CPNI & Telecom Privacy Procedure
How Business Phone HQ protects call-detail and service-usage information and handles access, disclosure, approvals, incidents, and privacy complaints.
Customer Proprietary Network Information can include information a provider receives because it provides telecommunications service, such as the telephone numbers called, call frequency, duration, timing, service configuration, and certain usage or billing information. CPNI generally does not include a customer's name, address, or telephone number merely because those items are listed subscriber information.
1. General protection rule
Business Phone HQ treats qualifying call-detail and service-usage information as sensitive telecom information. Where Business Phone HQ is subject to FCC CPNI rules, those rules govern. We use CPNI to provide and support the communications service, protect the network, bill for service, and for other purposes permitted by law or authorized by the customer.
2. Customer authentication before disclosure
We do not disclose detailed call information merely because someone knows readily available biographical or account information. Online CPNI access requires authenticated account access. For support interactions involving sensitive call detail, support may require authenticated portal access, a secure verification step, a callback to a number of record, or another approved method before discussing or releasing CPNI.
3. Password and account-change safeguards
Customer authentication should not rely solely on readily available biographical information. Where required, customers are notified when passwords, backup authentication information, online-account access, or the address of record is created or changed, using a permitted notification method that does not reveal the changed secret itself.
4. Use of CPNI for marketing
Business Phone HQ maintains the customer's CPNI approval status before using individually identifiable CPNI for marketing in a manner that requires approval. Where opt-in or opt-out approval is required, the applicable approval mechanism must be honored, and records of approvals or revocations are retained for the period required by law.
5. Workforce access and training
Personnel with access to telecom information are expected to use it only for authorized business purposes. Access should be limited by role and business need. Personnel handling CPNI must be trained on when CPNI may and may not be used or disclosed, and violations may result in disciplinary action or loss of access.
6. Third-party access and disclosures
Telecommunications carriers, subprocessors, integration vendors, and support providers may receive limited CPNI when necessary to provide, maintain, secure, or bill for the service, or when otherwise permitted by law. Required records of covered third-party disclosures, marketing uses, and approvals are maintained where applicable.
7. Supervisory review and records
Covered outbound marketing uses of CPNI are subject to supervisory controls where required. Business Phone HQ maintains compliance and disclosure records for the applicable retention period and supports annual CPNI compliance review and certification obligations where those obligations apply.
8. CPNI security incidents
Suspected unauthorized access to, use of, or disclosure of CPNI is escalated for investigation. Where 47 C.F.R. § 64.2011 applies, required law-enforcement notifications are made through the designated federal process within the applicable deadline before customer notification, subject to the rule's emergency and investigative exceptions. Required breach and notification records are retained for the required period.
9. Customer CPNI complaints
Send suspected unauthorized access or disclosure to support@businessphonehq.com with the subject line CPNI / Privacy Incident. Include the affected account or business number and a description of the concern, but do not email passwords, PINs, or full payment credentials.
10. Regulatory references
Key federal requirements include Section 222 of the Communications Act, 47 U.S.C. § 222, and FCC rules at 47 C.F.R. §§ 64.2001–64.2011.