1. Who We Are
This policy explains how Telebase handles personal data. The data controller for the processing described in section 3 is:
- Company: TELEBASE d.o.o. Beograd, a limited liability company registered in the Republic of Serbia
- Registered office: Jove Ilića 185, 11000 Belgrade, Voždovac, Serbia
- Company registration number (matični broj): 22316419
- Tax number (PIB): 115830010
- Contact for privacy matters: [email protected]
Telebase has not appointed a Data Protection Officer. Privacy enquiries are handled by the contact address above and are the responsibility of the company's director.
2. Scope: Our Two Different Roles
Telebase processes personal data in two distinct roles, and the rules that apply are different in each case. This distinction matters, so it is set out first.
- As a controller. When you visit our website, contact us, or hold a Telebase account, we decide why and how your data is processed. That processing is described in sections 3 to 5 of this policy.
- As a processor. When a customer submits a phone number to our API, that customer is the controller and Telebase is the processor acting on its instructions. We do not decide why a number is looked up, and we do not use the results for our own purposes. That processing is described in sections 6 to 8 and is governed by our Data Processing Agreement, not by this policy.
If you are an individual whose phone number has been submitted to Telebase by a business, that business is the controller. Please contact that business to exercise your rights. If you contact us and identify the business concerned, we will forward your request to them.
3. Data We Process as Controller
In our own right, we process the following.
- Account data: name, business email address, company name, and the credentials associated with your Telebase account.
- Billing data: company name, registered address, tax or VAT number, order and invoice records, and payment references. Telebase invoices customers directly and receives payment by bank transfer. We do not collect or store card numbers.
- Enquiry data: the content of messages you send through our contact form or by email, and any information you provide in the course of a sales or support conversation.
- Usage data: API key identifier, request timestamps, response codes, and query volume, used to operate the service, apply rate limits, calculate usage and detect abuse.
- Website data: aggregated, privacy-preserving analytics about pages visited. We do not use advertising cookies, we do not build visitor profiles, and we do not track you across other websites.
4. Legal Bases for Processing
Each purpose relies on a specific legal basis under Article 6 GDPR.
- Providing the service and managing your account: Article 6(1)(b), performance of a contract with you or steps taken at your request before entering into a contract.
- Responding to enquiries and sales conversations: Article 6(1)(b), pre-contractual steps at your request.
- Invoicing, accounting and tax records: Article 6(1)(c), compliance with a legal obligation to which Telebase is subject under Serbian law.
- Service security, abuse prevention and rate limiting: Article 6(1)(f), our legitimate interest in keeping the service secure and available, and in preventing misuse of telecom data.
- Website analytics: Article 6(1)(f), our legitimate interest in understanding how the site is used. The analytics we use do not identify individuals.
- Operational notices about the service: Article 6(1)(b), performance of a contract.
Where we rely on legitimate interest, we have considered whether that interest is overridden by your rights and freedoms. You may object to processing based on legitimate interest at any time using the contact details in section 1.
We do not send marketing email to individuals who have not asked to hear from us, and we do not sell or rent contact data.
5. How Long We Keep Controller Data
- Account data: for as long as your account is active, and for 12 months after closure.
- Invoices, accounting and tax records: for the period required by Serbian accounting and tax law.
- Enquiry and sales correspondence: up to 24 months from the last contact.
- Usage records used for billing: for as long as needed to support the relevant invoice and any subsequent query about it.
- Website analytics: aggregated only, with no individual-level record retained.
6. Phone Numbers Submitted to the API
This section describes processing carried out on behalf of our customers. In this processing, our customer is the controller and Telebase is the processor.
When a customer submits a phone number to the Telebase API, we pass that number to one or more upstream telecom data providers, receive the resulting signals, and return them to the customer. The signals we return are: validity, carrier name, country, line type, line status, and SIM swap status with, where the operator makes it available, the date of the most recent SIM change.
- Raw numbers are not stored. A submitted phone number is held in memory only for as long as it takes to complete the request to our upstream providers and return a response.
- Logs are hashed. Where a record of a request is needed for billing, abuse prevention and troubleshooting, the phone number is stored as a SHA-256 hash, not in plain text.
- Results are not retained as a database. We do not build, maintain or sell a database of individuals, phone numbers or their attributes. We do not enrich, combine or profile the data we return.
Hashed request records are retained for a maximum of 90 days and are then deleted.
7. Carrier Data and Authorisation
The signals returned by the Telebase API originate from mobile network operators and are accessed through licensed telecom aggregators under their agreements with those operators. Telebase does not obtain this data from public sources, scraped sources or leaked datasets.
Where a lookup is performed, the subscriber's wireless carrier is authorised to use or disclose information about the account and the wireless device, where available, to Telebase or its service provider for the duration of the business relationship, solely to help identify the subscriber or the device and to prevent fraud. That authorisation may extend to details such as name and address. Telebase does not request name or address data, and the Telebase API does not return it.
Businesses using Telebase are responsible for establishing a lawful basis for each lookup and for providing any notice or disclosure required of them as controller. Our Terms of Service set out those obligations.
8. What We Never Do
These are commitments, not aspirations. They apply to all data handled by Telebase, in either role.
- We never sell, rent or license personal data to any third party.
- We never use telecom data, or the results of any lookup, for advertising, marketing, audience building or profiling.
- We never share data with advertising networks, data brokers or people-search services.
- We never use lookup results for our own commercial purposes, including product analytics, beyond the aggregate operational counts needed to run and bill the service.
- We never disclose data to law enforcement or any authority except where we are legally compelled, and we will notify the affected customer unless prohibited by law.
9. Recipients and Sub-processors
We share personal data only with the following categories of recipient, and only to the extent needed.
- Upstream telecom data providers. The phone number submitted for a lookup is passed to our telecom aggregators in order to retrieve the requested signals. Our current upstream providers are Vonage and Twilio.
- Infrastructure and hosting providers. Used to run the API and store operational records.
- Our development partner. A contracted engineering partner that builds and operates the Telebase platform, bound by written confidentiality and data protection obligations.
- Professional advisers. Our accountant and lawyers, in connection with invoicing, tax and legal compliance.
Each recipient acting as a processor is engaged under a written contract that meets the requirements of Article 28 GDPR. A current list of sub-processors is available on request from [email protected].
10. International Transfers
Telebase is established in the Republic of Serbia. Serbia is not currently the subject of an adequacy decision by the European Commission under Article 45 GDPR, and is not covered by UK adequacy regulations.
This means that where a customer established in the European Economic Area or the United Kingdom sends personal data to Telebase, that is a restricted transfer under Chapter V GDPR. Telebase addresses this as follows.
- Standard Contractual Clauses. Transfers to Telebase are made under the European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, incorporated into our Data Processing Agreement.
- UK transfers. Where the UK GDPR applies, the International Data Transfer Addendum issued by the UK Information Commissioner is incorporated alongside those clauses.
- Onward transfers. We do not transfer personal data onward to a sub-processor in a third country without a valid transfer mechanism under Chapter V GDPR.
Serbian data protection law, the Law on Personal Data Protection, is closely modelled on the GDPR and Serbia is a party to Council of Europe Convention 108. A copy of our Data Processing Agreement, including the completed transfer annexes, is available to customers on request.
11. Security
We maintain technical and organisational measures appropriate to the risk, including:
- TLS encryption for all API traffic and all website traffic, with HTTPS enforced.
- Authentication of every API request using a per-customer secret key. Keys are stored as hashes, never in plain text, and can be rotated or revoked by the customer at any time.
- Administrative access limited to named individuals on a need-to-use basis.
- Storage of submitted phone numbers as hashes rather than plain text, as described in section 6.
- Per-key rate limits and daily caps, and monitoring for unusual query patterns.
- Written confidentiality and data protection obligations for all personnel and contractors with access to production systems.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach affects a customer's data, we will notify that customer without undue delay in accordance with our Data Processing Agreement.
12. Your Rights
Where Telebase is the controller of your personal data, you have the following rights under Articles 15 to 22 GDPR.
- Access (Article 15): confirmation of whether we process your data, and a copy of it.
- Rectification (Article 16): correction of inaccurate or incomplete data.
- Erasure (Article 17): deletion of your data where one of the grounds in Article 17 applies.
- Restriction (Article 18): restriction of processing in the circumstances set out in Article 18.
- Portability (Article 20): a copy of data you provided to us, in a structured, commonly used and machine-readable format.
- Objection (Article 21): objection to processing based on legitimate interest.
To exercise any of these rights, contact [email protected]. We will respond within one month of receiving the request. Where a request is complex, we may extend that period by up to two further months and will tell you if we do.
If your phone number was submitted to Telebase by a business, that business is the controller and you should direct your request to them. See section 2.
13. Complaints
If you are not satisfied with how we have handled your personal data, you may lodge a complaint with a supervisory authority.
- In the EEA: the supervisory authority of the Member State where you live, work, or where the alleged infringement took place.
- In the United Kingdom: the Information Commissioner's Office, ico.org.uk.
- In Serbia: the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), poverenik.rs.
We would prefer the chance to resolve the matter first, so please contact us before or alongside any complaint.
14. Children
Telebase is a business-to-business service. It is not directed at children, and we do not knowingly collect personal data from anyone under 18 as a controller. Customers must not use the Telebase API in a manner directed at children, and must not submit phone numbers for the purpose of profiling minors.
15. Changes to This Policy
We may update this policy. When we do, we will change the date at the top of this page. Where a change materially affects how we process personal data, we will notify account holders by email before it takes effect.
Changes to our sub-processors are notified separately under our Data Processing Agreement, which gives customers a period to object before a change takes effect.