Section 1Overview
This policy explains how Billistra (“we”, “us”, “our”) handles personal data across billistra.com, the Billistra application at app.billistra.com, the white-labelled storefronts our customers publish, our documentation and status sites, and the emails we send.
- We sell software to businesses. We do not sell, rent or trade personal data — ever.
- We show no advertising and run no advertising or cross-site tracking cookies.
- For our own customers (IPTV operators and their staff) we are the controller. For the end-customer records an operator loads into the platform we are only a processor, acting on that operator’s instructions.
- Data is isolated per tenant at the database layer, so an Owner, a Reseller and a Sub-Reseller cannot read each other’s records.
- You can request access, correction, export or deletion at any time by writing to privacy@billistra.com.
Where this policy uses GDPR terminology (controller, processor, data subject, legal basis), the equivalent concepts under the UK GDPR, the Swiss FADP and US state privacy laws apply in the corresponding jurisdictions.
Section 2Our two roles: controller and processor
Billistra sits between businesses. Which privacy role we occupy depends on whose data is in question, and it determines who you should contact to exercise a right.
We are the controller for
- the operator, reseller and sub-reseller businesses that contract with us, and the individual staff users who hold Billistra logins;
- visitors to billistra.com, our documentation and our status page;
- prospects, trial users, event contacts and people who email or call us;
- our own billing records, support tickets, security logs and audit trail.
For that data, this policy is the notice required by Article 13 GDPR.
We are a processor for
- the end-customer records an operator or reseller creates, imports or synchronises — subscriber names, emails, phone numbers, addresses, subscription and device history, wallet and invoice records;
- portal-user data synchronised to and from the operator’s Ministra portals;
- content the operator sends through the platform, such as transactional email bodies.
For that data the operator (and, one tier down, the reseller as their own controller or joint controller) decides why and how it is processed. We act only on documented instructions given through the platform and the Data Processing Agreement. If you are an end customer of an IPTV service billed through Billistra and you want your data accessed or erased, contact that provider first — they hold the relationship and the decision. If you cannot identify or reach them, write to privacy@billistra.com and we will route the request to the right tenant and follow up.
Section 3Data we collect as controller
Account and identity data
Company name, trading name, business address and country; the name, business email, telephone number, job title and preferred language of the staff who register and use accounts; role and permission assignments; salted and hashed passwords; multi-factor authentication settings; API key metadata (never the plain-text secret after issuance); session and device identifiers.
Billing and financial data
Plan, portal count and user-count tiers; subscription and renewal dates; invoices, credit notes and payment status; VAT or tax identification numbers; billing contacts and addresses; the last four digits, card brand and expiry of a payment card, plus the payment-method token held at our processor. We never see or store full card numbers, CVV codes or bank credentials — those are captured directly by Stripe or PayPal in a PCI-DSS-compliant environment.
Usage and telemetry
Pages and features used, actions taken in the console, portal and tenant counts, sync volumes, API call counts and error rates, performance timings, browser type and version, operating system, screen size, referring page, approximate location derived from IP address, and timestamps. We use this to operate the service, size infrastructure, meter plan limits and overage, and decide what to build next.
Security and audit data
IP addresses, authentication events and failures, permission changes, administrative actions, export events, anti-abuse signals, and the per-tier audit trail recording actor, target, timestamp and metadata for every operator action.
Support and communications
The content of your emails, support tickets, in-app messages and any attachments you send; call and meeting notes; onboarding and migration notes. If we record a demo or support call we tell you first and ask for consent.
Marketing data
Contact details you give us in forms, at events or through referrals; your subscription and consent status; and whether you opened or clicked a marketing email. We do not buy contact lists and we do not enrich your profile with data purchased from brokers.
We do not intentionally collect special-category data (health, biometrics, political or religious views, trade-union membership, sexual orientation) or government identity numbers. Please do not put such data into free-text fields, ticket attachments or customer notes.
Section 4Data we process for operators
When an operator or reseller runs their business on Billistra, the following categories of personal data about their customers pass through and are stored in the platform under their control:
| Category | Typical fields |
|---|---|
| Identity and contact | Name, email address, telephone number, postal or billing address, country, language, notes added by staff |
| Account and subscription | Customer ID, tenant and reseller assignment, package or plan, price, currency, start and renewal dates, trial and grace status, suspension or cancellation reasons |
| Portal and device | Ministra portal user ID, MAC or device identifiers, entitlements, connection status, activation and revocation events |
| Financial | Wallet balance and ledger entries, invoices, payment status, refunds and chargeback flags, recharge-PIN redemptions, commission and withdrawal records |
| Communications | Transactional emails sent (welcome, renewal, dunning, receipt, expiry and similar templates), delivery and bounce events, support interactions |
| Behavioural and technical | Storefront sign-ups and logins, IP address at signup or payment, fraud and anti-abuse signals, audit events |
We process this data only to provide the service, to keep it secure, to meter usage against plan limits, and where a documented instruction, a support request or a legal obligation requires it. We do not use operator or end-customer data to train machine-learning models, to build advertising profiles, or for any purpose of our own beyond aggregate, irreversibly anonymised service statistics.
Section 5Where the data comes from
- Directly from you — registration, forms, console input, imports, emails and calls.
- Automatically — cookies and similar technologies on our sites, server and application logs, and product telemetry.
- From your Ministra portals — bi-directional synchronisation of portal-user records through the Go sync agent, using credentials you supply.
- From your payment gateways — Stripe and PayPal return transaction, payout and dispute metadata to the tier that owns the account.
- From your upstream tier — a Sub-Reseller’s account data reaches us via the Reseller that created it, and a Reseller’s via the Owner.
- From public and business sources — company registries, your public website and business directories, used only to verify a prospective customer and prevent fraud.
Section 6Why we use it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating accounts, provisioning tenants and portals, delivering the platform | Contract — Art. 6(1)(b) |
| Metering usage, invoicing, collecting fees, applying overage, dunning | Contract — Art. 6(1)(b); legal obligation for tax records — Art. 6(1)(c) |
| Synchronising subscriber state with your Ministra portals | Contract — Art. 6(1)(b); processor instruction for end-customer data |
| Sending service, security and transactional notices | Contract — Art. 6(1)(b) |
| Support, troubleshooting, migration assistance | Contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| Securing the platform, preventing fraud and abuse, maintaining audit trails | Legitimate interests — Art. 6(1)(f); legal obligation — Art. 6(1)(c) |
| Improving and developing the product from aggregate usage patterns | Legitimate interests — Art. 6(1)(f) |
| Marketing to business contacts about products like the ones you use | Legitimate interests — Art. 6(1)(f); consent where the law requires it — Art. 6(1)(a) |
| Complying with tax, accounting, sanctions and law-enforcement obligations | Legal obligation — Art. 6(1)(c) |
| Establishing, exercising or defending legal claims | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded that the processing is necessary, proportionate and within your reasonable expectations for a B2B platform. You can object at any time — see Your rights — and we will stop unless we have compelling grounds that override your objection or need the data for legal claims. Where we rely on consent, you can withdraw it at any time without affecting processing already carried out.
Section 8Transactional and marketing email
Transactional email — invoices, renewal and expiry notices, dunning, password resets, security alerts, storefront receipts — is part of the service. You cannot unsubscribe from it while you hold an account, because it carries information you need. It is delivered through Resend, either from our platform sending domain or, on Enterprise, from the tenant’s own verified domain. Delivery, bounce and complaint events are recorded so deliverability problems can be diagnosed.
Marketing email — product news, release notes, occasional offers — goes only to business contacts, always carries a one-click unsubscribe, and stops immediately when you use it. Unsubscribing adds you to a suppression list, which we must keep so that we do not accidentally mail you again. Operators sending marketing to their own customers through the platform are responsible for their own consent, sender identification and unsubscribe obligations under the ePrivacy Directive, PECR, CAN-SPAM, CASL and equivalent laws.
Section 10Subprocessors
These third parties may process personal data on our behalf. Each is engaged under Article 28 GDPR terms with equivalent data-protection obligations to those we owe you.
| Provider | Purpose | Data involved | Region |
|---|---|---|---|
| Cloudflare | Website and application delivery, DNS, DDoS protection, WAF | IP address, request metadata, security telemetry | Global edge network (EU/US) |
| Stripe | Payment processing for Billistra subscription fees, and — under each operator’s own account — for that operator’s customer payments | Name, email, billing address, payment-method token, transaction records | EU / US |
| PayPal | Alternative payment gateway, connected per tier under the operator’s own merchant account | Name, email, transaction records | EU / US |
| Resend | Transactional email delivery (platform sending domain, or the tenant’s own sending domain on Enterprise) | Recipient email address, name, message content, delivery events | EU / US |
| Cloud infrastructure provider | Managed hosting, PostgreSQL databases, Redis, backups, object storage | All Customer Data stored in the platform, encrypted at rest | Region selected at provisioning (EU by default) |
| Google Fonts (fonts.googleapis.com) | Web font delivery on the billistra.com marketing site only | IP address, browser user-agent (as part of the font request) | Global |
| Error monitoring & log aggregation | Application error reporting, uptime and performance monitoring | Diagnostic events, user/tenant identifiers, IP address | EU / US |
Self-hosted deployments involve fewer of these: if you run Billistra in your own Docker environment, your infrastructure and database are yours, and only the services you actively connect apply.
To be notified before we add or replace a subprocessor, email privacy@billistra.com and ask to join the notification list. We give at least 30 days’ notice of a new subprocessor. If you have a reasonable, documented data-protection objection, tell us within that window and we will work to offer an alternative; if we cannot, you may terminate the affected service without penalty for the remainder of the term.
Section 11International transfers
Billistra is operated for a global customer base, so personal data may be transferred to and processed in countries other than your own, including the United States. Where data leaves the European Economic Area, the United Kingdom or Switzerland, we rely on one or more of:
- an adequacy decision by the European Commission or the UK government;
- the European Commission’s Standard Contractual Clauses (2021/914), with the UK International Data Transfer Addendum and the Swiss annex where relevant;
- the EU–US and UK–US Data Privacy Framework, where the recipient is certified under it;
- your explicit informed consent or contractual necessity, for the limited cases the GDPR permits.
We carry out transfer impact assessments for new subprocessors, and we apply supplementary measures — encryption in transit and at rest, access controls, minimisation and a policy of challenging unlawful requests. Managed environments are provisioned in the EU by default; if you require a specific hosting region for data-residency reasons, ask before onboarding and we will confirm what is available. Copies of the transfer mechanisms are available from privacy@billistra.com.
Section 12How long we keep data
We keep personal data only as long as it serves the purpose it was collected for, plus any period the law requires. Our default schedule:
| Record | Retention | Why |
|---|---|---|
| Account and user profile data | Life of the account, then 90 days | Contract performance; short tail for reactivation and dispute handling |
| Customer Data in a deleted tenant | 30-day grace window with undo, then a 365-day pseudonymized archive, then purge | Accident recovery, dispute resolution, forensic and audit obligations |
| Invoices, payments, wallet and commission ledgers | 7 years (or longer where local tax law requires) | Legal obligation — accounting, VAT and sales-tax records |
| Audit trail (operator actions) | 365 days online, then archived | Legitimate interest in security, accountability and dispute resolution |
| Transactional email delivery logs | 30 days | Deliverability troubleshooting and abuse prevention |
| Security, access and application logs | 90 days | Legitimate interest in detecting and investigating abuse |
| Encrypted backups | Rolling 35 days | Business continuity; deletions propagate as backups age out |
| Support tickets and correspondence | 3 years from last contact | Legitimate interest in service quality and claim defence |
| Marketing contact records | Until you unsubscribe, then a suppression-list entry only | Consent / legitimate interest; suppression is a legal obligation |
Operators may configure shorter retention for their own tenant data where the platform allows it, and may request a documented custom schedule under a Data Processing Agreement. Nothing in a shorter schedule overrides a statutory obligation to keep financial records, or a legal hold arising from actual or anticipated litigation, which suspends deletion for the records covered until the hold lifts.
Section 13Deletion and right to be forgotten
Deletion in a billing platform cannot mean “drop the row”: tax law requires the financial record to survive. Billistra resolves that tension with pseudonymisation rather than selective forgetting.
When a right-to-be-forgotten request is executed against a customer record:
- directly identifying fields — name, email, phone, address, free-text notes and similar — are pseudonymised, so the person can no longer be identified from the record;
- financial events — invoices, payments, wallet movements, commissions — are preserved on the archive substrate in pseudonymised form, because VAT, sales-tax and accounting law requires them;
- device entitlements are revoked through the Ministra sync agent;
- an audit row is written recording the actor, the subject and the actions taken, and a signed compliance report is produced as evidence for a regulator.
Deleting an entire tenant follows the same philosophy at a larger scale: a 30-day grace window with undo, then a 365-day pseudonymized archive, then final purge. Encrypted backups age out on their own rolling cycle, after which deleted data is unrecoverable from them too.
Where we act as processor, the operator triggers the workflow; we execute it and confirm completion. Where we act as controller, write to privacy@billistra.com and we will run it for you.
Section 14How we protect data
- In transit — TLS 1.2 or better everywhere, with HSTS on our domains.
- At rest — encrypted database and object storage volumes; encrypted backups.
- Credentials — passwords hashed with a modern memory-hard algorithm; API keys stored as hashes and shown once; portal credentials and gateway secrets held in encrypted storage.
- Access control — role-based permissions per tier, least privilege for staff, multi-factor authentication for administrative access, and access to production data only for named personnel with a logged operational reason.
- Isolation — tenant scoping enforced in the data layer, not the interface. See Section 15.
- Monitoring — centralised logging, anomaly and rate-limit alerting, dependency and vulnerability scanning, and a documented incident-response runbook.
- Resilience — automated encrypted backups with periodic restore testing.
- People — confidentiality obligations for staff and contractors, and access removal on the day an engagement ends.
No system is perfectly secure, and we do not claim otherwise. Your part matters: use strong unique passwords, enable multi-factor authentication, rotate API keys, review who holds administrative roles, and remove people the day they leave.
Section 15Tenant isolation between tiers
Isolation is a privacy control here, not just a product feature. Every row carries a tenant identifier, and foreign-key constraints in PostgreSQL make cross-tier reads impossible at the data layer. API queries are rewritten with the caller’s tenant scope before they reach the database, so a Reseller’s call cannot return another Reseller’s customers, pricing or payment data — including through bulk export, reporting or the API. The audit trail is scoped the same way: an Owner sees the superset of their network, a Reseller sees only their own actions.
The practical consequence for privacy: a data-protection incident inside one reseller’s branch does not expose another’s customers, and one reseller cannot lawfully or technically obtain another’s customer list through the platform.
Section 16Automated decisions and anti-abuse
The platform includes an anti-abuse engine and configurable event rules that can act automatically — flagging suspicious signups, rate-limiting requests, blocking a card-testing pattern, or suspending a session. These protect the platform and its users, and they are configured by operators for their own tenants.
We do not carry out automated decision-making that produces legal effects or similarly significantly affects an individual within the meaning of Article 22 GDPR without a human in the loop. Where an automated control restricts an account, a person reviews it on request: write to privacy@billistra.com to contest a decision, state your point of view and obtain human review. We do not use personal data for profiling for marketing purposes.
Section 17Your rights
Subject to the conditions in applicable law, you have the right to:
- Be informed about how your data is used — this policy.
- Access a copy of the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase data where there is no overriding basis to keep it.
- Restrict processing while a dispute about accuracy or basis is resolved.
- Port the data you provided to us in a structured, machine-readable format.
- Object to processing based on legitimate interests, and to direct marketing at any time and absolutely.
- Withdraw consent where consent is the basis, without affecting prior processing.
- Complain to a supervisory authority — see Section 23.
How to exercise them
Email privacy@billistra.com from the address on file, or use the export and deletion tools inside the application. We respond within one month, extendable by two further months for complex or numerous requests, in which case we tell you why within the first month. There is no charge unless a request is manifestly unfounded or excessive. We may ask for information to verify your identity — we will not use it for anything else. You may use an authorised agent if you give them written authority we can verify.
If your request concerns data we hold as a processor for an operator, we will tell you promptly and forward it to that operator, who decides the outcome. That is a legal constraint, not an evasion: acting unilaterally on their data would breach our obligations to them.
Section 18US state privacy rights
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas or another state with comprehensive privacy legislation, you may have the right to know what personal information we collect and disclose, to access and delete it, to correct inaccuracies, to opt out of sale, sharing or targeted advertising, and not to be discriminated against for exercising any of these rights.
In the twelve months before this policy’s date we collected the categories described in Section 3 — identifiers, commercial information, internet activity, professional information and approximate geolocation — for the business purposes in Section 6, and disclosed them for business purposes only to the subprocessors in Section 10. We did not sell personal information, and did not share it for cross-context behavioural advertising. We do not knowingly process the personal information of anyone under 16 for those purposes, and there is therefore nothing to opt into or out of.
Submit a request to privacy@billistra.com. We acknowledge within 10 business days and respond within 45 days, extendable once by a further 45 days with notice. If we deny a request you may appeal by replying to our decision with the word “appeal”; we will respond to the appeal within 45 days and, if we still decline, tell you how to complain to your state attorney general. Where we act as a service provider or processor for an operator, we handle requests as described in Section 17.
Section 19Children
Billistra is a business platform not directed at children, and we do not knowingly collect personal data from anyone under 16. Accounts require the account holder to be an adult acting in a business capacity. Operators are responsible for the age-appropriateness of their own services and for any age-verification obligations that apply to the content they sell. If you believe a child’s data has reached us, write to privacy@billistra.com and we will delete it promptly.
Section 20Breach notification
We maintain an incident-response process covering detection, containment, assessment, notification and post-incident review. If a personal-data breach occurs, we notify the competent supervisory authority within 72 hours of becoming aware of it where the breach is likely to result in a risk to individuals, and we inform affected customers without undue delay with what we know: what happened, which data categories were involved, the likely consequences, the measures taken, and what you should do. Where we act as processor, we notify the affected operator without undue delay so they can meet their own notification duties, and we support them with the information they need.
Section 21Data processing agreement
Customers who need a Data Processing Agreement under Article 28 GDPR can request one at privacy@billistra.com. Our standard DPA covers the subject matter, duration, nature and purpose of processing; the categories of data and data subjects; our obligations of confidentiality and security; subprocessor terms and change notification; assistance with data-subject requests, breach notification and impact assessments; deletion or return of data at the end of the service; audit and information rights; and the Standard Contractual Clauses for international transfers. Once signed, the DPA forms part of your agreement with us and prevails over this policy for the data it covers.
Section 22Changes to this policy
We update this policy when our practices, subprocessors or legal obligations change. The version and last-updated date at the top of the page always reflect the current text. For material changes — a new purpose, a new category of recipient, a materially different retention period — we give at least 30 days’ notice by email to account administrators or by prominent in-app notice before the change takes effect, and we ask for fresh consent where the law requires it. We keep prior versions and provide them on request.
Section 23Contact and complaints
For anything in this policy — questions, requests, or a concern about how we handled your data — write to privacy@billistra.com. General enquiries can go to contact@billistra.com, and our full corporate details are on the Legal Notice page.
Please raise concerns with us first — we would rather fix a problem than have you discover it through a regulator. You always retain the right to complain to a data-protection supervisory authority, whether in the country where you live, where you work, or where the alleged infringement took place.
Questions about this document? Write to legal@billistra.com. For anything else, contact@billistra.com reaches us just as well.