3CX Privacy Policy

Law Enforcement & Fraud Prevention

Introduction

This privacy policy outlines how 3CX processes and protects personal data collected via 3CX Phone System, its Transcription Services, and its Video Conference (WebMeeting) platform. 3CX ensures all processing activities comply with the General Data Protection Regulation (GDPR), applicable local legislation, and other relevant regulatory obligations. This Privacy Policy is intended to provide transparency in accordance with Articles 12–14 GDPR.

By using these services, you agree to the collection, use, and handling of your data as described in this policy.

Where 3CX acts as a processor, the legally binding terms governing such processing are set out in the 3CX Data Processing Addendum (DPA).

3CX acts as:

  • a controller for account, licensing, subscription, support and service-usage data; and
  • a processor for Transcriber and WebMeeting data where these features are activated by a customer.

The PBX-owning organisation remains the data controller for PBX data, Transcriber data and WebMeeting data.

For the avoidance of doubt, 3CX does not act as a controller for PBX call data, meeting content, or transcription data, for which the PBX-owning organisation remains solely responsible.

What Data Do We Collect?

Transcriber Service

  • Audio recordings (.wav files) from calls and voicemails
  • Transcriptions of audio
  • Metadata including call type, caller/callee extension numbers and names, and PBX default language

Web Meeting (Video Conference)

  • Participant names
  • Participant IP addresses
  • 3CX System Information: FQDN, IP Address, Unique ID
  • Files shared during a meeting (names anonymized on upload)
  • Meeting quality survey data (anonymous)

No chat content is stored; chat exists only in transit unless meeting recording (if enabled) captures it.

How Do We Collect Your Data?

  • Through 3CX System configuration and activation (Transcriber + WebMeeting)
  • Automatically via system APIs when meetings or recordings are initiated
  • Uploaded via secure Google Cloud Buckets
  • Runtime system logs, surveys, and debug logs
  • Data generated by AI-based processing where enabled (e.g. summaries, sentiment analysis)

3CX does not collect any data beyond what is necessary for the provision, maintenance, and improvement of the services enabled by the customer.

The processing of IP addresses is necessary for the performance of the WebMeeting service (Art. 6(1)(b)) and for 3CX’s legitimate interest in ensuring security and fraud prevention (Art. 6(1)(f)).

How Will Your Data Be Used?

Transcriber Service

  • To transcribe audio to text
  • To generate summaries and sentiment analysis
  • For AI feature development (always using anonymised or pseudonymized data whenever technically feasible). AI development uses data only after irreversible anonymisation, unless explicitly instructed otherwise in the DPA and only where strictly necessary.
  • For debugging and improving service performance
  • To ensure fraud prevention, service security and abuse detection (metadata only)

Web Meeting Platform

  • To display participant names during meetings
  • To process and store shared files for up to 7 days
  • To generate anonymous meeting quality feedback
  • For platform optimization and bug fixing
  • To ensure performance, security and compliance with applicable laws.

3CX does not monitor, access, or analyse the content of communications except where the customer explicitly activates features such as recording or transcription.

Data Processing & Storage

  • All data is stored in Google Cloud Platform (GCP) or other reputable cloud providers (Vultr, AWS, DigitalOcean, etc.)
  • Storage is regional - aligned with the selected conferencing zone or user location (e.g., EEA)
  • Secure, encrypted communication protocols are enforced

Where 3CX acts as a processor, data is processed solely on documented instructions of the customer/controller.

Retention Periods

Data Type

Retention Duration

Audio Files (Transcriber)

2 days

Transcriptions

7 days

Files Shared via WebMeeting

7 days

Participant IPs

7 days

Meeting Recordings

7 days

Debug Logs

Up to 6 months

Transcribed metadata & analysis

7 days (or longer if legally required)

Chat messages

Not stored; only exist in transit

Survey Data

Stored anonymously

Backups (post-termination)

Up to 1 year (if legally needed)

Retention periods may be extended where necessary to comply with legal obligations, resolve disputes, prevent fraud and abuse, or enforce agreements.

After expiration of the retention period, data is securely deleted or anonymised.

Security Measures

  • Industry-standard encryption protocols during data upload and download
  • Access restricted to authorized personnel only
  • Access logging and audit trails
  • Regular security audits
  • Administrator responsibilities: Customers must implement appropriate access-control configurations, retention settings, and security rules within their PBX and WebMeeting environments.

User Rights

  • Users may request access, deletion, or correction of their data by contacting their 3CX administrator
  • 3CX supports data controllers in responding to such requests under applicable data laws

Data subjects may also exercise GDPR rights (access, rectification, erasure, restriction, objection, portability) directly with 3CX for data that 3CX controls.

For data where 3CX acts as processor, 3CX cannot respond directly to data subject requests without instructions from the PBX-owning controller.

Consent & Legal Basis

  • The PBX owning organization is responsible for obtaining legal basis and necessary user consents
  • Users are clearly informed about how their data is collected and processed

3CX relies on:

  • performance of contract (Art. 6(1)(b));
  • legitimate interests (service security, fraud prevention, product improvement) (Art. 6(1)(f));
  • compliance with legal obligations (Art. 6(1)(c));
  • consent (where applicable, e.g. transcription features enabled by the customer).

The PBX owner is responsible for ensuring lawful processing of employee or participant data in accordance with local employment or telecommunications laws.

Geolocation & Server Selection

  • EEA-based customers are routed to EEA-located servers if the “Europe” region is selected
  • Server location may vary for redundancy and load balancing
  • International transfers are subject to appropriate safeguards under GDPR (e.g., SCCs)

Cookies & Browser Storage

  • No cookies are used
  • Browser local storage is used for participant names and configuration
  • Local storage is only used for functionality and is not accessed by 3CX

Statistical & Aggregated Data

  • Usage statistics are anonymous
  • 3CX may share anonymized aggregated data for statistical or legal reasons
  • Aggregated data cannot be used to identify any individual user

Law Enforcement & Fraud Prevention

Requests from Law Enforcement Authorities

  • We may disclose Personal Data only when required to do so by applicable law or in response to valid legal process formally addressed to the relevant 3CX entity.
  • 3CX does not provide customer information to third parties, including foreign law-enforcement bodies, unless:
  • a lawful request is properly served through the competent Cypriot authority or other legally recognised channel; and
  • the request is specific, proportionate, and establishes a clear legal basis for disclosure.
  • Where a request does not satisfy these conditions, 3CX reserves the right to decline or to request further clarification before taking action. 3CX does not act upon informal notifications, unsubstantiated allegations, or requests made outside legally established procedures.
  • 3CX may process metadata (not call content) to detect, prevent or investigate fraudulent or abusive activity.
  • 3CX may disclose data to law enforcement authorities only upon receipt of a valid and lawful request, and only to the extent required by applicable law.

International Data Transfers

Where data is transferred outside the EU/EEA, 3CX relies on:  

  • the European Commission’s Standard Contractual Clauses (SCCs), or
  • other approved transfer mechanisms under GDPR Art. 46.

Data center selection is always aligned with regional performance and compliance considerations.

3CX implements supplementary security measures in line with EDPB recommendations to ensure equivalent protection for international transfers.

Changes to This Policy

This privacy policy may be updated periodically. Users are encouraged to review it regularly. Any changes will be published on the 3CX website.

Contact Information

For questions or concerns regarding this privacy policy, please contact us by filling in this contact form

***

See Also

Last Updated

This document was last updated 26 June 2026

https://www.3cx.com/company/privacy-policy/