Data handling
How we look after other people's data.
Our work can involve researching, checking, organising and preparing professional business information on behalf of our clients. We keep that work within a clearly defined project scope, with controlled access, documented working practices and human oversight.
Our position
Four things that shape everything we do with data.
Professional business information
Our research services focus on professional business information such as names, roles, employers and business contact details. We do not build consumer marketing lists or intentionally research private information about individuals.
Research from appropriate business sources
Where research forms part of the agreed service, information may be gathered from appropriate business and publicly available sources and checked by our researchers before delivery.
Working to your agreed scope
Where we process data on behalf of a client, we work to documented instructions and use the information only for the agreed service. Data is returned or deleted in accordance with the agreed project terms.
Named people, not an anonymous pool
You know who is working on your project. Access is limited to the people assigned to it, and everyone working with client data is subject to confidentiality obligations.
In practice
The controls we apply on every project.
Access and transfer
- Access to client data is restricted to the people assigned to the project
- Client information is handled through agreed, access controlled working environments
- Transfer methods are chosen to suit the requirements of the project
Working practices
- Work is carried out within the systems and environments agreed with you at the start of the project
- Where the project involves data cleansing or transformation, changes can be tracked and reviewed as part of the agreed workflow
- Where clients have specific security requirements, we can work within their approved systems, tools or controlled environments
Retention and deletion
- Client data is retained only for the agreed project requirements
- Return, retention and deletion arrangements are agreed with the client as part of the project terms
Paperwork we can complete
- Data Processing Agreement, where required
- Non Disclosure Agreement, ours or yours
- Security and supplier questionnaires as part of your onboarding
For legal and procurement
What clients often want to know before we start.
Straight answers, written the way we would give them on a call. Anything specific to your engagement is agreed and documented in the contract.
How do you handle an opt out or data rights request?
If a request relates to information being processed as part of an active client project, we handle it in accordance with the agreed project process and, where appropriate, refer it promptly to the client. We can also provide reasonable information about the sourcing or processing work we have carried out where required.
Where is the work carried out?
Working environments and access arrangements are agreed according to the requirements of each project. Where required, work can be carried out within client controlled systems and environments.
What happens if something goes wrong?
We maintain a defined process for identifying, escalating and responding to issues involving client data. Where an incident affects client data, we will notify the client in accordance with the applicable contractual and legal requirements and provide the information reasonably required to support their response.
Need something signed, completed or confirmed before we start?
Send us your Data Processing Agreement, Non Disclosure Agreement or security questionnaire and we will work through it with you. If you would rather ask a question first, our team can direct it to the right person.
This page describes our general working practices and does not replace the contractual, security or data protection terms agreed for a specific client engagement. See also who we are.
