Page guide

On this page

What this page is, and what it is not

This describes the controls we apply to personal data in delivering customer support. It is written to be checkable rather than reassuring, because a security page full of adjectives helps nobody.

We hold no information security certification and this page claims none. RH International Ltd. is registered with the Information Commissioner's Office under reference ZB879055 - a register entry, not a certification or an assessment of our practices, and we do not present it as one. We do not display Cyber Essentials or any similar mark. If your procurement requires a specific certification, tell us early and we will say plainly whether we meet it rather than discovering it at the final stage.

What we will do is walk your security team or data protection officer through the detail below and answer specific questions with specific answers.

Who controls the data

This determines almost everything else, so it comes first.

When we deliver support for you, you are the data controller and we are your processor. You decide what data is collected and why; we act on your instructions. Your privacy notice governs your customers' data, not ours. The processing terms, permitted purposes, sub-processors, security measures, breach notification and deletion obligations are set out in the services agreement.

Separately, we are a controller for data we collect for our own purposes - website enquiries and recruitment. That is covered by our privacy policy.

Access control

Access is least-privilege and role-based. An agent is granted access to the systems and records their role requires, and nothing else. Access is provisioned per named individual - never shared accounts - and revoked when someone changes role or leaves, as part of the leaver process rather than a periodic clean-up.

Where you require tighter arrangements, they are configured during scoping rather than negotiated afterwards: restricted desktop environments, no local storage, disabled copy and paste, IP-restricted access to your systems, or agents working only within your own platform. Tell us at scoping, because some of these change the cost and the go-live timeline.

Verification before disclosure

The most common practical data protection failure in a support operation is disclosing information to someone who has not been adequately identified, usually because they sounded plausible and the agent wanted to help.

Verification rules are agreed with you, trained explicitly, and scored on the quality scorecard as a pass-or-fail criterion rather than a graded one - a partial pass on verification is a failure. Agents are trained to hold the line under social pressure, which is a skill that needs practising rather than announcing.

Call recording, retention and deletion

Recording happens only where you require it, and is configured to your retention period. Recording law differs by country - including whether and how a caller must be notified - and it is not ours to assume. We will implement what you specify and flag it if what you specify looks inconsistent with the market you are calling.

Retention is enforced automatically rather than by someone remembering. Deletion and anonymisation run on a schedule, and where a record must be kept for statistical purposes it is anonymised rather than retained in identifiable form.

Handling data in the front line

Support work exposes personal data in ways a systems diagram does not capture. Data gets read aloud on calls, pasted into chats by customers, attached to emails, and typed into notes fields. Three practical controls address this:

  • Note discipline. Agents are trained on what belongs in a case note and what does not. Payment details and unnecessary special-category data do not.
  • Attachment handling. Where customers attach documents, retention and access follow the same rules as the case record rather than sitting outside them.
  • Channel awareness. A chat transcript, a call recording and an email attachment carry different obligations, so retention is configured per channel rather than once.

Recruitment vetting and training

Staff are vetted to a level appropriate to the work, and vetting requirements for your account can be raised where the data warrants it. Every new hire completes data protection training before taking a live contact - not as an induction slide, but as part of the assessment they must pass.

Confidentiality obligations continue after employment ends. Refresher training follows policy or regulatory change rather than an annual calendar.

International transfers

Delivery is from India, so data from the United Kingdom or the European Economic Area is transferred internationally. We rely on appropriate safeguards including standard contractual clauses, and we will provide the detail applying to your engagement on request.

Where a transfer is genuinely unacceptable for your use case, UK onshore or nearshore delivery is available. It costs materially more per agent and the honest conversation is about which parts of your queue require it.

Job applicant data

Candidate data is handled separately from commercial and client data, with separate access permissions. CVs are stored outside the publicly accessible part of our website under randomly generated filenames, retrievable only by authorised recruitment staff through an access-controlled route, with every access logged.

This separation is deliberate. Merging candidate records into the sales pipeline would mean one careless export exposing applicant data, so the two are kept structurally apart rather than by policy alone.

AI and data protection

Where automation assists agents - summarising, classifying, surfacing knowledge, drafting replies - the same access and retention rules apply to it as to a person. We do not send your operational or customer data to a general-purpose AI service outside the agreed processing arrangements, and any AI assistance in scope is documented in the services agreement rather than added quietly.

Any AI feature on this website is separately gated and is disabled unless explicitly configured. It answers only from approved information about our own services.

Incidents

Suspected incidents are escalated immediately rather than investigated quietly first. Where we are your processor, notification obligations and timescales are in the services agreement - you need to know quickly because the reporting duty is yours.

We would rather tell you about something that turns out to be nothing than delay while we establish whether it is serious.

What to ask us

If you are assessing us, these are the questions worth asking, and we would rather you asked them: how access is provisioned and revoked, who your sub-processors are, where data is processed and under what safeguards, what your retention periods are and how they are enforced, how verification failures are detected, and what your breach notification timescale is.

Next: our privacy policy, where we operate, or put your security questions to us directly.

Frequently asked questions

No, and we do not display marks we do not hold. We are registered with the Information Commissioner's Office under reference ZB879055, which is a register entry rather than a certification. If your procurement requires a specific certification, tell us early and we will say plainly whether we meet it.

You are. We process it on your instructions as your processor, and your privacy notice governs it. Processing terms, sub-processors, security measures, breach notification and deletion are in the services agreement.

In India, since that is our delivery base. For UK and EEA clients that is an international transfer, and we rely on appropriate safeguards including standard contractual clauses. Where that is genuinely unacceptable, UK onshore or nearshore delivery is available at a materially higher rate.

Yes - restricted desktop environments, no local storage, disabled copy and paste, IP-restricted access, or agents working only inside your own platform. Raise it at scoping, because some of these affect cost and the go-live timeline.

Verification rules agreed with you, trained explicitly, and scored as pass-or-fail on the quality scorecard rather than graded - a partial pass on verification is a failure. Holding the line under social pressure is a skill that needs practising, not announcing.

Immediately, and before we have established whether it is serious. Where we are your processor the reporting duty is yours, so you need to know quickly. Timescales are in the services agreement.