Privacy Policy

Last updated: 1 September 2026

This Privacy Policy explains how ippi processes your personal data across the ippi website (www.ippi.com), the ippi telephony service, and the ippi Softphone application (together, the "Services"). ippi cares deeply about protecting your privacy and limits the collection of personal data to what is necessary to provide the Services.

1. Data controller

The data controller is Worldline Communication, the company that publishes and operates the ippi Services (the "Company").

  • Address: ippi – Worldline Communication, 128 rue La Boétie, 75008 Paris, France
  • Privacy contact: privacy@ippi.com

2. Scope of this policy

This policy applies to the three ways you may interact with ippi:

  • The website (www.ippi.com): browsing our pages, contacting us and subscribing to the newsletter;
  • The telephony service: as an electronic communications operator, when you subscribe to and use ippi (virtual numbers, calls, billing);
  • The ippi Softphone application: when you use the mobile app to place and receive calls.

3. Data collected on the website

3.1. Contact and newsletter

When you use a contact form or subscribe to the newsletter, we collect the data you provide (such as your name, email address and the content of your message) in order to answer you or send you the communications you requested.

Newsletter subscription is based on your consent: you may withdraw it at any time, without giving a reason, using the unsubscribe link in every message or by writing to privacy@ippi.com. Withdrawal does not affect the lawfulness of messages sent before it.

3.2. Server logs

Our servers keep technical logs (IP address, browser type, pages viewed, timestamps) needed to operate the site, ensure its security and prevent abuse.

3.3. Cookies

The website uses only strictly necessary technical cookies:

  • Session and authentication: to keep you signed in to your personal area;
  • CSRF protection (XSRF-TOKEN): to secure form submissions;
  • Language preference (ippi_locale): to remember your chosen language.

These cookies are strictly necessary for the site to function and are exempt from consent. ippi uses no advertising cookies and no third-party tracking.

4. Data collected as a service subscriber

4.1. Account, service and billing data

As an operator, when you subscribe to and use the ippi service, we process:

  • Identity and contact details: name, postal address, email address, phone number;
  • Account credentials: your login, used to access the network and your personal area;
  • Service data: your virtual number(s) and the configuration of your services;
  • Billing and payment data: invoices, and the payment means you register (bank card, or bank details for SEPA direct debit). Payments and card registration are handled by Payline (Monext), our secure payment provider; ippi never stores your full card number in clear text;
  • Traffic data (call detail records, "CDR"): date, duration, calling and called numbers, kept as necessary to provide the service, for billing, and to comply with our legal retention obligations as an operator. ippi does not record the content of your conversations: only the technical data required to route and bill the call is processed.

4.2. Identity verification

When certain accounts are opened, and when you register your first payment means, the Company must make sure that the information provided matches your identity. You may therefore be asked to complete an identity verification. On that occasion, the following are processed:

  • a copy of your identity document;
  • a supporting document: a telecom invoice, or your bank details (RIB) in the case of SEPA direct debit.

These documents are used solely for that verification: they are never used for marketing, advertising or any other processing.

5. Data collected in the Softphone app

5.1. Account identifier (SIP login)

To sign in and place/receive calls, you enter your ippi account credentials. Your login (identifier) is sent to the Company's servers for SIP registration and to enable call notifications.

5.2. Notification token (VoIP push)

To alert you to incoming calls even when the app is in the background or closed, the Company sends its servers a push notification token that is specific to your device and associated with your identifier.

5.3. Diagnostic data and crash reports

To improve the app's stability, the Company uses Firebase Crashlytics (provided by Google), which collects, in the event of a malfunction:

  • crash data (stack trace, device model, OS version, app version);
  • diagnostic data about the state of the app at the time of the incident (e.g. SIP connection state, call state, audio output route);
  • an identifier corresponding to your SIP login, in order to link a report to an account for support purposes.

This data is linked to your identity but is never used for advertising or tracking.

5.4. Data that stays on your device

The following data does not leave your device and is not transmitted to the Company:

  • Your contacts: read only to display the names of your correspondents. No contact is uploaded.
  • Your password: stored securely in the device's secure store (e.g. the iOS Keychain). It is never transmitted in clear text; only a cryptographic hash is used to authenticate notifications.

5.5. Call data

The numbers you dial and the content of your calls pass through the Company's servers only to route the communication (like a telephone carrier). Between the ippi app and the Company's servers, signaling is encrypted by default (TLS) and media may be encrypted (SRTP). If you use other software or a SIP handset, encryption depends on how that equipment is configured. In all cases this is transport encryption, not end-to-end encryption between correspondents.

6. Purposes and legal bases (GDPR)

  • Managing your account and providing the service (identity, credentials, virtual numbers, calls) — Legal basis: performance of a contract.
  • Billing and payment (invoices, payment means) — Legal basis: performance of a contract / legal obligation.
  • Traffic data (CDR) — Legal basis: performance of a contract / legal obligation (operator retention).
  • Routing emergency calls, where such access has been enabled on your line (identity and location information passed to the competent emergency service) — Legal basis: legal obligation.
  • Porting your number (exchanges with the donor or recipient operator) — Legal basis: performance of a contract / legal obligation.
  • Identity verification (identity document, supporting document, verification result) — Legal basis: performance of a contract and the legitimate interest of the Company in ensuring the accuracy of subscription information and securing access to the service.
  • App notifications (push token) — Legal basis: performance of a contract.
  • Answering your requests and sending the newsletter — Legal basis: consent (newsletter, withdrawable at any time) / legitimate interest (support).
  • Diagnostics, security and quality (crash data, server logs) — Legal basis: legitimate interest.

The Company performs no advertising tracking, displays no advertising, and sells no data. No decision producing legal effects concerning you is taken solely on the basis of automated processing, and the Company carries out no profiling.

7. Sharing with third parties

The Company shares your data only in the cases described below. The processors strictly needed to provide the Services are:

  • Payline (Monext): securely processes card payments and the registration of payment means on the Company's behalf;
  • Google (Firebase Crashlytics): processes, on the Company's behalf, the app crash and diagnostic data described in section 5.3. See Google's privacy policy: https://firebase.google.com/support/privacy.

The Company may also be required to disclose certain data to competent judicial or administrative authorities, in the cases and under the procedures provided for by law.

Partner carriers. Routing your calls requires the involvement of other electronic communications operators, responsible for call collection and termination. The data strictly necessary for routing — in particular the calling and called numbers — is passed to them, as for any telephone call. These operators act as separate controllers, each subject to its own legal obligations.

Number porting. If you request the porting of your number to or from another operator, the data needed for that operation (identity, number concerned, contract references) is exchanged with the operator concerned, in accordance with the applicable regulations.

Emergency calls. The Services are provided as a secondary line and access to emergency numbers is not enabled by default (see the Terms and Conditions). Where such access has been requested and enabled on your line, calling an emergency number causes your identity and the location information available to the Company — as declared for your line — to be passed to the competent emergency service; that transmission is then required by law and cannot be disabled.

Apart from the cases described above, the Company does not share your data with any other third party and does not sell it.

8. Transfers outside the European Union

Diagnostic data processed by Google may be transferred outside the European Union. Such transfers are governed by the appropriate safeguards provided for by the GDPR (standard contractual clauses).

When you call a correspondent located outside the European Union, the data needed to route the call is passed to the operators of the destination country. This transmission follows from your own request and from the performance of the contract entered into with you.

9. Data retention

  • Account and contract data: kept for the duration of your contract, then for the applicable limitation period, so that the Company can respond to a claim or assert its rights;
  • Traffic data (CDR, server-side): kept for one year from the date of recording, in accordance with the legal retention obligations applicable to electronic communications operators;
  • Billing data: kept for the statutory accounting retention period (10 years for accounting records);
  • Identity verification documents (identity document, supporting document): kept for as long as necessary to carry out the verification. They are not used for any other purpose;
  • Contact and newsletter data: kept until you unsubscribe, then for as long as is necessary to handle your request and to evidence the consent obtained;
  • Identifier and notification token: kept for as long as your account is active / notifications are enabled. The token is deleted from the Company's servers when you disable notifications or sign out;
  • Crash data: kept for a limited period by Firebase Crashlytics (generally 90 days);
  • Server logs: kept for as long as is necessary to secure the site and detect abuse;
  • Website cookies: technical cookies kept for up to one year;
  • Local app data (contacts): kept on your device until you delete it or uninstall the app.

10. Security

  • Website served over HTTPS with a strict content security policy;
  • SIP signaling encrypted via TLS between the ippi app and the Company's servers, enabled by default. With other software or a SIP handset, signaling encryption depends on how that equipment is configured;
  • Media encryption via SRTP between the app and the Company's servers, depending on the configuration used;
  • Identity verification documents transmitted over an encrypted channel and accessible only to authorised staff;
  • Credentials stored in the device's secure store (e.g. the iOS Keychain).

11. Your rights

In accordance with the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability regarding your personal data. Where processing is based on your consent (newsletter), you may withdraw it at any time. You may also issue directives, general or specific, concerning what happens to your data after your death.

To exercise these rights, contact the Company at: privacy@ippi.com (or by post: ippi – Worldline Communication, 128 rue La Boétie, 75008 Paris, France). Proof of identity may be requested where there is reasonable doubt as to your identity.

You may also lodge a complaint with the CNIL (the French data protection authority, www.cnil.fr), without prejudice to any judicial remedy.

12. Minors' data

The Services are not intended for persons under the age of 18, and the Company does not knowingly collect their data. If you believe that a minor under 18 has provided us with their data, please write to privacy@ippi.com so that we can delete it.

13. Changes

The Company may update this policy. Any change will be published on this page with a new "last updated" date.

14. Contact

For any question regarding this privacy policy: privacy@ippi.com