Privacy Policy
UK privacy notice for website visitors, business contacts and customers
Version 1.0
Effective date: 27 September 2026
1. Who we are
PRASMO LTD ("Prasmo", "we", "us") is registered in England and Wales under company number 17296533. Our registered office is 128 City Road, London, United Kingdom, EC1V 2NX. We provide wholesale voice, SIP trunking, business numbers, cloud phone and business messaging services to businesses, using our own systems and a number of network and messaging partners.
For the purposes described in this policy, Prasmo is the controller of your personal data. Where we process personal data on behalf of a business customer (for example, call recordings or voicemail in a hosted service), that customer is the controller and our Data Processing Addendum applies (see section 7).
Contact for privacy questions: info@prasmo.com.
2. Who this policy covers
This policy covers visitors to our website, people who contact us, prospective and current business customers and their staff, suppliers and partners, and people whose calls or messages pass through our network.
3. Personal data we collect
- Contact and identity information: name, job title, employer, business address, email and phone number.
- Onboarding and verification information: information about a customer's company, directors, owners and authorised persons, identity and address documents where required, intended use, and the results of company, credit, sanctions and fraud-prevention checks.
- Account, billing and contract information: orders, invoices, payment status and contract records, including records of who accepted our terms and when.
- Service and technical information: PBX or platform details, IP addresses, SIP configuration, requested numbers, destinations, traffic profiles and support records.
- Communications data: calling and called numbers, sender IDs, date, time, duration, routing information, location information for emergency calls, and similar records created when calls or messages pass through our network. We do not listen to or read the content of Communications, except where the law requires it or a customer asks us to help with a fault.
- Correspondence: emails, messages, and records of calls or meetings with us.
- Website information: IP address, browser and device information, pages viewed and cookie data (see our Cookie Policy).
- Marketing preferences: whether you have subscribed to our updates or opted out.
4. Where we get it
We collect personal data from you or your organisation, from people authorised to act for your organisation, from our network and messaging partners when they carry traffic, from verification, credit-reference and fraud-prevention services, from public sources such as Companies House, and through our website.
5. How we use it and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries and preparing quotations | Steps before a contract; legitimate interests |
| Verifying customers before and during supply (identity, company, credit, sanctions and fraud checks) | Legitimate interests in preventing fraud and misuse; legal obligations |
| Providing, configuring, supporting and billing for Services | Contract; legitimate interests (for customers' staff) |
| Connecting calls and messages, routing emergency calls with location information | Contract; legal obligations |
| Detecting and preventing fraud, nuisance calls, spoofing and misuse, including automated traffic controls | Legitimate interests; legal obligations |
| Responding to regulators, law enforcement and traceback requests | Legal obligations; legitimate interests |
| Keeping records of contracts and acceptance, and handling disputes and legal claims | Legitimate interests; legal obligations |
| Sending business updates and marketing | Consent where required; otherwise legitimate interests. You can opt out at any time |
| Improving our website and services | Legitimate interests |
We process communications data only as permitted by the Privacy and Electronic Communications Regulations 2003: to transmit communications, bill for them, prevent fraud and misuse, and comply with the law.
6. Automated fraud controls
To protect customers and networks, our systems may automatically restrict traffic that looks fraudulent or harmful, for example a sudden spike in calls to a high-risk destination. If this affects you, you can contact us and ask for a person to review it.
7. Call recording, transcription and AI features
Some of our Services let customers record, transcribe or analyse their own calls. The customer decides whether to use these features, what they are used for, and is responsible for giving callers the notices the law requires. We process this data on the customer's behalf under our Data Processing Addendum. If you have a question about a recording, please contact the organisation you spoke to.
8. Who we share it with
- Network operators, carriers, numbering providers and messaging platforms that connect and carry calls and messages.
- Hosting, infrastructure, security, CRM, verification and other technology providers.
- Credit-reference, identity-verification and fraud-prevention services.
- Professional advisers, auditors, insurers, banks and payment providers.
- Ofcom, the ICO, other regulators, the emergency services, law enforcement and courts, where the law requires it or it is needed to prevent fraud or misuse.
- A buyer, investor or successor in a genuine corporate transaction, with appropriate safeguards.
We do not sell personal data.
9. International transfers
Some of our network and messaging partners are based outside the UK, including in the United States and the European Union. Calls and messages to international destinations also necessarily pass to networks in those countries. Where UK law requires safeguards for a transfer, we use [TO CONFIRM: mechanism for each partner, e.g. UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or the UK International Data Transfer Agreement / Addendum]. You can ask us for more information about these safeguards.
10. How long we keep it
| Record | Retention |
|---|---|
| Enquiries that do not lead to a contract | [TO CONFIRM] |
| Customer account, contract and acceptance records | [TO CONFIRM] after the contract ends |
| Verification (KYC) records | [TO CONFIRM] after the relationship ends |
| Call and message detail records | [TO CONFIRM] |
| Invoices and accounting records | [TO CONFIRM] |
| Misuse and investigation records | [TO CONFIRM] |
| Marketing preferences | Until you opt out, then kept as a suppression record |
We may keep data longer where needed for a legal claim, investigation or legal requirement.
11. Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration. No system is completely secure.
12. Your rights
Subject to the law, you can ask to access, correct or erase your personal data, restrict or object to its use, receive it in a portable format, and withdraw consent where we rely on it. You can object to direct marketing at any time. To use a right, email info@prasmo.com. We may need to verify your identity.
13. Complaints
Please contact us first at info@prasmo.com so we can try to resolve your concern. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
14. Cookies
See our Cookie Policy for the cookies and similar technologies we use and how to control them.
15. Changes
We may update this policy. The current version is published on our website with its effective date.
PRASMO LTD · Registered in England and Wales · Company number 17296533 · 128 City Road, London, United Kingdom, EC1V 2NX · Privacy: info@prasmo.com