We do not provide telemarketing, cold-calling, or unsolicited outbound calling services.

Compliance and responsible use

Nufono is inbound-only in our marketing and acceptable use. The notes below describe product behaviour. They are not audited certifications unless we say otherwise.

GDPR

GBK Solutions Limited provides account data-export tools intended to support UK GDPR and EU GDPR data-subject requests. Registration collects contact details and consent preferences. This describes product behaviour; it is not a claim that Nufono holds a formal GDPR certification or seal.

HIPAA

Nufono is not offered as a HIPAA-certified service and does not currently provide a Business Associate Agreement. Do not use Nufono to create, receive, maintain, or transmit protected health information. Clinic pages describe inbound reception only — not clinical systems.

TCPA

Nufono must not be used for unsolicited telephone contact. Conversations are customer-initiated or explicitly opt-in. Customers are responsible for consent records, do-not-contact lists, and any TCPA duties that apply to them. We prohibit telemarketing and cold calling in the Acceptable Use Policy.

PCI-DSS

Subscription and credit-pack payments are processed by Stripe (and other configured gateways). Nufono does not store full card numbers. This is not a claim that GBK Solutions Limited is PCI-DSS certified. Do not collect card data through voice or chat agents.

Audit logs

The product records administrative and API audit events, and team activity logs, so workspace owners can review important actions. These are operational logs, not an independently audited compliance certification.

Sub-processors

Voice, hosting, email, and payment providers process data on our behalf when you use those features. See the sub-processors page for the categories we rely on. We do not claim a dedicated EU-only residency option unless a written agreement says otherwise.

Sub-processors · Acceptable use