Data processing
Last updated 11 September 2026
This page is for clients — the businesses whose customer data our teams handle. If you are a visitor to this website, our privacy notice is the page you want.
In one paragraph
You stay in charge of your customers' data. We only touch it to do the job you have asked us to do. Because our team works from Pakistan, the arrangement needs a written contract and a transfer safeguard — both of which we put in place before your first live call.
1. Who is who
Under UK data protection law the roles matter:
| Role | Who | What it means |
|---|---|---|
| Controller | You, our client | You decide why and how your customers' data is used. It is your data and your relationship with those customers. |
| Processor | Talkify Solutions | We act only on your documented instructions. We do not decide what the data is used for, and we never use it for our own purposes. |
| Data subjects | Your customers | The people whose names, numbers, addresses and order details we handle on your behalf. |
2. What we typically process
It depends entirely on the service, and we keep it to the minimum the job needs:
- Order taking: name, phone number, delivery address, order contents, payment method (we do not store card numbers).
- Dispatch: name, phone number, pickup and destination addresses, timings.
- Telemarketing: business contact details from lists you supply and instruct us to call.
- Support: whatever is in the ticket or on the account you give us access to.
We do not ask for, and do not want, special category data — health, ethnicity, beliefs and so on. If your workflow would involve it, raise it before we start.
3. The written agreement
Article 28 of the UK GDPR requires a contract between controller and processor. We sign one with every client before any live work, covering the subject matter and duration, the nature and purpose of the processing, the types of data and categories of data subject, and your rights and our obligations. It commits us to:
- process only on your documented instructions;
- keep our staff under a duty of confidence;
- apply appropriate technical and organisational security measures;
- not engage a sub-processor without your authorisation;
- help you respond to data subject requests and to security incidents;
- delete or return the data at the end of the contract; and
- make available the information you need to demonstrate compliance.
4. International transfer — the honest bit
Our floor is in Faisalabad, Pakistan. Pakistan is not covered by UK adequacy regulations, which means a transfer of personal data from the UK to us needs a safeguard under Article 46. We use the UK's International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses where a client prefers that route.
We complete that paperwork with you as part of onboarding. We also support you in carrying out a transfer risk assessment if your policies require one. What we will not do is wave the question away — it is the single most common reason a UK business hesitates about outsourcing, and it deserves a straight answer.
5. Security measures
- Least privilege. Agents are given access only to the systems and records the job requires, with the permissions you grant. We do not take bulk copies of your database.
- Controlled floor. No personal phones or removable storage at operating positions; screens locked when unattended.
- Named accounts. Individual logins, never shared credentials, so activity is attributable.
- Confidentiality. Every agent signs an agreement covering your data and your commercial information.
- Call recording. Recordings are access-controlled and retained for the period agreed with you.
- Leavers. Access is revoked when someone comes off your account or leaves.
We do not currently hold ISO 27001 or an equivalent certification, and we do not claim to. If certification is a requirement for your business, tell us early and we will be straight with you about whether we are a fit.
6. Outbound calling on your behalf
Where we make outbound sales or marketing calls for you — energy contracts included — you remain the regulated party and the instructing controller. Our commitments are practical:
- we call only the data you supply or instruct us to use;
- we screen against the Telephone Preference Service and the Corporate TPS, and against any suppression or do-not-call list you give us;
- we use only the script you have signed off, and we do not deviate from it;
- agents never claim to be the customer's existing supplier, or to be calling from one;
- where your process requires a commission or fee disclosure, it is read as written;
- every call is recorded, retained for the period you set, and available for you to audit.
UK direct marketing rules — including PECR and, for energy, Ofgem's microbusiness requirements — apply to you as the instructing party. Tell us what your framework requires and we build it into the script and the quality scoring rather than leaving it to the agent.
7. Sub-processors
Where we rely on a third party — for example a telephony or ticketing platform — we will name them to you and will not add a new one without telling you first, in line with the agreement.
8. Data subject requests and incidents
If one of your customers contacts us directly with a request to access or delete their data, we will not action it ourselves. We pass it to you promptly, because it is your decision as controller. If we become aware of a personal data breach we will notify you without undue delay and give you what you need for your own reporting obligations.
9. Ending the contract
When we stop working together, we return or delete the personal data we hold, at your choice, and confirm in writing once it is done — except anything we are required to keep by law.
10. This is not legal advice
This page explains how we work, in plain English. It is not legal advice, and your own obligations as controller are yours to satisfy. We are happy to supply our agreement and transfer documentation for your adviser to review before you commit to anything.
Questions about any of this: info@talkifysolutions.com.