Last Updated: 26/08/2026
VOICY ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε. (“VOICY”, “we”, “our” or “us”) is an electronic communications provider established in Greece, with registered office at Leoforos Kifisias 166A, Marousi, 15126 Athens, Greece.
This Privacy Policy explains how VOICY collects, uses, stores and protects personal data in connection with our website, voicy.gr, and the electronic communications and related services that we provide.
Our services include, among others, Cloud PBX, SIP Trunking, VoIP, DIDs and virtual numbers, Wholesale Voice, Voice Hubbing, IPX Voice and other telecommunications services made available by VOICY from time to time.
Our services are primarily provided to businesses, telecommunications providers and other professional customers, although certain services may also be provided to individuals.
For processing activities where VOICY determines why and how personal data is processed, VOICY acts as the Data Controller. In certain customer-specific services, VOICY may instead act as a Data Processor on behalf of the customer.
This Privacy Policy is intended to comply with Regulation (EU) 2016/679 (the General Data Protection Regulation or “GDPR”), applicable Greek data protection and electronic communications legislation, and other applicable Greek and European Union laws.
The personal data we process depends on your relationship with VOICY and the services you use.
When you contact us, request a quotation, enter into an agreement or use our services, we may process information such as your name, company name, business contact details, telephone number, email address, billing address, VAT information, job title or capacity within an organisation, and information relating to the services provided to you.
We may also process correspondence and communications exchanged with our commercial, administrative and technical support teams.
Certain telecommunications services, telephone numbers or jurisdictions require us to verify the identity of a customer or authorised representative.
Depending on the circumstances and applicable legal requirements, we may therefore request information or documentation such as an identity card, passport, proof of address, company registration information, VAT information, details of authorised representatives, beneficial ownership information or other documentation necessary to comply with telecommunications, numbering, customer-verification or regulatory obligations.
The information requested varies according to the particular service, customer and jurisdiction.
This may include calling and called numbers, telephone numbers and DIDs, IP addresses, the date and time of communications, call duration, call status, routing and interconnection information and other technical information necessary for the operation, troubleshooting and security of the service.
VOICY processes such information only to the extent necessary for the provision, operation, security, billing and legal compliance of its services.
When you submit a contact form through our website, we may collect your name, company name, telephone number, email address, message, IP address, submission date and other information included in the form.
Our website is operated using Webflow. Contact-form submissions are stored within Webflow and are also transmitted to VOICY so that we can receive and respond to the enquiry.
Communications received through the website may subsequently be processed through VOICY’s business email environment, which is provided through Microsoft 365.
We use this information to respond to your enquiry, provide information about our services, prepare quotations, communicate with you and, where appropriate, take steps towards entering into a business relationship.
Customers may pay using the payment methods made available by VOICY, which may include bank transfer, Stripe, PayPal or other available payment methods.
Where a payment is made through a third-party payment provider such as Stripe or PayPal, payment-card information is submitted directly to and processed by that provider.
VOICY does not receive or store full payment-card numbers or CVV/security codes.
VOICY may nevertheless process information necessary for billing and accounting purposes, such as payment status, transaction references, invoice information and amounts paid.
We process personal data only where there is a valid legal basis and where the processing is necessary for a legitimate and defined purpose.
We primarily process personal data in order to provide and administer our services. This includes activating telecommunications services, allocating and managing telephone numbers, configuring Cloud PBX systems and SIP trunks, routing calls, maintaining customer accounts, providing technical support, managing billing and responding to customer requests.
We also process personal data where necessary to comply with legal and regulatory obligations applicable to electronic communications providers. These obligations may relate to telephone numbering, customer identification, billing and taxation, emergency communications, telecommunications security, lawful requests from competent authorities, statutory data retention and other regulatory requirements.
Certain processing is based on VOICY’s legitimate interests, including protecting our network and systems, preventing telecommunications fraud and unauthorised access, managing customer and supplier relationships, responding to business enquiries and establishing, exercising or defending legal claims.
Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
VOICY does not currently operate a general promotional newsletter or direct-marketing mailing programme. If this changes in the future, appropriate information and opt-out mechanisms will be provided.
Operational communications relating to services, billing, security, outages, contractual matters or regulatory changes are not considered marketing communications.
For certain services or features configured by a customer, VOICY may process personal data on the customer’s behalf and according to its instructions.
This may include, for example, customer-controlled call-recording functionality, managed PBX services or technical support requiring access to personal data controlled by the customer.
In such cases, VOICY acts as a Data Processor, and the relevant processing is governed by the applicable service agreement and/or Data Processing Agreement.
VOICY does not record customer telephone calls for its own quality assurance, customer support, marketing or monitoring purposes.
VOICY takes measures to protect the security and integrity of its telecommunications network and services.
This may include technical and routing rules designed to detect or prevent unauthorised, manipulated or fraudulent traffic, including irregular or manipulated Calling Line Identification (“CLI”), unauthorised access and other forms of telecommunications abuse.
These controls are based on technical and operational rules and are not used by VOICY for artificial-intelligence profiling or automated decision-making concerning individuals that produces legal or similarly significant effects.
VOICY does not sell personal data.
We disclose or make personal data available to third parties only where this is necessary for the provision of our services, required by law, requested by the customer or otherwise permitted under applicable data protection legislation.
The operation of telecommunications services requires communications to pass between different networks.
When a call or other communication is routed to or from another network, information necessary to establish, route, terminate or bill that communication may be transmitted to interconnected telecommunications providers, originating or terminating carriers, wholesale carriers or other communications networks.
This may include calling and called telephone numbers and other necessary signalling and routing information.
Additional personal data may be exchanged where a customer requests a service such as telephone number portability, number registration or another service requiring cooperation with another telecommunications provider or authority.
VOICY may use third-party providers necessary for the operation of its business and website.
These currently include Webflow for website hosting and contact-form functionality and Microsoft 365 for business email and communications.
Where applicable, third-party payment providers such as Stripe and PayPal may process payment information directly.
Other infrastructure or service providers may also be used where necessary for a particular service or customer arrangement.
Where a provider processes personal data on behalf of VOICY, appropriate contractual and data-protection requirements are applied as required by applicable law.
VOICY may disclose personal data to courts, law-enforcement bodies, regulatory authorities, tax authorities, EETT, judicial or prosecutorial authorities or other competent public bodies where disclosure is required or permitted by applicable law or pursuant to a valid legal request.
If VOICY is involved in a merger, acquisition, financing, corporate restructuring or sale of all or part of its business or assets, relevant personal data may be disclosed to professional advisers and prospective or actual transaction parties where lawful and subject to appropriate confidentiality arrangements.
VOICY’s principal telecommunications and hosted PBX infrastructure is located in Greece and/or elsewhere within the European Union, depending on the particular service.
However, some providers used in connection with our website, communications or payment services operate internationally.
In particular, information processed through Webflow, including contact-form submissions, may be processed or stored outside the European Economic Area (“EEA”), including in the United States.
Other international service providers, including Microsoft, Stripe and PayPal, may also process certain information in different jurisdictions depending on the service used and their technical infrastructure.
Where personal data is transferred outside the EEA, such transfers are carried out in accordance with applicable data protection legislation. Where required, appropriate safeguards may include adequacy decisions, European Commission Standard Contractual Clauses or other legally recognised transfer mechanisms.
Due to the international nature of electronic communications, telecommunications traffic may also pass through networks located in different countries when a communication is routed internationally.
VOICY retains personal data only for as long as necessary for the purpose for which it was collected and for any additional period required by applicable legal, regulatory, contractual, accounting or limitation requirements.
Customer, contractual, invoicing and accounting information is retained for the duration of the relevant business relationship and thereafter for the period required by applicable tax, accounting and legal obligations.
Identification and regulatory documentation is retained for as long as necessary to provide the relevant service and for any additional period required under applicable telecommunications or other legislation.
Telecommunications traffic data and CDRs are retained in accordance with applicable Greek and European electronic communications and data-retention legislation. Where statutory telecommunications retention requirements apply, the relevant data is retained for the legally required period and deleted when that period expires, unless applicable law permits or requires further retention.
Customer-controlled data processed by VOICY on behalf of a customer is retained in accordance with the applicable service agreement, Data Processing Agreement and customer instructions.
Contact-form submissions may be retained within Webflow and in VOICY’s Microsoft 365 email environment for as long as reasonably necessary to respond to the enquiry, maintain relevant business correspondence, prepare or follow up a quotation, manage any resulting relationship or establish, exercise or defend legal claims.
When personal data is no longer required for the purpose for which it is held and there is no applicable legal requirement for continued retention, it is deleted in accordance with VOICY’s applicable procedures.
VOICY implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Depending on the system and service concerned, these measures may include access controls, authentication mechanisms, network-security controls, firewalls, telecommunications anti-fraud measures, secure administrative access, encryption technologies where appropriate, backup procedures and restrictions on personnel access.
No electronic communications network or information system can be guaranteed to be completely secure. VOICY therefore reviews and adapts its security measures having regard to the nature of the processing, technological developments and the risks involved.
Our website may process technical information necessary for its operation, security and delivery, such as IP address, browser and device information.
VOICY does not currently use non-essential cookies or tracking technologies for advertising or analytics purposes.
If our use of cookies or similar technologies changes, we will provide the information and consent options required by applicable law.
Subject to the requirements and limitations of applicable law, you may have the right to:
These rights are not absolute. In particular, VOICY may be required by telecommunications, accounting, tax or other legislation to retain particular information even where deletion is requested.
To exercise your rights or ask a question concerning the processing of your personal data, please contact:
We may request information reasonably necessary to confirm your identity before acting on a request.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA).
Our website and services may contain links to, or integrations with, third-party websites and services.
Where a third party determines independently how and why it processes personal data, its own privacy policy and terms apply. VOICY is not responsible for the privacy practices of independent third-party websites or services.
Where a third party processes personal data on behalf of VOICY, the relationship is governed in accordance with applicable data-protection requirements.
VOICY’s services are primarily intended for businesses, professional customers and adults who have the legal capacity to enter into the relevant contractual relationship.
VOICY does not knowingly offer its telecommunications services directly to children who do not have the legal capacity to enter into the applicable agreement.
If we become aware that personal data relating to a child has been provided inappropriately, we will take reasonable steps to address the matter in accordance with applicable law.
We may update this Privacy Policy from time to time where necessary to reflect changes to our services, processing activities, service providers, technologies or applicable legal and regulatory requirements.
The latest version will always be available on our website and will show the date on which it was last updated.
Where a change materially affects how personal data is processed, we will provide any additional notification required by applicable law.
For questions concerning this Privacy Policy, the processing of personal data or the exercise of your data-protection rights, please contact:
VOICY ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε.
Leoforos Kifisias 166A
Marousi, 15126 Athens
Greece
Privacy and Legal Contact: legal@voicy.gr