Privacy Policy

TelcoSignal (by PryvX)

Last updated: 6th January 2026

1. Who We Are

TelcoSignal is a privacy-preserving telco risk signals platform provided and operated by PryvX ("PryvX", "we", "us"). TelcoSignal enables regulated financial institutions to access telecom-derived fraud and verification signals (such as SIM swap, device change, number verification, and related indicators) via secure APIs.

2. Our Privacy-First Design

TelcoSignal is built using confidential computing and secure execution environments, meaning:

  • API requests are processed in isolated, encrypted environments
  • PryvX does not view, inspect, or store raw personal data
  • Data is decrypted only within secure hardware enclaves
  • Only derived risk signals are returned to customers
  • Privacy and data minimization are core to the platform's architecture.

3. Our Role in Data Processing

  • Customers (banks, NBFCs, fintechs) are the Data Controllers
  • PryvX acts as a Data Processor / Technical Service Provider
  • Telecom operators and network partners are data providers and may act as independent data controllers
  • We process data strictly on customer instructions and only to deliver the requested signals.

4. Data We Process

Business & Platform Data

  • Account and contact details
  • API credentials
  • Usage and security logs

API Request Data (Processed Securely)

Depending on the API:

  • Mobile number (MSISDN) or tokenized identifiers
  • Request metadata required to resolve signals
  • Derived telco risk indicators (e.g., SIM swap = yes/no)

🚫 We do not process or store:

  • Call content or SMS content
  • Browsing activity
  • Precise location data
  • Telecom subscriber profiles

5. Purpose of Processing

Data is processed only for:

  • Fraud prevention
  • Identity and number verification
  • Risk assessment
  • Regulatory compliance
  • Platform security and reliability

6. Data Retention

  • API transaction metadata is retained for a limited period for security and audit purposes
  • Telco risk signals are not retained beyond operational necessity
  • No long-term storage of raw personal data

7. Data Sharing

Data may be shared only with:

  • Authorized telecom network partners (to resolve signals)
  • Cloud and infrastructure providers (no data access)
  • Regulators or authorities, where legally required

PryvX does not sell or monetize personal data.

8. Security Measures

We use:

  • Confidential computing environments
  • Encryption in transit and at rest
  • Strict access controls
  • API authentication and rate limiting
  • Continuous monitoring and audit logging

9. Your Rights

End users should exercise privacy rights through the financial institution they interact with. PryvX supports customers in fulfilling such requests.

10. Contact

  • 📧 Email: hello@pryvx.com
  • 📍 Company: PryvX AB