Effective date: May 3, 2026
1. Who we are
DialNext Inc. (“DialNext,” “we,” “us,” or “our”) operates the DialNext websites (including our public marketing site and authenticated web application at domains we operate, including https://dialnext.io) and cloud software used to administer business communications—such as placing and receiving calls, exchanging SMS messages with contacts, purchasing or releasing phone numbers, viewing call logs, collaborating with teammates in workspaces, integrations where enabled, usage/analytics tied to service improvement, and managing subscription billing (Services).
Registered office / principal address: [Insert principal business address].
For privacy inquiries: privacy@dialnext.io. For general legal notices: legal@dialnext.io.
2. Scope of this policy
Use of our Services is also governed by our Terms of Service.
This Privacy Policy describes how we handle personal information when you:
- Visit our marketing website or authenticated application;
- Create or administer an account or workspace;
- Use voice or messaging capabilities we enable through telecommunications providers;
- Interact with billing, support, or transactional emails.
If you enter into a separate enterprise agreement with us, that agreement may supplement or supersede portions of this Policy where expressly stated.
3. Business customers & end users
Where an organization subscribes to DialNext for its personnel, that organization is typically the business customer that directs how workspace features are used. The customer may submit or enable processing of personal information about employees and contractors (Authorized Users) as well as personal information relating to its own contacts and messaging counterparties (Customer Contacts).
Depending on jurisdiction and context, the customer may act as an independent controller for Customer Contact data, and DialNext may process such data as a processor/service provider strictly on documented instructions and consistent with our agreement with that customer and applicable law. Authorized Users should contact their organization’s administrator with privacy requests relating to workspace administration or contact lists maintained by the organization.
4. Personal information we collect
We collect the following categories of information (exact fields depend on features you use):
- Account & profile data: name, email address, password hash (stored by our authentication systems), company name, workspace identifiers, role or permission attributes, optional profile photo or avatar, verification codes for email verification, and similar onboarding details you supply.
- Communications metadata & content: telephone numbers (including numbers you dial or message, purchased inbound lines, caller ID fields where permitted), timestamps, duration, routing metadata, SMS/MMS thread identifiers, message bodies you send or receive through the Services, delivery status codes, consent preferences or compliance banners surfaced through workspace settings, internal notes entered by Authorized Users, and related logs necessary to operate messaging and voice features.
- Contacts & CRM-style records: information you upload or synchronize about Customer Contacts, such as display names, tags, notes, avatars, or identifiers tied to conversations.
- Billing data: subscription identifiers, plan selections, invoices or receipts, payment status, tokens or redirects handled by our payment processor(s), tax identifiers where provided, and billing contact details.
- Technical & usage data: IP address, device/browser type, approximate location derived from IP, diagnostic logs, cookie or local-storage identifiers used for session continuity, crash information, API request metadata, security telemetry (such as failed login attempts when logged), and similar operational signals.
- Support & survey content: information you volunteer when contacting support or responding to surveys.
We may derive aggregated or de-identified datasets that cannot reasonably identify you and use them for analytics, benchmarking, product improvement, or research.
Recording, transcripts & AI-assisted features. Where the Services allow call recording, transcripts, summaries, or similar AI-assisted communication features, your organization is typically responsible for obtaining and documenting any notices and consents required under applicable wiretap, employment, telecom, or privacy laws. DialNext processes associated audio, text, or model outputs strictly to provide or secure those features (and as described in supplemental in-product notices where provided)—not to independently judge whether a particular communication may lawfully be recorded or monitored.
5. Sources
We collect personal information from:
- You directly (forms, settings pages, chat/support interactions);
- Your devices when you use our web application;
- Telecommunications carriers and communications APIs—primarily so we can originate/terminate calls and SMS/MMS on your behalf (for example through carriers such as Twilio or successors);
- Workspace administrators who invite users or configure integrations that transmit data into DialNext systems;
- Payment processors (for billing confirmations and fraud-prevention signals necessary to complete transactions).
6. How we use personal information
We process personal information to:
- Provide, operate, maintain, secure, monitor, support, and improve the Services;
- Authenticate users, authorize workspace roles, enforce acceptable-use restrictions, investigate misuse, and prevent fraud or unlawful activity;
- Route voice sessions and SMS/MMS traffic, correlate conversations with workspace threads, surface contact context, and generate billing or usage accounting tied to telecommunications vendors;
- Deliver realtime notifications within the application through messaging infrastructure such as Pusher channels tied to your workspace identifier (subject to configuration);
- Perform contractual billing through checkout flows hosted by payment processors such as Dodo Payments or successors, manage subscriptions, issue receipts, collect taxes where applicable, and communicate billing messages;
- Provide administrative notices (such as policy updates or security alerts), transactional messaging necessary to the Services, and—where permitted—marketing communications you can opt out of;
- Comply with law, lawful regulatory demands (when narrowly validated), lawful emergency disclosure policies;
- Exercise or defend legal claims; enforce contracts (including collections); protect DialNext, users, or the public.
Where features labeled as artificial intelligence or summarization exist or are introduced, we process relevant communications content only as described in-product or in supplemental notices (such notices govern when there is a conflict). Absent explicit disclosure, do not assume recordings are monitored by humans.
7. Legal bases (EEA/UK/Switzerland visitors)
Where GDPR or comparable frameworks apply, we rely on one or more of the following legal bases: (i) performance of a contract with you or your organization; (ii) legitimate interests that are not overridden by your rights (for example securing our networks, preventing abuse, analytics with appropriate safeguards); (iii) consent where required (such as certain cookies/marketing); (iv) compliance with legal obligations.
You may withdraw consent where processing is consent-based without affecting prior lawful processing.
9. International transfers
DialNext operates globally enabled infrastructure and may process personal information in the United States or other countries where we or subprocessors maintain facilities—possibly with different data-protection laws than your home jurisdiction.
Where required (for example EEA/UK/Switzerland transfers to countries without adequacy decisions), we implement appropriate safeguards such as Standard Contractual Clauses, supplementary measures where mandated by regulators, or other lawful transfer mechanisms together with organizational and technical protections.
You may request copies of relevant safeguards by emailing privacy@dialnext.io.
10. Retention
We retain personal information only as long as necessary for the purposes described above, unless a longer period is required or permitted by law. Factors influencing retention include whether data is needed to provide active Services, satisfy telecom billing/settlement obligations, defend legal claims, comply with lawful governmental retention mandates, or maintain backups securely isolated with bounded restoration windows.
Workspace administrators may be able to delete or export certain categories of Customer Contact content consistent with product capabilities and contractual commitments.
When retention periods expire, we delete or irreversibly de-identify personal information according to documented schedules subject to technical limits (for example immutable backups rotating off on defined schedules).
11. Security
We implement administrative, technical, and organizational controls appropriate to the risk—including encryption in transit where applicable to web sessions and APIs, access controls tied to workspace roles, credential hashing, vendor diligence, monitoring, least-privilege engineering practices, and incident-response procedures.
No internet-connected system is perfectly secure; you are responsible for safeguarding passwords, MFA tokens where enabled, and devices used to reach the Services.
12. Your privacy rights & choices
Depending on jurisdiction, you may have rights to access, rectify, delete, restrict or object to certain processing, obtain portability of machine-readable personal information you supplied, lodge complaints with supervisory authorities, or withdraw consent where processing relies on consent.
EEA/UK/Switzerland: contact privacy@dialnext.io. You may also complain to your local supervisory authority.
United States state privacy laws: Residents of states with comprehensive privacy statutes (for example California, Colorado, Connecticut, Utah, Virginia, and others as enacted) may have additional rights regarding access, deletion, correction, portability, and opt-out of certain sharing/sale as defined locally. Submit requests via privacy@dialnext.io. We will verify requests consistent with law (you may designate an authorized agent where permitted).
California (CPRA) summary: California residents may request categories/specific pieces of personal information collected, deletion, correction, and details about disclosures. We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising as defined under the CPRA. Where regulators recognize broader definitions of “sale” or “sharing,” see Section 8 above for opt-out posture.
Marketing opt-out: use unsubscribe links or email legal@dialnext.io. Transactional notices may continue where legally permitted.
We do not knowingly engage in profiling producing legal or similarly significant effects without appropriate safeguards and disclosures where required.
14. Children
DialNext is not directed to individuals under 16 (or higher age thresholds where mandated locally). We do not knowingly collect personal information from children. Contact us at privacy@dialnext.io if you believe we collected such data inadvertently so we can delete it promptly subject to verification.
15. Third-party links
Our sites may reference integrations or linked destinations operated independently. Their privacy statements—not this Policy—govern personal information collected there.
16. Changes to this Policy
We may revise this Privacy Policy periodically. Material updates may be communicated via in-product notices, email (when appropriate), or posting an updated effective date. Continued use after the effective date constitutes acceptance unless objection rights arise under applicable law.
17. Contact
Questions about this Privacy Policy: privacy@dialnext.io
Written correspondence may also be mailed to DialNext Inc., [Insert principal business address], attn: Privacy.