Skip to main content

InexPhone.ge

Personal Data Protection Policy

Preamble

Inexphone LLC (hereinafter referred to as “Inexphone” or the “Company”) processes personal data lawfully, fairly and transparently and ensures the protection of the rights and freedoms of data subjects.

The Company provides office and VoIP telephony, the InexPHONE application, SMS services, telephone call analytics integration, contact center outsourcing and other electronic communications services.

In the course of its activities, the Company processes the data of subscribers, application users, representatives of business clients, contact persons, employees, partners, SMS recipients and participants in telephone or digital communications.

Depending on the specific processing activity, Inexphone acts either as a data controller or as a data processor acting on the instructions of a client.

This Policy sets out the fundamental principles governing the processing of personal data, the applicable security measures and the responsible persons, taking into account the requirements of the Law of Georgia on Personal Data Protection (the “Law”) and other applicable legal acts.

 

Article 1. Scope

This Policy applies to all personal data processing activities carried out by Inexphone, including:

  • the registration, identification and servicing of subscribers, users and representatives of business clients;
  • the management of contracts, applications, user accounts and subscriber numbers;
  • the operation of fixed and VoIP telephony services and the InexPHONE application;
  • the processing of technical data relating to telephone and SMS communications, service usage data and itemized records;
  • billing, settlements, outstanding balances, invoicing and other financial and accounting processes;
  • the management of technical support, customer requests, complaints and business correspondence;
  • the recording and analysis of telephone communications, subject to an appropriate legal basis and prior notification;
  • the management, on behalf of a client, of SMS messages, calls, emails, social media communications and online chats;
  • information and network security and the prevention of fraud and unauthorised access;
  • the processing of employee data in the context of employment relationships and administration;
  • relationships with partners, telecommunications operators, technical service providers and other authorized persons.

Where Inexphone processes data on behalf of a business client, such processing shall be carried out on the basis of the client’s documented instructions and in accordance with the purposes and scope specified in the relevant service agreement.

Depending on the purposes and means of a specific processing activity, Inexphone may act as a data controller, a data processor or, where applicable, a joint controller.

 

Article 2. Definition of Terms

The terms used in this Policy shall have the meanings assigned to them by the Law of Georgia on Personal Data Protection.

 

Article 3. Principles of Personal Data Processing

  1. Inexphone processes personal data where an appropriate legal basis exists and in compliance with the following principles:

a) personal data shall be processed lawfully, fairly and transparently in relation to the data subject;

b) personal data shall be collected only for predetermined, specific and legitimate purposes;

c) only personal data that are necessary and proportionate for achieving the relevant purpose shall be processed;

d) the accuracy of personal data shall be ensured and, where necessary, the data shall be updated or corrected;

e) personal data shall be retained only for the period necessary for the relevant purpose or for the period prescribed by law;

f) personal data shall be protected against unauthorised or unlawful processing and against accidental loss, destruction or damage;

g) data protection by design and by default shall be taken into account when introducing new services and technological solutions.

  1. The Company shall maintain records of its data processing activities and retain relevant documentation in a manner that enables it to demonstrate compliance with the Law and this Policy.

 

Article 4. Measures to Ensure Compliance with the Law

To ensure the secure and lawful processing of personal data, Inexphone shall implement the following measures:

a) determine the purpose, legal basis, categories of personal data, categories of recipients and retention periods for each processing activity;

b) designate persons responsible for information assets and data processing activities;

c) define the scope of employees’ access to personal data according to their duties and periodically review the permissions granted to them;

d) use individual authentication, activity logging, backups and other technical and organisational measures appropriate to the relevant risks;

e) upon expiry of the applicable retention period, ensure the deletion, destruction or depersonalisation of personal data, unless another legal basis exists for their continued retention;

f) impose confidentiality obligations on employees and other persons involved in the provision of services and provide them with periodic training;

g) where a personal data security incident is identified, ensure its immediate recording and assessment, mitigation of its consequences and provision of the notifications required by law;

h) provide data subjects with the information required by law and ensure timely responses to their requests;

i) maintain records of information relating to data processing activities, security incidents, consents and data subject requests;

j) conduct a data protection impact assessment when planning high-risk processing activities and implement measures to mitigate the identified risks;

k) define in writing, together with data processors, the purposes, scope and duration of processing, security requirements and the responsibilities of the parties;

l) when processing personal data on behalf of a business client, act solely within the scope of the client’s documented and lawful instructions;

m) take into account the principles of data minimization, security, restricted access and limited retention when planning new services and projects;

n) transfer personal data to another country only where a legal basis and appropriate safeguards required by law are in place;

o) use encryption, pseudonymization or depersonalization measures, where appropriate and technically feasible.

 

Article 5. Implementation and Enforcement

  1. For the purpose of implementing this Policy, Inexphone shall develop and approve relevant internal rules, procedures, instructions and data processing agreements.
  2. The following parties shall participate in the implementation of this Policy:

a) Company Management – shall ensure the implementation of the data protection system, the allocation of appropriate resources and the designation of responsible persons;

b) Data Protection Officer – shall participate in the development of internal data protection documents and data protection impact assessments, monitor compliance with the Law and internal rules, issue recommendations, advise employees and coordinate responses to requests from data subjects and the supervisory authority;

c) Owners of Information Assets and Data Processing Activities – shall ensure that personal data under their responsibility are processed in accordance with the specified purposes, access limitations and retention periods;

d) Persons Responsible for Information Technology and Security Functions – shall ensure the implementation of technical security measures, management of system access rights, logging of activities and response to security incidents;

e) Employees and Persons Involved in the Provision of Services – shall process personal data solely within the scope of their assigned authority, the Company’s instructions and their confidentiality obligations.

  1. Where an employee identifies a personal data security incident, unlawful processing, unauthorised access or a possible breach of this Policy, the employee shall immediately notify their direct supervisor, the Data Protection Officer or the person responsible for information security.
  2. Where Inexphone acts as a data processor, it shall process personal data in accordance with the client’s documented instructions. If an instruction conflicts with the Law, Inexphone shall notify the client accordingly and shall not implement the relevant instruction until the matter has been resolved.

 

Article 6. Review of the Policy

This Policy shall be reviewed at least once a year and whenever there is a material change in data processing activities, the Company’s services, the technologies used or the applicable legislation.

Individual offer

To receive more details and an individual offer regarding this service, please leave your contact information, and our representative will contact you.