This policy explains what data Ringfence collects when you use our voice call compliance monitoring platform, how we use it, and the rights you have over it. It applies to Ringfence's customers (the businesses using our platform) and, where relevant, to the individuals whose calls are monitored on a customer's behalf.
Call audio, transcripts, and any content derived from them are never used to train, fine-tune, or improve any machine learning model — ours or a third party's. This applies without exception, including to customers on trial or free-tier evaluation. Your call data is used exclusively to run the rule checks you've configured and to generate your audit trail. If we ever change this policy, it will require opt-in consent from existing customers, not a silent update to these terms.
We do not collect payment card data directly — billing is processed by a PCI-DSS Level 1 compliant payment processor, and Ringfence never stores full card numbers.
Default retention for transcripts and flagged-segment audio is 90 days (Starter), 1 year (Growth), or a custom window up to 7 years (Enterprise), configurable within your plan. Full-call audio beyond flagged segments is retained only if enabled on your account. Upon account cancellation, data remains available for export for 30 days, after which it is permanently deleted from production systems within 14 additional days and from backups within 45 days.
We use a limited set of sub-processors for infrastructure (cloud hosting), transcription, and payment processing. A current list of sub-processors is available on request to support@ringfence.tech. Any new sub-processor with access to call content is announced to customers at least 14 days before it takes effect, with an objection window.
If you or the individuals whose calls are monitored are located in the European Economic Area, you have the right to:
Because Ringfence typically processes call data on behalf of our customers (the business running the call floor) rather than the individual callers directly, requests concerning a specific caller's data should generally be directed to that business first. We support our customers in fulfilling these requests within the required timelines.
California residents have the right to know what personal information is collected, request deletion, opt out of the sale of personal information (Ringfence does not sell personal information, and never has), and not receive discriminatory treatment for exercising these rights. Requests can be submitted to privacy@ringfence.tech.
Where data is transferred outside the region it was collected in, we rely on Standard Contractual Clauses or an equivalent approved transfer mechanism. Enterprise customers may request data residency within a specific region as part of their contract.
We'll notify active customers by email at least 30 days before any material change to this policy takes effect. Continued use of Ringfence after that date constitutes acceptance of the updated policy.
Questions about this policy or requests regarding your data can be sent to privacy@ringfence.tech. For general support, use support@ringfence.tech.