Legal
Privacy Policy
This policy explains how JEGA (SIA), registration number 40203632010, a company registered in Latvia at Krišjāņa Valdemāra iela 37A - 17, Rīga, LV-1010, and operator of volta.network, collects and processes personal data when you use our network, our partner portal or this website. It is maintained by JEGA (SIA) and reviewed regularly.
GDPR
Governing framework
EEA
Primary data residency
24 mo
Maximum CDR retention
30 days
Rights request response
What we process
As a wholesale carrier, most of what crosses our network is signalling rather than content. We process call detail records (calling and called numbers, timestamps, duration, route, disposition codes), signalling metadata, IP addresses of interconnected session border controllers, and the business contact details of the people who administer partner accounts. We do not record, store or listen to call media unless a customer explicitly instructs us to enable recording under a written contract.
Why we process it
Traffic data is processed to route and terminate calls (performance of a contract), to rate and invoice minutes (contract and legal obligation), to detect fraud such as IRSF, Wangiri and artificially inflated traffic (legitimate interests), and to meet lawful interception and data retention duties imposed by national regulators (legal obligation). Marketing communications are sent only to business contacts on the basis of legitimate interests, with a one-click objection in every message.
How we protect it
The estate is certified to ISO/IEC 27001:2022. Access to production systems requires hardware-backed multi-factor authentication and is granted on a named, least-privilege basis with quarterly recertification. Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Signalling can be delivered over SIP-TLS with SRTP media on request. Independent penetration tests are commissioned twice yearly against the signalling, portal and API surfaces.
Where it lives
Primary processing takes place in the European Economic Area, in our Frankfurt, Amsterdam and Vilnius facilities. Partners may elect regional data residency in Dubai or Singapore, in which case transfers rely on the European Commission's standard contractual clauses together with a documented transfer impact assessment. We do not sell personal data and we do not transfer it to any jurisdiction without an appropriate safeguard in place.
Roles
Controller and processor
Our role depends on the data in question, and it determines who you should contact about it.
JEGA (SIA) as controller
For business contact details, onboarding and KYC documentation, billing records, website analytics and recruitment data, VOLTA determines the purposes and means of processing and acts as controller. Requests about this data should go to our data protection officer.
JEGA (SIA) as processor
For traffic carried on behalf of an operator or enterprise customer, that customer is the controller and VOLTA acts as processor under a data processing agreement. If you are an end user whose call was carried by us, contact your own service provider first; we will support them in answering you.
Retention
How long we keep each record
Nothing is kept indefinitely. Where a legal obligation sets a floor, we retain to that floor and delete immediately after.
| Record | Retention | Notes |
|---|---|---|
| Call detail records | 24 months | Pseudonymised after 90 days; retained longer only where a national retention obligation applies. |
| Signalling traces and PCAPs | 30 days | Captured for fault diagnosis and fraud investigation, then purged automatically. |
| Fraud and abuse case files | 36 months | Retained to evidence disputes and to support cross-carrier fraud intelligence. |
| KYC and onboarding documents | 5 years after contract end | Required under anti-money-laundering and sanctions screening rules. |
| Invoices and settlement records | 10 years | Latvian accounting and tax law. |
| Website analytics | 14 months | Aggregated; no cross-site advertising identifiers are set. |
| Support and NOC ticket history | 36 months | Used for SLA reporting and recurring-fault analysis. |
Your rights
Exercising control over your data
Write to contact@volta.network. We acknowledge within two business days and respond substantively within one month, extendable by two months for complex requests with notice.
Data Protection Officer
JEGA (SIA) · Reg. No. 40203632010
Krišjāņa Valdemāra iela 37A - 17, Rīga, LV-1010, Latvia
contact@volta.network
Access and portability
Request a copy of the personal data we hold about you, in a structured, machine-readable format where technically feasible.
Rectification
Ask us to correct inaccurate or incomplete contact, billing or account records without undue delay.
Erasure
Ask us to delete data we no longer need, subject to retention duties that apply to traffic, financial and KYC records.
Restriction and objection
Object to processing based on legitimate interests, including all marketing, or ask us to restrict processing while a dispute is resolved.
Withdraw consent
Where processing relies on consent, withdraw it at any time without affecting the lawfulness of prior processing.
Complain
Lodge a complaint with the Latvian Data State Inspectorate or the supervisory authority in your country of residence.
Third parties
Categories of subprocessor
A current, named subprocessor list is provided to contracted partners under NDA, with thirty days' notice before any addition.
| Category | Purpose | Region |
|---|---|---|
| Interconnect and terminating carriers | Delivery of calls and messages to destination networks | Global |
| Colocation and data centre operators | Housing of switching, signalling and storage infrastructure | EEA, UAE, Singapore |
| Fraud intelligence providers | Shared detection of IRSF, Wangiri and simbox patterns | EEA |
| Billing and settlement platform | Rating, invoicing and dispute management | EEA |
| Support and ticketing platform | Handling of NOC, billing and abuse enquiries | EEA |
Cookies and this website
We set strictly necessary cookies to keep sessions secure and to remember your consent choice. Aggregated, privacy-preserving analytics help us understand which technical pages partners actually read; no advertising or cross-site tracking identifiers are used, and we do not run third-party ad pixels. You can clear or block cookies in your browser without losing access to any part of this site other than the authenticated partner portal.
Incidents and changes
Where a personal data breach is likely to result in a risk to individuals, we notify the Latvian Data State Inspectorate within 72 hours and affected controllers without undue delay, with the facts, the likely consequences and the measures taken. Material changes to this policy are announced to contracted partners at least thirty days before they take effect; the revision date at the top of this page always reflects the current version.