WPPBX™ Partners
Pricing FAQ
wppbx.com Partner Portal Login
Pricing FAQ wppbx.com Partner Portal Login
Home / Legal / Privacy Policy

Privacy Policy

Last updated: 2026-08-28

On this page
  • 1. Who We Are
  • 2. Information We Collect
  • 3. How We Collect It
  • 4. How We Use It
  • 5. Legal Basis for Processing
  • 6. Sharing and Subprocessors
  • 7. International Transfers
  • 8. Cookies and Analytics
  • 9. Retention
  • 10. Your Rights
  • 11. Security
  • 12. Children
  • 13. The WPPBX Phone Mobile App
  • 14. Changes to this Policy
  • 15. Contact
Historical version. You are viewing v3.1 of this document. The current version is at /legal/privacy.

This Privacy Policy explains how WPPBX handles personal information collected through the WPPBX Partner Network, including the public Site at partners.wppbx.com, the Reseller Portal, and related authenticated interfaces. It is written to satisfy the Protection of Personal Information Act, 2013 (South Africa) ("POPIA") and the EU General Data Protection Regulation ("GDPR") in respect of in-scope processing activities.

Personal information processed on behalf of our customers (for example, end-user call metadata or voicemail inside a Tenant) is covered by the relevant customer contract and by the Non-User Privacy Policy.

1. Who We Are

1.1 The responsible party (data controller) for the processing described in this Policy is:

WPPBX Pty Ltd
Registration number: 2026/314638/07
Trading as: WPPBX
Registered address: 70 Aleppo Crescent, Rooihuiskraal Noord, Centurion, Gauteng, 0157, South Africa

1.2 References to “WPPBX”, “we”, “our” or “us” in this Policy and in every other WPPBX policy are to the entity identified above.

1.3 You can reach our privacy team at [email protected].

2. Information We Collect

2.1 We collect the following categories of personal information:

  • Application data, name, email, phone, company, country, city, website, message and any other fields you submit on the "Become a Partner" form;
  • Contact-form data, name, email, phone (optional), company (optional) and message when you contact a listed Partner;
  • Reseller account data, company details, billing address, tax identifier, designated contact persons, banking or payment instrument information and login credentials for the Reseller Portal;
  • Technical data, IP address, user-agent, browser language and approximate geolocation derived from IP, logged for security and anti-abuse purposes;
  • Cookies and analytics data, see section 8 below.

3. How We Collect It

3.1 We collect personal information directly from you when you submit it to us through a form on the Site or in the Reseller Portal. We also collect technical data automatically when your browser or device connects to us. We may receive limited information from our subprocessors about the delivery of emails we send you and about challenge results from our anti-abuse provider.

4. How We Use It

4.1 We use personal information to:

  • Operate the Site and the Reseller Portal;
  • Process Partner applications and manage the Partner relationship;
  • Deliver contact-form submissions to the Partner you selected;
  • Respond to your queries and provide support;
  • Send you transactional and policy-related notifications;
  • Detect, prevent and respond to fraud and abuse;
  • Comply with our legal and regulatory obligations.

5. Legal Basis for Processing

5.1 Under the GDPR, we rely on the following legal bases:

  • Performance of a contract, where processing is necessary to provide the Services you or your organisation have purchased;
  • Legitimate interests, for security, anti-abuse, service operation, product improvement and direct communication about your account, balanced against your rights and freedoms;
  • Consent, where required by law (for example, non-essential cookies), and only until you withdraw it;
  • Legal obligation, where processing is required by applicable law.

5.2 Under POPIA, processing is carried out on equivalent bases recognised by section 11 of that Act.

6. Sharing and Subprocessors

6.1 We do not sell personal information. We share it only with subprocessors that act on our instructions under written contracts containing appropriate safeguards. Our current subprocessors are:

  • Amazon Web Services (AWS), hosting, compute and storage. Primary processing region: European Union.
  • Cloudflare, Inc., DNS, content delivery, web application firewalling and the Turnstile anti-abuse challenge.
  • Creem (Armitage Labs OÜ, Estonia), our merchant of record, payment processing, subscription billing and tax handling.
  • Resend, transactional email delivery.
  • Umami (self-hosted), privacy-preserving visitor analytics, operated within our own infrastructure.
  • OpenStreetMap contributors, base cartography for the Partner directory map. No personal data is sent to OpenStreetMap at runtime.
  • Public content-delivery networks (jsDelivr, unpkg, Cloudflare CDN), for standard stylesheet and icon assets. Your browser’s request to these networks includes its IP address by technical necessity.

6.2 We may disclose personal information where required by law, in response to a valid legal request, or to protect our rights, our Partners, or the public.

7. International Transfers

7.1 Our primary hosting and our payment processor (Creem, in Estonia) are located in the European Union. Certain subprocessors (including Resend) are located in the United States. Where personal information is transferred outside the European Economic Area to a country not recognised as providing adequate protection, we put in place appropriate safeguards, including the European Commission’s Standard Contractual Clauses for cross-border transfers.

8. Cookies and Analytics

8.1 We use a small number of strictly-necessary cookies for session management, security and CSRF protection. These do not require your consent under applicable law.

8.2 We use first-party, privacy-preserving analytics (Umami) self-hosted within our infrastructure. Analytics do not identify individual visitors by name and do not set cross-site tracking cookies.

8.3 Where we ever introduce non-essential cookies or trackers, we will do so only with your prior, informed consent collected through a cookie banner.

9. Retention

9.1 We retain personal information only as long as is necessary for the purpose for which it was collected, or to comply with a legal obligation. Indicative retention periods are:

  • Contact-form submissions, up to twenty-four (24) months from submission, or until you request deletion;
  • Unsuccessful Partner applications, up to twelve (12) months;
  • Reseller account records, for the duration of the account and up to seven (7) years thereafter for financial, tax and dispute reasons;
  • Security logs, up to twelve (12) months;
  • Aggregated analytics, indefinitely, in a form that does not identify individuals.

10. Your Rights

10.1 Subject to applicable law you have the right to:

  • Access the personal information we hold about you;
  • Correct or update inaccurate information;
  • Object to or restrict processing in certain circumstances;
  • Request the deletion of your information (the "right to be forgotten");
  • Receive your information in a portable format;
  • Withdraw consent where we rely on it;
  • Lodge a complaint with a supervisory authority, in South Africa, the Information Regulator; in the EU, the Data Protection Authority in your country of residence.

10.2 To exercise any of these rights, email [email protected]. For the specific case of a contact-form submission, the fastest route is the Delete my contact submission form.

11. Security

11.1 We use reasonable technical and organisational measures to protect personal information, including transport-layer encryption, web application firewalling, rate limiting, audit logging, encryption at rest on managed storage and role-based access control. No system is completely secure; where we become aware of a personal-data breach, we will notify affected individuals and regulators in accordance with applicable law.

12. Children

12.1 The Site is not directed at children under sixteen (16). We do not knowingly collect personal information from children. If you believe a child has submitted data to us, please contact [email protected] so that we can remove it.

13. The WPPBX Phone Mobile App

13.1 WPPBX Phone is a mobile application that connects a person's mobile handset to a WPPBX phone system operated by their own employer or that employer's provider. This section describes what the application handles on the handset. It is written to be read on its own, because app stores require a plain account of an application's behaviour.

13.2 Who holds the information. The application does not send calls, messages or recordings to WPPBX. They travel to the phone system the customer's own organisation operates. That organisation determines what is retained and for how long, and is the controller of it. WPPBX supplies the software and does not operate the customer's phone system.

13.3 What the application handles. The signed-in person's name and extension number, so the phone system can identify them; the calls they make and receive and the history of those calls; sound from the microphone, carried live for the duration of a call; messages and notes they write to colleagues; voicemail and, where their administrator has enabled it, recordings of their own calls; and an identifier for the handset so that an incoming call can reach it while the application is closed.

13.4 What the application does not do. It does not read the contacts stored on the handset, and does not request permission to do so; the colleagues shown in it come from the organisation's own directory. It does not collect location and requests no location permission. It contains no advertising, no analytics and no tracking components. It does not record calls on the handset; where call recording is in use, it is performed by the organisation's phone system under that organisation's policy.

13.5 Notifications. So that a call can reach a handset while the application is closed, the phone system asks Google's notification service to wake it, which is how notifications operate on Android. That wake-up message carries only who is calling or who has sent a message, and which conversation it belongs to. It does not carry the contents of a message or any part of a call; the application retrieves those directly from the phone system once it is running.

13.6 Security. Sign-in and all subsequent traffic use encrypted connections, call signalling uses an encrypted connection, and call audio is encrypted in transit. Sign-in credentials are held on the handset by the application and are not readable by other applications.

13.7 Retention and removal. Accounts are created by the customer's administrator, and how long call history, voicemail, recordings and messages are kept is determined by that organisation. A person wishing to have their information removed should ask their administrator to remove their extension, which removes the account and the information held against it. Signing out of the application, or removing it, clears the credentials from the handset.

13.8 Children. WPPBX Phone is a workplace tool. It is not directed at children and is not intended for anyone under 13.

14. Changes to this Policy

14.1 We may revise this Policy from time to time. Each revision is published through the Policy Manager with an effective date and a summary of material changes. Historical versions are available at partners.wppbx.com/legal/privacy/versions.

15. Contact

Privacy questions, rights requests and complaints can be directed to [email protected].

Version 3.1 · effective 2026-08-28 View version history
Back to home Contact legal
WPPBX™ Partners

The WPPBX Partner Network,
find a partner or become one.

WPPBX Pty Ltd (Registration No. 2026/314638/07),
trading as WPPBX. All rights reserved.

Platform
Features How it works About FAQ
Partners
Become a Partner Pricing
Legal
Consumer Terms Commercial Terms Refund Policy Privacy Policy Non-User Privacy Usage Policy Delete my contact submission
Other
Supported Countries Dispute Resolution
Contact
[email protected] [email protected] [email protected]
© 2026 WPPBX™ WPPBX

Contact this partner

Your message goes directly to the partner. Your contact details stay private to WPPBX and the partner you're contacting.

We use strictly-necessary cookies. These power session login, CSRF protection and Cloudflare Turnstile anti-bot checks. We don't track, advertise or share data with third parties beyond what's listed in our Privacy Policy.
Privacy details