# Privacy Policy

> Draft privacy policy: what MobileValidate collects from customers and website visitors, why, how long it is kept and how to exercise your rights.

Canonical: https://mobilevalidate.com/legal/privacy · Last updated: 2026-09-25

> **Draft — pending legal review.**

This policy explains how BroadNet Technologies Inc., 5th floor, Minkara Building, Clemenceau Street, Beirut, Lebanon ("we") handles personal data about our business customers, the people who ask for access, and visitors to mobilevalidate.com. Phone numbers and e-mail addresses that customers submit for checking are covered separately in the [data-subject notice](/legal/data-subject-notice).

## What data do we collect?

| Where it comes from | Data | Why |
|---|---|---|
| Request-access form | Name, work e-mail, company, website, intended use case, expected monthly volume, services of interest | To assess the request and set up an account |
| Form security | A Cloudflare Turnstile token, and a keyed hash of your IP address (we don't store the IP address itself) | To block automated abuse and repeated submissions |
| Customer account | Contact details, organisation name, API key metadata (prefix, scopes, IP allowlist, creation and last-use dates), credit balance and transactions | To provide and bill the service |
| API use | Request metadata such as time, endpoint, service, counts, cost, request ID and masked identifiers | Operation, billing, support, security and abuse prevention |
| Opt-out form | The number or e-mail address you submit, encrypted at rest, plus a masked copy for staff review | To handle your request |

We only store API keys as keyed hashes. They are shown once, when created. Logs never contain full phone numbers or e-mail addresses. Numbers are masked, for example `+44770*****01`, and so are e-mail addresses, for example `re•••@example.com`.

## On what basis do we use it?

- **Contract:** to set up and run customer accounts, bill for use and give support.
- **Legitimate interests:** security, fraud and abuse prevention (including Turnstile and IP hashing), improving the service, and answering business enquiries.
- **Legal obligation:** accounting, tax and responses to lawful requests.

We don't sell personal data. We don't use analytics or advertising cookies on this website (see the [cookie notice](/legal/cookies)).

## How long do we keep it?

- Request-access submissions: 90 days for rejected or spam requests. If a request is approved, the data becomes part of the customer account.
- Account and billing records: for the life of the account and then as long as accounting law requires ([period — pending]).
- API single-lookup inputs: 7 days. Bulk-job inputs and results: 30 days by default. Customers can set bulk retention from 1 day to 24 months, or delete a job at any time.
- Audit and security logs: [period — pending].

## Who receives it?

Our service providers act for us under written agreements. By category, they are hosting and infrastructure, storage, e-mail delivery, payments, and data-verification partners that carry out the checks customers request. We publish only the categories. Customers who sign our [Data Processing Agreement](/legal/dpa) can get the named list under confidentiality. Some providers may process data outside your country. Where that happens, we use appropriate safeguards ([transfer mechanism — pending]).

## What are your rights?

Depending on where you live, you may have the right to access, correct or delete your data, to restrict or object to its use, to data portability, and to complain to a data-protection supervisory authority. To use these rights, contact [privacy contact — pending]. We may need to confirm your identity first. If your phone number or e-mail address was checked by one of our customers, see the [data-subject notice](/legal/data-subject-notice) or use the [opt-out form](/opt-out).

## Changes and contact

We will update this page when our practices change and show the date at the top. Controller: BroadNet Technologies Inc., 5th floor, Minkara Building, Clemenceau Street, Beirut, Lebanon, Lebanon. Contact: info@broadnet.me. Data protection contact or representative: [pending].
