Legal
Privacy Statement
We sell phone systems, not your data. This page says exactly what we collect, why we have it, who else can see it, and how to make us delete it.
Last updated: 13 August 2026 · Covers filantis.com, the Filantis admin interface and the Filantis mobile app
The short version
- No tracking scripts. This site loads no analytics, no advertising pixels, no webfonts and nothing from anybody else's server. We do count visits — on our own server, with no cookie and without ever storing your address.
- Two cookies, both doing a job — the currency you picked, and your signed-in session. Neither follows you anywhere.
- We never see your card. The payment gateway takes it. We store a transaction reference and nothing else.
- Your calls are yours. Recordings, voicemail and call records belong to your business — and on an appliance or your own server they never leave your building at all.
- We never sell, rent or trade your details. Not to anyone, for any price.
This summary exists to be read. The sections below are what actually applies.
1.Who we are
Filantis is a business telephone system, sold as a hosted service and as software you run on your own hardware. This statement covers the marketing site at filantis.com, the admin interface at your own Filantis address, and the Filantis mobile app.
Questions about anything here go to privacy@filantis.com, which reaches a person rather than a queue.
2.Whose data is whose
There are two different relationships on this page and it is worth separating them before anything else.
- Your own account with us — the person who signed up, the billing details, the emails between us. Here we decide what to collect and why, so we are responsible for it. That is what most of this statement is about.
- What your phone system holds — your staff's extensions, your call records, your voicemail and recordings, your customers' numbers. That is your data about your people. We hold it on your instructions so the system can work, and for no purpose of our own. We do not mine it, sell it, train anything on it, or look at it except when you ask us to help with a specific problem.
On an appliance or an office server, the second one never reaches us at all. The recordings, the voicemail and the call log live on hardware in your building. That is the entire point of those editions, and it is why some industries and some auditors insist on them.
3.What we collect, and why
| What | Why we have it | What happens without it |
|---|---|---|
| Name, work email, phone number, company | To create your workspace, invoice you and talk to you about it | There is no account to create |
| Billing address and tax number | Because an invoice legally has to carry them | We cannot issue a valid invoice |
| Transaction reference and amount | To prove what you paid and to refund it if you ask | No way to reconcile a payment or a refund |
| Your workspace name and plan | To route your address and apply what you have paid for | No system |
| Sign-in records and IP address | Security — spotting a break-in attempt, and answering "who changed this" | We could not tell you whether an account had been misused |
| What you tell us in a dedicated server quote request | To size the server and send you the quote you asked for | We cannot prepare a quote |
| Support correspondence | So the next person you speak to knows what the last one said | You explain it again every time |
That is the whole list for a hosted account. There is no profiling, no scoring, no enrichment from data brokers, and no automated decision-making that has any legal or similarly significant effect on anybody.
4.Visiting this website
This page and every other page on filantis.com are served from our own machine and load nothing from a third party: no analytics, no advertising or conversion pixels, no webfonts, no tag manager, no chat widget, no social buttons. Your browser talks to us and to nobody else.
Our web server keeps ordinary access logs — the address that made the request, the page, the time, the browser's user-agent string. They are used to keep the service running and to investigate abuse, and for nothing else.
Counting visits
We count how many people read each page. It is worth being precise about how, because “analytics” usually means something we are not doing:
- It happens on our server, as the page is built. There is no script, no pixel and no beacon — nothing appears in your browser's network tab, because nothing is sent.
- No cookie is involved. The two cookies below are still the only two this site sets.
- Your address is never stored. What is recorded is a short hash of your address and browser under a secret that changes every day. That is enough to know that two pages were read by the same person this morning, and it is deliberately not enough to know that you also came last week. When the day's secret is deleted, no record from that day can be connected to any address by anybody, including us.
- We keep the page, the site that linked you here (the site only, never the full address or your search terms), a two-letter country, and whether you were on a phone, a tablet or a computer.
- We honour Do Not Track and Global Privacy Control. If your browser sends either, nothing at all is recorded about your visit.
Records are deleted after the period in the retention table below, together with the secret that made them.
The prices you are shown
The site guesses whether to open in dollars or rupees. In order, that guess comes from a currency you picked yourself on an earlier visit, then a country header our own front end already receives, then an allocation table shipped inside the product, then your browser's language setting.
If none of those answers, we may look the address up in an IP location database we run ourselves, on our own hardware — the same one behind sslretail.com, which is ours. No third-party geolocation service is ever contacted, your address is not stored by that lookup, and the answer is cached against the address for a week so that repeat visits ask nothing at all. It is used to choose which price to show first and for nothing else — it gates no feature and restricts no payment method.
There is always a visible switch, because a guess you cannot correct is worse than no guess at all — and whichever currency you are shown, what you are actually charged is decided by the payment method you choose at the till.
We honour Do Not Track. Nothing about your visit is recorded when you send it, and there is nothing else being collected for it to apply to.
6.Payments
We do not store your card details. Ever. They are entered on the payment provider's own page, under their PCI-DSS certification, and what comes back to us is a transaction reference, an amount, a currency and a status. We could not charge your card again on our own if we wanted to.
Where you pay by UPI, there is no card at all: you are shown a QR code, a payment link and our VPA in plain text, you pay from your own banking app, and you give us the UTR afterwards. We receive the reference and the amount. A UPI payment is confirmed by a person here, because UPI gives a merchant no way to ask whether a payment arrived — that is a property of UPI, not a choice of ours.
Refunds go back to the account the payment came from, and only there. See the Refund Policy.
7.Call data, voicemail and recordings
A phone system necessarily knows who called whom, when, and for how long. On a hosted workspace that record lives in your own separate area of our platform, and so do your voicemail messages and any calls you have chosen to record.
- It is yours. We hold it to run your phone system and for nothing else, and we do not claim any other right over it.
- We do not listen to your calls, read your voicemail, or analyse your call records — not for product improvement, not for advertising, and not to train any machine-learning model.
- A free workspace may show advertising in its interface, and this is the rule that governs it: what is shown is never selected using your call records, your contacts or anything said on a call, and no advertisement is ever played to a caller. Paid plans show none. See section 6 of the Terms of Service.
- Our engineers access a workspace only to investigate a fault, only for as long as that takes, and normally only when you have asked. Where the system records an action, it records who took it.
- We do not carry your calls as a telephone company. Your calls travel over your own SIP trunks with your own carrier, who has their own records and their own privacy policy — worth reading, because that is where your call detail also exists.
Recording calls is regulated where you are, and that part is your responsibility. Most jurisdictions require notice to one or both parties. We give you the switch and the announcement; whether and how you use them is a decision only you can make lawfully.
8.The mobile app
The Filantis app turns a phone into an office extension. It contains no advertising SDK and no analytics SDK, and it talks to one server: your own phone system.
- Microphone and camera — for calls, and used during a call only.
- Notifications — so an incoming call can ring when the app is not on screen.
- Contacts — optional, and off unless you switch it on. When it is on, the handset uploads its address book to your own system so you can dial from it. It is stored against that extension, it goes to no one else, and switching the permission off stops the sync. Your existing upload is set aside rather than destroyed, because a phone book an office has been working from is not something to delete on a silent permission change.
- Battery exemption — so the phone does not stop the app receiving calls overnight.
The app does not read your location, your photos, your messages or your call history, and it does not ask for permission to.
9.Email we send you
Emails about your account — the setup link, invoices, renewal notices, security notifications, and answers to things you have asked us — are part of the service and are sent whether or not you have opted into anything.
Marketing email is separate, infrequent, and always has an unsubscribe link that works immediately. We never sell, rent or trade your email address to anyone. Our emails carry no tracking pixel, so we do not know whether you opened one.
11.How it is protected
- Everything travels over TLS — the admin interface, the app, and SIP signalling on the encrypted transport.
- Passwords are never stored in a readable form. Your sign-in password is also your SIP password, and it is held only as the cryptographic digests a handset needs to authenticate.
- Connector credentials and other stored secrets are encrypted with a key that is unique to your installation and is not in any backup we distribute.
- Each hosted customer's data is kept in its own separate area of the platform, addressed by that customer's own name.
- The application files are read-only to the web server, the software is updated from cryptographically signed releases, and a database snapshot is taken before an update changes anything.
- The platform has a built-in firewall and repeated-failure blocking on the sign-in and SIP paths.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach affects your data we will tell you what happened, what was exposed and what to do, as soon as we know it — not after we have finished deciding how it looks.
12.How long we keep it
| What | Kept for |
|---|---|
| Your account and workspace | While the account is open |
| A closed workspace's data | Up to about 30 days, then permanently deleted — a courtesy window, not guaranteed, and possibly sooner. Tell us what you need out of it before you close the account, while it still exists. |
| Disaster-recovery backups | Aged out on rotation within 90 days |
| Invoices and payment records | As long as tax law requires, typically 7 years |
| Web server logs | 90 days |
| Visit records for this website | 90 days, deleted together with the daily secret that made them — after which no record can be linked to any address |
| Support correspondence | 2 years after the conversation ends |
| Call records, voicemail, recordings | As long as you configure — you control this, and can delete any of it yourself |
13.Your rights
Whatever country you are in, you may ask us to:
- Show you what we hold about you, and where we got it.
- Correct anything wrong or out of date.
- Delete it, where we are not required to keep it — invoices being the usual exception, because tax law does not care what either of us prefers.
- Export it in a portable form, where the law gives you that right. Ask, and we will tell you what we can provide and how long it will take.
- Withdraw consent to marketing, at any moment, with no effect on the service you have paid for.
- Object to a use of your data, or complain to your data protection authority if you think we have got it wrong. We would rather you told us first, but that is your right and not ours to grant.
Write to privacy@filantis.com. We reply within 30 days and usually within two working days. We may ask you to confirm who you are first — handing an account's data to whoever asked for it would be a worse failure than a slow reply.
If your request is about data inside somebody else's Filantis system — you were called by a business that uses us, say — we will pass you to that business, because it is their record and their decision, not ours to make on their behalf.
14.Children
Filantis is a business product and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.
15.Changes to this statement
We may update this page as the product changes. The date at the top says when it last did. If a change materially affects how we handle your data, we will email customers with an active account before it takes effect rather than quietly reposting the page.
16.Contact
Privacy questions, access requests and deletion requests: privacy@filantis.com
Anything else: hello@filantis.com
If something on this page does not match what the product actually does, that is a bug and we want to hear about it — this statement is meant to describe the software as built, not to describe an intention.