Privacy Policy, We protect your
digital footprint

Privacy Policy

DORA TECHNOLOGIES LIMITED

PRIVACY POLICY

Effective Date: 1st July 2026 — Version 1.0

Prepared ByDora Technologies Limited — Legal & Compliance
Effective Date1st July 2026
Applies ToAll users of Dora Technologies' platform, website, and Services
Primary JurisdictionFederal Republic of Nigeria
Also CoversUnited Kingdom | Australia
Applicable LawNDPA 2023 | UK GDPR & DPA 2018 | Australian Privacy Act 1988
Contactpartners@usedora.com

1. ABOUT THIS POLICY

Dora Technologies Limited ("Dora Technologies", "we", "us", or "our") is a cloud communications company providing DID provisioning, inbound and outbound voice services, SIP trunking, call routing, call recording, WebRTC communications, voice APIs, and related business telephony infrastructure. Our registered office is in the Federal Republic of Nigeria.

This Privacy Policy explains how we collect, use, store, share, and protect personal information in connection with our platform, website, and Services. It applies to:

  • business customers and their authorised users who access our platform ("Customers");
  • end-users of our Customers' products and services whose communications are processed through our infrastructure;
  • visitors to our website and anyone who contacts us directly.

We are committed to handling personal information responsibly and in compliance with applicable data protection law, including the Nigeria Data Protection Act 2023 (NDPA), the UK General Data Protection Regulation and Data Protection Act 2018 (UK GDPR), and the Australian Privacy Act 1988 (Privacy Act). Jurisdiction-specific rights are set out in Section 10.

If you are an end-user of one of our Customers' platforms, please note that our Customer — not Dora Technologies — is responsible for how your data is collected and used within their product. We process that data on their behalf. Please contact the relevant Customer for information about their privacy practices.

2. WHO WE ARE AND HOW TO CONTACT US

Dora Technologies Limited is the Data Controller for personal information we collect about our Customers, website visitors, and individuals who contact us directly. For personal information we process on behalf of our Customers in connection with the Services, we act as a Data Processor; in those cases, our Customer is the Data Controller.

CompanyDora Technologies Limited
Registered Office2 Umuleri street, Lagos, Nigeria
Data Protection Contactpartners@usedora.com
DPO (where applicable)Anosike C. Nice
Australian Privacy Contactpartners@usedora.com

To exercise any rights described in this Policy or to raise a concern, please contact us at partners@usedora.com. We will respond within thirty (30) days for most requests, or within the timeframe required by applicable law.

3. PERSONAL INFORMATION WE COLLECT

3.1 Information You Provide Directly

When you register for an account, purchase Services, or contact us, we collect:

  • Account information: full name, business email address, phone number, job title, company name, and billing address.
  • Payment information: billing details necessary to process payments (we use third-party payment processors; we do not store full card details).
  • Communications: messages, emails, support tickets, and any other correspondence you send us.

3.2 Information Generated by Your Use of the Services

When you or your end-users use our platform, we automatically collect:

  • Telephony identifiers: phone numbers (DIDs), caller line identifiers (CLIs), called numbers, SIP URIs, and extension numbers.
  • Call metadata: call timestamps, duration, origin and destination numbers, call routing paths, call direction, call status codes, and concurrent session data.
  • Call recordings: audio recordings of voice calls, where you (as our Customer) enable the call recording feature. You are responsible for obtaining all legally required consents from call participants before enabling recording.
  • Webhook and API data: call event payloads (call start, answer, end, recording availability) delivered to your registered endpoint.
  • Network and technical identifiers: IP addresses of SIP endpoints and API clients, SIP headers, session tokens, and device type indicators.
  • Usage and analytics data: call volumes, answer rates, duration statistics, quality scores, API usage metrics, and other platform analytics.

3.3 Information Collected Automatically from Website Visitors

When you visit our website, we collect:

  • Log data: your IP address, browser type, pages visited, time and date of visit, and referring URL.
  • Cookies and similar technologies: see Section 9 (Cookies) for details.

3.4 Information from Third Parties

We may receive information about you from third parties including payment processors, identity verification providers, credit reference agencies (where applicable), and publicly available business directories, to the extent permitted by law.

4. HOW WE USE YOUR PERSONAL INFORMATION

PurposeLegal Basis
Providing and managing the Services, including account setup, DID provisioning, call routing, and API access.Contract performance (NDPA s.25(2)(b); GDPR Art. 6(1)(b); APP 3.2).
Processing payments and managing billing, including invoice generation, payment collection, and dispute resolution.Contract performance; legitimate interests (accurate financial records).
Communicating with you about your account, service updates, and support requests.Contract performance; legitimate interests.
Detecting, investigating, and preventing fraud, abuse, security incidents, and unauthorised use of the Services.Legitimate interests; legal obligation.
Complying with legal and regulatory obligations, including responding to lawful requests from courts, regulators (NDPC, NCC, ICO, OAIC), and law enforcement.Legal obligation (NDPA s.25(2)(c); GDPR Art. 6(1)(c); APP 3.4).
Improving and developing our Services through analysis of aggregated or anonymised usage data.Legitimate interests. We anonymise data before using it for this purpose.
Sending you information about new products, features, or promotions (marketing).Consent (where required by law) or legitimate interests. You may opt out at any time.
Maintaining the security and integrity of our platform and network infrastructure.Legitimate interests; legal obligation.

We will only use your personal information for the purposes for which it was collected, or for compatible purposes that would reasonably be expected. We will notify you before using your information for a materially different purpose.

5. HOW WE SHARE PERSONAL INFORMATION

5.1 Service Providers and Sub-processors

We share personal information with carefully selected third-party service providers who assist us in delivering the Services. These include cloud infrastructure providers, telecommunications carriers, SIP trunking providers, payment processors, and platform monitoring services. All service providers are bound by written agreements requiring them to protect personal information to a standard consistent with this Policy and applicable law.

5.2 Our Corporate Group

We may share personal information within the Dora Technologies group of companies for operational, administrative, and support purposes. All intra-group transfers are governed by appropriate data protection agreements.

5.3 Legal and Regulatory Requirements

We may disclose personal information where required or permitted by law, including to comply with a court order, regulatory direction, or lawful request from a government authority or law enforcement agency. Where permitted, we will notify you of such a request before disclosing.

5.4 Business Transfers

If Dora Technologies is involved in a merger, acquisition, restructuring, or sale of assets, personal information held by us may be transferred to the acquiring entity. We will notify affected individuals and continue to protect personal information in accordance with this Policy.

5.5 With Your Consent

We may share your personal information with other third parties where you have given us your explicit consent to do so.

We do not sell personal information to third parties. We do not share personal information with advertisers.

6. INTERNATIONAL TRANSFERS OF PERSONAL INFORMATION

Dora Technologies is headquartered in Nigeria. Our infrastructure and service providers may be located in other countries. When we transfer personal information outside Nigeria, we ensure appropriate safeguards are in place as required by section 43 of the NDPA 2023, including binding data transfer agreements with overseas recipients that impose data protection obligations consistent with Nigerian law.

For personal information of individuals in the United Kingdom or European Economic Area, transfers outside the UK/EEA are covered by UK International Data Transfer Agreements or EU Standard Contractual Clauses as applicable.

For personal information of individuals in Australia, transfers to overseas recipients comply with Australian Privacy Principle 8, and recipients are bound by obligations substantially similar to the Australian Privacy Principles.

You may contact us at partners@usedora.com to request information about the specific safeguards applied to transfers of your personal information.

7. DATA RETENTION

We retain personal information only for as long as necessary for the purposes described in this Policy, or as required by applicable law. Our standard retention periods are:

Data TypeRetention Period
Customer account informationDuration of account + 2 years after closure.
Call metadata / CDRs90 days from call completion (platform). 6 years for billing records.
Call recordings30 days from recording date (default). Extended storage available on plan.
Webhook event logs30 days.
Platform analyticsRolling 12 months (identifiable). Anonymised data: indefinite.
Financial and billing records6 years (Nigerian commercial limitation period).
Communications and support records2 years after resolution.
Website log data90 days.
Data held for legal / regulatory complianceAs required by applicable law (typically 2–10 years).

When personal information is no longer required, we securely delete or anonymise it. Where immediate deletion is not technically feasible (e.g. in automated backups), data is isolated and overwritten within ninety (90) days.

8. SECURITY

We implement technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • Encryption of data in transit (TLS 1.2+; SRTP/SIPS for voice) and at rest (AES-256).
  • Role-based access controls and multi-factor authentication on production systems.
  • Periodic vulnerability assessments. Dora Technologies may engage independent penetration testing as appropriate to its size, risk profile, and business requirements.
  • Access logging and audit trails are maintained for an appropriate period consistent with operational, security, and legal requirements.
  • Dora Technologies maintains business continuity, backup, disaster recovery, and incident response procedures appropriate to its operations, and reviews them periodically.

No method of electronic transmission or storage is completely secure. While we use commercially reasonable measures to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you and relevant Supervisory Authorities as required by applicable law.

9. COOKIES AND TRACKING TECHNOLOGIES

Our website uses cookies and similar technologies. A cookie is a small text file placed on your device. We use:

Cookie TypePurpose
Strictly NecessaryRequired for the website and platform to function (e.g. session management, authentication). Cannot be disabled.
Performance / AnalyticsHelp us understand how visitors use our site (e.g. page views, traffic sources). Data is aggregated and anonymised.
FunctionalRemember your preferences (e.g. language, display settings).
MarketingUsed to deliver relevant advertising. Only placed with your consent where required by law.

You can control cookies through your browser settings or our cookie consent tool. Disabling strictly necessary cookies may affect website functionality. For more information, see our Cookie Policy at usedora.com/cookies.

10. YOUR RIGHTS

10.1 Rights Under the NDPA 2023 (Nigeria)

If you are in Nigeria, you have the right to:

  • Access personal data we hold about you.
  • Correct inaccurate or incomplete personal data.
  • Delete your personal data (subject to legal retention requirements).
  • Object to or restrict certain types of processing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time where processing is based on consent (without affecting prior lawful processing).
  • Lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.

10.2 Rights Under UK GDPR (United Kingdom)

If you are in the United Kingdom, you have equivalent rights under UK GDPR including the right to access, rectification, erasure, restriction, portability, and objection. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10.3 Rights Under the Australian Privacy Act 1988 (Australia)

If you are in Australia, you have the right to access and correct personal information we hold about you under Australian Privacy Principles 12 and 13. You may also complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have handled your information in breach of the Privacy Act.

10.4 How to Exercise Your Rights

To exercise any of the rights above, please contact us at partners@usedora.com. We will respond within thirty (30) days, or within the timeframe required by applicable law. We may need to verify your identity before processing your request. We do not charge a fee for reasonable requests.

Note: If you are an end-user of one of our Customer's platforms, you should direct your request to that Customer. We will assist them in responding if required.

11. CHILDREN'S PRIVACY

Our Services are intended for business use only and are not directed at individuals under the age of 18. We do not knowingly collect personal information from persons under 18. If you believe we have inadvertently collected information from a minor, please contact us at partners@usedora.com and we will delete it promptly.

12. THIRD-PARTY LINKS AND SERVICES

Our website and platform may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third parties. We are not responsible for the privacy practices of third-party websites or services. We encourage you to review the privacy policies of any third party you interact with.

13. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. We will notify you of material changes by posting the updated Policy on our website with a revised effective date, and where required by law, by sending you direct notice. Your continued use of the Services after the effective date of any update constitutes acceptance of the revised Policy.

All previous versions of this Policy are available on request.

14. COMPLAINTS AND SUPERVISORY AUTHORITIES

We take privacy concerns seriously. If you have a complaint about how we handle your personal information, please contact us at partners@usedora.com. We will acknowledge your complaint within five (5) business days and aim to resolve it within thirty (30) days.

If you are not satisfied with our response, or if you wish to escalate your concern directly, you may contact the relevant supervisory authority:

JurisdictionAuthority
NigeriaNigeria Data Protection Commission (NDPC)
United KingdomInformation Commissioner's Office (ICO)
AustraliaOffice of the Australian Information Commissioner (OAIC)

24/7 Support partner

You've got something in mind? Let's Talk

Contact us

Email us

partners@usedora.com
support@usedora.com
usedoranow@gmail.com