Data and compliance
What we actually do with your files
When you outsource, you hand personal data to a third party. Here is concretely how we handle it, rather than a compliance statement with nothing in it.

Our status: processor
Under the GDPR you remain the controller and we are the processor. We act only on your documented instructions, for the purpose you have defined, and never on our own account. This is set out in a data processing agreement attached to our commercial contract.
Data subject rights
If a data subject exercises their rights with us, we do not answer on your behalf: we pass the request to you and help you answer within the deadline. Access, rectification, erasure, restriction, portability and objection all go through you.
Our commitments
Documented instructions
We process only what you ask us to process. Any change of purpose goes through a written amendment.
Staff confidentiality
Every agent signs a named confidentiality undertaking on hiring. It covers their employment and survives their departure.
Controlled physical access
Production areas are closed. Personal phones, cameras and removable media do not go in.
Minimal system access
Each agent only reaches the records for their own campaign, through a named account. Rights are revoked on the day they leave.
No local copies
We work inside your tools or in environments you approve. Your databases are not duplicated onto workstations.
Return and deletion
At the end of the contract, data is returned and then deleted, with a deletion certificate if you ask for one.
Breach notification
Any data breach is reported to you without undue delay, with what you need for your own notification duties.
Sub processing
We do not bring in an additional processor without your prior written authorisation.
The point that matters: transfers outside the European Union
Madagascar and Mauritius do not benefit from a European Commission adequacy decision. Any transfer of data from the Union to our floors therefore has to be framed. We do this through the Commission's standard contractual clauses, backed by a transfer impact assessment and by the technical measures described above. We raise it during scoping, because it determines whether your own processing is compliant.
Do you have a security questionnaire or a data processing agreement template for us to complete? Send it over, we handle it during the scoping phase.
Let's talk about your volume
Describe your need in three lines. We come back with sizing and a price range, with no commitment.
