Snapshot 35635
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Privacy Policy 1. The FreJun Group and Products 1.1 About FreJun FreJun is a voice infrastructure platform. We build and operate the technology that powers business communication and developer telephony across three regional entities. This policy governs all personal information processed by any FreJun Group entity in connection with either of our two products. 1.2 Our products FreJun Dialer is our business communication product. It is designed for sales teams, recruitment operations, and customer support functions. It provides features including click-to-call, auto-dialer, call recording, AI-generated call notes and summaries, post-call surveys, virtual numbers, and integrations with CRM and productivity tools. Users of FreJun Dialer are typically employees or contractors of a subscribing business. FreJun Teler is our developer API product. It provides programmatic access to voice infrastructure – including number provisioning, call routing, PSTN connectivity, call data, and webhooks – for developers and technical teams building telephony applications and workflows. Users of FreJun Teler are primarily developers, engineers, and organisations integrating voice capabilities into their own products. Both products are built on and governed by the same underlying legal and compliance framework. Where data collection, processing, or retention differs between them, this policy says so explicitly. 1.3 The entities responsible for your data The entity responsible for your personal information depends on where you access and use the Services: FreJun Inc. – Incorporated in Delaware, USA. Serves users in North America and globally where no regional entity applies. Governing data framework: CCPA/CPRA (California residents). FreJun India Pvt. Ltd. – Incorporated in India under the Companies Act, 2013. Serves users in India. Governing data law: Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025. Al-FreJun – Operating in the United Arab Emirates. Serves users in the UAE and the wider MENA region. Governing data law: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). For EU residents, whichever entity you contract with acts as the GDPR Controller. All three entities maintain intra-group data sharing agreements that ensure equivalent data protection standards apply regardless of which entity holds the data. Collectively, the three entities are referred to in this policy as “we”, “us”, “our”, or “the FreJun Group”. 2. Key terms The following definitions apply throughout this policy: “Personal information” / “personal data”: Any information that identifies or can reasonably identify a specific individual. “Services”: All FreJun Group products, platforms, websites, mobile applications, and APIs – including FreJun Dialer and FreJun Teler. “Account holder”: The business or individual that holds a subscription to FreJun Dialer or a registered developer account for FreJun Teler. “End user” (Dialer): An employee, contractor, or agent of the account holder who uses FreJun Dialer to make or receive calls. “Developer” (Teler): An individual or entity that accesses FreJun Teler via API to build or operate telephony functionality. “Participant”: A third party who is a party to a call made or received through the Services, whether via FreJun Dialer or an application built on FreJun Teler. “Controller” (GDPR) / “Data Fiduciary” (DPDP Act) / “Controller” (UAE PDPL): The entity that determines the purposes and means of processing personal data. The relevant FreJun Group entity serves in this role. “Data Subject” (GDPR, UAE PDPL) / “Data Principal” (DPDP Act): The individual whose personal data is being processed. “Data Processor”: A third party that processes personal data on behalf of a FreJun Group entity under documented instructions. 3. What personal information we collect What we collect depends on which product you are using and in what capacity. The following sets this out clearly. 3.1 Information you provide directly When you create an account, contact us for support, or register for communications, you share information with us directly. This typically includes your name, email address, phone number, company name, and designation. Account setup also involves payment details. The specific categories collected vary slightly by product: FreJun Dialer: FreJun Dialer account holders and end users provide contact information, billing details, and company identifiers during onboarding. End users added to an organisation account may have their profiles created by the account holder, in which case the account holder is responsible for ensuring that information is accurate and that any required notifications to end users have been given. FreJun Teler: FreJun Teler developers provide contact information, company or individual identification details, and payment information during API account registration. Developers may also provide test phone numbers and other telephony configuration details during setup. 3.2 Information generated through use of the Services Use of either product generates personal information as a direct result of the Services being delivered: FreJun Dialer: FreJun Dialer collects voice recordings of calls made or received through the platform, including recordings of Participants. It also collects call metadata (duration, timestamp, number dialled, call outcome), AI-generated call notes and summaries, Participant contact details, CRM integration data, and post-call survey responses. This information is core to the product’s functionality; features such as call review, coaching, and AI insights depend on it. FreJun Teler: FreJun Teler collects API call logs, call data records (CDRs), webhook payloads, provisioned number details, call audio where recording is enabled by the developer, and metadata associated with calls routed through the infrastructure. Developers control what data their applications collect from end users of those applications. Where Teler is used to process personal data of third parties, the developer acts as the Controller for that data and FreJun acts as a Data Processor. In both cases, the personal data of Participants – individuals on the other end of calls – may be collected as an inherent function of the communication service. 3.3 Information collected automatically Our website uses Google Analytics (Google Inc.) with IP anonymisation enabled. You may opt out at https://tools.google.com/dlpage/gaoptout. We also collect data when you interact with FreJun content on social media channels including LinkedIn, Twitter/X, Instagram, and Facebook, or use social login credentials to register. 3.4 Cookies and tracking technologies We use cookies, beacons, tags, and scripts to understand platform usage, improve user experience, and serve relevant content. Types deployed include session, first- and third-party, secure, HTTP-only, and persistent cookies. Information collected includes IP addresses, location indicators, browser and device specifications, and session data. Disabling cookies does not restrict access to the Services. India (DPDP Act 2023): Under the DPDP Act 2023, this policy constitutes the notice to Data Principals in India describing the categories of personal data collected, the purposes of processing, and the mechanism for exercising rights. Where consent is the basis for processing, it is obtained through our registration and onboarding flow and must be free, specific, informed, unconditional, and unambiguous. UAE (PDPL 2021): Under the UAE PDPL (Federal Decree-Law No. 45 of 2021), processing personal data requires the informed consent of the Data Subject unless a statutory exemption applies. By creating an account and using the Services, UAE users confirm their consent to the processing described in this policy. Consent may be withdrawn at any time by writing to infosecurity@frejun.com. 4. Accuracy of information Please ensure the personal information you provide is accurate and current, particularly contact and payment details. If you are providing information on behalf of another individual – for example, as an account holder creating end user profiles for FreJun Dialer – you confirm that you have the authority to do so and that the information shared is accurate. FreJun Dialer: Account holders who manage end user profiles within a FreJun Dialer organisation are responsible for the accuracy of those profiles and for ensuring that end users have been appropriately informed about data processing in accordance with applicable law. 5. How we use your personal information We process personal information only where there is a clear and lawful basis. The purposes differ slightly between products but include the following across both: Delivering and maintaining the Services, including calling, routing, recording, and AI features Account management, billing, and payment processing Customer support, service updates, and responses to queries Internal product analytics and development to improve the Services Marketing and promotional communications, where you have not opted out Fraud prevention, abuse detection, and platform security Compliance with legal and regulatory obligations Processing of job applications submitted through the platform FreJun Dialer: For FreJun Dialer, we additionally use call recordings and AI-generated data to provide call coaching features, post-call analytics, and summary reports to account holders. Participant data is processed solely to enable the call service and is not used for marketing purposes. FreJun Teler: For FreJun Teler, we process API usage data, CDRs, and log data to maintain infrastructure reliability, enforce API usage limits, troubleshoot developer issues, and generate usage-based billing. Where a developer has enabled call recording via the API, the resulting audio data is stored on the developer’s behalf and processed under their instructions. Participant information is retained to the extent necessary to fulfil contractual obligations to account holders and to comply with applicable law. Legal basis for processing EU (GDPR): We rely on: (a) your consent – Article 6(1)(a); (b) performance of a contract – Article 6(1)(b); and (c) our legitimate interests in operating and improving the Services – Article 6(1)(f), where not overridden by your rights. India (DPDP Act 2023): Under the DPDP Act 2023, consent is the primary lawful basis. A second basis – “legitimate use” – applies in specific circumstances including legal compliance and employment-related processing. Where we rely on legitimate use, the applicable ground is documented. You may withdraw consent at any time by writing to infosecurity@frejun.com; withdrawal does not affect prior processing. UAE (PDPL 2021): Under the UAE PDPL, processing is permitted where the Data Subject has given consent, or where processing is necessary for contract performance, legal compliance, protection of vital interests, or legitimate Controller interests not overriding the rights of the Data Subject. United States: FreJun Inc. relies on contractual necessity, legitimate business interests, and consent where applicable. California residents have rights under CCPA/CPRA, including the right to know, delete, and opt out of sale of personal information. FreJun does not sell personal information. Requests may be submitted to infosecurity@frejun.com. 6. To whom we disclose your information We do not sell, rent, lease, or otherwise transfer personal information to third parties for commercial gain. Disclosure is limited to the following: Service providers and Data Processors We engage third-party providers for hosting, payment processing, analytics, infrastructure, and related operational services. They receive only what is necessary to perform their function and are contractually bound to handle data in accordance with applicable data protection standards. India (DPDP Act 2023): Third parties processing data on behalf of FreJun India Pvt. Ltd. are Data Processors under the DPDP Act. Written agreements are maintained with all processors restricting processing to documented instructions and requiring appropriate security safeguards. UAE (PDPL 2021): Processors engaged by Al-FreJun are bound by written contracts specifying data protection obligations in accordance with the UAE PDPL. Al-FreJun remains responsible for processor compliance. FreJun Teler: Where FreJun Teler developers use the API to process personal data of their own users, FreJun acts as a Data Processor on the developer’s instructions. The developer, as Controller, is responsible for ensuring a lawful basis for that processing and for providing appropriate notices to their own users. 6.1 Intra-group transfers The three FreJun Group entities may share personal information with each other to the extent necessary to operate the platform and provide the Services globally. Such transfers are governed by intra-group data sharing agreements ensuring equivalent protections apply regardless of which entity holds the data. 6.2 Business transfers In the event of a merger, acquisition, or sale of all or part of any FreJun Group entity, personal information may transfer to the acquiring entity, which would be bound by the commitments in this policy or equivalent protections. 6.3 Legal and regulatory requirements We may disclose personal information where required by law, court order, or regulatory authority. We disclose only what is required and, where lawful, will endeavour to notify affected individuals in advance. 6.4 Call participants Call recordings, AI notes, and summaries generated by FreJun Dialer are accessible to the relevant account holders and authorised end users. Where applicable law requires prior notification to a Participant that a call is being recorded, that obligation rests with the account holder. Developers using FreJun Teler are responsible for any recording notifications required by law in relation to calls made through their applications. 7. International transfer of personal information Given the global structure of the FreJun Group, personal information may be processed and stored in jurisdictions other than the one in which you are located, including India, the United States, and the UAE. All such transfers are carried out in accordance with applicable law. EU (GDPR): Transfers of EU personal data to third countries are conducted in accordance with GDPR Chapter V, including through standard contractual clauses where required. India (DPDP Act 2023): Under the DPDP Act, personal data of Indian Data Principals may be transferred to countries other than those restricted by notification of the Central Government. No such restricted countries have been formally notified at the time of this policy. FreJun India Pvt. Ltd. currently processes data in India and the United States. This section will be updated if any restriction is notified. UAE (PDPL 2021): Under Articles 22 and 23 of the UAE PDPL, cross-border data transfers are permitted to countries providing adequate protection or where contractual safeguards are in place. Al-FreJun ensures any transfer of UAE user data is subject to appropriate contractual protections. 8. How long we retain your information Personal information is retained only for as long as is necessary to fulfil the purpose for which it was collected, or as required by law. Retention periods differ by data type and product: FreJun Dialer: Account and profile data is held for the duration of the subscription and for a reasonable period thereafter to enable account reactivation or to respond to post-termination queries. Call recordings are retained in accordance with the account holder’s chosen plan. AI-generated data such as call notes and summaries follow the same retention period as the underlying recording unless deleted earlier by the account holder. FreJun Teler: API usage logs, CDRs, and call metadata are retained for the period necessary for billing reconciliation, technical support, and regulatory compliance. Call audio stored on behalf of developers via the Teler API is retained in accordance with the developer’s account configuration and applicable legal requirements. On receiving a written deletion request, we will take reasonable steps to remove your information from active systems. Residual copies may persist in backup infrastructure for a limited period owing to standard data management cycles; these are not accessible in normal operations. India (DPDP Act 2023): Under Section 8(7) of the DPDP Act, FreJun India Pvt. Ltd. is required to erase personal data when the purpose of processing has been fulfilled and retention is no longer legally necessary. Data retention schedules are maintained and reviewed periodically. Data Principals may request erasure under Section 12 (see Section 10). UAE (PDPL 2021): The UAE PDPL requires personal data to be retained only for the period necessary for the stated purpose. Al-FreJun maintains data retention schedules in compliance with this requirement and will delete data on request subject to applicable legal constraints. 9. Security measures and breach notification The FreJun Group maintains technical and organisational safeguards – including firewalls, access controls, encrypted transmission, and access logging – reflecting reasonable industry practice for a voice infrastructure platform. No internet-connected system is impenetrable. We do not warrant absolute security and do not accept liability for breaches caused by circumstances outside our reasonable control. We will never request your password or payment credentials by email. Report any suspicious communication to infosecurity@frejun.com before acting on it. FreJun Teler: FreJun Teler provides developers with tools to manage API key security, including key rotation, scoped permissions, and IP allowlisting. Developers are responsible for maintaining the security of their API credentials and for implementing appropriate safeguards within applications they build on the Teler infrastructure. India (DPDP Act 2023): Under the DPDP Act and Rule 7 of the DPDP Rules 2025, in the event of a personal data breach: (i) the Data Protection Board of India must be notified without delay, with a detailed report submitted within 72 hours; (ii) each affected Data Principal must be notified without delay with details of the breach and remedial steps taken. All breaches must be reported – there is no de minimis threshold. Access and processing logs are retained for a minimum of one year. UAE (PDPL 2021): The UAE PDPL requires appropriate technical and organisational measures to prevent unauthorised access, loss, or misuse of personal data. In the event of a breach, Al-FreJun will notify the UAE Data Office and affected Data Subjects in accordance with the timelines and procedures prescribed by the PDPL. EU (GDPR): Breaches affecting EU users will be notified to the relevant supervisory authority within 72 hours where there is a risk to individual rights and freedoms, and to affected individuals without undue delay where there is a high risk. 10. Your rights as a user Your rights over your personal information depend on your location and, in some cases, on which product you are using. EU residents – GDPR Right of access to the personal information we hold Right to rectification of inaccurate or incomplete data Right to erasure (“right to be forgotten”), subject to legal constraints Right to restriction of processing in certain circumstances Right to object to processing on legitimate interest grounds Right to data portability in a machine-readable format Right to lodge a complaint with the competent supervisory authority Indian users – DPDP Act 2023 Right to access (Section 11): Request a summary of personal data held and a description of processing activities. Right to correction and erasure (Section 12): Request correction of inaccurate data, or erasure where the purpose of processing has been fulfilled or consent withdrawn. Right to grievance redressal (Section 13): Raise a complaint regarding our handling of your personal data. All grievances will be addressed within 90 days of receipt. Right to nominate (Section 14): Nominate another individual to exercise your data rights in the event of your death or incapacity. Right to withdraw consent: Withdraw consent at any time; withdrawal does not affect processing completed before that point. India (DPDP Act 2023): Requests should be submitted to infosecurity@frejun.com, marked as a data rights request. FreJun India Pvt. Ltd. has designated this address as the point of contact for all Data Principal requests and grievances in accordance with the DPDP Rules 2025. Unresolved complaints may be escalated to the Data Protection Board of India. UAE users – PDPL Right to access: Be informed about the collection of your personal data and obtain a copy of it. Right to rectification: Request correction of inaccurate or outdated data. Right to erasure: Request deletion where data is no longer necessary for the purpose of collection. Right to restriction: Request that processing be limited in certain circumstances. Right to data portability: Receive data in a structured, commonly used format. Right to object to automated processing: Object to decisions made solely through automated means with legal or significant effects. UAE (PDPL 2021): UAE users should direct requests to infosecurity@frejun.com, marked for UAE data rights. Al-FreJun will respond within the period prescribed by the UAE Data Office. Unresolved complaints may be directed to the UAE Data Office, established under Federal Decree-Law No. 44 of 2021. Teler developer note FreJun Teler: FreJun Teler developers who process personal data of their own application users act as independent Controllers for that data. FreJun’s obligations as Data Processor are set out in the Data Processing Agreement (DPA) available to Teler account holders. End users of developer-built applications should direct data rights requests to the developer, not to FreJun, unless FreJun is the direct Controller of the relevant data. 11. Children’s data Neither FreJun Dialer nor FreJun Teler is directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a child’s information has been provided to us, please contact infosecurity@frejun.com and we will take prompt steps to remove it. India (DPDP Act 2023): Section 9 of the DPDP Act requires verifiable parental or guardian consent before processing personal data of any person under 18 in India. FreJun India Pvt. Ltd. implements age-based safeguards at registration. Penalties for breach of children’s data obligations may reach ₹200 crore. UAE (PDPL 2021): The UAE PDPL requires specific protections for minors’ data. Al-FreJun does not knowingly register or serve users under 18. Where parental or guardian consent is required under UAE law, it will be obtained before processing commences. 12. Links to third-party websites and integrations Our Services, documentation, and website may contain links to third-party websites or applications not owned or operated by any FreJun Group entity. We have no control over their content or data practices. Visiting them is at your own discretion and risk. FreJun Teler: FreJun Teler provides integrations and webhooks that connect to third-party systems. Once data is transmitted to a third-party endpoint configured by a developer, it is subject to that party’s privacy practices. FreJun is not responsible for how third parties handle data received via Teler webhooks or API callbacks. 13. Limitation of liability To the fullest extent permitted by applicable law, no FreJun Group entity shall be liable for any direct, indirect, incidental, consequential, or exemplary damages arising out of or in connection with this Privacy Policy, including damages for loss of data, business interruption, or loss of goodwill, even if advised of the possibility of such damages. Nothing in this section limits any entity’s obligations under the DPDP Act, the GDPR, the UAE PDPL, or any other applicable data protection legislation. Statutory rights are not affected. 14. Governing law and dispute resolution The governing law depends on which FreJun Group entity you have contracted with: FreJun Inc. (USA): Governed by the laws of the State of Delaware. Disputes subject to the exclusive jurisdiction of the competent courts of Delaware. FreJun India Pvt. Ltd. (India): Governed by the laws of India. Data protection matters are additionally subject to the jurisdiction of the Data Protection Board of India. Al-FreJun (UAE): Governed by the federal laws of the United Arab Emirates. Data protection matters are subject to the jurisdiction of the UAE Data Office and competent UAE courts. For EU residents, this does not affect your right to lodge a complaint with the supervisory authority of the EU member state in which you are habitually resident. 15. Changes to this policy We review and update this policy periodically to reflect changes in our practices, Services, or legal requirements. When we make material changes, the effective date at the top of this document will be updated. Continued use of the Services following any update constitutes acceptance of the revised policy. If you disagree with a material change, you may discontinue use and request deletion of your data in accordance with Section 8. India (DPDP Act 2023): Where a change affects the scope or basis of processing of personal data of Data Principals in India, FreJun India Pvt. Ltd. will issue a fresh notice as required by the DPDP Act before the revised processing commences. UAE (PDPL 2021): Al-FreJun will notify UAE users of material changes through the platform or by email, and will obtain fresh consent where the change affects the basis on which personal data is processed. 16. Contact us For questions, concerns, or formal data rights requests, please contact us at the address below. Please mark your message with your region and the nature of your request so it reaches the right team without delay. All users – General enquiries: infosecurity@frejun.com India – FreJun India Pvt. Ltd.: Data Principal requests and DPDP Act matters: infosecurity@frejun.com (subject: “Data Rights – India”). Escalation: Data Protection Board of India. UAE – Al-FreJun: Data Subject requests and PDPL matters: infosecurity@frejun.com (subject: “Data Rights – UAE”). Escalation: UAE Data Office. USA – FreJun Inc.: CCPA/CPRA and general US privacy requests: infosecurity@frejun.com (subject: “Data Rights – US”). FreJun Teler: Teler developers with questions about Data Processing Agreements (DPAs) or processor-level obligations should contact infosecurity@frejun.com with the subject: “Teler DPA Enquiry”. © 2026 FreJun Inc. / FreJun India Pvt. Ltd. / Al-FreJun. All rights reserved.