Legal

Privacy Policy

NocTel Communications, Inc. · Washougal, Washington

We don’t care for trying to glean every little detail about you for something you’re not okay with – that’s crummy and we’re not data brokers. NocTel respects your data and privacy, but there are often reasons we request or require various types of personal data. We’d like you to trust we’re doing the right thing, but it’s not exactly easy if we can’t explain what we’re doing with your information. This page will walk you through how we collect, store, handle, and share personal data in plain language – we’re not fond of overly complicated terms and explanations, so we’re willing to bet you aren’t either.

As an existing, potential, or former customer/end user; you have the right to object to data collection and processing that occurs on your personal data at any time. Objection to data collection and processing can be voiced by contacting NocTel Support via phone, written notice, or a ticket submission sent to support@noctel.com. For objections sent via email, please include your organization’s name and “Objection to Data Processing” in the subject line. If you object to data processing in response to an email received by NocTel for direct marketing, the objection will be processed expediently and without question.

Types of personal data collected

Purpose of collected personal data

Retention of personal data

Who can access personal data

While we’d be happy if we had written every aspect of what makes NocTel work ourselves, we sadly didn’t. As a result, NocTel leverages several third parties to help us out. In particular these parties are:

Personal data that resides on NocTel systems and hardware are accessed by the minimum relevant staff on a legitimate need to know basis. This means someone in marketing cannot simply go peek at what other organizations you’re calling, nor can they go listen to your voicemail. Access to personal data is also handled on a minimum necessary duration basis. If we have no reason to access it, we aren’t.

NocTel engineers have strict rules for interacting with personal data. Perhaps most relevant is the rule that NocTel engineers shall not tamper with or create copies of personal data. Modifications may be made, but must be logged with valid reason that demonstrates legitimate purpose to enforce accountability.

Consent and opting in for collection and processing of personal data

NocTel is a business-to-business service provider and in reference to GDPR law, this designates us as a Data Processor relative to our customers. Generally, our customers (other organizations and businesses) assume the role of Data Controller. This means end user consent for data collection and processing are typically handled as organization policies and terms as the end users are representatives, associates, and staff.

Personal data collection and processing complaints in relation to individuals (“data subjects” under GDPR) and their personal data rights are recommended to be provided to NocTel from the customer organization, not the individual directly. This recommendation is in place to prevent NocTel from accommodating an individual’s request in relation to personal data rights that adversely affects the customer organization the individual belongs to. A simple example of this consequence would be a secretary requesting NocTel delete all reference of her name without notifying her employing organization. This would result in confusion for account administrators of the secretary’s organization who would then not be able to search for her extension in the NocTel control panel or being able to correctly identify her handset among potentially many in the account.

Potential and former customers

On the basis of potential customers and former customers, NocTel observes the following in regard to personal data consent:

Existing customers and end users

Personal data rights requests

NocTel recognizes and accommodates personal data rights requests with all due diligence and reason. We recommend personal data rights requests be sent to your associated organization and then provided to NocTel. The intent here is to prevent the potential for services to be impacted for our customer organizations and confusion the customer organization was not informed of an end user’s request.

For personal data rights requests that are received, where applicable NocTel will provide an impact of services disclosure to ensure the end user understands what fulfillment of the request entails and subsequent nontrivial changes that might occur to how they use NocTel’s services or its availability. A simple example of this in practice would be if a request were received by NocTel to not collect, store, or process an end user’s handset’s MAC address and IP address. NocTel would provide an impact of services notice explaining fulfilling this request would result in the end user no longer being able to receive or place calls on their designated handset. If the end user agrees and acknowledges this impact, NocTel will fulfill the request as received to accommodate the end user.

Revocation of a personal data rights request after being provided an impact of services notice where applicable is handled as explicit consent for NocTel to continue or resume collecting, storing, processing, and/or sharing the personal data in question. Personal data rights requests may also be nullified at the submitting individual’s request after being fulfilled, which has the same effect as revoking a yet to be fulfilled request.

Cookies & security

Policy changes may occur frequently into the future. Privacy is an important but big topic affecting us all that generally never stays put for very long. This page is intended to provide as much detail as possible without being exhaustive. If you have questions or concerns, don’t hesitate to reach out to us. See also our Terms of Use.