Privacy Policy
Effective Date: July 22, 2026 | Previous version: September 15, 2025
1. Introduction
Dialvia Limited (“DialVia”, “we”, “us”, or “our”) is committed to protecting your privacy. This policy explains how we collect, use, disclose, and safeguard your information.
Dialvia Limited is the data controller for the personal data described in this policy. For any privacy question, or to exercise the rights described in Section 11, contact us at [email protected].
2. Information We Collect
- Account Data: Name, email, encrypted password.
- Call Metadata: Timestamps, durations, dialed numbers, caller ID used, call status and outcome, and the carrier that handled the call. We do not listen to or record the audio content of your calls.
- Payment Data: Stripe Customer IDs and masked card details (no raw card data stored), together with your purchase and top-up history.
- Technical & Security Data: IP address, device and browser information, and server logs of your interactions with the Service. We use this to keep the Service secure and to detect fraud and abuse.
- Optional Data: Contacts, verified caller IDs.
- Cookies: Session cookies for authentication only.
- Analytics Data: Where you consent, we use PostHog to collect usage analytics including page views, feature usage, device information, and user interactions. When you are signed in, this data is linked to your account identifier and email address so we can understand how the Service is used. You can decline analytics at any time — see Section 10.
3. How We Use Your Data
- To authenticate and manage your account.
- To route your calls and to calculate and deduct Credits.
- To process and record payments via Stripe, including Auto Top-Up charges.
- To provide, maintain, and improve the Service.
- To detect, investigate, and prevent fraud, abuse, and prohibited use of the Service, to protect our systems and those of our carriers, and to enforce our Terms of Service. This is described in detail in Section 5.
- To communicate offers, updates, and support responses.
- To analyze usage patterns and user behavior through PostHog analytics, where you have consented, to enhance user experience and service functionality.
- To comply with our legal and regulatory obligations, and to establish, exercise, or defend legal claims.
4. Our Lawful Bases
Under the UK GDPR and EU GDPR we must have a lawful basis for each purpose for which we use your personal data:
- Performance of a contract: creating and managing your account, routing calls, deducting Credits, processing payments, and providing support.
- Legitimate interests: detecting and preventing fraud, abuse, and prohibited traffic; securing our systems and our carriers’ networks; enforcing our Terms; and establishing or defending legal claims. The prevention of fraud is expressly recognised as a legitimate interest under the GDPR. We have assessed that these interests are not overridden by your rights, in part because we analyse only call metadata and never call content.
- Consent: analytics and non-essential cookies, and marketing communications where consent is required. You may withdraw consent at any time without affecting the lawfulness of processing carried out beforehand.
- Legal obligation: retaining financial and tax records, responding to lawful requests from authorities, and meeting anti-fraud and regulatory requirements.
5. Fraud Prevention & Automated Decision-Making
To protect the Service, our carriers, and other users from telecommunications fraud, we operate automated systems that analyse how the Service is used.
- What we analyse: call metadata only — such as the numbers dialed, the frequency, timing, and volume of call attempts, how many attempts connect, call durations, and patterns of activity across accounts, including shared payment methods and devices. We do not listen to, record, or analyse the content of your calls.
- What may happen automatically: where activity matches patterns associated with automated calling, traffic pumping, or other prohibited traffic, our systems may block an individual call, apply limits to your account, disable Auto Top-Up, or suspend your account’s ability to make calls. In some cases this happens without prior human review.
- Consequences for you: a suspension prevents you from placing further calls and may lead to termination of your account under our Terms of Service.
- Your right to human review: if an automated decision has been applied to your account, you have the right to obtain human intervention, to express your point of view, and to contest the decision. Email [email protected] and a person will review your case.
- Limits on what we disclose: we will explain the general reason for a decision, but we do not publish the specific thresholds or rules our fraud systems apply, because doing so would allow them to be circumvented.
6. Data Sharing & Disclosure
We do not sell your personal data. We share information with trusted third parties to operate the Service:
- Twilio (call routing)
- Telnyx (call routing)
- Stripe (payment processing)
- Resend (email delivery)
- Cloudflare (security and CDN)
- DigitalOcean (hosting)
- PostHog (analytics and product insights) — only when you provide explicit consent.
We may also disclose personal data:
- To our carriers and payment processors where reasonably necessary to investigate, report, or prevent fraud, abuse, or misuse of their networks or services, including in response to a fraud investigation opened by them.
- To law enforcement, regulators, or other authorities where we are legally required to do so, or where disclosure is necessary to prevent or report suspected criminal activity.
- To our professional advisers, and where necessary to establish, exercise, or defend legal claims, including in relation to payment disputes and chargebacks.
- To a successor entity in connection with a merger, acquisition, or sale of assets.
7. International Transfers
Some of our service providers are located outside the United Kingdom and the European Economic Area, including in the United States. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards recognised under the UK GDPR and EU GDPR — such as the UK International Data Transfer Agreement or Addendum, the European Commission’s Standard Contractual Clauses, or an applicable adequacy decision. You may request further information about these safeguards by contacting us.
8. Data Retention
We keep personal data only for as long as necessary for the purposes set out in this policy:
- Account data: for as long as your account is open, and for a reasonable period afterwards to handle any residual queries.
- Call metadata and billing records: retained for up to six years to meet our accounting, tax, and record-keeping obligations, and to resolve billing or payment disputes.
- Fraud and abuse records: where an account has been restricted, suspended, or terminated for prohibited use, we retain the relevant account, call, and payment records for as long as necessary to prevent recurrence, to respond to carrier or payment-processor investigations, and to establish, exercise, or defend legal claims. This applies even if you ask us to delete your account, because these records are needed for those purposes.
- Analytics data: retained in line with our analytics provider’s retention settings, and deleted or anonymised when no longer needed.
9. Data Security
We implement industry-standard technical and organizational measures (encryption, access controls) to protect your data. However, no system is entirely secure.
10. Cookie Consent & Tracking Preferences
We respect your privacy choices regarding analytics and tracking:
- Explicit Consent: We only collect analytics data through PostHog when you explicitly accept our cookie banner.
- Opt-Out Rights: You can decline tracking at any time through our cookie banner or by clearing your browser data.
- Essential vs. Analytics: We distinguish between essential cookies (required for service functionality) and analytics cookies (optional for service improvement).
- Data Retention: Your consent preferences are stored locally in your browser and respected across all future visits.
- Fraud prevention is not analytics: the security and fraud-prevention processing described in Section 5 is essential to operating the Service, is carried out on the basis of our legitimate interests, and is not affected by your analytics choices.
11. Your Rights
Subject to certain conditions and exemptions, you have the right to:
- Access the personal data we hold about you, and receive a copy of it.
- Rectify inaccurate or incomplete data.
- Erase your data (the “right to be forgotten”).
- Restrict or object to our processing, including processing carried out on the basis of our legitimate interests.
- Data portability — receive certain data in a structured, machine-readable format.
- Withdraw consent at any time where our processing is based on consent.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to obtain human review of such a decision — see Section 5.
To exercise any of these rights, email [email protected]. We will respond within one month, and will tell you if we need longer. We may ask you to verify your identity first.
These rights are not absolute. In particular, we may decline an erasure or objection request where we need to keep the data to comply with a legal obligation, or to establish, exercise, or defend legal claims — including records relating to fraud, abuse, or payment disputes, as described in Section 8.
If you are unhappy with how we have handled your personal data, you may complain to the UK Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority if you are in the EEA. We would appreciate the chance to address your concerns first.
12. Children’s Privacy
Our Service is not intended for, and may not be used by, anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy periodically. We will post the revised date here, and where a change is material we will notify you by email or through the Service. Your continued use indicates acceptance of any changes.