← Back to Everglades Communications

PRIVACY POLICY

What we hold, why we hold it, and when we destroy it.

We verify identities for a living, which means we handle sensitive information including identity documents and biometric data. This notice sets out exactly what happens to it.

Effective
10 September 2026
Last updated
10 September 2026
Version
1.0
Controller
Everglades Communications LLC
Contact
privacy@evergladescomms.com

01 Who we are, and how to reach us

Everglades Communications LLC is a Wyoming limited liability company providing wholesale SIP trunking, termination, origination and telephone numbers to business customers. For the purposes of the UK and EU General Data Protection Regulation we are a controller of the personal data described in this notice. We are a controller of all of it; we do not act as a processor for anyone in relation to this data.

Postal address
Everglades Communications LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States
Privacy inquiries and rights requests
privacy@evergladescomms.com
Legal notices
legal@evergladescomms.com

02 The short version

  • We collect what onboarding a carrier customer requires, and very little else.
  • This website sets no cookies, runs no analytics and carries no advertising trackers. It loads typefaces from Google Fonts, and the contact form is processed by our hosting provider — see sections 08 and 13.
  • We do not sell personal information, and we do not share it for cross-context behavioral advertising.
  • Identity documents and biometric data are processed for verification only, and biometric data is destroyed on a fixed short schedule.
  • Call detail records are treated as confidential customer information under U.S. telecommunications law.

03 What we handle

Website visitors

Our hosting provider records standard server logs — IP address, timestamp, page requested, user agent — for security and availability. We do not combine these with anything else, and we do not use them to identify individuals.

Inquiries

If you use the contact form we receive your name, business name, work email, telephone number, declared use case, approximate monthly volume, and whatever you write in the notes field.

Customers and applicants

  • Business information: legal name, registered and operating addresses, formation documents, tax identifiers, regulatory filings, website and corporate contact details.
  • Personal information about owners, officers and authorized contacts: name, date of birth, residential address, nationality, role, ownership percentage, contact details, and signature.
  • Identity documents: passport, driving license or national identity card, including the document image and the data encoded in it.
  • Biometric information: a facial image and the facial geometry derived from it during liveness checking. See section 05.
  • Screening results: sanctions, denied-party, politically exposed person and adverse media check outcomes.
  • Financial information: billing contact, bank or card details handled by our payment processor, invoices and payment history.
  • Service and traffic data: account credentials, IP addresses, configuration, and call detail records. See section 04.
  • Correspondence: support tickets, emails, and records of compliance inquiries.

04 Call detail records and CPNI

Operating a voice network means we necessarily see who called whom, when, for how long, and from where. Under U.S. law (47 U.S.C. § 222 and 47 C.F.R. §§ 64.2001–64.2011) some of this constitutes Customer Proprietary Network Information, and its use is restricted by statute rather than by our own discretion.

You have a right, and we have a duty under federal law, to protect the confidentiality of your CPNI.

We use CPNI to provide, route, complete and bill for the service you subscribe to, to protect the network and to protect ourselves and other carriers from fraudulent, abusive or unlawful use of the service, to respond to traceback requests, and to comply with legal obligations — all of which § 222(c)(1) and § 222(d) permit without your approval. We do not sell CPNI. We do not disclose it to third parties except as § 222(d) permits, as law or lawful process requires, or with your approval.

Marketing

We do not use CPNI to market to you, other than to discuss with you the service you already take from us and the rates that apply to it, which federal law permits without your approval.

Your approval

Because we do not use CPNI for marketing beyond that, we do not currently seek your approval for any such use. If that changes we will first give you the notice federal law requires; you will be free to withhold or withdraw approval at any time by writing to privacy@evergladescomms.com; approval or refusal lasts until you change it; and refusing or withdrawing approval will not affect the provision of any service you take from us.

Safeguards

We authenticate anyone seeking access to CPNI before we disclose it. We do not disclose call detail information on a customer-initiated telephone call unless the caller provides the account password, or we call back on the telephone number of record, or we send the information to the address of record. Online access requires a password not derived from readily available biographical or account information. We notify the account contacts of record whenever a password, address of record or back-up authentication response is created or changed. Employee access to CPNI is role-restricted, logged and reviewed, and misuse is a disciplinary matter. 47 C.F.R. § 64.2010.

Breach

If CPNI is breached, we notify the Commission, the Federal Bureau of Investigation and the United States Secret Service through the FCC’s central reporting facility within seven business days of reasonably determining that a breach occurred, and we notify affected customers without unreasonable delay and no later than 30 days after that determination, unless law enforcement asks us to delay or we reasonably determine that no harm to customers is reasonably likely. 47 C.F.R. § 64.2011.

Certification

An officer of Everglades Communications LLC signs and files an annual CPNI compliance certificate with the Commission under 47 C.F.R. § 64.2009(e), with a statement explaining how our procedures ensure compliance, a summary of any customer complaints about unauthorized release of CPNI, and a summary of any action taken against data brokers.

Other carriers

Where another carrier gives us proprietary information for the purpose of providing telecommunications service, 47 U.S.C. § 222(b) requires us to use it only for that purpose. We do, and we do not use a customer’s or a peer’s traffic information to compete with them.

Called parties

Where a call involves an individual who is not our customer, we hold the record as a necessary consequence of carrying the call and use it only for the purposes above. Such a record is not that individual’s CPNI — CPNI belongs to the carrier’s own customer — but we treat it with the same confidentiality.

05 Identity documents and biometric information

This section describes the most sensitive processing we carry out. Read it before you begin verification, not after.

This section, together with the retention table in section 11, is Everglades Communications LLC’s written policy on the retention and destruction of biometric identifiers and biometric information, established and made available to the public under 740 ILCS 14/15(a). It is also our biometric policy for the purposes of Tex. Bus. & Com. Code § 503.001 and Colo. Rev. Stat. § 6-1-1314.

To verify the individuals behind an account, we use a third-party identity verification provider. That provider checks the authenticity of a government-issued identity document, and performs a liveness check in which you present your face to a camera. The check confirms that a live person is present and that their face matches the document.

The liveness check derives a mathematical representation of facial geometry. In Illinois this is a biometric identifier under the Biometric Information Privacy Act, 740 ILCS 14; in Texas under the Capture or Use of Biometric Identifier Act, Tex. Bus. & Com. Code § 503.001; and in Colorado under Colo. Rev. Stat. § 6-1-1314. Under the UK and EU GDPR it is a special category of personal data under Article 9(1). Washington’s biometric statute, RCW 19.375, excludes data generated from a photograph from its definition and so does not apply to this processing; we apply the commitments below to Washington residents in any case.

Our commitments

  • Purpose. Biometric information is used only to confirm that the person presenting an identity document is the person it depicts. Our contract with our verification provider prohibits it from using your biometric information for any other purpose, including surveillance, enrollment in any cross-customer identity or fraud database, and the training or improvement of any model or product, and we disable every optional feature of that service that would involve such use.
  • Consent. Before any biometric capture takes place, and separately from this notice, we present you with a written disclosure and obtain your written release, signed by you — an electronic signature is sufficient under 740 ILCS 14/10. That disclosure names Everglades Communications LLC and the identity verification provider we have engaged, states that a biometric identifier and biometric information are being collected and stored, states the specific purpose for which they are collected, stored and used, states the specific length of term for which they will be retained, and authorizes disclosure to that named provider for that purpose only. We do not begin capture until that release is executed, and we name the provider to you before capture rather than on request. You may refuse.
  • An alternative always exists. If you will not or cannot complete a biometric check, we verify you by a manual route instead — a notarized identity affidavit with certified document copies, reviewed by a person. We do not charge for the manual route, we do not treat it as a negative factor in the decision, it does not change your risk rating, and it reaches the same outcome on the same evidence. It may take longer because you must obtain a notarization; we tell you the expected timescale before you choose, and delay attributable to the manual route does not count against your application.
  • No sale, lease, trade or profit. We do not sell, lease, trade or otherwise profit from biometric information, in any jurisdiction, under any circumstances.
  • Destruction. Biometric information is permanently destroyed as soon as the verification purpose is satisfied, and in any event within 30 days of the verification decision — well inside the limit BIPA sets, which is the earlier of satisfaction of the initial purpose or three years after your last interaction with us (740 ILCS 14/15(a)). Destruction means irreversible deletion of the facial image and the derived facial template from production systems and from backups, by us and by our verification provider, who certifies each destruction to us in writing. We never receive or store the facial template ourselves: it is generated and destroyed inside the provider’s environment, and what is returned to us is the outcome alone. What we retain is that outcome (verified, or not) and an audit record of when verification occurred and by what method — not the biometric data.
  • How destruction is carried out. Destruction is triggered by the verification decision. Where a facial image has reached us another way — for example attached to a support ticket — it is deleted on the same schedule. Compliance with this schedule is reviewed quarterly by our compliance function and each destruction certificate is retained as part of the audit record. Destruction is not deferred by a litigation hold except where a court orders preservation, in which case the data is segregated, access-restricted, and destroyed immediately on release of the hold.
  • Identity document images are retained for the period required to evidence the verification to regulators and upstream carriers, and no longer than five years after the account closes.
  • Disclosure. We do not disclose biometric information except to the verification provider processing it on our behalf, or where a court order, warrant or subpoena compels it.

Our verification provider acts solely as our processor for the verification described in this section, under a written data processing agreement, on documented instructions, and is contractually prohibited from acting as a controller of your biometric data or from using it for its own purposes.

Where the individual to be verified is in the United Kingdom, the European Economic Area or Switzerland, we do not offer the biometric route at all. Those individuals are verified by the manual route described above. We do not process biometric data about them, and nothing in this section applies to them.

06 Where the information comes from

  • From you — your application, the documents you upload, your correspondence, and your use of the service.
  • From your organization — where a colleague names you as an officer, owner or authorized contact.
  • From public registries — state and national company registries, tax authority confirmations, FCC filings and the Robocall Mitigation Database.
  • From screening and verification providers — sanctions, denied-party, PEP and adverse media data, and identity verification results.
  • From our network — call records, signaling and telemetry generated by your traffic.
  • From other carriers and the Industry Traceback Group — where traffic is the subject of a traceback or complaint.

07 Why we process it, and our legal bases

PURPOSELEGAL BASIS (UK/EU GDPR)
Responding to inquiriesSteps taken at your request prior to entering a contract; legitimate interests.
Identity and business verification (non-biometric)Art. 6(1)(b) steps taken at your request prior to a contract; Art. 6(1)(f) our legitimate interest, and that of the public and of the carriers we interconnect with, in preventing fraud and unlawful traffic (Recital 47).
Biometric verification (facial geometry)Not offered to individuals in the UK, EEA or Switzerland. Where it is offered, Art. 9(2)(a) explicit consent together with Art. 6(1)(a). We rely on consent alone and on no other condition; refusing or withdrawing it leaves your application unaffected.
Sanctions and PEP screeningArt. 6(1)(f) legitimate interests; and, where a result concerns criminal convictions or offences, Art. 10 GDPR. U.S. sanctions law does not create an Art. 6(1)(c) obligation as to UK or EEA data subjects; where an EU or UK sanctions regime applies directly to us, we also rely on Art. 6(1)(c).
Providing and billing for servicePerformance of a contract.
Network security and fraud preventionLegitimate interests in protecting the network, our customers and called parties.
Traceback and regulatory cooperationLegal obligation; legitimate interests.
Record keeping and defending claimsLegal obligation; legitimate interests in establishing and defending legal claims.

Providing the identity and ownership information described in section 03 is a requirement of entering into a contract with us: without it we cannot verify your organization and cannot open an account. Providing biometric information is never required — it is one of two routes to the same verification, and the manual route in section 05 is always available.

Where we rely on legitimate interests we have assessed that our interest is not overridden by your rights; you can ask us for that assessment. Where we rely on consent, you may withdraw it at any time, without affecting processing already carried out.

08 Who we share it with

  • Identity verification provider — identity documents and biometric data, as our processor, for verification only.
  • Screening data providers — names and identifiers, to run sanctions, PEP and adverse media checks.
  • Upstream and interconnecting carriers — signaling information necessary to complete calls, and customer identification where a carrier or regulator requires it to investigate traffic.
  • The Industry Traceback Group, the FCC, the FTC, state attorneys general and law enforcement — in response to traceback requests and lawful process.
  • Payment processors — billing data necessary to take payment. We do not store full card numbers.
  • Infrastructure and hosting providers — including Netlify, which hosts this website, processes its server logs, and receives and stores the contents of the contact form on our behalf.
  • Professional advisers — lawyers, auditors and accountants, under duties of confidence.
  • An acquirer — if the business is sold or merged, subject to this notice continuing to apply.

Most of these recipients act as our processors or service providers, on documented instructions under a written contract, and are not permitted to use the data for their own purposes. Some act as independent controllers in their own right for their own legal and regulatory obligations — in particular our payment processors, our screening data providers, our professional advisers, and any acquirer — and process your data under their own privacy notices, which we will identify on request.

09 What we do not do

  • We do not sell personal information, and have not since we began operations.
  • We do not share personal information for cross-context behavioral advertising.
  • We do not sell, lease or trade biometric information under any circumstances.
  • We do not use CPNI for marketing.
  • We do not make decisions producing legal or similarly significant effects by automated means alone. A verification result from our provider is a recommendation, not a decision. Where it is adverse, a named member of our compliance team, with authority to reach a different conclusion and access to the underlying evidence, reviews it before any application is refused, and records the reasons. You may ask us for those reasons, contest the outcome, and give us further evidence.

10 International transfers

We are established in the United States and our infrastructure is primarily located there. If you are in the United Kingdom, the European Economic Area or Switzerland, providing information to us involves a transfer to the United States.

Where you provide information to us directly from the United Kingdom, the EEA or Switzerland, we are subject to the UK and EU GDPR under Article 3(2) and we process that data in the United States. That direct collection is not a restricted transfer requiring a Chapter V mechanism, but we apply the same protections to it as if it were.

Where we disclose personal data onward to a recipient outside the UK, EEA or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, supported by a transfer risk assessment for each recipient, and we apply encryption in transit and at rest, strict access control and data minimization. We do not represent that encryption at rest defeats a lawful access demand made to a recipient that holds the keys; where that risk is material to a category of data, we do not transfer that data. A copy of the relevant clauses and the transfer risk assessment is available on request.

11 How long we keep it

CATEGORYRETENTION
Biometric informationDestroyed within 30 days of the verification decision.
Identity documentsUp to five years after the account closes.
Onboarding and screening recordsFive years after the account closes.
Call detail recordsAs required for billing, dispute resolution and regulatory cooperation; ordinarily 24 months.
Billing and tax recordsSeven years, as tax law requires.
Refused and abandoned applications, including identity documentsFive years from refusal or abandonment, so we can evidence the decision to regulators and carriers and detect a reconstituted applicant. Biometric information is destroyed on the 30-day schedule above whether or not the application succeeds.
Unsuccessful inquiries that did not reach verification24 months from last contact.
Website server logsOrdinarily 30 days.

Periods are extended where a litigation hold, regulatory investigation or legal obligation requires it, and shortened where we no longer need the data.

12 Your rights

If you are in the UK, EEA or Switzerland

You have the right to access your personal data; to have inaccurate data corrected; to erasure; to restrict processing; to data portability; to object to processing based on legitimate interests; and to withdraw consent where processing relies on it. You also have the right to lodge a complaint with your supervisory authority.

If you are a California resident

Under the CCPA as amended by the CPRA you have the right to know what personal information we collect, use and disclose; to delete it; to correct it; to opt out of sale or sharing (we do neither); to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. Identity documents and biometric information are sensitive personal information; we use them only to verify identity and to resist fraudulent and illegal activity, which are purposes specified in Cal. Code Regs. tit. 11, § 7027(m), and we never use them to infer characteristics about you. Because we limit ourselves in that way we are not required to offer, and do not offer, a separate “Limit the Use of My Sensitive Personal Information” control. If you nonetheless want us to confirm what we hold, write to us and we will.

Other U.S. states

Residents of states with comprehensive privacy laws — currently including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia — have rights of access, deletion and portability, and in most of those states rights of correction and to appeal a refused request. Utah and Iowa do not provide a correction right, and Utah does not provide an appeal process. Minnesota residents may additionally ask us to explain a profiling result. Where a state gives you a right to appeal, we tell you how when we respond, and if we deny an appeal we tell you how to contact your state attorney general.

These laws treat biometric data, and in several states identity documents, as sensitive data requiring your affirmative opt-in consent before processing. We obtain that consent before any biometric capture, in the written release described in section 05, and we process biometric data on no other basis. Maryland law additionally limits our collection of sensitive data to what is strictly necessary to provide the service you have requested and prohibits its sale absolutely; we comply, and we do not sell sensitive data in any state. We conduct and document a data protection assessment for this processing where state law requires one.

Making a request

Write to privacy@evergladescomms.com. We acknowledge requests promptly and respond within the period the applicable law allows: one month under the UK and EU GDPR, extendable by up to two further months where the request is complex or numerous, in which case we tell you within the first month; and 45 days under the CCPA and comparable state laws, extendable once by a further 45 days where reasonably necessary, in which case we tell you within the first 45 days and explain why. We do not use an extension as a delaying tactic. We will ask you to verify your identity proportionately to the sensitivity of the request — and, given what we do, we will not use that verification as an excuse to collect more than we need. An authorized agent may act for you with written authorization.

These rights are not absolute. Where a legal obligation requires us to keep a record — a sanctions screening result, a call detail record subject to a regulatory hold — we will tell you which obligation applies rather than simply refusing.

13 Cookies, and what this website stores

This website sets no cookies. It uses no analytics, no advertising pixels, and no third-party tracking of any kind.

It stores exactly one item in your browser’s sessionStorage: a flag recording that the opening title sequence has already played, so it does not replay on every page you visit. It contains no identifier, it is not transmitted anywhere, and it is discarded when you close the tab.

Fonts

Typefaces are loaded from Google Fonts. This means your browser makes a request to fonts.googleapis.com and fonts.gstatic.com, and Google receives your IP address and user agent as a consequence. Google’s own privacy policy governs what it does with that request; we do not control it and make no representation about it. If you would rather avoid it, a content blocker will prevent the request and the site falls back to your system’s own fonts with no loss of function.

14 Security

We encrypt data in transit and at rest across the systems we control, restrict access to personnel whose role requires it, log access to onboarding material, and separate production systems from administrative ones. Signaling is protected with TLS and media with SRTP where the interconnect supports it.

Biometric information is stored, transmitted and protected using the reasonable standard of care within our industry, and in a manner at least as protective as the manner in which we store, transmit and protect other confidential and sensitive information: it is held only within our verification provider’s environment, is never exported to our systems, is encrypted in transit and at rest, is accessible to no Everglades personnel, and is destroyed on the schedule in section 05.

No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we notify you and the relevant regulator within the time limits the applicable law sets, including the state breach-notification statutes that treat biometric data as personal information. Breaches of customer proprietary network information follow the separate federal timetable in section 04.

15 Children

Our service is sold to businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, write to privacy@evergladescomms.com and we will delete it.

16 Changes to this notice

We update this notice as our processing changes. The effective date at the top of the page always reflects the current version. Where a change materially affects how we handle information we already hold, we will notify account contacts directly rather than relying on you to notice the new date.

17 Complaints

If you are unhappy with how we have handled your information, tell us first at privacy@evergladescomms.com — we would rather fix it than have you escalate.

You may also complain to your data protection supervisory authority. In the United Kingdom that is the Information Commissioner’s Office; in the EEA it is the authority for your country of residence. California residents may contact the California Privacy Protection Agency or the Attorney General.

EVERGLADES COMMUNICATIONS LLC · PRIVACY POLICY · VERSION 1.0
EFFECTIVE 10 SEPTEMBER 2026 · 30 N GOULD ST STE R, SHERIDAN, WY 82801
RIGHTS REQUESTS: PRIVACY@EVERGLADESCOMMS.COM