Security & Compliance

How we handle your data
stated plainly, no badge-collecting

What we actually do about access control, GDPR, US outbound compliance, vetting, recordings, and incidents — written for the ops director who has to sign off on us.

This page exists for the person whose job is to be sceptical of outsourcing vendors. It describes our current operating practice — not aspirations, not certifications we don't hold. Where a bigger BPO would show you a badge, we show you the actual mechanism, and you can verify any of it on the scope call and get it in writing.

The honest headline: we are not SOC 2 certified and we are not ISO 27001 certified. Here is exactly what we do instead — described section by section below. If your procurement process strictly requires a certified vendor, we are not your vendor yet, and we would rather say that here than after your security review.

Data handling and access control

The core of our security model is architectural: our agents work inside your systems, not ours. Calls are logged in your CRM, appointments booked in your calendar, dispositions recorded in your dialler. We do not maintain a parallel copy of your customer database, and our working practice is no local exports — agents do not download lead lists or customer records to local machines.

The practical consequence: if we parted ways tomorrow, your data would already be sitting in your systems, because that is where it lived all along.

GDPR alignment (UK and EU clients)

For UK and EU campaigns we operate as a processor acting on your documented instructions — the lawful basis for the calling itself is established by you as controller, and our agents work within the scripts, lists, and purposes you define. A data processing agreement (DPA) is available on request and we will review yours if you prefer your own paper. Because work happens inside your UK/EU-hosted systems, the primary data residency remains with your stack; we will walk through the UK–EU–Egypt data-flow picture for your specific toolchain on the scope call, honestly, including the parts that depend on your telephony provider rather than on us.

US outbound compliance

For US cold calling and outbound campaigns, our process commitments are:

These are process commitments, not legal guarantees, and nothing on this page is legal advice. Telemarketing law is fact-specific — your own counsel should confirm your campaign's compliance posture, and we will implement what they specify.

Agent vetting and NDAs

Every agent signs a confidentiality agreement (NDA) covering client data before touching a campaign, alongside their employment contract. Hiring includes identity verification, reference checks, and an English-proficiency and role assessment; agents work from our supervised environment rather than as anonymous freelancers, which means a team leader is physically present for coaching and oversight.

Call recording and retention

Calls are recorded through the dialler or telephony platform used for your campaign, and recordings are available to you — QA scoring is done against those recordings and you can audit any call we score. Retention follows your instruction: recordings are kept for the period you specify (or your platform's configured default when the telephony stack is yours) and deleted or handed over at campaign end as you direct.

Incident response

We are a founder-led company and escalation reflects that: the named incident contact is our founder, Mohamed Hanafy, and any suspected security incident affecting your data triggers prompt notification to you with what we know, what we've done, and what we recommend — no waiting for a scheduled review to disclose. Small enough that the person accountable answers the phone; that is the trade we offer against a big BPO's ticketing queue.

Subprocessors

Our subprocessor footprint is deliberately small because we work inside your stack. Telephony and dialler platforms are typically your vendors, chosen per campaign from your existing stack — meaning that data flow is one you already govern. Where we supply a component (for example a dialler on an outbound campaign), we name it during scoping so you can assess it before go-live, and we don't swap it without telling you.

Frequently asked questions

Are you SOC 2 or ISO 27001 certified?

No — we hold neither certification today, and we would rather tell you that in plain text than imply otherwise, so this page describes the actual controls we run instead: least-privilege access inside your systems, no local exports, NDAs for every agent, recordings you can audit, and founder-level incident escalation. If certification is a hard requirement, we will tell you on the scope call rather than waste your review cycle.

Where does our customer data actually live?

In your systems — agents log into your CRM, dialler, and booking tools and work there, so records are created and updated in the platforms you already control, under accounts you can see and revoke. We do not keep a parallel database of your customers, and our working practice is no local exports of lists or records to agent machines.

Will you sign a DPA or our security addendum?

Yes — a data processing agreement is available on request for UK and EU clients, and we will review and work from your own DPA or security addendum if your legal team prefers their paper. Specific commitments — retention periods, access rules, notification terms — are agreed in writing during scoping, before any agent touches your systems.

How do you handle US calling compliance like DNC and TCPA?

Outbound lists are scrubbed against the National DNC Registry and your suppression list before dialling, scripts are TCPA-aware with immediate opt-out handling, calling windows follow federal and state rules, and recording disclosures follow two-party-consent handling for the states involved. These are process commitments, not legal guarantees — your counsel sets the compliance bar and we implement it.

What happens if something goes wrong?

Any suspected incident affecting your data goes straight to our founder as the named incident contact, and you get prompt notification with the facts as we know them, the containment steps taken, and our recommendation — not a disclosure held for a monthly report. Because access lives in your systems, you can also revoke it yourself at any moment.

Questions? Ask on the scope call — you'll get answers in writing.