1. Purpose

These Data Processing & Data Protection Terms (“DPT”) establish the framework under which Oxyvin processes personal information provided by or on behalf of a client in connection with Oxyvin’s services. These terms should be read together with the applicable MSA, SOW or Order Form.

2. Roles of the Parties

Depending on the processing activity, the client and Oxyvin may have different responsibilities under applicable data-protection law. Where the client determines the purpose and essential means of processing and Oxyvin processes information to deliver the client’s campaign, Oxyvin will process such information according to the client’s documented instructions and applicable law. The parties will cooperate to determine their respective responsibilities for specific processing activities.

3. Processing Instructions

Oxyvin will:

  • Process client personal information only for agreed business purposes.
  • Follow documented client instructions where applicable.
  • Restrict access to authorised personnel.
  • Maintain appropriate confidentiality obligations.
  • Notify the client of material security incidents affecting client data, subject to applicable law.
  • Provide reasonable cooperation regarding applicable data-protection obligations.

4. Data Categories

Depending on the engagement, information may include names, telephone numbers, email addresses, lead information, customer identifiers, call history, call recordings, appointment or enquiry information, campaign responses and other information specifically supplied for the engagement. Clients should not provide sensitive or highly regulated information unless the processing has been expressly agreed and appropriate safeguards are in place.

5. Purpose Limitation

Oxyvin will not intentionally use client personal information for unrelated purposes. Client information may be used for campaign execution, customer contact, lead qualification, appointment scheduling, customer support, reporting, quality monitoring, service improvement, security and fraud prevention, and legal and contractual compliance.

6. Security Measures

Depending on the operating model and risk involved, Oxyvin may use role-based access controls, authentication mechanisms, access restrictions, data masking, secure client systems, endpoint security controls, monitoring and logging, confidentiality agreements, controlled access to call recordings, and operational security procedures. The specific controls applicable to an engagement may be documented in the MSA, SOW or security questionnaire.

7. Client-Controlled Operating Model

Where the client provides access to its CRM, dialer, contact-center platform or other systems:

  • The client may establish its own access controls.
  • The client may apply its own security and DLP policies.
  • Oxyvin personnel will use those systems only for authorised business activities.
  • The client remains responsible for the configuration and security of systems it controls.

8. Oxyvin-Managed Operating Model

Where Oxyvin manages the operational environment:

  • Oxyvin will apply reasonable security controls appropriate to the services.
  • Access will be restricted to authorised personnel.
  • Appropriate data masking may be applied.
  • Client data will be handled according to contractual instructions.
  • Security and operational controls may be reviewed periodically.

9. Subprocessors and Service Providers

Oxyvin may use technology providers and other service providers necessary to deliver its services. Where required by the applicable agreement or law, Oxyvin will maintain appropriate contractual and security controls over such providers.

10. Data Retention and Deletion

At the end of a campaign or engagement, Oxyvin will retain or delete client information according to the client’s documented instructions, the applicable MSA/SOW, legal or regulatory retention requirements, and legitimate requirements for dispute resolution, security or accounting.

11. Security Incidents

Oxyvin will maintain procedures for identifying and responding to suspected security incidents. Where a confirmed incident materially affects client personal information, Oxyvin will notify the client within the timeframe required by applicable law or the applicable agreement and provide reasonably available information concerning the incident.

12. Data Subject Requests

Where an individual makes a request relating to personal information processed by Oxyvin on behalf of a client, Oxyvin may refer the request to the client where appropriate. Oxyvin will provide reasonable assistance to the client where required by the applicable agreement and law.

13. Compliance

Oxyvin will maintain reasonable measures designed to support compliance with applicable data-protection requirements, including requirements applicable to the services and jurisdictions involved. The parties will cooperate where additional contractual, technical or organisational measures are required.

Questions about this policy?

Reach out to our team and we’ll be glad to help.

Talk to Oxyvin