Symfy
หน้าแรกPOSขายออนไลน์โมดูลราคาคำนวณค่าใช้จ่ายSymfy Shop(เปิดในแท็บใหม่)
เข้าสู่ระบบสมัครใช้งานฟรี
หน้าแรกPOSขายออนไลน์โมดูลราคาคำนวณค่าใช้จ่าย
Symfy Shop(เปิดในแท็บใหม่)
เข้าสู่ระบบสมัครใช้งานฟรี
Home/Zubsip Privacy Policy

Zubsip Privacy Policy

Privacy Policy for Zubsip, the SIP softphone for business voice communication.

Effective date: 18 September 2026Last updated: 18 September 2026

1. Introduction and scope

This Privacy Policy explains how information is handled when you use Zubsip, a SIP softphone application for business telephony. Zubsip lets you register an extension on a compatible SIP/PBX account and place and receive voice calls on your mobile device.

Zubsip is a client application. It does not create phone service of its own: you can only make and receive calls after entering credentials for an extension that your organisation or your telephony provider has issued to you. Because of that, two different parties are involved in any call you make:

  • The Zubsip app and the Symfy Cloud PBX services described in this policy, which handle your app configuration, device registration for incoming-call wake-up, and — where Symfy operates the PBX for your organisation — the telephony platform itself.
  • Your organisation and its PBX/SIP provider, which own the extension, decide which calls are allowed, and decide whether calls are logged or recorded on the platform. If your employer or a third-party provider operates the PBX you connect to, their own policies apply to that data, and this policy cannot vary them.

This policy covers the Zubsip mobile application (iOS and Android) and the Symfy PBX device and call-notification services that the app talks to. It does not cover the Symfy Cloud ERP product, the symfy.co website, or any other Symfy service; those are covered by the Symfy Privacy Policy and the Symfy Cookie Policy.

2. Who we are

Zubsip and the Symfy platform are provided by CNY CORPORATION COMPANY LIMITED, a company registered in Thailand.

  • Legal entity: CNY CORPORATION COMPANY LIMITED (บริษัท ซีเอ็นวายคอร์ปอเรชั่น จำกัด)
  • Company registration number: 0935558000211
  • Registered address: 541/1-3 Moo 1, Mae Khari Subdistrict, Tamot District, Phatthalung 93160, Thailand
  • Brands: Symfy (platform) and Zubsip (this application)
  • Country: Thailand
  • Contact: [email protected] for product and support enquiries, [email protected] for privacy and legal enquiries

Where your organisation operates its own PBX or buys telephony from another provider, that organisation is normally the controller of the call data generated on the platform, and we act as its service provider for the parts we operate.

3. Information we process

The table below summarises every category of information the current version of the app and its supporting services handle. Each category is explained underneath.

InformationCollected?Where it is heldPurpose
SIP account details (company code, extension number, password)Yes — entered by youDevice keychain; transmitted to the PBX for verificationRegister your extension and authorise device registration
Installation identifier (random UUID)Yes — generated on your deviceDevice keychain; stored in the device registryTell your device apart from other devices on the same extension
Push token (Apple APNs on iOS, Google FCM on Android)YesSymfy PBX device registryWake your device when a call arrives
Incoming-call details (caller number and name, call identifier, extension)Yes — in transitDelivered through Apple or Google push infrastructure to your deviceShow you who is calling before you answer
Call history and favouritesYesYour device only — never uploaded to usRecents list and quick dialling
Microphone audioDuring a call onlyNot recorded by the appTwo-way voice conversation
Call detail records, and recordings where the PBX records callsBy the telephony platform, not by the appPBX platform and Symfy storageOperate the telephony service for your organisation
Contacts / address bookNo——
Analytics or advertising identifiersNo——
Crash-reporting SDK dataNo——

3.1 SIP and account information

To activate Zubsip you enter three things: your company code, your extension number and your SIP password. From the company code the app derives the SIP server for your organisation and registers your extension over an encrypted TLS connection.

These details are handled as follows:

  • They are stored in the operating system keychain on your device, marked so that they are never copied to another device or restored onto a different device from a backup.
  • They are sent to your PBX server as part of SIP registration — this is what logging in to a phone system means — and they are sent over HTTPS to the Symfy PBX device service when your device registers or unregisters for incoming-call wake-up. In that request the password is used only to prove that you are entitled to receive calls for that extension; it is compared against the PBX directory and discarded.
  • They are not stored in the device registry, and they are removed from diagnostic logs before those logs are written.
  • If you use Reset extension in the app, the stored credentials are deleted from your device. Reinstalling the app also starts from a clean state, so you will be asked for your details again.

3.2 Device and push notification information

So that a call can reach you when the app is in the background or closed, your device registers for push wake-up. The registry holds, per device:

  • the company code and extension the device answers for;
  • an installation identifier — a random identifier created on your device and kept in the keychain. It identifies the installation, not you, and it is not used for advertising or tracking;
  • the push token issued by Apple (APNs VoIP token) or by Google (FCM registration token) for this installation;
  • the platform (iOS or Android), the push environment of the build, whether the registration is currently enabled, the time it was last updated, and — if we had to disable it — the technical reason (for example, that the push service reported the token as no longer valid).

The registry contains no name, e-mail address, phone number of yours, or contact list. Its only purpose is to answer one question: which devices should be woken when this extension rings?

3.3 Call information

Call information exists in three separate places, and it is important to keep them apart.

  • On your device. The app keeps its own call history: the number dialled or received, a name where one was supplied, the direction of the call, the outcome (answered, missed, declined, or not connected), the time, and the duration. The list is capped at the most recent entries and is stored in the app’s own storage area on the device. It is not synchronised to us or to any server, and we cannot read it. Favourites that you create — a number and a label you type yourself — are stored the same way. You can delete individual entries, clear the whole history, or remove everything with Reset extension.
  • In transit, when a call arrives. To show you who is calling before you answer, the call identifier, the company code, the extension and the caller’s number and display name are included in the push message that wakes your device. See section 6.
  • On the telephony platform. A PBX keeps its own record of calls that pass through it — typically the call identifier, the domain, the direction, the calling and called numbers, the start time, the duration, and a reference to a recording if the call was recorded. This is generated by the phone system, not by the app, and it exists whether you use Zubsip or a desk phone. Where Symfy operates the PBX, we process those records to run the service for your organisation. Where your organisation or another provider operates it, that record is theirs.

3.4 Audio and microphone

Zubsip uses the microphone for one purpose: carrying your voice during a call. The permission is requested by the operating system and you can withdraw it at any time in your device settings, although calls will then have no audio from your side.

The Zubsip app does not record your calls. It has no call-recording feature and it does not write call audio to storage or send call audio anywhere other than to the other party through the PBX.

A PBX can, however, record calls independently of the app. If the PBX your extension belongs to is configured to record, the recording is made by the phone system. Where Symfy operates that PBX, the resulting audio file is transferred into Symfy storage together with technical details about it (an identifier, the call it belongs to, the account and tenant it belongs to, the time, the file type and size, and a checksum) so that it can be retrieved by those whom your organisation has authorised. Whether recording is switched on, and who may listen to recordings, is a decision of the organisation that owns the PBX service — not of the app, and not something you can change from inside the app.

3.5 Contacts

Zubsip does not ask for access to your contacts and does not read your address book. The app does not include the operating system’s contacts framework at all. Names shown on an incoming call come from the phone system (the caller ID supplied by the PBX) or from a label you typed yourself when saving a favourite.

3.6 Technical and diagnostic information

  • On-device diagnostic log. The app keeps a technical log of SIP activity on the device to make call failures diagnosable. Authentication credentials are stripped out before anything is written. The log stays on your device; it is shown only behind a hidden engineer view in Settings, and it leaves the device only if you choose to share it — for example when you send it to support. Please review it before sending if that matters to you.
  • Network address. When your device contacts the PBX and the device-registration service, your network (IP) address is visible to those servers, as it is to any internet service you connect to. It is used to deliver the connection and to apply rate limits that protect the service from abuse, and it may appear in server-side operational logs.
  • Service-side operational logs. The call-notification service records what it did — which extension key was involved, the call identifier, how many devices were registered, and whether the push was accepted by Apple or Google — so that failures can be investigated. App version, operating-system version and device model are not collected automatically; they are useful when you contact support, which is why we ask you for them there.

3.7 Analytics and crash reporting

The current version of Zubsip contains no analytics SDK, no advertising SDK and no third-party crash-reporting SDK. We verified this against the application’s own build configuration: apart from the operating system’s own frameworks and the SIP engine, the iOS build links no third-party service, and the Android build includes only Google’s messaging library, which exists to deliver incoming-call pushes. The app does not build a usage profile of you and does not send behavioural data anywhere.

The symfy.co website — including this page — is separate from the app and does use website analytics, subject to the cookie banner. See the Cookie Policy.

4. How we use information

We use the information described above only for these purposes:

  • Registering your extension so your device can act as a phone on your organisation’s system.
  • Placing and receiving calls, including showing you who is calling.
  • Delivering incoming-call wake-ups to the devices registered for your extension.
  • Keeping the service secure — verifying that whoever registers a device for an extension holds that extension’s credentials, and applying rate limits against abuse.
  • Diagnosing failures such as registration or call-delivery problems.
  • Providing support when you contact us, using what you send us.
  • Operating the telephony service for your organisation where Symfy runs the PBX, which includes call records and, where enabled, recordings.
  • Meeting legal obligations, including responding to lawful requests from competent authorities and to obligations applying to communications services.

We do not use this information to build advertising profiles or to make automated decisions about you.

5. Legal bases and business purposes

Zubsip is a workplace tool, and the information above is processed to deliver a service that an organisation has arranged for you. Where Thai personal data protection law (the Personal Data Protection Act B.E. 2562) or a comparable law in your country applies, we rely on:

  • Performance of a contract — the service agreement with your organisation, and your use of the app under it: registering your extension, connecting your calls, and waking your device for incoming calls cannot be done without the information in section 3.
  • Legitimate interests — keeping the service secure and available, preventing abuse, and diagnosing faults.
  • Legal obligation — where we must keep or disclose information to comply with applicable law.
  • Consent — for device permissions that the operating system asks you for (microphone access, and notification permission on Android). You can withdraw these in your device settings, with the effect described in section 12.

This policy describes our actual practices. It is not a claim of certification under any particular regime, and where your organisation is the controller of call data, its own notice governs that processing.

6. Push notifications and incoming calls

A mobile phone cannot keep a telephone connection alive indefinitely in the background, so Zubsip relies on push infrastructure to be woken when a call arrives.

  • On iPhone, the app registers with Apple Push Notification service (APNs) for VoIP pushes and receives a token that identifies this installation. The token is stored in the device registry described in section 3.2.
  • On Android, the same role is played by Google Firebase Cloud Messaging (FCM).
  • When your extension rings, the phone system asks our call-notification service to wake the registered devices. The message that Apple or Google delivers contains the call identifier, the company code, the extension, and the caller’s number and display name, so that the app can show the incoming call. It contains no credentials and no audio.
  • This means Apple (or Google) transports the caller’s number and display name on the way to your device. We cannot and do not claim otherwise. Their handling of that message is governed by their own terms: see Apple’s Privacy Policy and Google’s Firebase privacy information.
  • Wake-up messages are short-lived and time-critical: a message that arrives too late to ring is useless, so they are sent with a short expiry.

On iPhone, incoming Zubsip calls are presented by the system as a telephone call (using Apple’s CallKit), not as a notification banner, and the app does not ask you for notification permission. On Android, the app does ask for notification permission, because Android needs it to show a call on a locked screen. Either way, your organisation’s desk phones ring independently of whether any mobile device is registered.

7. Voice calls, your PBX and SIP providers

Zubsip is a SIP client. Your calls do not travel “inside the app” — they travel through the telephone system your extension belongs to, and on to the public telephone network when you call an outside number. This means parties other than us may process information about your calls:

  • the PBX operator — Symfy, your organisation, or a third party — which routes calls, keeps call records and decides whether calls are recorded;
  • your SIP trunk or telecommunications provider, which carries calls to and from numbers outside your organisation and keeps its own records as telecommunications law requires;
  • your organisation or employer, which owns the extension issued to you and may have its own rules about monitoring, retention and recording of business calls;
  • the network you connect over — a mobile carrier, an office network, or a VPN.

We cannot control, and this policy does not vary, the privacy practices of a PBX, provider or employer that we do not operate. If you need to know whether your calls are recorded or how long call records are kept on the system you use, ask the administrator of that system. Where Symfy operates the PBX for your organisation, our agreement with your organisation governs those points.

8. Sharing and service providers

We do not sell information, and we share it only as follows:

  • Push infrastructure. Apple (APNs) for iOS devices and Google (FCM) for Android devices, strictly to deliver incoming-call wake-ups, as described in section 6.
  • Cloud infrastructure. The Symfy PBX services run on Amazon Web Services. The device registry, the storage used to stage call recordings where recording is enabled, and the release and deployment tooling for these services are hosted there, in AWS’s Asia Pacific (Thailand) region.
  • Your organisation. Where the PBX is operated for your organisation, the organisation’s authorised administrators can see the extensions, call records and, where recording is enabled, recordings belonging to their own PBX.
  • Support. Information you send us when you ask for help is used to answer you.
  • Authorities and legal requirements. Where we are legally required to disclose information, or where disclosure is necessary to establish, exercise or defend legal claims.

We do not share your information with advertising networks, data brokers or analytics providers, because the app collects nothing for those purposes in the first place.

9. No sale of personal data, no advertising

We do not sell your personal data. Zubsip contains no advertising, no advertising identifiers and no third-party behavioural tracking, and we do not use the information described in this policy for third-party advertising or for cross-app tracking.

10. Data retention

We keep information only as long as it serves the purpose it was collected for.

  • Device push registrations. Kept while the device is registered for the extension. A registration is replaced when the app re-registers, disabled when Apple or Google tells us the token is no longer valid, and deleted when you use Reset extension or ask support to remove it. There is no automatic expiry, so a device that is simply switched off stays registered until one of those things happens.
  • Call history and favourites on your device. Kept on the device until you delete them, until older entries drop off the end of the list, or until the app is removed. They are under your control, not ours.
  • Credentials on your device. Kept until you reset the extension or remove the app.
  • Call records and recordings on the telephony platform. Retention is set by the telephony service arrangement for your organisation, because these records belong to that service rather than to the app. Ask your administrator, or contact us, for the period that applies to your organisation.
  • Operational and security logs. Kept for a limited period for troubleshooting and security purposes, then rotated out.
  • Support correspondence. Kept for as long as needed to handle your request and to keep a record of support we have provided.

11. Security

The measures below are the ones actually implemented in the current version:

  • Encrypted signalling. The app connects to your PBX using SIP over TLS only. The server’s certificate chain is validated and the certificate must match the host for your company code; if it does not, the connection is dropped before registration is attempted.
  • Encrypted API traffic. Device registration and de-registration go over HTTPS.
  • Credential storage. Your SIP password is kept in the operating system keychain, marked as device-only so it cannot migrate to another device, and it is redacted from diagnostic logs.
  • Separated trust boundaries on the service side. The interface used by the phone system to trigger call wake-ups, the interfaces used by Symfy to administer the PBX, and the interface used by the app are separately authenticated; holding one does not grant the others. A device registration request is accepted only if it presents valid credentials for the extension it asks to receive calls for, and failed attempts are answered identically so that they cannot be used to discover which companies or extensions exist.
  • Protecting your calls. Zubsip is built to protect your account information, your authentication and the connection between the app and the telephone system. For the content of a conversation itself, the current version works to the same standard as business telephone systems generally do, and it is not designed for conversations that require high-grade or end-to-end encryption. If your work involves conversations of that kind, speak to your administrator before using Zubsip for them.

No service can promise perfect security, and we do not claim that ours is “100% secure”. If you believe you have found a security problem in Zubsip, please write to [email protected] and describe what you found without posting it publicly.

12. Your choices and rights

Permissions you control on your device

  • Microphone. Required for the other party to hear you. You can withdraw it in your device settings; calls will then connect without your audio.
  • Notifications. On Android, notification permission is needed to display an incoming call; if you deny it, calls may not be shown. On iPhone, incoming calls are shown as system calls and no notification permission is requested — but a Focus mode or Do Not Disturb may silence them, and that setting is yours.
  • Contacts. Not requested; there is nothing to turn off.

Removing your data

  • Reset extension in the app removes the stored credentials, clears the call history and favourites on the device, and unregisters the device so it stops being woken for calls. This is the self-service deletion path, and it is the one to use before handing a phone to someone else.
  • Removing the app deletes the app’s own stored data on the device. If you remove it without resetting first, the device registration may remain until it is replaced or reported invalid — write to support if you want it removed immediately.
  • Your extension itself, and any call records or recordings held on the telephony platform, belong to the PBX service. Requests about those should go to your organisation’s administrator, or to us where Symfy operates the PBX.

Rights under data protection law

Subject to the conditions and exceptions of applicable law — in Thailand, the Personal Data Protection Act B.E. 2562 — you may request access to your personal data, correction of inaccurate data, deletion, restriction of or objection to processing, portability where it applies, and withdrawal of consent where processing relies on consent. You may also lodge a complaint with the competent supervisory authority.

Write to [email protected] or [email protected] to exercise these rights. We may need to verify your identity, and where your organisation is the controller of the data you ask about we will refer the request to them and tell you that we have done so. There is no self-service portal for these requests today; the e-mail addresses above are the real route.

13. Children

Zubsip is a business communications tool. It is provided to people whose organisation or telephony provider has issued them an extension, and it is not directed to children or designed for use by them. We do not knowingly collect personal data from children through the app, and the app has no public sign-up: without credentials issued by an organisation it cannot place or receive calls. If you believe a child’s personal data has reached us through the app, contact us and we will deal with it.

14. International processing

The Symfy PBX services described here run on Amazon Web Services in the Asia Pacific (Thailand) region, and our company is established in Thailand.

Push delivery is different in kind: Apple’s and Google’s push networks are global services, so a wake-up message for your device may be processed outside Thailand by those providers before it reaches you. Likewise, if you use Zubsip while travelling, your connection reaches our servers from wherever you are. Where information is transferred across borders, we rely on the mechanisms available under applicable law and on the terms of the providers concerned. We do not claim that all processing connected with your calls stays within one country, because push delivery and international telephony make that claim untrue.

15. Changes to this policy

We may update this policy as the app changes — for example if a new protection or a new service is introduced. The current version is always published at this address, and the Last updated date at the top of the page shows when it last changed. Where a change is significant we will give notice through the app, the website, or your organisation’s administrator, as appropriate. Continuing to use Zubsip after an update means the updated policy applies to that use.

16. Contact us

You can reach a real person at:

  • Support: [email protected]
  • Privacy and legal: [email protected]
  • LINE: @symfysupport
  • Postal address: CNY CORPORATION COMPANY LIMITED, 541/1-3 Moo 1, Mae Khari Subdistrict, Tamot District, Phatthalung 93160, Thailand

Please do not send SIP passwords or other secrets by e-mail. Support will never need your password to help you.

17. Related links

  • Zubsip Support — setup, permissions, troubleshooting and how to contact us
  • Symfy website — the platform behind Zubsip
  • Symfy Privacy Policy — for the Symfy Cloud ERP service and this website
  • Symfy Terms and Conditions
  • Symfy Cookie Policy — for this website

On this page

  1. 1. Introduction and scope
  2. 2. Who we are
  3. 3. Information we process
  4. 4. How we use information
  5. 5. Legal bases and business purposes
  6. 6. Push notifications and incoming calls
  7. 7. Voice calls, your PBX and SIP providers
  8. 8. Sharing and service providers
  9. 9. No sale of personal data, no advertising
  10. 10. Data retention
  11. 11. Security
  12. 12. Your choices and rights
  13. 13. Children
  14. 14. International processing
  15. 15. Changes to this policy
  16. 16. Contact us
  17. 17. Related links
Symfy

Symfy Cloud ERP และ POS ออนไลน์ สำหรับธุรกิจในประเทศไทย — จัดการสต็อก เอกสารซื้อ-ขาย และการขายหน้าร้านในระบบเดียว

[email protected]LINE@symfysupport

ผลิตภัณฑ์

  • หน้าแรก
  • Symfy POS (Android)
  • ขายออนไลน์ (Shopee / Lazada / TikTok)
  • โมดูล
  • ราคา
  • คำนวณค่าใช้จ่าย
  • Symfy Shop — อุปกรณ์ POS
  • สมัครใช้งาน
  • เข้าสู่ระบบ

นโยบาย

  • นโยบายความเป็นส่วนตัว
  • ข้อกำหนดและเงื่อนไข
  • นโยบายการคืนเงิน
  • นโยบายคุกกี้
© 2026 Symfy. All rights reserved.