subprocessor register. Where Telfron processes personal information for a customer, the parties must establish the actual roles and enter the required written terms before that processing begins. A product licence does not settle every data-protection responsibility.
2. Define the processing schedule
- Identify the customer/controller and Telfron entity/processor, relevant services and authorized contacts.
- Record the subject matter, duration, nature and purpose of processing, people affected and information categories.
- Specify documented instructions, permitted access, deployment locations and who configures recording and retention.
- Identify sensitive information and any processing that needs additional legal conditions or sector safeguards.
3. Document protections and assistance
The agreement should address confidentiality, appropriate technical and organizational measures, assistance with individual rights, incident reporting, assessments and audits, and the handling of unlawful instructions. Measures must describe the service actually delivered, including customer responsibilities. Do not substitute generic claims such as ‘military-grade encryption’ for evidence.
4. Subprocessors and international transfers
The processing agreement should list the relevant subprocessors, service functions, countries and access arrangements. Establish authorization, flow-down obligations and a process for changes and objections where required. Decide the appropriate transfer mechanism and safeguards for each restricted transfer. Request supplier and transfer details for the proposed service; this overview is not a subprocessor register or evidence that a particular agreement has already been executed.
5. AI and communication content
Document whether audio, messages, transcripts, prompts or summaries leave customer infrastructure; which provider receives them; and how provider retention, training use and access are controlled. Define approved knowledge, review, handover and any restrictions on sensitive content. A private PBX deployment can still use an external AI provider if configured that way.
6. Retention, return and deletion
Agree active-record retention, backup rotation, legal holds, export format, return or deletion at service end and any permitted exceptions. Specify verification and assistance arrangements. Do not promise immediate erasure from every backup without a documented and workable process.
7. Request deployment-specific documents
Contact info@telfron.com with the subject ‘Data-processing review’ and your proposed service and deployment. The review should establish the required agreement, processing schedule, measures and supplier/transfer information before processing customer content.
Reference frameworks
References explain relevant frameworks; their inclusion is not a claim of certification or universal compliance.
- ISO/IEC 27001:2022
- ISO/IEC 27701:2025
- NZ Privacy Act principles
- NZ indirect-collection notice (IPP3A)
- NZ access and correction requests
- NZ international disclosures
- NZ breach notification guidance
- EDPB lawful processing
- EDPB controller and processor roles
- EDPB individual rights
- ICO cookies and similar technologies
- ICO consent withdrawal