Skip to content
TISA Business

TISA Business

Business Privacy Policy

How we handle personal data when your business uses Cloud PBX, Business SIMs, the Pocket Office SIM, business broadband or business messaging. This is the business notice. It is complete on its own and it does not send you to the personal policy.

Updated
8 September 2026
Controller
9Eons Limited, company 06393882
Data protection
[email protected]
Regulator
ico.org.uk
Contents

Contents

  1. 1Who we are, and how to reach us
  2. 2When you are the controller, not us
  3. 3What we collect
  4. 4Why we process it, and on what basis
  5. 5Call recordings and voicemail
  6. 6Who we share it with
  7. 7Where it is held, and transfers
  8. 8How long we keep it
  9. 9How we protect it
  10. 10If something goes wrong
  11. 11Profiling and automated decisions
  12. 12Marketing
  13. 13Your rights
  14. 14Complaints
  15. 15Changes to this policy
1

Who we are, and how to reach us

TISA Business is the business division of TISA, operated by 9Eons Limited, registered in England and Wales, company number 06393882, VAT number GB 920 145 856. Registered address: Luminous House, 300 South Row, Milton Keynes, MK9 2FR, United Kingdom.

For the services described in this notice, 9Eons Limited is the data controller except where clause 2 says otherwise.

Data protection enquiries[email protected]
General enquiries[email protected]
Telephone01908 737 500
Post9Eons Limited, Luminous House, 300 South Row, Milton Keynes, MK9 2FR

We comply with UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and applicable Ofcom and ICO guidance.

2

When you are the controller, not us

This is the part a business buyer needs first, and it is the part a general privacy policy does not cover. Your contract with us already sets it out; this states it plainly.

ActivityWho is the controllerWhat it covers
Business messaging, and any service where you supply recipient dataYou are the controllerYou must have a lawful basis, including consent where it is required, to share that data with us. We are your processor.
Account managementTISA is the controllerYour account, your users and your contacts, held so we can run the service you bought.
BillingTISA is the controllerInvoices, payments and the records we are required to keep.
Service deliveryTISA is the controllerProvisioning, routing, support and the technical records that make the service work.

Where we are your processor

A Data Processing Agreement governs that processing. It forms part of your business terms and is available on request. It includes audit rights, so you or your representative can verify our compliance, subject to reasonable notice and confidentiality. We may engage sub-processors to deliver the service. We keep an up to date list, available on request, and we impose equivalent data protection obligations on all of them.

3

What we collect

What we hold depends on which services you take and how your team uses them.

CategoryExamples
Business and account detailsCompany name, registered address, company number and VAT number where they apply, Account Administrator contact details, the identity verification we carry out at registration.
Users and accessExtension numbers, login identities, the organisation a user belongs to, profile name, administrator permissions.
Contacts and presenceSynchronised work contacts and colleague availability, so that calling and presence work inside the apps.
Call detail recordsCalling and called numbers, timestamps, duration and signalling metadata, used for routing, delivery, billing, security and the records we must keep by law.
Voicemail and call recordingsStored voicemail, and call recordings where you have enabled them on an extension.
Device and connectionIP address, device identifiers and SIP user agent, used to keep an encrypted session connected.
Billing recordsInvoices, payment method details held by our payment providers, and payment history.
Support correspondenceEmails, messages and call notes you send us so we can answer a technical, billing or account question.
Website useWhat the business pages store in your browser is set out separately in the business cookie policy.

We do not process the personal data of people outside your organisation beyond what is technically necessary to set up and route a call.

4

Why we process it, and on what basis

PurposeLawful basis
Providing the telephony, mobile, broadband and messaging services you have bought, authenticating users and giving accessPerformance of the contract, UK GDPR Article 6(1)(b)
Billing, credit control and the recovery of debtPerformance of the contract, and our legitimate interests in being paid, Article 6(1)(b) and 6(1)(f)
Network security, fraud prevention and service logsOur legitimate interests in protecting the network and our customers, Article 6(1)(f)
Regulatory compliance, including Ofcom obligations, tax records and the Investigatory Powers Act 2016Legal obligation, Article 6(1)(c)
Optional call recordingConsent, Article 6(1)(a), controlled by you on each extension
Marketing to business contactsConsent, Article 6(1)(a), and PECR. See clause 12.

Where we rely on consent you may withdraw it at any time, and that does not affect processing lawfully carried out before you withdrew it.

5

Call recordings and voicemail

Cloud PBX includes 1 GB of call recording storage on every account, kept for 30 days. Larger retention tiers are available if you need recordings kept longer, and they are priced in the schedule of charges.

Recordings and voicemail are stored in the UK region only and are encrypted at rest using AES-256-GCM.

Recording other people carries obligations that sit with you, as the business operating the phone system: telling callers, having a lawful basis, and handling any request for a copy. Where sensitive information is discussed, such as payment card details, recording should be paused. We provide the facility and the storage. How it is used on your extensions is your decision.

6

Who we share it with

We share personal data only where it is necessary to deliver the service, where the law requires it, or with your own administrators.

  • Your administrators. The people you designate can see account level data relevant to administration and billing.
  • Infrastructure providers. Amazon Web Services, in UK regions, hosts the platform. Data is stored and processed in the United Kingdom.
  • Network and delivery partners. Mobile services run on the EE network. Message delivery partners carry business messages to the recipient network.
  • Payment providers. Card and direct debit processing is carried out by regulated payment providers, who hold the payment details rather than us.
  • Law enforcement and regulators. Where we are required by law to disclose, including under the Investigatory Powers Act 2016. We are prohibited from disclosing the existence of a specific warrant or notice.

We do not sell personal data, and we do not share it for anyone else to market to you.

7

Where it is held, and transfers

Data is held primarily in the United Kingdom and the EEA, and the platform runs in UK regions. We do not routinely transfer personal data outside the United Kingdom.

Where a transfer outside the UK becomes necessary, we use UK Standard Contractual Clauses or the UK International Data Transfer Agreement, an adequacy decision, or binding corporate rules, and we will tell you where we are required to.

8

How long we keep it

WhatHow long
Call detail records90 days
Voicemail90 days
Call recordings30 days on the included 1 GB tier, or the period of the storage tier you have bought
Business account data after the contract ends24 months, unless the law requires longer
Billing and tax recordsAs long as tax law requires
Your data after terminationA 30 day window to retrieve it, after which it is securely deleted

Call detail records and business account data are different categories with different periods. After the relevant period expires, data is securely deleted or anonymised.

9

How we protect it

  • In transit. TLS for signalling, and SRTP is compulsory for audio and media.
  • At rest. AES-256-GCM for stored data, including recordings and voicemail held in the UK region.
  • Access. Least privilege, separation between customers, and logging of administrative access.
  • The network. The measures required by the Telecommunications (Security) Act 2021 and the Electronic Communications (Security Measures) Regulations 2022, described in clause 22 of the business terms.

No system is completely secure. Keep your credentials confidential and tell us promptly if you suspect unauthorised access.

10

If something goes wrong

There are two clocks, and they are different.

To the regulator72 hours to notify the ICO of a breach posing a risk to rights and freedoms.
To you, where we are your processor48 hours from becoming aware of a breach affecting your data.

Where a breach is high risk to you, we notify you directly and without undue delay, whichever role we are in.

11

Profiling and automated decisions

We do not make decisions about you by automated means that produce legal effects or similarly significant effects. We do not profile you for advertising, and we do not use your calling, messaging or account data to build a marketing profile.

12

Marketing

In compliance with PECR we send marketing only where you have opted in. Every message carries a way out: reply STOP to a text, or use the unsubscribe link in an email. You can also opt out by contacting Business Support. Opting out does not stop the essential service messages we have to send you, such as a notice about your bill or an outage.

13

Your rights

Under UK GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict how we process it, to object to processing, to portability, and to withdraw consent where processing relies on consent.

To exercise any of them, write to [email protected], copying [email protected]. We respond within 30 days. We may need to verify your identity, and where the request concerns data held under a business account we may need to confirm it with your Account Administrator.

If you are asking about data that your business controls, for example the recipients of your own messaging campaigns, the request belongs to you rather than to us. We will help you answer it under the Data Processing Agreement.

14

Complaints

If you are unhappy with how we have handled your personal data, tell us first at [email protected] so we have the chance to put it right.

You also have the right to complain to the Information Commissioner at ico.org.uk, or on 0303 123 1113. Complaining to us first does not affect that right.

A complaint about the service itself, rather than about data, follows a different route, with free alternative dispute resolution for qualifying businesses. That is set out in clause 11 of the business terms.

15

Changes to this policy

We may update this policy. Where a change is material we will tell you, and the date at the top of this page always shows the version in force. This version is effective from 8 September 2026.

TISA Business is a service of 9Eons Limited, registered in England and Wales, company 06393882, VAT GB 920 145 856, at Luminous House, 300 South Row, Milton Keynes, MK9 2FR. See also the business terms and conditions and the business cookie policy.

Talk to someone who knows the network.

A 30 minute call with the UK team. No script, no obligation, and you pick the time.

Book a meeting

Or call 01908 737 500, Monday to Friday, 9.30am to 5pm.