GDPR
GBK Solutions Limited provides account data-export tools intended to support UK GDPR and EU GDPR data-subject requests. Registration collects contact details and consent preferences. This describes product behaviour; it is not a claim that Nufono holds a formal GDPR certification or seal.
HIPAA
Nufono is not offered as a HIPAA-certified service and does not currently provide a Business Associate Agreement. Do not use Nufono to create, receive, maintain, or transmit protected health information. Clinic pages describe inbound reception only — not clinical systems.
TCPA
Nufono must not be used for unsolicited telephone contact. Conversations are customer-initiated or explicitly opt-in. Customers are responsible for consent records, do-not-contact lists, and any TCPA duties that apply to them. We prohibit telemarketing and cold calling in the Acceptable Use Policy.
PCI-DSS
Subscription and credit-pack payments are processed by Stripe (and other configured gateways). Nufono does not store full card numbers. This is not a claim that GBK Solutions Limited is PCI-DSS certified. Do not collect card data through voice or chat agents.
Audit logs
The product records administrative and API audit events, and team activity logs, so workspace owners can review important actions. These are operational logs, not an independently audited compliance certification.
Sub-processors
Voice, hosting, email, and payment providers process data on our behalf when you use those features. See the sub-processors page for the categories we rely on. We do not claim a dedicated EU-only residency option unless a written agreement says otherwise.
Sub-processors · Acceptable use