Privacy Policy
Visitors to this website
We keep ordinary server logs (IP address, browser, pages requested, time) for security and troubleshooting and delete them within ninety days. We do not use advertising cookies, tracking pixels or third-party analytics. Signed-in users receive a session cookie and a CSRF cookie that are needed for the site to work.
Customers
When an organisation opens an account we collect the names and email addresses of its users, its FCC Registration Number, the FRNs of providers it asks us to watch, its answers to the mitigation plan questions (including the name, title, business address, telephone and email of its designated robocall mitigation contact, which the FCC requires to be public), its deadlines and traceback log entries, evidence files it uploads, and billing details. We use this information only to provide the Service, to bill for it, to send operational email such as alerts, reminders and weekly summaries, and to answer support requests. We never sell it.
Public FCC data
We read the FCC's public Robocall Mitigation Database listing every night and keep a history of it. This contains business names, addresses and the designated contact person for each filer, as published by the FCC. If you are a contact person named in a filing and have a question about that information, please direct it to the FCC or the filing provider; we reproduce the public record and do not alter it.
What we deliberately do not hold
The Service is designed so that we never receive call detail records, telephone number inventories, customer proprietary network information (CPNI), subscriber lists or identity documents of a provider's customers. Customers agree not to upload them. If we find such material we delete it and tell the customer.
Where information is stored and who helps us
All information is stored in the United States. We use the following subprocessors: Render (application hosting, Oregon), Amazon Web Services (encrypted file storage), Postmark (operational email), Sentry (error reports, configured not to include personal data). Each is bound by written terms that restrict its use of the data to providing its service to us.
Security
Files are stored in private buckets with no public access. Access to production systems is limited to the people who operate the Service and is logged. Passwords are hashed; we never see them.
Retention
Customer account information is kept while the account is open and for two years afterwards, matching the FCC's two-year regulatory look-back, unless the customer asks for earlier deletion. Server logs are kept for ninety days. Email we exchange with you is kept as ordinary business correspondence.
Your choices and rights
You may ask us what information we hold about you, ask for a correction, or ask for deletion, by writing to support@jayanas.com. We answer within thirty days. We do not discriminate against anyone for exercising a privacy right.
Changes
If this policy changes we will post the new version here with a new effective date and email customers about material changes.