1. Data Processing Agreement (DPA)
Our Data Processing terms for business customers are incorporated into:
bOnline General Business Terms and Schedules, which govern the provision of our VoIP and related services
bOnline Privacy Policy, which sets out how we process personal data in line with UK GDPR and (where applicable) EU GDPR
These documents are available here: https://www.bonline.com/terms-privacy/
2. bOnline’s role – Data Processor
For call data generated by your use of the service, including:
Call metadata (e.g. calling and called numbers, timestamps, call duration), and
Optional call recordings and associated transcripts
bOnline generally acts as a Data Processor, processing this data on your documented instructions as the customer (Data Controller), for the purposes of providing and supporting the telephony service.
Separately, for data relating to our direct relationship with you as a customer (e.g. billing contact details, account administration), we act as a Data Controller, as described in our Privacy Policy.
3. Location of call data and recordings
Core call recordings
Call recordings are stored in Google Cloud Storage in the europe-west2 (London) region, i.e. in data centres located in the United Kingdom.
Storage buckets are restricted to access by a small, privileged group of authorised bOnline developers/staff for operational and support purposes.
Advanced Call Recordings – transcription
For customers who enable Advanced Call Recordings (AI transcription and related features):
Audio/recordings are securely transmitted to Deepgram, our speech-to-text provider, solely for the purpose of generating transcripts.
These customers are opted out of Deepgram’s Model Improvement Program, so audio and transcripts from your account are not used to train or improve Deepgram’s AI models.
Deepgram acts as a sub-processor under our data processing terms. They maintain SOC 2 and other data privacy/compliance certifications.
4. Encryption at rest
All customer data stored in Google Cloud Storage is encrypted at rest by default using Google-managed encryption keys. This is enforced at the storage layer and cannot be disabled.
Within our own implementation:
We rely on Google Cloud’s built-in encryption at rest, plus strict access controls and logging on our side.
Transport of audio and metadata between our systems, Google Cloud, and Deepgram is protected using TLS/HTTPS.
5. Retention of call recordings
Where you have chosen 12-month or 7 year call recording retention:
Call recordings are retained for 12 months or 7 years from the date of the call depending on the package,
After this period they are scheduled for deletion in line with our retention policy, so they are no longer accessible via the customer portal or our internal tools.
6. Sub-processors
For the telephony and call-recording components relevant to your query, the key sub-processors are:
Google Cloud Platform (GCP) – hosting and storage infrastructure for call recordings and related data. A current list of Google Cloud sub-processors is maintained here: https://cloud.google.com/terms/subprocessors
Deepgram – only where Advanced Call Recordings (transcription and AI features) are enabled. Deepgram’s data privacy and compliance information is available here: https://developers.deepgram.com/trust-security/data-privacy-compliance
We keep our sub-processor list under regular review and on our website.
