Controller and representatives
The data controller is FNA Global Network LLC (Company Reg. No. 10637816), 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Dico.tel is a trading brand of FNA Global Network LLC — all Dico.tel divisions (Personal, Business, VIP, Phone, Web, Connect and Academy) are operated by, and all contracts are entered into with, FNA Global Network LLC.
Our EU Article 27 representative is [EU Article 27 representative — replace or remove] and our UK representative is [UK representative — replace or remove]. Privacy contact: privacy@dico.tel.
Data we collect
- —Account data: name, email, phone number, country, and account preferences.
- —Billing data: plan, billing address, tax status and payment records. Full card numbers are handled by our PCI-DSS compliant payment processor and never stored on Dico.tel systems.
- —Service data: device and network security telemetry needed to detect threats — app risk signals, connection metadata, blocked domains, alert history.
- —Support data: messages, attachments and call notes you send us.
- —Site data: basic analytics such as pages viewed, referrer and approximate region.
Why we use it, and our legal bases
- —To deliver, monitor and improve the services you subscribe to — performance of our contract with you.
- —To take payment, prevent fraud, and secure our platform — contract and our legitimate interests.
- —To meet accounting, tax, sanctions and law-enforcement obligations — legal obligation.
- —To notify you about threats, incidents, renewals and material policy changes — contract and legitimate interests.
- —To send marketing — consent, withdrawable in one click at any time.
What we never do
- —We do not sell or share personal data for cross-context behavioural advertising, as those terms are defined under US state privacy laws.
- —We do not read the content of your messages, calls or files as part of monitoring.
- —We do not share protection telemetry with advertisers or data brokers.
- —We do not use personal data to train third-party AI models.
Automated decisions
Security scoring and threat detection use automated analysis, but no decision producing legal or similarly significant effects about you is made solely by automated means without human review. You can ask a human to review any account decision.
Who processes data for us
We use a small set of vetted processors: a payment processor for checkout and billing, cloud infrastructure and security-analytics providers, an email provider for transactional messages, and a support desk platform. Each is bound by a data-processing agreement, may act only on our instructions, and is listed on request via privacy@dico.tel. We disclose data to authorities only where legally compelled, and we challenge overbroad requests.
International transfers
We operate globally, so data may be processed outside your country, including in the EEA, UK and United States. Where we transfer personal data out of the EEA, UK or Switzerland, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), together with a transfer risk assessment and technical safeguards such as encryption in transit and at rest. Comparable mechanisms are used for transfers under Brazilian, South African, Nigerian, UAE and other regional laws. A copy of the safeguards is available on request.
Storage, security and retention
Data is stored on encrypted infrastructure, protected in transit with TLS, and access-controlled on a least-privilege basis. Account and billing records are retained while your account is active and then for the period required by law — typically seven years for financial records. Security telemetry is retained on a rolling window appropriate to the product and then deleted or aggregated. Support tickets are retained for 24 months.
Your rights
- —Access a copy of the personal data we hold about you.
- —Correct data that is wrong or out of date.
- —Delete your account and associated personal data, subject to legal retention duties.
- —Export your data in a portable, machine-readable format.
- —Object to or restrict certain processing, and withdraw consent at any time.
- —Complain to your local supervisory authority — for example an EU data protection authority, the UK ICO, or your national regulator.
Regional rights
- —EEA / UK (GDPR): the rights above, plus the right to lodge a complaint and to be told the safeguards used for international transfers.
- —California and other US states (CCPA/CPRA, VCDPA, CPA and similar): rights to know, delete, correct, and to opt out of sale, sharing and targeted advertising — we do not sell or share, and we honour Global Privacy Control signals. We will never discriminate against you for exercising a right.
- —Canada (PIPEDA/Law 25), Australia (Privacy Act), Brazil (LGPD), South Africa (POPIA), Nigeria (NDPA), India (DPDP Act), UAE and Saudi Arabia: equivalent access, correction, deletion and complaint rights under local law.
- —Exercise any right at privacy@dico.tel. We verify identity before acting.
Children
Dico.tel accounts are for adults. We do not knowingly collect personal data from children under 16 (or the local digital-consent age). Family plans may protect devices used by children, but the account holder must be an adult, is responsible for the account, and must have authority to consent on the child's behalf.
Breach notification
If a personal data breach is likely to affect your rights, we notify affected customers and the relevant supervisory authority without undue delay — and within 72 hours where GDPR or an equivalent regime requires it — describing what happened, what data was involved and what to do next.
Contact our privacy team
Email privacy@dico.tel for any privacy request. We respond within 30 days, or sooner where local law requires.
