Privacy Policy

Privacy Policy

How Savari handles your data.

A straightforward account of what personal information we collect, why we hold it, how long we keep it, and what rights you have over it — written to meet the requirements of UK GDPR and the Data Protection Act 2018.

Effective date: 7 August 2026
Regulation: UK GDPR & DPA 2018
Controller: Savari Solutions Ltd
ICO registered: United Kingdom
01 — Identity

Who we are

Savari Solutions Ltd (“Savari”, “we”, “us”, “our”) is a business process outsourcing company registered in England and Wales. We provide customer service, technical support, back-office operations, virtual assistant services, AI training data support and related outsourcing functions to clients across the United Kingdom, Ireland, Europe, the United States and Australia. Our delivery teams are based in Nairobi, Kenya.

We are registered with the United Kingdom Information Commissioner’s Office as a data controller. For all enquiries relating to this Privacy Policy or your personal information, please contact us at:

Savari Solutions Ltd

Website: savarisolutions.com

Email: hello@savarisolutions.com

Registered in England and Wales

02 — Roles

Data controller and data processor

UK GDPR draws a clear distinction between a data controller (the party that determines the purposes and means of processing personal data) and a data processor (the party that processes personal data on behalf of a controller). Understanding which role Savari occupies in a given context is important because it determines the nature of your rights and our obligations.

When Savari is the controller

  • When you visit our website or enquire about our services
  • When we manage our own marketing and communications
  • When we process employment or recruitment data
  • When we manage supplier or partner relationships

This Privacy Policy governs these activities.

When Savari is the processor

  • When our teams handle personal data belonging to our clients’ customers as part of service delivery
  • When we process data in fulfilment of a Data Processing Agreement (DPA)
  • When we act on documented instructions from a client controller

Client-specific DPAs govern these activities, not this Policy.

Where Savari acts as a data processor on behalf of a client, the client is responsible for their own lawful basis for processing. We operate only within the instructions provided by the client controller and do not use client data for any purpose beyond the contracted service.

03 — Collection

Information we collect

Information you provide directly

  • Full name and job title
  • Company name and business address
  • Work email address and telephone number
  • Enquiry details and correspondence
  • Information submitted through website forms
  • Booking and scheduling information
  • Content of emails, messages and calls with us

Information collected automatically

  • IP address and approximate location
  • Browser type, version and language
  • Device type and operating system
  • Pages visited and navigation paths
  • Session duration and click behaviour
  • Referral source and campaign identifiers
  • Cookie identifiers and analytics data

Information from third parties

  • Business contact data from CRM and outreach platforms
  • Publicly available professional information (LinkedIn, company registries)
  • Referral and partner introductions
  • Calendly booking data when you schedule a call
  • Analytics platform data (where enabled)

We primarily process business contact data. We do not seek to collect special category personal data (as defined by UK GDPR Article 9) through our website or standard business communications.

04 — Purpose

How we use your information

Purpose
Activity
Lawful basis
Enquiry handling

Responding to website enquiries, emails and booking requests

Legitimate interests — responding to business enquiries

Service delivery

Managing contracts, scoping work, onboarding clients and delivering outsourcing services

Performance of a contract; legitimate interests

Relationship management

Maintaining and improving client relationships, account management, service reviews

Legitimate interests — managing ongoing business relationships

Legal and compliance

Meeting statutory obligations, record-keeping, responding to lawful requests from authorities

Legal obligation; legal claims

Website improvement

Analysing how visitors use our website to improve content, navigation and performance

Legitimate interests — improving our website

Security and fraud

Protecting our systems, detecting unauthorised access and preventing fraudulent activity

Legitimate interests — protecting our business and clients

Marketing

Sending information about our services to business contacts where permitted

Legitimate interests (B2B); consent where required by PECR

05 — Legal basis

Our lawful bases for processing

Every processing activity requires a lawful basis under UK GDPR. We rely on the following:

Legitimate interests

The basis we rely on most frequently for business-to-business activities — responding to enquiries, managing relationships, improving our services and protecting our systems. We carry out a legitimate interests assessment (LIA) for each activity to confirm that our interests are not overridden by your rights and freedoms.

Performance of a contract

Where we are processing data in order to fulfil a contract with you or to take steps at your request before entering into a contract — including scoping, onboarding and delivering services.

Legal obligation

Where we are required to process personal data to comply with a statutory or regulatory duty, including financial record-keeping obligations, anti-money laundering requirements and responses to lawful authority requests.

Consent

Where we rely on consent — primarily for direct marketing to individual consumers or sole traders under PECR — we will collect it clearly and separately, and you may withdraw it at any time without detriment.

06 — Marketing

Marketing communications

We may send information about our services to business contacts where we have a legitimate interest in doing so and where those communications are relevant to your business. Under the Privacy and Electronic Communications Regulations (PECR), we observe the corporate subscriber exemption for B2B email marketing where it applies.

Every marketing communication we send includes a clear and functional unsubscribe mechanism. You may also opt out at any time by contacting us directly at hello@savarisolutions.com. We will act on your request promptly and without condition.

We do not purchase third-party marketing lists. We do not use personal information obtained for one purpose to send unrelated marketing communications.

07 — Disclosure

Who we share your data with

We do not sell personal information. We share it only where necessary and with appropriate safeguards in place.

Employees and delivery teams

Personnel who need access to your information to respond to your enquiry or deliver the contracted service. All staff are subject to confidentiality obligations and data protection training.

Technology and cloud providers

The platforms we use to operate our business — CRM, communication, scheduling, cloud infrastructure and collaboration tools. We use Data Processing Agreements with all sub-processors.

Professional advisers

Solicitors, accountants and other advisers where necessary for legal, financial or regulatory purposes, each subject to their own professional confidentiality obligations.

Regulators and authorities

Where we are legally required to disclose information to a regulator, law enforcement body or court. We will notify you where legally permitted to do so.

We never sell personal data. We never share personal information with third parties for their own marketing purposes. Sharing with sub-processors is governed by written agreements that impose obligations equivalent to those we carry ourselves.

08 — Transfers

International data transfers

Savari’s client-facing teams are based in the United Kingdom. Our delivery operations are located in Nairobi, Kenya. Personal data processed as part of service delivery may therefore be transferred to and processed in Kenya, a country outside the United Kingdom.

Kenya is not currently the subject of a UK adequacy decision. Where personal data is transferred to Kenya in connection with service delivery, we rely on the following safeguards:

Data Processing Agreements

All client accounts governed by a DPA that specifies the lawful basis, processing instructions, security requirements and sub-processor obligations applicable to that transfer.

International Data Transfer Agreements

Where required, we execute UK IDTAs (or their approved equivalents) to provide appropriate safeguards for personal data transferred outside the UK.

Contractual controls

All personnel with access to client data are bound by confidentiality obligations, access restrictions and data handling procedures agreed and documented before any data transfer takes place.

Transfer impact assessment

We assess the legal landscape of the destination country to confirm that the agreed safeguards are effective in practice, and document that assessment for each client engagement where a transfer occurs.

We are transparent with clients about where data will be processed and the safeguards in place. Prospective clients may request sight of our transfer impact assessment and standard DPA before entering into a contract.

09 — Confidentiality

Client confidentiality provisions

When Savari acts as a data processor on behalf of a client, we are bound by specific obligations that go beyond those set out in this Privacy Policy. The following commitments apply to every client engagement involving personal data:

Processing only on instruction

We process personal data solely in accordance with documented client instructions. We do not use client data for any purpose other than the delivery of the contracted service.

Confidentiality of personnel

Every member of staff with access to client data is subject to a binding confidentiality obligation. This applies to all delivery, management and support personnel.

Sub-processor management

We maintain an up-to-date sub-processor list. We notify clients of any intended change to sub-processor arrangements in advance, giving them the opportunity to object.

Breach notification

In the event of a personal data breach affecting client data, we notify the client controller without undue delay, providing sufficient information to enable them to meet their own notification obligations.

Audit rights

We cooperate with reasonable client audit requests and provide information necessary to demonstrate compliance with applicable data protection obligations.

Return and deletion

At the end of an engagement, we return or securely delete client data in accordance with the terms of the applicable DPA and any instructions provided by the client controller.

10 — Security

Information security and organisational controls

We implement appropriate technical and organisational measures designed to protect personal data against accidental loss, unauthorised disclosure or unlawful processing. Our approach includes:

Access controls

Role-based access permissions ensure that personnel access only the data necessary for their specific function. Access rights are reviewed and withdrawn promptly when no longer required.

Authentication

Multi-factor authentication is applied to systems and platforms holding personal data wherever technically feasible.

Encryption

Personal data transmitted over public networks is encrypted. We apply encryption at rest where risk assessment indicates it is appropriate.

Infrastructure

We use established cloud infrastructure providers with their own security certifications and contractual commitments. We do not operate on-premise servers for the storage of client personal data.

Confidentiality obligations

All personnel are subject to binding confidentiality agreements. Data handling procedures are communicated during onboarding and reinforced through ongoing training.

Security reviews

We conduct periodic reviews of our security measures and update them in response to new risks, threats or changes to the processing environment.

No system can be guaranteed completely secure. Where a personal data breach occurs, we follow documented incident response procedures and fulfil applicable notification obligations under UK GDPR.

11 — Retention

How long we keep your data

We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, meet our legal obligations and defend against potential claims. The following schedule sets out our standard retention periods.

Data type
Retention period
Reason
Enquiry & contact records

2 years from last contact

Legitimate interests in managing business relationships and following up on enquiries

Client contract records

7 years from contract end

Legal obligation — financial record-keeping and limitation periods for contractual claims

Client personal data (as processor)

As specified in the DPA

Governed by client instructions; data returned or deleted at contract end

Marketing contact records

Until opt-out or 3 years of inactivity

Legitimate interests in B2B marketing; suppression lists maintained indefinitely

Website analytics data

Up to 26 months

Legitimate interests in website improvement; data aggregated where possible

Security and access logs

12 months

Legitimate interests in security monitoring and incident investigation

Legal and compliance records

As required by law

Legal obligation

Where personal data is no longer required, we delete or anonymise it in a manner designed to prevent reconstruction.

12 — Rights

Your rights under UK GDPR

Subject to applicable law and exemptions, you have the following rights in relation to personal data we hold about you. We will respond to all rights requests within one calendar month, extended where permitted by law for complex or numerous requests.

Article 15

Right of access

Request a copy of the personal data we hold about you and information about how we use it.

Article 16

Right to rectification

Request that inaccurate or incomplete personal data about you is corrected without undue delay.

Article 17

Right to erasure

Request deletion of personal data where there is no longer a legitimate reason to hold it, subject to legal retention obligations.

Article 18

Right to restrict processing

Request that we limit how we use your personal data in certain circumstances, for example while a rectification request is resolved.

Article 20

Right to portability

Receive a copy of data you have provided to us in a structured, commonly used and machine-readable format, where technically feasible.

Article 21

Right to object

Object to processing carried out on the basis of legitimate interests, including direct marketing. We will stop processing unless we have compelling legitimate grounds.

Article 7

Right to withdraw consent

Withdraw consent at any time where processing is consent-based. Withdrawal does not affect the lawfulness of processing before withdrawal.

ICO

Right to complain

Lodge a complaint with the Information Commissioner’s Office (ICO) if you are not satisfied with how we have handled your personal data.

To exercise any of these rights, contact us at hello@savarisolutions.com. We may need to verify your identity before processing the request. We will not charge a fee for reasonable requests.

13 — Cookies

Cookies and website analytics

Our website uses cookies and similar technologies to support functionality, measure performance and improve your experience. A cookie is a small text file placed on your device when you visit a website.

Strictly necessary cookies

Required for the website to function. These cannot be disabled as they enable core functionality such as page delivery and security. No consent is required for these.

Analytics cookies

Used to understand how visitors interact with the website — pages visited, session duration, referral source. This data is aggregated and used to improve content and navigation. We obtain consent for analytics cookies where required by PECR.

Third-party cookies

Embedded tools such as Calendly may set their own cookies when you interact with them. These are governed by the relevant third party’s privacy policy. We minimise third-party cookie use wherever possible.

You can manage or disable cookies through your browser settings. Disabling cookies may affect website functionality. Where we use a consent management platform, your preferences will be recorded and honoured on subsequent visits.

14 — External sites

Third-party websites

Our website may contain links to third-party websites, including social media platforms, reference sources and technology partners. This Privacy Policy applies only to our website. We are not responsible for the privacy practices or content of any third-party site, and we encourage you to read the privacy policy of any site you visit via a link from our pages.

Where we embed third-party tools — such as Calendly for appointment scheduling — those tools are governed by the relevant provider’s own privacy policy. We select tools that meet our data protection expectations and include them in our sub-processor register.

15 — Children

Children’s privacy

Our services are designed for and directed at businesses and business professionals. They are not intended for, and we do not knowingly collect personal information from, children under the age of 16.

If you believe that a child has provided personal information to us without appropriate consent, please contact us at hello@savarisolutions.com and we will take prompt steps to delete that information.

16 — Updates

Changes to this policy

We review this Privacy Policy periodically and update it to reflect changes in our processing activities, legal requirements or regulatory guidance. The date of the most recent revision is shown at the top of this page.

Where a change is material, we will take reasonable steps to bring it to your attention — for example by updating the date prominently or, where we have your contact details and the change affects you directly, by notifying you directly. Continued engagement with our website or services after an update constitutes acknowledgement of the revised Policy.

We recommend checking this page periodically if you interact with us on an ongoing basis.

17 — Contact & complaints

Questions and complaint rights

If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or have a concern about how we have handled your personal information, please contact us in the first instance:

Savari Solutions Ltd

Email: hello@savarisolutions.com

Website: savarisolutions.com

We aim to respond to all data protection enquiries within 10 working days. For formal rights requests, we will respond within one calendar month of receiving sufficient information to process your request.

If you are not satisfied with our response, or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the United Kingdom Information Commissioner’s Office:

Information Commissioner’s Office (ICO)

Website: ico.org.uk

Telephone: 0303 123 1113

The ICO is the UK’s independent supervisory authority for data protection.

Have a question about how we handle data?

We’re happy to discuss our data processing practices before you engage with us — ask on the call or send us an email.