telebase.io
  • Signals
  • How it works
  • Who it's for
  • Pricing
  • Request access
Legal

Privacy Policy

Last updated: 29 September 2026
On this page
  • 1. Who We Are
  • 2. Scope: Our Two Roles
  • 3. Data We Process as Controller
  • 4. Legal Bases
  • 5. Controller Data Retention
  • 6. Phone Numbers in the API
  • 7. Carrier Data and Authorisation
  • 8. What We Never Do
  • 9. Recipients and Sub-processors
  • 10. International Transfers
  • 11. Security
  • 12. Your Rights
  • 13. Complaints
  • 14. Children
  • 15. Changes

1. Who We Are

This policy explains how Telebase handles personal data. The data controller for the processing described in section 3 is:

  • Company: TELEBASE d.o.o. Beograd, a limited liability company registered in the Republic of Serbia
  • Registered office: Jove Ilića 185, 11000 Belgrade, Voždovac, Serbia
  • Company registration number (matični broj): 22316419
  • Tax number (PIB): 115830010
  • Contact for privacy matters: [email protected]

Telebase has not appointed a Data Protection Officer. Privacy enquiries are handled by the contact address above and are the responsibility of the company's director.

2. Scope: Our Two Different Roles

Telebase processes personal data in two distinct roles, and the rules that apply are different in each case. This distinction matters, so it is set out first.

  • As a controller. When you visit our website, contact us, or hold a Telebase account, we decide why and how your data is processed. That processing is described in sections 3 to 5 of this policy.
  • As a processor. When a customer submits a phone number to our API, that customer is the controller and Telebase is the processor acting on its instructions. We do not decide why a number is looked up, and we do not use the results for our own purposes. That processing is described in sections 6 to 8 and is governed by our Data Processing Agreement, not by this policy.

If you are an individual whose phone number has been submitted to Telebase by a business, that business is the controller. Please contact that business to exercise your rights. If you contact us and identify the business concerned, we will forward your request to them.

3. Data We Process as Controller

In our own right, we process the following.

  • Account data: name, business email address, company name, and the credentials associated with your Telebase account.
  • Billing data: company name, registered address, tax or VAT number, order and invoice records, and payment references. Telebase invoices customers directly and receives payment by bank transfer. We do not collect or store card numbers.
  • Enquiry data: the content of messages you send through our contact form or by email, and any information you provide in the course of a sales or support conversation.
  • Usage data: API key identifier, request timestamps, response codes, and query volume, used to operate the service, apply rate limits, calculate usage and detect abuse.
  • Website data: aggregated, privacy-preserving analytics about pages visited. We do not use advertising cookies, we do not build visitor profiles, and we do not track you across other websites.

4. Legal Bases for Processing

Each purpose relies on a specific legal basis under Article 6 GDPR.

  • Providing the service and managing your account: Article 6(1)(b), performance of a contract with you or steps taken at your request before entering into a contract.
  • Responding to enquiries and sales conversations: Article 6(1)(b), pre-contractual steps at your request.
  • Invoicing, accounting and tax records: Article 6(1)(c), compliance with a legal obligation to which Telebase is subject under Serbian law.
  • Service security, abuse prevention and rate limiting: Article 6(1)(f), our legitimate interest in keeping the service secure and available, and in preventing misuse of telecom data.
  • Website analytics: Article 6(1)(f), our legitimate interest in understanding how the site is used. The analytics we use do not identify individuals.
  • Operational notices about the service: Article 6(1)(b), performance of a contract.

Where we rely on legitimate interest, we have considered whether that interest is overridden by your rights and freedoms. You may object to processing based on legitimate interest at any time using the contact details in section 1.

We do not send marketing email to individuals who have not asked to hear from us, and we do not sell or rent contact data.

5. How Long We Keep Controller Data

  • Account data: for as long as your account is active, and for 12 months after closure.
  • Invoices, accounting and tax records: for the period required by Serbian accounting and tax law.
  • Enquiry and sales correspondence: up to 24 months from the last contact.
  • Usage records used for billing: for as long as needed to support the relevant invoice and any subsequent query about it.
  • Website analytics: aggregated only, with no individual-level record retained.

6. Phone Numbers Submitted to the API

This section describes processing carried out on behalf of our customers. In this processing, our customer is the controller and Telebase is the processor.

Why phone numbers are processed

Our customers are businesses, such as banks, fintechs and other online services, that use Telebase to protect their own users' accounts and transactions from fraud. A customer submits a phone number that one of its users has registered with it, and asks whether the SIM card linked to that number has recently changed (a "SIM swap"), together with basic information about the line. A recent SIM change is a common sign that someone other than the subscriber has taken control of a phone number, for example to intercept one-time passcodes. The customer then decides for itself whether to ask its user for additional verification. Telebase does not make that decision, and our Terms of Service prohibit customers from using a result as the sole basis for a decision that has a legal or similarly significant effect on an individual.

How phone numbers are verified with the mobile network

When a customer submits a phone number to the Telebase API, we pass that number to one or more upstream telecom data providers. The provider checks the number with the mobile network operator that serves it, so a phone number may be verified with the individual's own mobile network, and that operator will receive the request. The operator, or the provider acting under its agreement with the operator, confirms whether the SIM changed within the period requested and returns carrier and line information, which we return to the customer. The signals we return are: validity, carrier name, country, line type, line status, and SIM swap status with, where the operator makes it available, the date of the most recent SIM change.

The check takes place between systems. We do not send a message to or call the individual, we do not access their handset, and we do not receive their name, address, contacts, message content, call records or location.

Notice and consent

Telebase has no direct relationship with the individuals whose numbers are checked. Our customers, as controllers, are responsible for telling those individuals that their phone number may be checked with their mobile network, and for obtaining any consent that the law or a mobile network operator requires, before the check is made. Our Terms of Service require this, including any wording that an operator requires in a particular country.

Records of queries

  • What is recorded. For each query we keep the phone number submitted, the time, the API key used, the result returned and the amount charged. This lets customers review their own query history and lets us bill, prevent abuse and investigate faults.
  • Who can see it. A customer can see only its own queries. Named Telebase personnel can access records only where needed for support, security and billing queries.
  • Retention. The phone number and result in a query record are kept while the customer's account is active, and are deleted within 30 days of the account closing, or earlier on the customer's written request. Billing information needed to support an invoice is kept as described in section 5.
  • No database of individuals. We do not combine results across customers, and we do not build, maintain or sell a database of individuals, phone numbers or their attributes. We do not enrich or profile the data we return.

7. Carrier Data and Authorisation

The signals returned by the Telebase API originate from mobile network operators and are accessed through licensed telecom aggregators under their agreements with those operators. Telebase does not obtain this data from public sources, scraped sources or leaked datasets.

Where a lookup is performed, the subscriber's wireless carrier is authorised to use or disclose information about the account and the wireless device, where available, to Telebase or its service provider for the duration of the business relationship, solely to help identify the subscriber or the device and to prevent fraud. That authorisation may extend to details such as name and address. Telebase does not request name or address data, and the Telebase API does not return it.

Businesses using Telebase are responsible for establishing a lawful basis for each lookup and for providing any notice or disclosure required of them as controller. Our Terms of Service set out those obligations.

8. What We Never Do

These are commitments, not aspirations. They apply to all data handled by Telebase, in either role.

  • We never sell, rent or license personal data to any third party.
  • We never use telecom data, or the results of any lookup, for advertising, marketing, audience building or profiling.
  • We never share data with advertising networks, data brokers or people-search services.
  • We never use lookup results for our own commercial purposes, including product analytics, beyond the aggregate operational counts needed to run and bill the service.
  • We never disclose data to law enforcement or any authority except where we are legally compelled, and we will notify the affected customer unless prohibited by law.

9. Recipients and Sub-processors

We share personal data only with the following categories of recipient, and only to the extent needed.

  • Upstream telecom data providers. The phone number submitted for a lookup is passed to our telecom aggregators, which check it with the mobile network operator serving that number, in order to retrieve the requested signals. The named providers are listed in our Data Processing Agreement, and a current list is available on request.
  • Infrastructure and hosting providers. Used to run the API and store operational records.
  • Our development partner. A contracted engineering partner that builds and operates the Telebase platform, bound by written confidentiality and data protection obligations.
  • Professional advisers. Our accountant and lawyers, in connection with invoicing, tax and legal compliance.

Each recipient acting as a processor is engaged under a written contract that meets the requirements of Article 28 GDPR. A current list of sub-processors is available on request from [email protected].

10. International Transfers

Telebase is established in the Republic of Serbia. Serbia is not currently the subject of an adequacy decision by the European Commission under Article 45 GDPR, and is not covered by UK adequacy regulations.

This means that where a customer established in the European Economic Area or the United Kingdom sends personal data to Telebase, that is a restricted transfer under Chapter V GDPR. Telebase addresses this as follows.

  • Standard Contractual Clauses. Transfers to Telebase are made under the European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, incorporated into our Data Processing Agreement.
  • UK transfers. Where the UK GDPR applies, the International Data Transfer Addendum issued by the UK Information Commissioner is incorporated alongside those clauses.
  • Onward transfers. We do not transfer personal data onward to a sub-processor in a third country without a valid transfer mechanism under Chapter V GDPR.

Serbian data protection law, the Law on Personal Data Protection, is closely modelled on the GDPR and Serbia is a party to Council of Europe Convention 108. A copy of our Data Processing Agreement, including the completed transfer annexes, is available to customers on request.

11. Security

We maintain technical and organisational measures appropriate to the risk, including:

  • TLS encryption for all API traffic and all website traffic, with HTTPS enforced.
  • Authentication of every API request using a per-customer secret key. Keys are stored as hashes, never in plain text, and can be rotated or revoked by the customer at any time.
  • Administrative access limited to named individuals on a need-to-use basis.
  • Query records visible only to the customer that made the query, and to named Telebase personnel only where needed for support, security and billing, as described in section 6.
  • Per-key rate limits and daily caps, and monitoring for unusual query patterns.
  • Written confidentiality and data protection obligations for all personnel and contractors with access to production systems.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach affects a customer's data, we will notify that customer without undue delay in accordance with our Data Processing Agreement.

12. Your Rights

Where Telebase is the controller of your personal data, you have the following rights under Articles 15 to 22 GDPR.

  • Access (Article 15): confirmation of whether we process your data, and a copy of it.
  • Rectification (Article 16): correction of inaccurate or incomplete data.
  • Erasure (Article 17): deletion of your data where one of the grounds in Article 17 applies.
  • Restriction (Article 18): restriction of processing in the circumstances set out in Article 18.
  • Portability (Article 20): a copy of data you provided to us, in a structured, commonly used and machine-readable format.
  • Objection (Article 21): objection to processing based on legitimate interest.

To exercise any of these rights, contact [email protected]. We will respond within one month of receiving the request. Where a request is complex, we may extend that period by up to two further months and will tell you if we do.

If your phone number was submitted to Telebase by a business, that business is the controller and you should direct your request to them. See section 2.

13. Complaints

If you are not satisfied with how we have handled your personal data, you may lodge a complaint with a supervisory authority.

  • In the EEA: the supervisory authority of the Member State where you live, work, or where the alleged infringement took place.
  • In the United Kingdom: the Information Commissioner's Office, ico.org.uk.
  • In Serbia: the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), poverenik.rs.

We would prefer the chance to resolve the matter first, so please contact us before or alongside any complaint.

14. Children

Telebase is a business-to-business service. It is not directed at children, and we do not knowingly collect personal data from anyone under 18 as a controller. Customers must not use the Telebase API in a manner directed at children, and must not submit phone numbers for the purpose of profiling minors.

15. Changes to This Policy

We may update this policy. When we do, we will change the date at the top of this page. Where a change materially affects how we process personal data, we will notify account holders by email before it takes effect.

Changes to our sub-processors are notified separately under our Data Processing Agreement, which gives customers a period to object before a change takes effect.

telebase.io

Telecom intelligence for AI agents. The missing signal layer for fraud teams and autonomous agents.

Product

  • Pricing
  • How it works
  • Signals
  • Who it's for

Developers

  • skills.md
  • Contact

Legal

  • Privacy policy
  • Terms of service
  • Refund policy

© 2026 Telebase. All rights reserved.