TELECOM PRIVACY

CPNI & Telecom Privacy Procedure

How Business Phone HQ protects call-detail and service-usage information and handles access, disclosure, approvals, incidents, and privacy complaints.

Last updated: August 19, 2026Procedure applies to qualifying Customer Proprietary Network Information where federal CPNI rules apply
What is CPNI?

Customer Proprietary Network Information can include information a provider receives because it provides telecommunications service, such as the telephone numbers called, call frequency, duration, timing, service configuration, and certain usage or billing information. CPNI generally does not include a customer's name, address, or telephone number merely because those items are listed subscriber information.

1. General protection rule

Business Phone HQ treats qualifying call-detail and service-usage information as sensitive telecom information. Where Business Phone HQ is subject to FCC CPNI rules, those rules govern. We use CPNI to provide and support the communications service, protect the network, bill for service, and for other purposes permitted by law or authorized by the customer.

2. Customer authentication before disclosure

We do not disclose detailed call information merely because someone knows readily available biographical or account information. Online CPNI access requires authenticated account access. For support interactions involving sensitive call detail, support may require authenticated portal access, a secure verification step, a callback to a number of record, or another approved method before discussing or releasing CPNI.

3. Password and account-change safeguards

Customer authentication should not rely solely on readily available biographical information. Where required, customers are notified when passwords, backup authentication information, online-account access, or the address of record is created or changed, using a permitted notification method that does not reveal the changed secret itself.

4. Use of CPNI for marketing

Business Phone HQ maintains the customer's CPNI approval status before using individually identifiable CPNI for marketing in a manner that requires approval. Where opt-in or opt-out approval is required, the applicable approval mechanism must be honored, and records of approvals or revocations are retained for the period required by law.

5. Workforce access and training

Personnel with access to telecom information are expected to use it only for authorized business purposes. Access should be limited by role and business need. Personnel handling CPNI must be trained on when CPNI may and may not be used or disclosed, and violations may result in disciplinary action or loss of access.

6. Third-party access and disclosures

Telecommunications carriers, subprocessors, integration vendors, and support providers may receive limited CPNI when necessary to provide, maintain, secure, or bill for the service, or when otherwise permitted by law. Required records of covered third-party disclosures, marketing uses, and approvals are maintained where applicable.

7. Supervisory review and records

Covered outbound marketing uses of CPNI are subject to supervisory controls where required. Business Phone HQ maintains compliance and disclosure records for the applicable retention period and supports annual CPNI compliance review and certification obligations where those obligations apply.

8. CPNI security incidents

Suspected unauthorized access to, use of, or disclosure of CPNI is escalated for investigation. Where 47 C.F.R. § 64.2011 applies, required law-enforcement notifications are made through the designated federal process within the applicable deadline before customer notification, subject to the rule's emergency and investigative exceptions. Required breach and notification records are retained for the required period.

9. Customer CPNI complaints

Send suspected unauthorized access or disclosure to support@businessphonehq.com with the subject line CPNI / Privacy Incident. Include the affected account or business number and a description of the concern, but do not email passwords, PINs, or full payment credentials.

10. Regulatory references

Key federal requirements include Section 222 of the Communications Act, 47 U.S.C. § 222, and FCC rules at 47 C.F.R. §§ 64.2001–64.2011.