Rangeholder

Privacy Policy

Rangeholder AB

Last updated: 21 August 2026 · Version 1.0

1. Who we are and what this policy covers

Rangeholder AB (“Rangeholder”, “we”, “us”) provides web software that keeps a list with one row per phone number a customer owns. The software combines the customer’s own records into that list, checks each number against published numbering data, and puts a status on every row, with the rule or the carrier’s written answer behind it. Under a letter of authority the customer signs, it also drafts written requests to providers, sends each one only after the customer’s own named porting lead approves it in the product, follows up on a fixed schedule and posts every reply to its row. No one at Rangeholder writes to a provider on a customer’s behalf. We are not a phone provider. We hold no numbers, carry no calls, never move a number ourselves, and can never be the provider a number moves to. We run no part of a contact center.

Registered at Första Långgatan 30, 413 27 Göteborg, Sweden.

We handle personal data in two different situations, and different rules apply to each:

Whose dataOur roleWhat applies
Part APeople who visit this website, ask about the service or write to usController: we decide why and how the data is usedThis policy
Part BThe numbers you load, the call records you supply, the requests sent to your providers in your name and their replies, and the user accounts you nameSet out in B.1, because it depends on the dataThis policy and the data processing agreement we sign with each customer

If the data processing agreement (“DPA”) and this policy ever disagree about Part B, the DPA wins.

2. Part A: this website and our contact with you

This part covers the personal data we collect for our own purposes: running this website, answering requests, and staying in touch with people who are or might become customers.

A.1 What we collect

What you give us. When you send the form on this site, we collect what you type into it, such as your name, email address, phone number or company, and the fact that you agreed to be contacted. If you email or talk to us, we keep that correspondence and any contact details in it.

What is collected automatically. Our web server records the IP address a request came from, the browser used, the pages requested, the page you came from and the time. These logs exist to keep the site running and secure.

We don’t ask for sensitive data (the “special categories” in Article 9 GDPR) through this website, so please don’t send any through the form.

A.2 Why we use it, and what allows us to

WhyWhatLegal basis (GDPR Art. 6)
Answering your request and working out whether the service fitsWhat you sent in the form, our correspondenceArt. 6(1)(b): steps you asked for before a contract
Looking after customers, billing and supportContact details, correspondenceArt. 6(1)(b): carrying out a contract
Keeping the site running, secure and free of abuseServer logsArt. 6(1)(f): our legitimate interest in running a secure service
Contacting you about the serviceEmail address, companyArt. 6(1)(f): our legitimate interest in business-to-business marketing. You can object at any time
Meeting tax, accounting and legal dutiesBilling and contract recordsArt. 6(1)(c): a legal obligation

Where we rely on legitimate interest, we have weighed that interest against your rights, and you can ask to see the assessment.

A.3 How long we keep it

A.4 Your rights

If you are in the EEA or the UK, you can ask to see your data, correct it, have it deleted, limit or object to how we use it, get a copy you can take elsewhere, and withdraw consent where we rely on it. Write to [email protected] and we will answer within one month.

You can also complain to a data protection authority. If you are in the EEA, that can be the authority where you live or work.

3. Part B: data inside the service

Most of what this service holds is data about your business, not about people. Two parts are different. The first is the call records. A call record says who called your company, when, from what number and for how long. That is personal data about your callers, even though they will never hear of us. You are the controller of it. We hold it as your processor, on your written instruction, and use it only to build a usage profile for each number. We don’t need or want the call content, the recording, the transcript or the agent’s identity. The second is the correspondence. The software writes to your providers in your name, under a letter of authority you sign and only after your porting lead approves each request, and those emails and the replies contain the names and contact details of your staff and theirs. We keep them because a status that came from a carrier’s written answer is only worth something if the answer can still be read years later.

B.1 What we handle, and in what role

Account data, meaning your work email, your company, your billing contact and the users you authorize, we hold as a controller. The numbers, the call records, the combined list, the statuses, the carrier correspondence, the letters of authority and the locked versions we process as your processor, on your instruction, for as long as the subscription runs.

We hold no data about what you spend on telecoms, and we don’t want it. If your provider’s bill has charges as well as numbers, the charge columns are dropped on arrival, and only the number and its description are kept.

Requests go out in your name, under the letter you sign, only to the providers you name in it, and only after your porting lead approves each one in the product. No request can agree anything, accept terms, place an order or change a contract for you, and the letter of authority says so in one sentence.

Please don’t send us call recordings, transcripts or customer records. We have no legal basis for them and nowhere in the product to put them.

B.2 What we do with it

Everything runs in one region. Loading, combining, checking against numbering data, both models, the review queue, the list, the correspondence and the locked versions all run on cloud infrastructure in Stockholm. We have no second region, and nothing is processed anywhere else.

No outside AI service, at any point. Both models run on GPU instances we control in Stockholm. No call record, number, label, usage profile or piece of correspondence is sent to a hosted model API. There is no model vendor on our subprocessor list, because none is involved.

Two sets of training data, handled differently. The label set holds a number’s text description plus a numeric usage profile, matched to the status a person chose. It contains no calling numbers, no called numbers and no call records, and it is shared across the service. The matching set holds pairs of descriptions of one of your numbers, with a person’s decision on whether they are the same line. It is kept separate for your account, never pooled, and never used to train anything that touches another customer’s list.

A locked version is never edited. Once you lock a version as your cutover baseline, its rows, statuses, sources, correspondence references and review history can’t be changed. A later change creates a new version with a reason and an author. The older version stays readable and is marked as replaced, because a go-live date was set against it.

Your list is never compared with anyone else’s. We check numbers against published numbering data and your own files. We publish no benchmark, coverage figure or total drawn from any customer’s numbers. To do that we would have to build something we have deliberately not built.

B.3 AI models: where they run and what they learn from

Where models run. Every model runs in Stockholm, on cloud GPU instances we control. A fine-tuned classifier suggests a status for a number from its text label plus a numeric profile of how it was used over 90 days. An embedding model suggests whether two descriptions in two of your files refer to the same line. No third-party model service is used at any point. No call record, calling or called number, label, usage profile or piece of carrier correspondence is sent to a hosted model API. There is no model vendor on our subprocessor list, because none is involved. We have no second region.

Training. We don’t train on your data, and the exception is narrow enough to state exactly. Two sets of training data build up from your users’ decisions, and they are handled differently. The label set holds a number’s text description together with a numeric usage profile: inbound volume, spread across the hours of the day, count of distinct calling numbers, average call length, answer rate and the share of outbound-only use, matched to the status a person confirmed. It holds no calling numbers, called numbers, call records or correspondence, and it is shared across the service. The matching set holds pairs of descriptions of one of your numbers, with a person’s decision on whether they are the same line. That is specific to your numbers, so it is kept separate for your account, never pooled across customers, and never used to train, tune or test anything that touches another customer’s list. Your call records, carrier correspondence, letters of authority and locked versions are used to train nothing at all.

Where a person decides. The model suggests and a person decides, in both places a model runs. A suggested status is applied only when its score clears a fixed threshold and one of your users confirms it in the review queue, row by row. Below the threshold nothing is guessed. The row stays in the queue marked unclear, and a list can’t be locked as a cutover baseline while unclear rows remain, with no override for you or for us. The column that says whether a number will move is stricter still, and no model can write to it under any circumstances. A row says a number will move only from published numbering data, with the rule named, or from a carrier’s written answer stored word for word. Every written request to a provider is sent only after your porting lead approves it, and no model writes one. No automated decision with legal effects for any individual is made anywhere in this service. Rangeholder does not move a number, carry a call, route a call, set your cutover date or decide anything about any person named in a call record.

B.4 Where the data is kept

All storage and processing is on cloud infrastructure in Stockholm. Source files, call records, the list and its versions, the correspondence, both training sets and the locked versions are kept in object storage in Stockholm and nowhere else.

No model runs on a third party’s service. The label classifier and the matching model run on cloud GPU instances we control in Stockholm.

Correspondence leaves the region when it is sent, because a written request to the provider you are leaving goes to that provider, wherever it is. That is the instruction you give in the letter of authority, and again each time your porting lead approves a request. Our copy and all processing stay in Stockholm.

Nobody at Rangeholder reads a customer’s list, call records or correspondence in the normal running of the service. Support access is opened only when a customer’s admin grants it for a named support ticket, is recorded in the same uneditable log as everything else, and is used only from inside the EU.

The suppliers that handle data in the service are named on our subprocessor list, which comes with the data processing agreement and which we send to anyone who asks: write to [email protected].

B.5 How long we keep it, and what deleting can’t remove

Source files, the combined list, statuses and their sources: for the life of the subscription and 24 months after, because a cutover gets argued about long after it happened. Deleted earlier on written instruction.

Call records: the rolling 90-day window only, plus the usage profile per number. Records outside the window are deleted, and all call records are deleted within 30 days of the subscription ending.

Letters of authority and carrier correspondence: for the life of the subscription plus 24 months, to match the statuses they support.

Locked versions and the activity log: for the life of the subscription plus 24 months, unedited.

Matching decisions kept for your account: deleted with the account, within 30 days of the subscription ending.

The shared label set: kept indefinitely. It holds descriptions and numeric usage profiles matched to a status, with no calling numbers and no call records.

Account and billing records: seven years after the subscription ends, as Swedish bookkeeping rules require.

Access and delivery logs, without content: 90 days.

B.6 Requests from people whose data is in the service

The people in a call record are your callers, not our data subjects. We have no way to reach them and no plan to get one. If someone writes to us about a call record, we won’t answer on the substance. We will tell them plainly that the company they called is the controller, name you, and forward the request to your contact within five working days. On your written instruction we will find, export or delete records about a named number or person. If that changes a row after a version was locked, it creates a new version, never a silent edit. About your own users and named contacts we hold work email, name and their entries in the activity log. Write to [email protected] and we will answer within 30 days.

For everyone

4. Moving data between countries

Rangeholder AB is a company in Sweden, inside the EEA. Section B.4 says where the data in the service is kept. If any personal data we control ever has to leave the EEA, for example because a supplier named on our subprocessor list handles it elsewhere, it is protected by the European Commission’s Standard Contractual Clauses or another safeguard the GDPR accepts. You can ask us for a copy.

5. Security

We protect data in line with the risk. That includes encryption in transit and at rest, access limited to the people and systems that need it, each customer’s data kept separate from every other’s, and a log of every access to production systems.

If a personal data breach affects you, we tell you without undue delay, and at the latest within 36 hours of finding out, with the information you need to meet your own reporting duties.

6. Children

The service is sold to businesses and is not meant for children. We don’t knowingly collect personal data from anyone under 16.

7. Changes to this policy

We may update this policy. If a change matters, we email customers at least 30 days before it takes effect. The version number and date at the top of this page change every time.

8. Contact

Privacy questions and anything else: [email protected]
By post: Rangeholder AB, Första Långgatan 30, 413 27 Göteborg, Sweden

← Back

Your request has been received.

Expect a message from Rangeholder. It goes to the address you gave.