Legal
Privacy policy
Last updated 1 September 2026. Terms of service
Two different people are described here
NexDial operates NexDial, a hosted outbound calling platform used by businesses to run their own calling campaigns. That means two quite different relationships, and mixing them up is the usual failure of a policy like this one.
If you hold an account with us — you signed up, you sign in, you are billed — then we decide what to do with your account information, and this policy describes that directly.
If you were called by one of our customers — your number was on a list somebody uploaded, an agent spoke to you, the call may have been recorded — then that business decides why you were called and what is kept about you. They are the controller of that data. We hold and process it on their instructions, as their processor, and we cannot lawfully hand it over, correct it or delete it on our own initiative. If you want your record removed, or a recording deleted, the fastest route is to ask the business that called you. If you do not know who that was, write to privacy@nexdial.example and, where we can identify the account from the number that called you and the time, we will pass your request to them and tell you we have.
What we hold about an account
- Who you are
- Company name, the name, work email address and phone number of each person you give a sign-in to, their role on the account, the country and time zone you chose, and a hashed password. We never store a password we could read.
- How the account is used
- Sign-in times and IP addresses, the pages and actions an audited event covers, agent status changes, and a record of who listened to or downloaded a recording. Some of this exists precisely so that access to other people's data is attributable to a named person.
- Your calling
- For each call: the numbers at both ends, when it started and ended, how long it was connected, the outcome your agent recorded, the campaign and list it belonged to, and what it cost. Recordings, where you have recording switched on.
- Your contacts and lists
- The files you upload and the records created from them — names, numbers, addresses, whatever columns you chose to map — plus the notes, dispositions and follow-ups your agents add. This is the data you are the controller of.
- Money
- Your wallet balance and every transaction behind it, invoices, top-up requests and the proof of payment you upload for a manual or crypto top-up. Card numbers are never sent to us: an automatic card payment happens on the gateway's own page, and what comes back to us is a reference, an amount, a status and at most the last four digits.
- Carrier credentials
- The keys and secrets for the telephony provider you connect, encrypted at rest and readable only by the account they belong to. They are never displayed again after you save them and never appear in an export.
Why we hold it
- To run the service you asked for: placing calls, storing their outcome, showing you the reports.
- To bill you, and to be able to show you the individual calls behind any figure on an invoice.
- To keep the platform secure and to work out what happened when something goes wrong — which is what the sign-in and audit records are for.
- To reply to you when you write to us, and to send the account notices a customer needs to receive: a low balance, a payment refused, a top-up approved.
- To meet our own tax and accounting obligations, which is why financial records outlive an account.
We do not sell your data, we do not sell or share your contact lists, and we do not use anything you upload to train anything. There is no advertising on this platform and no advertising trackers in it.
Call recording
Recording is a setting on each account, and where it is on, calls are recorded to storage the operator controls — a private disk or an S3-compatible bucket — and the copy held by the carrier is discarded once the file has been fetched. Recordings are never served from a public address: playback goes through a permission check, and the check writes down who listened to what and when.
Whether a call may be recorded, and whether the person on the other end has to be told first, depends on where both parties are. That decision belongs to the business making the call, not to us, and the platform provides the notice and consent tooling rather than the judgement. If you operate an account, this is yours to get right.
Who else sees it
Only where the service cannot be delivered otherwise, and never for their own purposes:
- The carrier you connect
- Necessarily receives the number being dialled, the caller ID you present and the audio of the call, because it is the one placing it. That is your account with them, on your terms, and their handling of it is governed by their agreement with you rather than ours.
- Payment gateways
- Receive the amount, a reference and whatever they need to take the payment. Which gateways are enabled is an operator setting; a card is entered on their page, not on ours.
- Hosting and infrastructure
- The servers, database, object storage and email delivery this install runs on. Where that is depends on the operator; for the hosted service it is the region stated on your order.
- When we are made to
- A lawful order compelling disclosure. Where we are permitted to tell you first, we will.
How long it is kept
The two figures below are read from this installation's own configuration — the same values the scheduled pruning commands act on — so they describe what this system does rather than what a default policy says.
- Call recordings
- Deleted 365 days after the call, by a nightly job. Deleting a recording early is available to you at any time and takes effect immediately.
- Uploaded list files
- The original CSV is kept for 365 days after it has been imported, so a mis-mapped column can be diagnosed against the file it came from, and is then deleted. The contact records created from it are unaffected and remain yours to keep or remove.
- Calls, contacts, notes and dispositions
- Kept for as long as the account is open, because they are the account. You can delete a contact, a list or a campaign at any time.
- A closed account
- Data is retained for 30 days after closure so an account reopened by mistake or in a hurry is not a loss, and is then deleted. Ask us within that window and we will delete it sooner or export it to you.
- Invoices, wallet transactions and payment records
- Kept for as long as tax and company law requires us to keep books, which is longer than the rest and is not something we can shorten on request.
- Security and audit records
- Sign-in history and audited actions are kept for 12 months. They are the record of who did what, so they cannot be edited from inside the application by anyone, including us.
How it is protected
- Traffic is served over HTTPS, and the application refuses to place a payment callback on an address that is not.
- Passwords are hashed, never stored in a readable form and never sent to you in an email.
- Carrier and gateway credentials are encrypted at rest, are not displayed again once saved, and are stripped from the stored copy of any callback that echoes them back at us.
- Every record belonging to an account carries that account, and the filter is applied by the data layer rather than by each screen remembering to ask — so a query written carelessly returns nothing rather than returning everybody's.
- Recordings and uploaded lists live on private storage and are reached only through a request that re-checks permission and records who made it.
- Access inside our own team is limited to the people who need it to run the service and is logged like anybody else's.
No system is beyond compromise, and a policy that claimed otherwise would not be worth reading. If we discover a breach affecting your data we will tell you what happened, what was affected and what we have done, without waiting to be asked.
Your choices
If you hold an account, most of this is in your hands already: you can read, correct and export your account data and your contact records from inside the application, delete a recording, close a list, or remove a user. Where you would rather we did it, or where you want something we have not built a button for — a copy of everything, deletion ahead of the retention window, an objection to a particular use — write to privacy@nexdial.example. We answer within 30 days and usually much sooner.
Depending on where you live you may have a statutory right of access, correction, deletion, portability or objection, and a right to complain to a supervisory authority. We do not ask you to give any of those up, and we do not charge for exercising them.
If you were called by one of our customers, see the second paragraph of this policy: the business that called you decides what happens to your record, and we will pass your request to them.
Cookies
Two, and both are necessary: a session cookie that keeps you signed in, and a token that stops a form on another site being submitted as you. There is no advertising cookie, no analytics cookie and no third-party script on these pages, which is why there is no consent banner in front of them.
Children
This is a tool for businesses. It is not offered to children and we do not knowingly hold an account for one.
Changes to this policy
The date at the top moves when the substance changes, and not when a paragraph is reworded — a date that moved on every deployment would teach you to ignore it. Where a change materially affects what we do with your data, account holders are told through the application and by email before it takes effect.
Who to write to
Privacy questions, requests and complaints:
- privacy@nexdial.example
- Anything else: support@nexdial.example
- +92 21 1111 2222
- NexDial, Karachi, Pakistan
Next: the terms of service, which cover what you may use the platform for and who is responsible for the calls placed through it.