Privacy Policy
Last updated: April 13, 2026 | Effective Date: April 13, 2026
1. Introduction
DataFrontier Inc. ("DataFrontier," "we," "us," or "our") operates the Mission Control AI Revenue Operating System ("ASOC," "Platform," or "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform, website (https://datafrontier.co), and related services.
We are committed to protecting the privacy of our users, their prospects, and end consumers. This policy complies with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA/CPRA), Telephone Consumer Protection Act (TCPA), CAN-SPAM Act, and other applicable data protection laws worldwide.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, company name, job title, phone number, billing information.
- Lead/Prospect Data: Names, phone numbers, email addresses, company information, job titles, and other business contact information you upload or import into the Platform.
- Call Data: Call recordings (with consent), call transcripts, disposition codes, agent notes, meeting details.
- Communication Content: Email templates, SMS messages, WhatsApp messages sent through the Platform.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, click patterns, session duration.
- Device Information: Browser type, operating system, IP address, device identifiers.
- Telephony Metadata: Call duration, call status, DID (phone number) used, area codes, timestamps, answering machine detection results.
- Cookies and Tracking: See our Cookie Policy for details.
2.3 Third-Party Sources
- Lead Enrichment: Business contact data from Apollo.io, LinkedIn, and similar providers.
- Authentication: Identity data from Clerk (Google, Microsoft, LinkedIn SSO).
- Telephony: Call metadata and recordings from our telephony provider.
3. How We Use Your Information
- Provide, operate, and maintain the Platform and its features.
- Process outbound calls, emails, and messages on behalf of our users.
- Generate AI-powered analytics, call summaries, and coaching insights.
- Enforce Do-Not-Call (DNC) and Do-Not-Dial (DND) compliance lists.
- Monitor call quality, detect voicemails via AMD, and optimize DID rotation.
- Record calls with appropriate consent for quality assurance and compliance.
- Send transactional communications (account alerts, system notifications).
- Improve our services through anonymized, aggregated analytics.
- Comply with legal obligations, including TCPA, GDPR, and STIR/SHAKEN attestation.
4. Legal Bases for Processing (GDPR)
- Contract Performance: Processing necessary to provide the Platform to you.
- Legitimate Interest: Business analytics, security monitoring, fraud prevention.
- Consent: Call recording, marketing communications, cookie tracking.
- Legal Obligation: DNC compliance, tax records, law enforcement requests.
5. Call Recording & Consent
Our Platform enables call recording for quality assurance, training, and compliance purposes. We adhere to the following practices:
- All call recordings are initiated only when the recording feature is enabled by the user organization.
- Users are responsible for ensuring appropriate consent is obtained in accordance with applicable state, federal, and international laws (including two-party consent states).
- Recordings are stored securely on our telephony provider's infrastructure and are accessible only to authorized personnel.
- Recordings may be transcribed using AI for quality assurance and coaching purposes.
- Prospects may request deletion of their recorded calls — see Opt-Out & Data Deletion.
6. Data Sharing & Disclosure
We do not sell your personal information. We may share data with:
- Service Providers: Telnyx (telephony), Clerk (authentication), OpenAI (AI processing), Pusher (real-time), PostgreSQL hosting providers — all bound by data processing agreements.
- Your Organization: Admins and supervisors within your organization may access call data, recordings, and agent analytics.
- Legal Requirements: When required by law, regulation, legal process, or governmental request.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
7. International Data Transfers
Data may be transferred to and processed in the United States and other countries. We use Standard Contractual Clauses (SCCs) and ensure adequate safeguards for international transfers in compliance with GDPR Chapter V.
8. Data Retention
- Account Data: Retained while your account is active, plus 30 days after deletion.
- Call Recordings: Retained for 90 days by default, configurable per organization.
- Call Metadata & Dispositions: Retained for 2 years for analytics and compliance.
- DNC Lists: Retained indefinitely to ensure ongoing compliance.
9. Your Rights
GDPR Rights (EEA/UK)
Right to access, rectify, erase, restrict processing, data portability, object to processing, and withdraw consent. Contact: privacy@datafrontier.co
CCPA/CPRA Rights (California)
Right to know, delete, correct, opt-out of sale/sharing, and non-discrimination. We do not sell personal information.
TCPA Rights
Prospects may request to be added to our internal Do-Not-Call list at any time. See Opt-Out.
10. Security
We implement industry-standard security measures including encryption in transit (TLS 1.3) and at rest (AES-256), role-based access controls, audit logging, and regular security assessments. Our telephony infrastructure uses STIR/SHAKEN attestation for caller ID authentication.
11. Children's Privacy
The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days before taking effect.
13. Contact Us
DataFrontier Inc.
Email: privacy@datafrontier.co
Website: https://datafrontier.co
For GDPR inquiries, contact our Data Protection Officer at dpo@datafrontier.co
