Establishing session

VOLTATelecommunications

Legal

Privacy Policy

This policy explains how JEGA (SIA), registration number 40203632010, a company registered in Latvia at Krišjāņa Valdemāra iela 37A - 17, Rīga, LV-1010, and operator of volta.network, collects and processes personal data when you use our network, our partner portal or this website. It is maintained by JEGA (SIA) and reviewed regularly.

GDPR

Governing framework

EEA

Primary data residency

24 mo

Maximum CDR retention

30 days

Rights request response

What we process

As a wholesale carrier, most of what crosses our network is signalling rather than content. We process call detail records (calling and called numbers, timestamps, duration, route, disposition codes), signalling metadata, IP addresses of interconnected session border controllers, and the business contact details of the people who administer partner accounts. We do not record, store or listen to call media unless a customer explicitly instructs us to enable recording under a written contract.

Why we process it

Traffic data is processed to route and terminate calls (performance of a contract), to rate and invoice minutes (contract and legal obligation), to detect fraud such as IRSF, Wangiri and artificially inflated traffic (legitimate interests), and to meet lawful interception and data retention duties imposed by national regulators (legal obligation). Marketing communications are sent only to business contacts on the basis of legitimate interests, with a one-click objection in every message.

How we protect it

The estate is certified to ISO/IEC 27001:2022. Access to production systems requires hardware-backed multi-factor authentication and is granted on a named, least-privilege basis with quarterly recertification. Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Signalling can be delivered over SIP-TLS with SRTP media on request. Independent penetration tests are commissioned twice yearly against the signalling, portal and API surfaces.

Where it lives

Primary processing takes place in the European Economic Area, in our Frankfurt, Amsterdam and Vilnius facilities. Partners may elect regional data residency in Dubai or Singapore, in which case transfers rely on the European Commission's standard contractual clauses together with a documented transfer impact assessment. We do not sell personal data and we do not transfer it to any jurisdiction without an appropriate safeguard in place.

Roles

Controller and processor

Our role depends on the data in question, and it determines who you should contact about it.

JEGA (SIA) as controller

For business contact details, onboarding and KYC documentation, billing records, website analytics and recruitment data, VOLTA determines the purposes and means of processing and acts as controller. Requests about this data should go to our data protection officer.

JEGA (SIA) as processor

For traffic carried on behalf of an operator or enterprise customer, that customer is the controller and VOLTA acts as processor under a data processing agreement. If you are an end user whose call was carried by us, contact your own service provider first; we will support them in answering you.

Retention

How long we keep each record

Nothing is kept indefinitely. Where a legal obligation sets a floor, we retain to that floor and delete immediately after.

VOLTA data retention periods by record type
RecordRetention
Call detail records24 months
Signalling traces and PCAPs30 days
Fraud and abuse case files36 months
KYC and onboarding documents5 years after contract end
Invoices and settlement records10 years
Website analytics14 months
Support and NOC ticket history36 months

Your rights

Exercising control over your data

Write to contact@volta.network. We acknowledge within two business days and respond substantively within one month, extendable by two months for complex requests with notice.

Data Protection Officer

JEGA (SIA) · Reg. No. 40203632010

Krišjāņa Valdemāra iela 37A - 17, Rīga, LV-1010, Latvia

contact@volta.network

Access and portability

Request a copy of the personal data we hold about you, in a structured, machine-readable format where technically feasible.

Rectification

Ask us to correct inaccurate or incomplete contact, billing or account records without undue delay.

Erasure

Ask us to delete data we no longer need, subject to retention duties that apply to traffic, financial and KYC records.

Restriction and objection

Object to processing based on legitimate interests, including all marketing, or ask us to restrict processing while a dispute is resolved.

Withdraw consent

Where processing relies on consent, withdraw it at any time without affecting the lawfulness of prior processing.

Complain

Lodge a complaint with the Latvian Data State Inspectorate or the supervisory authority in your country of residence.

Third parties

Categories of subprocessor

A current, named subprocessor list is provided to contracted partners under NDA, with thirty days' notice before any addition.

Categories of subprocessor used by VOLTA
CategoryPurpose
Interconnect and terminating carriersDelivery of calls and messages to destination networks
Colocation and data centre operatorsHousing of switching, signalling and storage infrastructure
Fraud intelligence providersShared detection of IRSF, Wangiri and simbox patterns
Billing and settlement platformRating, invoicing and dispute management
Support and ticketing platformHandling of NOC, billing and abuse enquiries

Cookies and this website

We set strictly necessary cookies to keep sessions secure and to remember your consent choice. Aggregated, privacy-preserving analytics help us understand which technical pages partners actually read; no advertising or cross-site tracking identifiers are used, and we do not run third-party ad pixels. You can clear or block cookies in your browser without losing access to any part of this site other than the authenticated partner portal.

Incidents and changes

Where a personal data breach is likely to result in a risk to individuals, we notify the Latvian Data State Inspectorate within 72 hours and affected controllers without undue delay, with the facts, the likely consequences and the measures taken. Material changes to this policy are announced to contracted partners at least thirty days before they take effect; the revision date at the top of this page always reflects the current version.