In brief. We do not sell personal information. We do not sell or share Customer Proprietary Network Information. We do not listen to your calls, and we do not record them unless you switch recording on yourself. We use what we hold to carry calls, bill accurately, stop fraud and meet our legal obligations as a carrier — and very little else.
1. About this policy
NexDial Communication LLC (“NexDial”, “we”, “us”) provides wholesale voice, numbering and call analytics services in the United States. This policy explains how we handle personal information when you visit nexdial.net, use the console, hold an account with us, place or receive a call that crosses our network, or dial a number one of our customers uses for call tracking.
It does not govern our customers' own privacy practices. If you called a business that uses our services, that business decides what happens to information about the call, and its notice applies.
2. Controller or processor
| Context | Our role | Meaning |
|---|---|---|
| Website, marketing, sales | Controller | We decide what is collected and why; this policy governs fully. |
| Your account, console and billing | Controller | We hold business and account data to run the relationship. |
| Carrying calls and producing CDRs | Carrier | We must create and retain certain records by law and handle CPNI under FCC rules. |
| Call tracking data, recordings, transcripts | Processor | We act on our customer's instructions; the customer is responsible for lawful basis, notice and consent. |
3. What we collect
3.1 Information you give us
- Account and contact details — name, job title, company, work email and telephone.
- KYC information — legal entity details, business address, ownership and control, authorised signatory, intended use and traffic profile, and evidence of your right to use calling numbers. We collect this because we are required to know who originates traffic on our network.
- Credentials — usernames, hashed passwords, API tokens, SIP credentials, authorised IP addresses and multi-factor settings.
- Billing information — billing contact, address, tax identifiers and payment method. Card details are handled by PCI-DSS compliant processors; we do not store full card numbers.
3.2 Information created when calls are carried
Operating a voice network necessarily produces records. For each call we process call detail records and signalling data, which may include calling and called numbers; date, time and duration; direction, disposition and release cause; routing information such as trunk, carrier, jurisdiction and LRN; STIR/SHAKEN attestation and identity headers; quality metrics such as jitter, packet loss and codec; and the IP addresses of the signalling endpoints.
We process the metadata of calls. We do not process call content except as described in Section 6.
3.3 Collected automatically
- IP address and approximate city-level location derived from it; browser, device and operating system.
- Pages viewed, console actions taken, and authentication events.
- Cookie and similar identifiers as described in Section 8.
3.4 From third parties
- Numbering and routing data from the numbering administrator, portability databases and underlying carriers.
- Fraud, sanctions-screening and credit signals from screening providers.
- Traceback and reputation data from the industry traceback process and analytics providers.
4. CPNI
Some of what we hold is Customer Proprietary Network Information, protected under Section 222 of the Communications Act and FCC rules. CPNI covers the quantity, technical configuration, type, destination, location and amount of use of the telecommunications services you buy, together with related billing information.
Our commitments: we do not sell CPNI — not to brokers, marketers or anyone. We use it to provide and bill for the services you bought, to protect the network and other customers from fraud and abuse, and where law requires or permits. We do not use CPNI to market outside the category you already buy without the consent FCC rules require. We authenticate before discussing CPNI and will not release call detail to an unauthenticated caller by telephone. We maintain CPNI training, access controls and records, and report unauthorised disclosure as required.
5. Call tracking and callers
Where a customer uses our call tracking product, we may process on their behalf the caller's telephone number and the tracking number dialled; date, time, duration and outcome; the marketing source attributed to the call — campaign, keyword, referrer, landing page, UTM parameters and, where the customer deploys our script, the visitor session identifiers needed to make that attribution; and, where the customer enables it, recordings, transcripts and conversation analytics.
If you are a caller rather than a customer. When you call a business using our platform, we handle your information as that business's service provider. We do not use it for our own marketing, do not sell it, and do not build advertising profiles from it. To ask what a business holds about your call or to request deletion, contact that business. If you cannot identify them, write to abuse@nexdial.net and we will route your request and support them in responding.
Customers are contractually required to give any notice and obtain any consent the law requires for call tracking, dynamic number insertion and recording — including all-party consent where applicable.
6. Recording and transcripts
NexDial does not listen to, record or transcribe calls as a matter of course. Recording occurs only where a customer has expressly enabled it on their own account — in which case they are responsible for announcements, consent and lawful use — or where we are compelled to assist under valid legal process.
Customer-enabled recordings are encrypted at rest, accessible only to that customer's authorised users and the minimum NexDial personnel needed to support the service, and deleted according to the customer's configured retention period or on request.
7. How we use information
| Purpose | Information | Basis |
|---|---|---|
| Routing and completing calls | CDRs, signalling, technical data | Performance of contract; provision of a telecommunications service |
| Rating, billing and dispute resolution | CDRs, account and billing data | Performance of contract; legal obligation |
| Fraud prevention and AUP enforcement | CDRs, traffic metrics, auth logs | Legitimate interests in protecting the network, customers and consumers |
| KYC, sanctions screening, traceback response | Onboarding data, CDRs | Legal and regulatory obligation |
| Console operation and support | Account data, support correspondence | Performance of contract |
| Providing call tracking | Call tracking data | On documented instructions of our customer, as processor |
| Security monitoring and incident response | Logs, IP addresses, auth events | Legitimate interests; legal obligation |
| Business-to-business marketing | Business contact data, site analytics | Legitimate interests, with opt-out at any time |
We do not use call content, CDRs or CPNI to train advertising models, build consumer profiles, or make automated decisions producing legal or similarly significant effects about individuals.
8. Website and cookies
We use a small number of cookies: strictly necessary ones for session integrity, security and load balancing; a preference cookie remembering your light or dark theme choice, which stays in your own browser; and aggregate analytics so we can improve the site. You can block or delete cookies in your browser, though strictly necessary ones are needed for the site and console to function.
We honour the Global Privacy Control signal as a valid opt-out where applicable law recognises it, and we do not engage in cross-context behavioural advertising.
9. Sharing
We do not sell personal information and do not share it for cross-context behavioural advertising. We disclose only as follows:
- Underlying and terminating carriers — signalling and the calling and called numbers must pass to other carriers to complete a call. This is inherent to how the telephone network works.
- Service providers — hosting, payment processing, fraud and sanctions screening, email delivery, support tooling and professional advisers, each bound by contract.
- Numbering and porting administrators — where required to assign or port numbers.
- Regulators, traceback participants and law enforcement — see Section 10.
- Our customers — where you are a caller and the data belongs to the customer whose tracking number you dialled.
- Corporate transactions — in a merger, acquisition or asset sale, subject to the acquirer honouring this policy.
- With your consent — in any other case we ask first.
10. Law enforcement
As a carrier we receive legal demands for subscriber and call record information. We require valid, properly served legal process appropriate to the data sought; we disclose the narrowest set the process actually compels, and push back on overbroad or improperly served requests; we comply with CALEA and the Stored Communications Act; and where legally permitted our practice is to notify the affected customer, unless notice is prohibited or would create a risk to life or an investigation. Emergency disclosures are made only on a good-faith belief of imminent danger of death or serious injury.
Requests should be directed to abuse@nexdial.net.
11. Retention
| Category | Typical retention | Reason |
|---|---|---|
| Call detail records | Up to 24 months | Billing, disputes, traceback and regulatory obligations |
| Billing and financial records | 7 years | Tax, accounting and audit |
| KYC records | Term plus 5 years | Regulatory and traceback obligations |
| Recordings and transcripts | Customer-configured; default 90 days | Under customer control |
| Call tracking attribution | Customer-configured; default 13 months | Under customer control |
| Security and access logs | 12 months | Security monitoring and investigation |
| Website analytics | 14 months | Site improvement |
| Marketing contacts | Until opt-out, then suppression list only | Honouring your opt-out |
We may retain longer where a legal hold, investigation or dispute requires. When retention ends we delete or irreversibly de-identify.
12. Security
We maintain safeguards appropriate to carrier data: encryption in transit and at rest; TLS and SRTP for signalling and media where endpoints support it; role-based access control and least-privilege provisioning; multi-factor authentication for administrative access; network segmentation between signalling, media and business systems; centralised logging and continuous monitoring; vulnerability management and periodic penetration testing; vendor security review; personnel background checks, confidentiality obligations and CPNI training; and a documented incident response plan.
No system is perfectly secure. Where a breach affecting personal information occurs we notify affected customers and regulators as required, including FCC breach notification rules applicable to CPNI and relevant state statutes. Report suspected vulnerabilities to noc@nexdial.net.
13. Your rights
Depending on where you live you may have the right to know and access, to correct, to delete (subject to our legal retention duties as a carrier), to portability, to opt out of sale, sharing and profiling (we do none of these, but the right stands), to opt out of marketing, to non-discrimination for exercising a right, and to appeal a decision on your request.
Exercise any right by emailing abuse@nexdial.net with “Privacy Request” in the subject. We verify identity in proportion to sensitivity — for CPNI and call records that verification is necessarily strict — and respond within 45 days, extending once by a further 45 days where reasonably necessary and telling you if we do. An authorised agent may act for you with verifiable written permission. There is no charge unless a request is manifestly unfounded or excessive.
Where a request concerns data we process for a customer, we forward it to that customer and support them in responding, since they decide the outcome.
14. US state disclosures
This supplements the above for residents of California and other states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas and Oregon.
Categories collected in the past 12 months, in CCPA terms: identifiers (name, business email, telephone, IP address); commercial information (services purchased, billing records); internet and network activity (site and console usage, CDR and signalling metadata); coarse geolocation inferred from IP or rate centre; professional information (job title, employer); and audio information, only where a customer enabled recording.
Sources, purposes and recipients are described in Sections 3, 7 and 9. We have not sold personal information and have not shared it for cross-context behavioural advertising in the preceding 12 months, and do not do so today. We do not knowingly sell or share personal information of consumers under 16, and do not use sensitive personal information beyond purposes permitted without a right to limit.
15. International transfers
NexDial is based in the United States and our infrastructure is operated there. If you contact us or use the Services from outside the US, your information will be transferred to and processed in the United States, where data protection law may differ from your own.
Where we process personal information subject to the UK or EU GDPR as a processor for a customer, we do so under a data processing agreement incorporating the Standard Contractual Clauses and the UK International Data Transfer Addendum. Customers needing a signed DPA should write to abuse@nexdial.net.
16. Children
The Services are sold to businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact abuse@nexdial.net and we will delete it promptly.
17. Changes
We review this policy at least annually and update it when our practices, the Services or the law change. The effective date above reflects the current version. Where a change materially affects how we handle your personal information we will notify account contacts by email or post a prominent notice before it takes effect.
18. Contact
- Privacy and compliance: abuse@nexdial.net
- Sales: sales@nexdial.net
- Network operations: noc@nexdial.net
- Telephone: +1 (805) 749-2804
- Post: NexDial Communication LLC, 16 Executive Plaza Courte, Maryville, IL 62062, United States
If you are dissatisfied with our response you may complain to your state attorney general, to the FCC, or — if you are in the UK or EU — to your local supervisory authority. We would ask you to raise it with us first so we can put it right.