1. Encryption
- All traffic between the app, browsers, our servers and your CRMs uses TLS.
- CRM access tokens and webhook secrets are encrypted at rest with AES-256-GCM.
- On the phone, sign-in tokens are kept in Android's encrypted storage, backed by the device keystore.
- Passwords are stored only as bcrypt hashes; API keys only as SHA-256 hashes, shown once at creation.
2. Recordings
- Stored in Cloudflare R2 or Amazon S3 — or your own S3-compatible bucket, so audio never sits with us.
- Played and downloaded only through signed links that expire, and only by roles allowed to.
- Deleted automatically at the end of your plan's retention period, and immediately when you delete a call.
- Recording can be turned off for the whole workspace, and agents can exclude personal SIMs entirely.
3. Access control
- Role-based permissions: agents see their own calls, managers their teams, admins the workspace. Custom roles on Business and above.
- Every recording download, setting change, integration change and export is written to an audit log.
- Phones can be signed out remotely; doing so also stops notifications to them.
- Our staff access a workspace only to provide support, through a time-limited, logged session that's visible on screen.
4. Our commitments as your processor
- We process Customer Data only to provide the Service and on your documented instructions.
- People who can access it are bound by confidentiality.
- We use sub-processors only for hosting, storage, push notifications, email and payments, and tell you before adding new ones.
- We help you answer requests from the people whose data it is, and with security assessments.
- We notify you without undue delay — and within 72 hours — after becoming aware of a breach affecting your data.
- At the end of the contract we delete Customer Data within 30 days, unless the law requires us to keep it.
5. Data processing agreement
Customers who need a signed data processing agreement (for GDPR or internal policy) can request one from hello@callbix.app.
6. Report a vulnerability
Found a security issue? Email hello@callbix.app with the details. Please give us reasonable time to fix it before telling anyone else, and don't access other customers' data. We won't pursue good-faith research that follows these rules.
Questions about this policy? Write to hello@callbix.app. CallBix (operated by Thinkbix Technologies Pvt. Ltd.), Sterling Tower, Pancard Club Road, Baner, Pune, Maharashtra, India.