Effective Date: August 24, 2020
Last Reviewed on: August 24, 2020
- Who we are
- Personal information that we collect
- How we collect your personal information
- How we use your personal information
- How we share your personal information
- EEA legal rights
- International data transfers and Privacy Shield
- Cookies and other tracking technologies
- California consumer legal rights
- California Online Privacy Protection Act (“CalOPPA”) and Delaware Online Privacy and Protection Act (“DOPPA”) do not track disclosure
- How long we retain your personal information
- How we protect your personal information
- Linked Websites
- Changes to this Privacy Notice
- How to contact us
Who we are
Hello there! We are Bandwidth, a cloud-based communications provider for enterprises. Our solutions include a broad range of software APIs for voice and text functionality, as well as our own IP voice network. A reference to “Bandwidth,” “we,” “us,” or “our” is a reference to Bandwidth and the relevant affiliate involved in the processing activity.
Please read this Privacy Notice carefully to understand how we collect and process personal information.
This Privacy Notice applies to information we collect on this website, in email, chat, text, or other electronic messages, through Bandwidth portals, through customer support, through other Bandwidth websites, when you use Bandwidth products and services, and offline activities and communications. We may collect data, including personal information, about you as you use our websites, products, services, and interact with us.
This Privacy Notice does not cover handling of your personal information as an employee, intern or applicant of Bandwidth and does not cover any information collected by third-party sites or content or applications that may link to or be accessible from or on Bandwidth websites. If you do not agree with our policies and practices, your choice is not to use the Bandwidth websites, products, and services. By accessing or using the Bandwidth websites and/or using Bandwidth products and services, you agree to this Privacy Notice.
This Privacy Notice is provided in a layered format so you can click through to the specific areas set out below. Alternatively, you can download a pdf version of the policy here: https://www.bandwidth.com/wp-content/uploads/privacy-notice.pdf
“Bandwidth” and “Bandwidth group” includes Bandwidth Inc. and all its subsidiaries including: Bandwidth.com CLEC, LLC; UK Bandwidth Limited; NL Bandwidth B.V; Bandwidth Iberia SL; DE Bandwidth GmbH.
“Bandwidth portals” include: https://dashboard.bandwidth.com; http://app.bandwidth.com; https://dashboard.dashcs.com; https://support.bandwidth.com; https://my.bandwidth.com; https://cdrs.evs.bandwidth.com/; https://finance.bandwidth.com; https://dev.bandwidth.com/; https://status.bandwidth.com/; https://investors.bandwidth.com; https://new.dev.bandwidth.com; https://old.dev.bandwidth.com; https://simulator.bandwidth.com
“Personal information” is any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular end user or device. This does not include anonymous or de-identified data, which cannot be linked to an individual.
“Personal data” is any information that can be used to identify an individual, directly or indirectly, and may include name, address, email address, phone number, an identification number, location data, online identifier, login information (account and password), marketing preferences, social media account information, or payment card information. For the purposes of this Notice, Personal data is included within the definition of personal information.
Personal information that we collect
Bandwidth processes personal information of its customers (or potential customers) in the context of creating or maintaining a business relationship. We call this information “Customer Information.” Sometimes you provide Customer Information to us directly, such as when you fill out a form on our website or request products or services information. Sometimes we collect it from you automatically, such as when you visit a Bandwidth website or click on a Bandwidth online advertisement.
Identifiers. Full name, postal address, registered address, email address, company name, company website, telephone number, unique personal identifier, online identifier, Internet Protocol (“IP”) address.
Account Payment Information. Credit card number, debit card number, signature, telephone number, employer name, bank wire transfer information.
Commercial Information. Records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
Internet or Similar Network Activity. Browsing history, search history, information on your interaction with our websites and advertisements.
Geolocation Data. Source and destination information about the communications delivered via the Bandwidth products or services.
Sensory Data. Your audio phone call to Bandwidth may be recorded for quality assurance and training purposes (e.g. customer support call).
We also process personal information of end users in the course of providing voice and messaging communications services. We call this information “Communications Information.” This includes both the content of calls and messages sent or received via out platform (“Communications Content”) and information about the communications delivered via our platform such as source and destination information, IP address, completion status, time and duration of use, registered address and/or real-time location information for emergency services, and caller ID information (known as “Metadata”).
Information that is necessary for the use of Bandwidth products and services (Communications Information, Communications Content, and Metadata)
Identifiers. Full name, postal address, registered address and/or real-time location information for emergency service, unique personal identifier, caller ID information, telephone number, account name, company name.
Internet or Similar Network Activity. Media contained in voice calls and text messages sent or received via our platform, information about the communications delivered via our platform (e.g. completion status, time and duration of use, source and destination identifiers).
Sensory Data. Media contained in your voice calls and text messages, text-to-speech transcriptions, and DTMF tones.
How we collect your personal information
We use different methods to collect personal information from and about you including through:
- Direct interactions. You may give us information about you by filling in forms, engaging in chat on our website, accessing or utilizing any Bandwidth website, opening an account with us, requesting support, subscribing to our newsletters, requesting information or materials (e.g. whitepapers), registering for events or webinars, visiting our booth at a trade show or other event, participating in surveys or evaluations, accessing or utilizing any Bandwidth portal (see listing of portal sites in the Definitions section), submitting questions or comments, or by corresponding with us by phone, email, or otherwise.
- Automated technologies or interactions. As you interact with Bandwidth websites, we may automatically collect technical data about your equipment, browsing actions, and patterns as specified above. We collect this information by using cookies and other similar tracking technologies (see Cookies and other tracking technologies section).
- Third parties or publicly available sources. We may receive information about you if you visit other websites employing our cookies or from third parties including, for example, advertising networks, analytics providers, through publicly available data, such as social media posts (like LinkedIn, Facebook, and others) and websites.
- Indirectly. As a service provider in the course of providing voice and messaging communications services.
How we use your personal information
We may use the personal information we collect for one or more of the following purposes:
- To fulfill or meet the reason you provided the information and to provide our products and services.
- To respond to your inquiry about our products and services, including to investigate and address your concerns and monitor and improve our responses.
- To enable our customers and end users to send and receive communications via our platform and to bill for those services.
- To allow you to interact with our systems, including the Bandwidth websites and Bandwidth portals.
- To create, maintain, customize and secure your account with us.
- To process your requests, purchases, transactions and payments.
- To bill, collect, and remit taxes, fees and surcharges to the appropriate jurisdictions.
- To personalize your website experience and to deliver content and service information relevant to your interests, including targeted offers, marketing communications and ads through our website, third-party sites and via email.
- To maintain the safety, security and integrity of our website, services, databases and other technology assets and business.
- For testing, research, development, and analysis; mitigation of fraud, spam, unlawful or abusive activity, or violations of Bandwidth’s Acceptable Use Policy; perform quality control; gauge routing effectiveness and deliverability and product development, including developing and improving our Bandwidth websites and products and services. Specifically, with respect to MMS and SMS messaging, we utilize industry-standard content-analysis software which utilizes electronic, algorithmic inspection of the originating telephone number and/or content of MMS and SMS messages for purposes of spam blocking.
- If you have elected to have your name, address, and telephone number published in directories, we may share such information with directory publishers (who publish white pages, yellow pages, and other similar directories) and directory assistance providers.
- As described to you when collecting your personal information.
- Law enforcement, security, and safety.
- To respond to law enforcement requests and as required by applicable law, court order, governmental regulations, or other legal process where we believe in good faith that disclosure protects your safety or the safety of others, and allows Bandwidth to enforce or protect our rights.
- For security purposes to register visitors to our offices and to manage non-disclosure agreements that visitors may be required to sign, to the extent such processing is necessary for our legitimate interest in protecting our offices and our confidential information against unauthorized access.
- Asset transfer and/or M&A Activity.
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Bandwidth’s assets, whether at Bandwidth’s discretion or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by Bandwidth about you is among the assets transferred.
Bandwidth will not use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice. We may use non-personal information for any business purpose. To improve our products and services, we commonly will de-identify or aggregate your personal information (so that it can no longer be associated with you), in which case we may use this information indefinitely without further notice to you.
How we share your personal information
We may disclose your personal information to a third party for a business purpose. Bandwidth may share your personal information in the following ways:
- To companies that perform services on our behalf only as needed for them to perform those services, including other communications providers in order to route communications over the Bandwidth network.
- To any member of our corporate group, which means our subsidiaries, our ultimate holding company and its subsidiaries.
- To advertising and marketing companies and networks.
- To data analytic providers.
- To any member of our corporate group, which means our subsidiaries, our ultimate holding company and its subsidiaries.
- To other companies and entities, to:
- Respond to emergencies or exigencies;
- Comply with court orders, law, and other legal process, including responding to any government or regulatory request;
- Assist with identity verification, preventing fraud, and identity theft;
- Provide directory assistance services, with your consent.
- To fulfill the purpose for which you provide it.
- For any other purpose that we disclose in writing when you provide the personal information.
- With your consent.
- To sell, transfer, merge, divest, restructure, reorganize, or dissolve all or a portion of our business or assets.
- To enforce our Terms and Conditions and other agreements.
- To protect the rights, property, or safety of our business, our employees, our customers, or others.
EEA legal rights
Bandwidth group is made up of different legal entities, details of which can be found in the Definitions section of this Notice. This Privacy Notice is issued on behalf of the Bandwidth group, so when we mention Bandwidth, “we”, “us” or “our” in this Privacy Notice, we are referring to the relevant company in the Bandwidth group responsible for processing your personal data.
Your personal data may be collected, transferred to, and stored by us in the United States and by our subsidiaries and/or third-party service providers that are in other countries. Therefore, your personal data may be transferred and processed outside your jurisdiction and in countries that may not provide for the same level of data protection as your jurisdiction, such as the European Economic Area (“EEA”). Where applicable law requires us to utilize a data transfer mechanism, we rely on adequacy decisions as adopted by the European Commission; standard contractual clauses issued by the European Commission; or pursuant to established derogations for specific situations. You may obtain a redacted copy (from which commercial information and information that is not relevant has been removed) of such EU Standard Contractual Clauses by sending a request to email@example.com.
Our legal basis for collecting and using the personal data described above will depend on the personal data concerned and the specific context in which we collect it. We will collect and process personal data from you when the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms; to perform a contract with you; where we have your consent to do so. In some cases, we may also have a legal obligation to protect your vital interests or those of another person or to comply with a legal requirement.
EEA data protection laws require that businesses processing personal data provide the lawful basis for which they collect and process that personal information. Bandwidth processes personal information for the following purposes:
- To provide the products and services we offer and to carry out core activities related to our provision of those products and services in performance of a contract or other commitments we have made to you;
- Legitimate business purposes (such as tax reporting and billing, auditing, management of network, technology assets and information systems security);
- To comply with our legal obligations;
- To perform legitimate business purposes, such as research and development, to market and promote the services, and to protect our legal rights and interests;
- In certain instances, you have given us your explicit consent to process your data. In the event our processing is based on your consent, you have the right to withdraw your consent at any time. To withdraw your consent, please contact firstname.lastname@example.org. Please note that withdrawal of your consent will not affect the lawfulness of the processing before the withdrawal;
- Vital interests, as we may process your personal information when we consider it a matter of life and death.
There may be more than one ground that form the basis of our use of your personal information. We will only use your personal data for the purposes outlined in this Privacy Notice or such purposes as may be reasonably compatible with the original purpose for which it was collected or there is an alternative legal basis for the further processing.
In the EEA, data privacy laws require us to enter into agreements with third parties who are acting as “sub-processors” of certain data. For a list of third parties who Bandwidth has engaged as sub-processors, please use the DATA SUBJECT RIGHT REQUEST FORM to request.
Under certain circumstances, you have the below rights under data protection laws in relation to your personal data.
- Right to access. You have the right to request a copy of your personal data and supplementary information.
- Right to rectification. You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete information you believe is incomplete.
- Right to erasure. You have the right to request that we erase your personal data, under certain circumstances.
- Right to restriction of processing. You have the right to restrict the processing of your personal data, under certain circumstances.
- Right to data portability. You have the right to receive personal data you have provided to us in a structured, commonly used and machine-readable format. You have the right to request that we transmit this data directly to another controller.
- Right to withdrawal consent. The withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
- Right to object to processing. You have the right to object to the processing of your personal data at any time, under certain circumstances.
Data controller of the Bandwidth websites: Bandwidth Inc., 900 Main Campus Drive, Suite #100, Raleigh, North Carolina, 27606, USA. Data controller for Bandwidth products and services is the entity that you contracted with.
To exercise any of the above rights or if you have any questions about this Privacy Notice, please enter them in the DATA SUBJECT RIGHT REQUEST FORM. You may also make a complaint to a relevant data protection supervisory authority in the EU and UK. We would, however, appreciate the opportunity to address your concerns before you do so.
Fees. You will not have to pay a fee to access your personal data or to exercise any of the other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
Information we may need from you. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data or to exercise any of your other rights. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to assist with our response.
Timing. We try to respond to all legitimate requests within one month of receipt of the request. Occasionally, it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
International data transfers and Privacy Shield
On July 16, 2020, the Court of Justice of the European Union (“CJEU”) declared the EU-US Privacy Shield invalid and may no longer be utilized to transfer personal data from the EEA. Our EEA Legal Rights section has been updated accordingly. We will continue to comply with our obligations under the EU-US Privacy Shield Framework (see FAQs from the U.S. Department of Commerce).
Bandwidth may transfer your personal data to Bandwidth in the United States, to other Bandwidth entities worldwide, or to third parties and service providers as described above that are located in various countries around the world who perform services on our behalf. The United States and other countries may not have the same data protection laws as the country from which you initially provided the information. By using our website or providing any personal information to us, you acknowledge and accept the transfer, processing and storage of such information outside of your country of residence or the country where the data was collected.
With respect to personal data received or transferred pursuant to the Privacy Shield Frameworks, Bandwidth is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. Bandwidth may use third-party service providers to assist us in providing services to our customers. We are liable for ensuring that the third-parties we engage support our Privacy Shield commitments. In certain situations, Bandwidth may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
In compliance with the Privacy Shield Principles, we commit to resolving complaints about our collection or use of your personal information. EU individuals with inquiries or complaints regarding our Privacy Shield policy should first contact us at email@example.com. If we are unable to resolve any complaint related to the Privacy Shield or if we fail to acknowledge your complaint in a timely manner, you may refer a complaint to your local data authority. Bandwidth has further committed to cooperate with the panel established by the EU data protection authorities (DPAs) with regard to unresolved Privacy Shield complaints concerning data transferred from the EU.
Under certain conditions, described more fully on the Privacy Shield website (https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint), you may invoke binding arbitration when other dispute resolution procedures have been exhausted. Some international users, including those whose information we collect under the Privacy Shield, have rights to access certain information we hold about them and to obtain its deletion. To exercise those rights, please contact us at firstname.lastname@example.org.
Cookies and other tracking technologies
We also use web beacons on the Bandwidth websites and in email communications. For example, we may place web beacons in marketing emails that notify us when you click on a link in the email that directs you to one of the Bandwidth websites. To unsubscribe from our marketing emails, click the link at the bottom of the email marked “Unsubscribe” or manage your email subscriptions at https://go.bandwidth.com/UnsubscribePage.html. Please note that you cannot opt out of receiving transactional emails related to our products and services.
The following describes how we use different categories of cookies and your options:
Strictly Necessary Cookies. Strictly necessary cookies are necessary for the Bandwidth websites to function and cannot be switched off in our systems. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies. If you have chosen to identify yourself to us, we may place a cookie on your device that allows us to uniquely identify you when you are logged into the Bandwidth websites and to process your online transactions and requests. If you are in the EEA (based on IP address), the Bandwidth websites will only serve you strictly necessary cookies.
Functional Cookies. Functional cookies enhance function, performance, and services on the Bandwidth websites. If you do not allow these cookies then some or all services may not function properly.
Targeting Cookies. Targeting cookies may be set through the Bandwidth websites by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant advertisements on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. Some examples include: cookies used for remarketing or interest-based marketing. Our website uses Google Analytics, a web analysis service provided by Google Inc., which utilizes cookies to find out how visitors use our website. You can opt out of Google Analytics by downloading, installing, and enabling the Google Analytics’ Opt-out Browser Add-on, which can be found at https://tools.google.com/dlpage/gaoptout/.
Performance Cookies. These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our Bandwidth websites. They help us to know which pages are the most and least popular.
California consumer legal rights
This section is effective as of January 1, 2020. The California Consumer Privacy Act (“CCPA”) provides California residents with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.
- Right to access
- Right to opt out of the sale of personal information
- Right to data deletion of consumer’s personal information
- Right to data portability
- Right to not be discriminated against for exercising any consumer rights under the CCPA
To exercise the rights described above, please submit a verifiable consumer request to us by either:
- Calling us toll free at 866-824-2792
- Completing our DATA SUBJECT RIGHTS REQUEST FORM
- Emailing us at email@example.com
Only you, or someone legally authorized to act on your behalf (this includes an authorized agent), may make a verifiable consumer request (“request”) related to your personal information. You may only make a request for access or data portability twice within a 12-month period. An authorized agent making a request on your behalf must provide us with written authorization providing the agent with the ability to make a CCPA request signed by you. Additionally, you will need to verify your identity directly with us. Please note that this authorized agent requirement is not applicable when the authorized agent has a power of attorney. The request must: (1) provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative; and (2) describes your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
Any disclosures we provide will cover the 12-month period preceding receipt of the request. We will provide a response to a request within forty-five (45) days of its receipt. If we reasonably require an extension of time, we will notify you within the first forty-five (45) day period and such extension will not exceed an additional forty-five (45) days. We will not discriminate against you for exercising any of your CCPA rights. Any personal information provided to us for verification and fraud-prevention purposes will only be used for that purpose and such information will be deleted as soon as practical after processing of your request. In the preceding 12-months to the effective date of this section, we disclosed the following categories of personal information for a business purpose: Cookie Information, which included Identifiers and Internet or Similar Network Activity. This information was provided to advertising companies and networks to select and serve relevant advertisements and content to you and to data analytic providers. We will not sell (as defined under the CCPA) California resident personal information we collect.
California Online Privacy Protection Act (“CalOPPA”) and Delaware Online Privacy and Protection Act (“DOPPA”) do not track disclosure
Do not track is a privacy preference that you can set in your web browser. When you turn on the do not track signal, the browser sends a message to websites requesting them not to track you. For information about do not track, visit http://www.allaboutdnt.org. At this time, we do not respond to do not track browser settings or signals.
How long we retain your personal information
We will only retain your personal information for as long as reasonably necessary to fulfill the purposes we collected it for, including the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal information for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal information, we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means and the applicable legal, regulatory, tax, accounting or other requirements. After expiration of the applicable retention periods, your personal information will be deleted. If there is any personal information that we are unable, for technical reasons, to delete entirely from our systems, we will put in place appropriate measures to prevent any further use of such personal information. To improve our products and services, we commonly will de-identify or aggregate your personal information (so that it can no longer be associated with you), in which case we may use this information indefinitely without further notice to you.
How we protect your personal information
Bandwidth takes precautions including administrative, technical, and physical measures to help safeguard against the accidental or unlawful destruction, loss, alteration and unauthorized disclosure of, or access to, the personal information we process or use. Bandwidth is ISO 27001:20013 certified and SOC II compliant. Bandwidth is a PCI Level 3 Merchant and has met Payment Card Industry Data Security Standard’s SAQ-A. To learn more about our security controls, please see https://www.bandwidth.com/wp-content/uploads/security-controls-overview.pdf.
Please note, though, that no provider can guarantee security, especially when providing services that rely on the public internet or during transmission through the interconnected landscape of telecommunications. You are solely responsible for protecting your account password(s), limiting access to your devices, and signing out of websites after your sessions. You are responsible for any activity conducted using your credentials or passwords. We ask you not to share your password with anyone and to take care when using public Wi-Fi. If you believe your password to any Bandwidth portal or system has been compromised, please notify us immediately at firstname.lastname@example.org.
For your convenience, hyperlinks may be posted on our Bandwidth websites that links to other websites (“third-party sites”). We are not responsible for the privacy practices of any third-party sites or of any companies that we do not own or control. This Privacy Notice does not apply to third-party sites. Third-party sites may collect information in addition to that which we collect on the Bandwidth websites. We do not endorse any of these third-party sites, the services or products described or offered on such third-party sites, or any of the content contained on the third-party sites. We encourage you to read the privacy notice of each third-party site that you visit to understand how the information that is collected about you is used and protected.
The Bandwidth websites, products, and services are not directed to children (under the age of 13 in the United States or under the age of 16 in the EEA) and Bandwidth does not knowingly collect online personal information directly from children. If you are a parent or guardian of a minor child and believe that the child has disclosed online personal information to us, please contact us at email@example.com.
Changes to this Privacy Notice
This Privacy Notice does not form part of any contract and we may update it at our discretion from time to time. When we do so, we will post the updated Privacy Notice on our website and update the Privacy Notice’s Effective Date at the beginning of the notice. We will notify our customers of material changes to this Privacy Notice, either by sending a notice to the customer email address you have provided us, or by placing a prominent notice on the Bandwidth website. We will obtain your consent to any material Privacy Notice changes if and where this is required by applicable data protection laws. We encourage you to periodically review this Privacy Notice. Historic versions are archived here: http://broadband.com/privacy/archive/.
How to contact us
If you have questions about this Privacy Notice, concerns, or questions, please contact firstname.lastname@example.org.
If you have questions that specifically relate to Bandwidth’s compliance with the GDPR, please email email@example.com. You may also make a complaint to a relevant data protection supervisory authority in the EU and UK. We would, however, appreciate the opportunity to address your concerns before you do so.
If you no longer wish to receive marketing or informational materials from us, you can opt-out at any time by using the link to unsubscribe contained in each communication. You can also manage your email subscriptions at https://go.bandwidth.com/UnsubscribePage.html.
To contact us in writing, please use:
Attn: Legal – Privacy
900 Main Campus Drive, Suite 100
Raleigh, North Carolina 27606