Privacy Policy
How ISPbills collects, uses, shares, protects, and retains information across our website, cloud platform, support, and connected services.
We do not sell Customer Data. Customers retain ownership of subscriber and operational data. We process that data to provide the Services and do not use it to train shared AI models.
01Scope and our role
This Privacy Policy applies to ISPbills websites, hosted software, applications, APIs, trials, demos, support, career applications, and related services. It does not govern a customer’s own subscriber privacy practices or third-party sites and integrations with separate policies.
For account, website, sales, and business-contact information, ISPbills generally acts as controller. When an ISP customer submits subscriber, billing, or network information and instructs us to process it, the customer generally acts as controller and ISPbills acts as processor or service provider. A data-processing agreement or customer contract may define these roles further.
02Information we collect
Account and business information
Name, business name, role, address, email, phone number, country, account identifiers, authentication methods, plan, billing contact, and communication preferences.
Customer and subscriber content
Information customers choose to store or connect, such as subscriber identities and contacts, service plans, invoices, payments, tickets, RADIUS and session records, device inventory, IP addressing, configurations, network events, NetFlow, sFlow or IPFIX telemetry, DNS or security policies, logs, and uploaded files.
Payment and transaction information
Invoices, amounts, currency, payment status, gateway references, and limited transaction metadata. Card or wallet credentials are normally collected directly by the selected payment provider, not stored by ISPbills unless explicitly disclosed.
Support, security, and usage information
Intercom conversations, Zendesk tickets, emails, call or messaging details, attachments, troubleshooting evidence, login and audit events, IP address, browser and device details, session identifiers, feature activity, performance, crash, and threat information.
Career information
Role applied for, contact details, location, experience, profile links, application message, CV, and an optional photo. Application attachments submitted through the public careers form are temporarily handled for delivery to the Careers mailbox and removed from website upload storage after delivery.
03Sources of information
We receive information directly from users and customers; automatically from browsers, applications, APIs, and connected infrastructure; from authorized team members, resellers, or implementation partners; and from service providers such as identity, payment, support, analytics, security, and communications platforms. We may also use lawful public business sources to maintain company records or prevent fraud.
04How we use information
- Provide, configure, operate, and support the Services.
- Authenticate users, enforce permissions, and secure accounts and infrastructure.
- Process customer instructions, billing, payments, messages, and network workflows.
- Monitor availability, diagnose faults, prevent fraud and abuse, and preserve audit evidence.
- Respond through Intercom, Zendesk, email, WhatsApp, or another requested channel.
- Improve usability, reliability, documentation, and product performance.
- Administer subscriptions, trials, careers, partnerships, and customer relationships.
- Meet legal, tax, accounting, sanctions, and regulatory obligations.
- Send service notices and, with required permission, product or marketing communications.
05Legal bases
Where a legal basis is required, we process personal data to perform a contract or take requested pre-contract steps; comply with legal obligations; pursue legitimate interests such as security, service improvement, fraud prevention, and business administration; protect vital interests in an emergency; or act with consent. Consent may be withdrawn at any time without affecting earlier lawful processing.
06Customer and subscriber data
Customers decide what subscriber and network data enters ISPbills, why it is processed, which users can access it, and how long it should be kept within available settings. Customers are responsible for their privacy notices, lawful basis, access controls, response to subscriber requests, and instructions to ISPbills.
We do not sell Customer Data or use it for unrelated advertising. We access Customer Data only when needed to provide support, maintain security and reliability, follow documented instructions, or comply with law. Authorized personnel and providers are subject to confidentiality obligations.
07AI-assisted features
When a customer enables AI-assisted features, relevant prompts, selected records, tool results, and operational context may be processed to produce the requested response or action. Customer controls what it submits and should not include information unnecessary for the task. ISPbills does not use Customer Data to train shared AI models. Provider-specific processing, retention controls, and regional availability may be described in the applicable feature or agreement.
AI output can be incomplete or incorrect. Approval controls, allowlists, permissions, and change review should be used before actions affecting subscribers, routing, billing, or network infrastructure.
09International transfers
ISPbills and its providers may process information in countries other than where a user or customer is located. Privacy laws may differ. Where required, we use contractual protections, provider commitments, access controls, and other recognized transfer mechanisms. Managed deployment region and data-residency requirements should be agreed during ordering; not every feature is available in every region.
10Retention and deletion
We keep information only as long as reasonably necessary for the Service, the customer’s instructions, security, dispute resolution, and legal, accounting, or tax duties. Retention depends on the data and deployment:
- Account and Customer Data are generally kept while the account is active and for a limited wind-down or export period afterward.
- Invoices, payment records, contracts, and audit evidence may be retained for legally required periods.
- Security and diagnostic logs are retained according to operational need, plan, and configuration.
- Backups rotate on managed schedules, so deleted information may remain protected in backup copies until overwritten.
- Career applications are retained only as needed to evaluate the role, maintain recruitment records, and resolve legal issues.
Customers should export required data before closing an account. We may retain de-identified or aggregated information that no longer identifies a person or customer.
11Security
We use administrative, technical, and organizational safeguards designed for the nature of the information, including encrypted connections, tenant and role scoping, authentication controls, audit records, backup workflows, monitoring, and restricted provider access. Managed cloud workloads are hosted on Microsoft Azure. Details and responsible-disclosure contact information are available on our Security page.
No system is completely secure. Customers must protect credentials, maintain appropriate user roles, secure connected devices and API access, and report suspected incidents promptly.
12Rights and choices
Depending on location and applicable law, a person may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and may complain to a data-protection authority. We may verify identity and retain information where an exception applies.
For data controlled by an ISPbills customer, contact that customer first. We will assist the customer with verified requests as required by contract and law. For information controlled by ISPbills, email [email protected]. Account users can also update certain details and preferences within the Service.
14Children
ISPbills is a business service and is not directed to children. We do not knowingly collect personal data directly from a child who cannot lawfully consent. Customers are responsible for ensuring that subscriber data they process through ISPbills is lawful, including where it relates to minors. Contact us if you believe a child submitted information directly to ISPbills without appropriate authorization.
15Policy changes
We may update this Policy to reflect product, provider, legal, or operational changes. The current date appears on this page. Material changes will be communicated through the website, Service, or account contact where appropriate. Earlier versions may be requested where records are available.
16Contact us
Questions, requests, or complaints about privacy can be sent to [email protected] or submitted through our Contact page.