Making sense of GDPR — and how iovox keeps your data safe.
At iovox, data privacy is not a compliance checkbox; it is fundamental to how we operate. We have never sold customer data and never will. Our business is built on trust, and that trust starts with how we handle the information you share with us.
Ryan Gallagher, CEO & Co-Founder
The General Data Protection Regulation (GDPR) came into force on 25 May 2018 and was designed to give individuals across the EU (and, under UK GDPR, within the United Kingdom) greater control over their personal data. It establishes clear obligations for any organisation that collects, stores, or processes personal data.
Personal data is any information related to an identified or identifiable natural person. This includes direct identifiers (name, email address, phone number) and indirect identifiers (IP address, device ID, location data) that can be used to single out an individual.
GDPR distinguishes between two key roles:
For our own marketing and billing, iovox acts as a data controller in its own right.
GDPR gives individuals a set of rights over their personal data:
A Subject Access Request is a formal written request from an individual to find out what personal data an organisation holds about them. iovox is required to respond to any SAR within 30 days. To submit a SAR relating to data controlled by iovox, contact privacy@iovox.com. For data processed by iovox on behalf of your business, SARs should be directed to you as the data controller.
As both a controller and a processor, iovox maintains four core obligations:
iovox is not legally required to appoint a Data Protection Officer under the criteria set out in GDPR. However, we maintain a dedicated compliance team responsible for data protection matters. All privacy enquiries are handled by that team at privacy@iovox.com.
Call tracking involves the processing of phone numbers, call duration, call recordings and related metadata. This data may constitute personal data under GDPR. As a data controller, you are responsible for ensuring that your use of iovox's call tracking Services complies with applicable data protection law in your jurisdiction, including providing appropriate notices to callers and, where required, obtaining their consent.
iovox provides a standard Data Processing Agreement (DPA) to all customers processing personal data through our platform. The DPA sets out the subject matter and duration of processing, the nature and purpose of processing, the categories of data and data subjects, and our respective obligations. To request our DPA or execute a customised version, contact privacy@iovox.com.
iovox operates globally. Where personal data is transferred from the UK or EEA to third countries, we rely on appropriate safeguards including UK International Data Transfer Agreements (IDTAs), EU Standard Contractual Clauses (SCCs), and adequacy decisions where applicable. Enterprise customers can configure data residency settings to restrict processing to specific regions.
For all data protection and GDPR enquiries:
privacy@iovox.com
iovox Limited, London, UK
Company No. 6057954