Security & Compliance
This page sets out where your data is held, how it is protected, and who can access it — in the form procurement and IT usually ask for before sign-off.
Some details are being confirmed before commercial launch
Details still to be confirmed or added are highlighted on this page. We deliberately list only what is actually in place in production.
Locations and data residency
XETEL operates two technical layers with different locations:
- Telephony platform (switching, call control, recordings): our own servers in a data centre in Germany, hosted with Hetzner.
- Web layer (website, portal, API): Cloudflare. Static content is delivered through Cloudflare's global network so that pages respond quickly.
- Application database: Cloudflare D1, pinned to the Western Europe (WEUR) region.
[To be added: the precise data centre location of the telephony platform (city) and operator details for tender documentation.]
Personal data held by the application — accounts, call data, number inventory — is processed and stored in the European Union.
Encryption
Traffic is encrypted on every path:
- Website, portal, and API: TLS on all connections.
- SIP signalling: TLS on port 5061.
- Voice media: SRTP. Media encryption is mandatory rather than optional for XETEL endpoints (Mandatory SRTP, RTP/SAVP).
[Confirm and document before launch: supported TLS versions and cipher suites, certificate management, and encryption of data at rest (database, recordings, backups).]
Access control
Administrative access is not publicly reachable and is protected at several levels:
- Administrative interfaces are protected by Cloudflare Access. Sign-in uses a one-time passcode sent by email and is restricted to named accounts.
- The management interface of the switching platform is not reachable from the public internet. Access runs exclusively through a Cloudflare Tunnel; inbound traffic on port 443 is dropped at the host firewall.
- SSH access is restricted to allowlisted networks, password authentication is disabled, and only registered keys are accepted.
- Service-to-service access uses dedicated credentials (service tokens and connector secrets). Requests without a valid credential are rejected.
[Confirm and document before launch: role and permission model, logging of administrative access, joiner and leaver procedures, and periodic access reviews.]
Data protection and processing agreements
XETEL processes personal data in accordance with the GDPR. We provide a data processing agreement under Article 28 GDPR on request; it is concluded before production use.
On request you will receive the current list of sub-processors we use, together with their roles and locations. We announce changes in advance so that you can object.
[To be added: published list of sub-processors, notice period for changes, and the objection procedure.]
Read the privacy policy for this website
[Confirm and document before launch: record of processing activities, technical and organisational measures under Article 32 GDPR, deletion and retention policy, and the procedure for personal data breaches under Article 33 GDPR.]
Call recording
The platform can record calls. Whether recording is permitted is determined by the applicable law — not by what is technically possible.
In Germany, the confidentiality of the spoken word is protected by criminal law under § 201 StGB. Recording a telephone call therefore generally requires the consent of all participants. The processing must additionally be justified under data protection law; where employees are involved, the works council's co-determination rights under § 87 BetrVG must be observed.
Recording is therefore configurable per line and per call flow and is not enforced by default. The customer is responsible for lawful use, for informing the participants, and for obtaining and documenting consent.
Regulatory position
XETEL provides telecommunications services in Germany and is therefore subject to the Telecommunications Act and to supervision by the Bundesnetzagentur.
[Confirm before launch: notification of the telecommunications service to the Bundesnetzagentur under § 5 TKG, allocation of the number ranges used, and the registration reference to be quoted in business dealings.]
Numbers are assigned to customers on a fixed basis and are reachable for callbacks. XETEL uses no technique that feigns local proximity to the person called, and the requirements on number presentation are observed.
[Confirm before launch: certifications held or planned, for example ISO/IEC 27001, and the date of the next external audit.]
Availability and operations
Platform availability is 99.99%. Voice delivery in Germany, Austria, and Switzerland runs over redundant interconnects, so the loss of a single interconnect does not end reachability.
[Confirm and document before launch: backup policy, recovery objectives (RTO and RPO), frequency of restore testing, and contingency planning.]
[To be added: public status page at status.xetel.de — not yet in operation.]
Reporting a security issue
If you find a vulnerability in our systems, please report it to us before publishing it. We will acknowledge receipt, keep you informed of remediation progress, and will refrain from legal action against reporters who follow these rules.
[To be added: contact address for security reports, for example security@xetel.de, and a commitment to acknowledge receipt within a stated period.]
[To be added: PGP key for encrypted reports and a security.txt at /.well-known/security.txt.]
When testing, please do not access data belonging to others, do not modify or delete data, and do not disrupt operations. Load testing and denial-of-service attempts are not permitted.
Questions procurement and IT ask most
Where is the data held?
We run the telephony platform on our own servers in a German data centre. The application database sits in Cloudflare's Western Europe region. Personal data held by the application is processed in the EU. Static website content is delivered through Cloudflare's global network for speed.
Is a data processing agreement available?
Yes. We provide a DPA under Article 28 GDPR on request; it is concluded before production use. Details of technical and organisational measures are supplied as an annex.
Who has access to our data?
Named accounts only. Administrative interfaces are protected by Cloudflare Access with a one-time passcode sent by email. The management interface of the switching platform is not reachable from the internet, SSH is restricted to allowlisted networks, and password authentication is disabled.
How is traffic encrypted?
The website, portal, and API run over TLS. SIP signalling uses TLS on port 5061 and voice media is carried over SRTP; media encryption is mandatory for XETEL endpoints.
Are calls recorded?
Only where you enable the feature for the line in question. In Germany, recording a call generally requires the consent of all participants (§ 201 StGB); where employees are involved, the works council must also be involved. Lawful use is your responsibility.
Which sub-processors do you use?
We use Cloudflare for hosting, delivery, and attack protection of the web layer. The telephony platform runs on our own infrastructure in Germany. You receive the full current list together with the DPA.