Privacy Policy
This policy covers three things: this website (branch.exchange), the BX9 service, and the BX9 iOS app (in beta). It is written to be read, not skimmed past. BX9 is a business phone system sold to organizations in the United States; most of the data we handle belongs to those organizations and the people who call them, and this policy is honest about what that involves.
1. Who we are, and whose data it is
The service is operated by Branch Exchange LLC, a New Hampshire limited liability company ("we"). Two roles matter throughout this policy:
- For this website, for sales and support correspondence, and for the account and billing records of our direct customers and reseller partners, we decide how data is used — we are the "controller" or "business" in privacy-law terms.
- For everything inside a customer's BX9 tenant — calls, messages, voicemail, users — the customer organization decides. We process that data only on the organization's behalf, to provide the service, as a service provider/processor. If you are an employee of, or a caller to, an organization that uses BX9, that organization is your first point of contact for privacy requests, and we support them in answering.
2. This website
This website is a static site. It sets no cookies, runs no analytics, embeds no third-party scripts or fonts, and does not track you. The only thing it stores in your browser is your light/dark theme choice, kept on your device and sent nowhere. Like any web server, ours keeps standard access logs (IP address, requested page, timestamp) for security and operations; these are retained briefly and used for nothing else.
If you email us, we receive what you send and use it to reply to you.
3. The BX9 service
What the service processes
- Account data — names, email addresses, extensions, roles, and sign-in credentials of an organization's users (or their single sign-on identity and directory profile, if the organization connects an identity provider), plus optional profile photos and personal contact lists.
- Call detail records — who called whom, when, for how long, how the call ended, and technical identifiers and network-quality measurements for the call. This is the call history every phone system keeps, and it is also how we diagnose "why did that call sound bad."
- Call and message content — voicemail messages; call recordings where the organization turns recording on (it is off by default); transcriptions of recordings and voicemail when requested; fax documents sent and received; and text messages (SMS/MMS), including their full text and attachments, sent and received on the organization's numbers.
- Call-flow data — if an organization builds call flows that ask callers for input (for example, "say or enter your account number"), what the caller provides is stored with the call record for the organization.
- Emergency-calling records — where an organization enables emergency calling, the dispatchable street addresses and callback numbers it registers for its users and sites, and a permanent record of any emergency call placed (see section 6).
- Administrative audit history — a log of configuration changes made by the organization's administrators, including the administrator's IP address and browser, kept so organizations can answer "who changed this."
- Device and delivery data — SIP device registrations, desk-phone provisioning records (device MAC addresses and models), and push-notification tokens for browsers and mobile devices.
Customer proprietary network information (CPNI)
Some of the data above — call detail records and related service-usage information — is the category federal communications law calls customer proprietary network information. We use CPNI only to provide, bill, protect, and troubleshoot the service. We do not use it for marketing, we do not sell it, and we do not share it except as directed by the customer organization or as the law requires. If you believe your CPNI has been mishandled, contact us at the address below; you may also complain to the Federal Communications Commission.
Where it lives
BX9 can be hosted by Branch Exchange LLC or self-hosted by the customer on their own hardware. In a hosted deployment, Branch Exchange LLC stores tenant data on servers in the United States, isolated per organization. In a self-hosted deployment, call content, recordings, voicemail, and transcriptions stay on the customer's own server. By default, speech-to-text runs on the server that hosts the deployment — not a third-party cloud — using NVIDIA Parakeet TDT 0.6b v3, used under CC-BY-4.0. An organization's transcription may instead be assigned to, or connected to, a third-party speech-to-text provider; that only happens where a platform operator has explicitly turned on sending call audio off the box for that organization, and it is off by default for every organization until an operator does.
What we don't do
- We do not sell personal data, and we do not share it for targeted advertising.
- We do not use call content, messages, or metadata for advertising or profiling, and we embed no third-party advertising or tracking in the product.
- We do not listen to calls or read messages except where strictly necessary to diagnose a problem the customer has reported, and with the customer's knowledge.
Third parties involved in providing the service
- Telephony and messaging carriers — calls, texts, and faxes necessarily traverse the SIP trunk and messaging providers the organization connects. Those carriers receive the phone numbers, message content, and media needed to deliver the traffic, under their own policies. The organization chooses its carriers.
- Payment processing — subscription billing is handled by Stripe; Branch Exchange LLC does not store card numbers.
- Push delivery — notifications for incoming calls and messages are delivered through platform push services (web push, and Apple's push service for the iOS app). Payloads carry the minimum needed to ring your device.
- Optional voice vendors — an organization may connect its own account with a third-party text-to-speech vendor for menu prompts. If it does, the prompt text it writes (never call audio) is sent to that vendor under the organization's own agreement with them.
- Optional speech-to-text and analysis vendors — an organization may be assigned by a platform operator, or may connect its own account with, a third-party speech-to-text or language-model provider in place of the on-box default. Where that happens, the recording audio (speech-to-text) or the call transcript (analysis, such as sentiment) is sent to that vendor under the organization's or Branch Exchange LLC's own agreement with them. Sending call audio off the box requires a platform operator to explicitly enable it for that organization, and it is off by default for every organization.
Billing data
For a subscription billed directly by us, Stripe holds the payment card, billing address, and invoice history for the organization — Branch Exchange LLC does not receive or store card numbers. What we store is limited to the Stripe customer and subscription identifiers, the plan and user count, and invoice metadata (amount, date, status) needed to show the organization its billing history and keep the subscription in sync. An organization billed through a reseller partner is invoiced by that partner instead.
Retention
- Recordings and voicemail: the organization's administrators set retention; by default nothing is auto-deleted until they choose a policy.
- Call detail records and fax documents: kept as the organization's business records for the life of the tenant.
- Audit history: retained per the organization's configured policy, subject to a platform minimum that an administrator cannot shorten — so an administrator cannot prune the record of their own changes.
- Emergency calls: the record that an emergency call was placed is kept permanently as a compliance record.
- Deleted tenants are deleted, not archived for our benefit.
4. Security
Tenant data is isolated per organization at the database layer, carrier and integration credentials are stored encrypted, and traffic between clients, our edge, and carriers is encrypted in transit where the far end supports it. No vendor should promise you perfection; we design so that one organization's mistake or compromise does not become another organization's problem.
5. Recording calls
Call recording is a feature the customer organization controls, and recording laws vary by state — several states require every participant's consent. Organizations are responsible for using the recording feature lawfully, including any announcements or consents their states require. If you are on a call with an organization that records, that organization is the right party to ask about its recording practices.
6. Emergency calling
Where emergency calling is enabled for an organization, placing a 911 call transmits the registered dispatchable location and callback number for the caller to the emergency network, and the product notifies the organization's administrators that an emergency call was placed, as U.S. law requires. Location addresses are used for emergency routing and for nothing else. See the Terms of Service for important limitations of VoIP emergency calling.
7. The BX9 iOS app
The BX9 iOS app is in beta — ask sales for access. It is a client for the same service, and this policy applies to it in the same way. In addition:
- It requests microphone access to place and receive calls — that is what a phone app is for.
- It uses push notifications so your device can ring on incoming calls.
- It contains no advertising, no third-party analytics, and no trackers.
8. Your privacy rights
Depending on your state, you may have the right to know what personal information we hold about you, to access a copy of it, to correct it, to delete it, and to receive it in a portable form. We honor these rights regardless of which state you live in, and we do not discriminate against you for exercising them. Because we do not sell personal data or share it for targeted advertising, there is nothing to opt out of on that front.
To exercise a right, email support@branch.exchange with "Privacy request" in the subject. We will verify the request and respond within the time your state's law requires (45 days in most states). An authorized agent may submit a request on your behalf with proof of authorization. If your request concerns data inside an organization's tenant — your employer's call history, for example — we will route the request to that organization, which controls it, and help them fulfill it.
If you are visiting from outside the United States: the service is offered to U.S. organizations and your data is processed in the United States. Where the law of your home jurisdiction grants you similar rights, the same mailbox honors them.
9. Children
The service is a workplace tool, is not directed to children, and we do not knowingly collect personal information from children under 13. If you believe a child's data has reached us, contact us and we will delete it.
10. Changes and contact
If this policy changes, we will update this page and its effective date; material changes to how we handle service data are also communicated to customer organizations. Questions go to support@branch.exchange.
Branch Exchange LLC, 27 Hazel Dr, Hampstead, NH 03841, United States