Your customers' data, and what we do with it.
Written for the person who has to sign this off. If a question is not answered here, ask it and we will answer in writing.
Where data lives
- Customer records stay in your systems wherever possible. We work inside your helpdesk and CRM rather than copying data into ours.
- Where we must hold data — QA samples, reporting extracts — it sits in a named region agreed in the contract. Data residency and processing can be supported across MENA, Asia and the United States, depending on the engagement and the infrastructure selected. Your engagement names one; it does not mean your data sits in all three.
- Data is retained only for the period stated in the data processing agreement, then deleted. Deletion is confirmed to you in writing.
- You can export everything we hold on your account at any time, in a machine-readable format, without giving a reason.
Who can see it
- Access is granted per account, not per company. An agent on another client's account cannot see yours.
- Access is role-based and reviewed when anyone joins, moves or leaves. Removal on departure is same-day.
- Every agent signs a confidentiality undertaking before their first shift, and background checks are run to the standard set out in your contract.
- Agent workstations are managed: full-disk encryption, screen lock, no removable media, no personal cloud storage.
- Actions on customer records are logged and the log is available to you.
Payment data
Our standard scope excludes cardholder data entirely. Agents do not take card numbers by phone, chat or message, and are trained to stop a customer who starts reading one out. If your process requires payment handling, it is a separate scoping conversation with its own controls — not something we absorb quietly into a support contract.
Regulatory position
We process personal data as your processor, under your instructions, and never for our own purposes. Because our clients sit across several MENA jurisdictions, we work to the strictest standard that applies to your engagement rather than the local minimum: the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), the Saudi Personal Data Protection Law, and the GDPR where your customers are in scope. Your data processing agreement names the regimes that govern your engagement specifically, along with purposes, sub-processors, retention, international transfer basis and breach notification timelines.
Before you sign
- Mutual NDA available on request, signed before any data is shared
- Data processing agreement issued with every proposal, not after
- Security questionnaire completed for your procurement team at no charge
- Sub-processor list supplied in full, with notice of any change
- Breach notification to you within 24 hours of us becoming aware
- Exit terms stated up front: data returned, then deleted, within 30 days
Send us your security questionnaire.
We will complete it and return it before the commercial conversation, not after. If we cannot meet a requirement we will tell you which one.
English and Spanish on every account
Extended 24/7 coverage available
Service targets written into the contract