Data Processing Addendum
Version 1.1 · Published September 28, 2026, amended September 29, 2026 · Effective October 12, 2026. Version 1.0 (effective September 26, 2026) applies until then; the change is the retention of call and message records in Annex I and section 10: 18 months, where version 1.0 said 7 years.
This Addendum forms part of the Terms of Service between the business customer that holds a MirageTEL account (the “Customer”, acting as controller) and Mirage Global Technologies LLC, a Wyoming limited liability company (“MGT”, “we”, acting as processor). It applies whenever the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the Swiss Federal Act on Data Protection or a comparable law governs personal data that MGT processes on the Customer’s behalf through MirageTEL (“Customer Personal Data”).
The Customer accepts this Addendum by accepting the Terms of Service; no separate signature is needed. A Customer that wants a countersigned copy can request one at privacy@miragetel.com.
1. Roles and scope
For the call records, messages, numbers and related data of the people the Customer calls, messages or is called by through MirageTEL, the Customer is the controller (or, where it acts for its own client, a processor) and MGT is its processor.
For the account, billing, identity-verification, security and usage data MGT needs to run and bill the service and to meet its own legal obligations, MGT is an independent controller, as described in the Privacy policy. This Addendum does not cover that data.
Terms used here and not defined have the meaning given in the GDPR.
2. Details of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.
3. Instructions
MGT processes Customer Personal Data only on the Customer’s documented instructions. The Terms, this Addendum and the way the Customer configures and uses the service — the numbers it holds, the devices it registers, the calls and messages it places and receives, the exports and deletions it requests — are those instructions.
MGT informs the Customer without delay if, in its opinion, an instruction infringes data-protection law. MGT does not sell Customer Personal Data, does not use it for advertising or to build profiles, and does not use it to train AI models.
Where applicable law requires MGT to process or disclose Customer Personal Data otherwise — including lawful requests from competent authorities for call or message records — MGT informs the Customer before doing so, unless that law prohibits it.
4. Confidentiality
MGT ensures that every person authorised to process Customer Personal Data is bound by confidentiality and that access is limited to what support, security, fraud prevention and operation of the service require.
5. Security
MGT implements the technical and organisational measures described in Annex II, appropriate to the risk under Article 32 GDPR. MGT may update those measures provided the overall level of protection is not reduced.
MGT does not record the audio of calls. Network captures taken to diagnose call quality contain call signalling and the headers of media packets only, never the audio itself.
6. Sub-processors
The Customer gives MGT general authorisation to engage the sub-processors listed in Annex III.
MGT informs the Customer by e-mail at least 14 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, MGT may switch off the affected feature for that Customer, or the Customer may terminate the affected service without penalty.
MGT engages each sub-processor under written terms that impose data-protection obligations no less protective than this Addendum, and remains responsible to the Customer for its sub-processors’ performance.
Telephone networks. To connect a call or deliver a message, the numbers involved necessarily pass through the public telephone networks and the operators of the called or calling party. Those operators act under their own legal obligations and are not sub-processors of MGT.
7. Assistance with data subjects’ rights
Taking into account the nature of the processing, MGT assists the Customer, by appropriate technical and organisational measures, in answering requests from data subjects. If MGT receives a request directly, it forwards it to the Customer and does not answer it except on the Customer’s instruction.
8. Personal data breaches
MGT notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay after becoming aware of it and, where feasible, within 24 hours. The notice describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed and a contact point; information not yet available follows in phases without undue delay (Article 33(3)–(4) GDPR).
9. Other assistance
MGT provides the Customer with the information reasonably needed for its data protection impact assessments and prior consultations (Articles 35–36 GDPR).
10. Retention, deletion and return
MGT keeps Customer Personal Data for the periods in Annex I and deletes it at the end of each period. When the Customer’s account ends, MGT deletes Customer Personal Data from the live systems within 30 days, unless the Customer asks for an export first, the law requires MGT to keep specific records — such as billing records — for longer, or the records are call and message records that MGT keeps as controller under Annex I. Encrypted off-site backups are used only to recover from a failure; if one is restored, deleted data is removed again.
11. Audits
MGT makes available the information reasonably necessary to demonstrate compliance with Article 28 GDPR: this Addendum and its annexes, written answers to reasonable questions and, under confidentiality, MGT’s security documentation for MirageTEL. Where that is not sufficient, or a supervisory authority requires it, the Customer may carry out an audit, itself or through an independent auditor bound by confidentiality, no more than once in any 12 months unless a personal data breach justifies it, on at least 30 days’ written notice, during business hours, at the Customer’s cost and without access to other customers’ data.
12. International transfers
Customer Personal Data is hosted in the European Union (Contabo GmbH). MGT is established outside the European Economic Area and its administration takes place outside it; transfers therefore take place under appropriate safeguards.
For transfers from the EEA, the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) are incorporated into this Addendum by reference: Module 2 (controller to processor) where the Customer is a controller, and Module 3 (processor to processor) where it is a processor. The Customer is the data exporter and MGT the data importer. Clause 7 (docking) applies; under Clause 9(a) Option 2 (general authorisation, 14 days’ notice) applies; the optional wording of Clause 11 does not apply; under Clauses 17 and 18 the law and courts of Ireland apply; the competent supervisory authority under Clause 13 is the one competent for the Customer. Annexes I to III of this Addendum complete the Annexes of the Clauses.
For transfers from the United Kingdom, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (version B1.0) is incorporated, with the information in Tables 1 to 3 taken from this Addendum; for transfers from Switzerland, the Clauses apply with the adaptations required by the Swiss Federal Act on Data Protection. If these Clauses and this Addendum conflict, the Clauses prevail.
13. United States privacy laws
Where the California Consumer Privacy Act or a similar US state law applies, MGT acts as the Customer’s service provider (or processor): it does not sell or share Customer Personal Data, does not retain, use or disclose it for any purpose other than providing the service, does not combine it with personal data from other sources except as that law permits, and complies with the obligations that law places on service providers.
14. Liability, precedence and changes
Each party’s liability under this Addendum is subject to the limitations in the Terms, except where the law does not allow such a limitation. If this Addendum conflicts with the Terms on the protection of personal data, this Addendum prevails. MGT may update this Addendum to reflect changes in law or in the service, without reducing the protection it gives, and notifies Customers of material changes at least 14 days before they take effect.
15. Contact
Privacy Officer, Mirage Global Technologies LLC — privacy@miragetel.com. Security vulnerabilities: security@miragetel.com.
Annex I — Details of the processing
Parties. Data exporter: the Customer (controller or processor), as identified in its MirageTEL account. Data importer: Mirage Global Technologies LLC (processor), 1621 Central Ave #8434, Cheyenne, WY 82001, United States; contact privacy@miragetel.com.
Data subjects. People who call, are called by, message or are messaged by the Customer through MirageTEL; the Customer’s own staff and users of its numbers, devices and eSIMs.
Personal data. Call records: calling and called numbers, time, duration, call result, the device used, and the IP address, port and software that placed the call. Messages: sender and recipient numbers, time and price; message content. Call quality data: packet loss, jitter and quality scores per call leg. Diagnostic network captures: call signalling and media packet headers — no audio. eSIM usage: subscriber identifiers (IMSI), data usage and network (MCC/MNC). Staff: name, e-mail address, role and devices.
Special categories. None are intended.
Nature and purpose. Routing, connecting and billing calls and messages; delivering messages and notifications; measuring and diagnosing call quality; fraud and abuse prevention; export and erasure on request — all to provide the MirageTEL service to the Customer.
Frequency. Continuous, for the duration of the account.
Retention. Message content: 90 days, then erased. Call records and message metadata: 18 months, then deleted — MGT keeps them as controller, for billing and for tracing calls on the request of carriers, regulators and law enforcement; they are not deleted earlier when the account ends, and a record named in such a request is kept with that request. Monthly traffic totals without any number or account: 3 years. The record of who accessed call records: no expiry date. Call quality data: 90 days; quality summaries: 13 months. Diagnostic captures: 14 days. Live quality samples: 1 hour. Revoked devices: 30 days. Supplier event records: 18 months, as call records. eSIM usage: for the life of the account, then deleted under section 10.
Identity-verification documents — kept 7 years — are processed by MGT as controller for its own legal obligations and are covered by the Privacy policy, not by this Addendum.
Annex II — Technical and organisational measures
Every measure below was verified on the running system on 26 September 2026.
- Encryption in transit: TLS 1.3 at the network edge.
- Encryption at rest: eSIM activation data and SIP device passwords are encrypted with AES-256-GCM; the key is kept outside the database and the source code.
- Separation between customers: every read and write is scoped to the customer’s own account in the application.
- Network exposure: the database and the application API are not reachable from the internet; only the public web edge is.
- Access control: role-based staff accounts; administrator access to servers by SSH key only, with password login disabled.
- Operations: automatic security updates; brute-force protection on public services.
- Logging: web-server access logs and an append-only audit trail of identity-verification actions.
- Backups: encrypted off-site backups, verified by restore.
- No call audio recording; diagnostic captures are limited to signalling and media headers and are deleted after 14 days.
- Security contact: security@miragetel.com.
Annex III — Sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| DIDWW | Phone numbers, voice calls and SMS | Ireland (EU) |
| OMAX Group Ltd (Telkor) | eSIM connectivity | United Kingdom |
| Cloudflare | Network edge and protection (IP addresses) | Global edge (EU / US) |
| Google (Firebase Cloud Messaging) | App notifications | United States |
| Apple (Push Notification service) | App notifications | United States |
| Contabo GmbH | Hosting of the service | Germany / EU |
Not sub-processors: payment processing by Stripe is MGT’s own billing as controller; TronGrid receives blockchain addresses only; the call-capture tool runs on MGT’s own server. Suppliers that do not process Customer Personal Data today are not listed; if one is switched on, the Customer is notified 14 days in advance.