How Savari handles your data.
A straightforward account of what personal information we collect, why we hold it, how long we keep it, and what rights you have over it — written to meet the requirements of UK GDPR and the Data Protection Act 2018.
Jump to any section
Who we are
Savari Solutions Ltd (“Savari”, “we”, “us”, “our”) is a business process outsourcing company registered in England and Wales. We provide customer service, technical support, back-office operations, virtual assistant services, AI training data support and related outsourcing functions to clients across the United Kingdom, Ireland, Europe, the United States and Australia. Our delivery teams are based in Nairobi, Kenya.
We are registered with the United Kingdom Information Commissioner’s Office as a data controller. For all enquiries relating to this Privacy Policy or your personal information, please contact us at:
Savari Solutions Ltd
Website: savarisolutions.com
Email: hello@savarisolutions.com
Registered in England and Wales
Data controller and data processor
UK GDPR draws a clear distinction between a data controller (the party that determines the purposes and means of processing personal data) and a data processor (the party that processes personal data on behalf of a controller). Understanding which role Savari occupies in a given context is important because it determines the nature of your rights and our obligations.
When Savari is the controller
- When you visit our website or enquire about our services
- When we manage our own marketing and communications
- When we process employment or recruitment data
- When we manage supplier or partner relationships
This Privacy Policy governs these activities.
When Savari is the processor
- When our teams handle personal data belonging to our clients’ customers as part of service delivery
- When we process data in fulfilment of a Data Processing Agreement (DPA)
- When we act on documented instructions from a client controller
Client-specific DPAs govern these activities, not this Policy.
Where Savari acts as a data processor on behalf of a client, the client is responsible for their own lawful basis for processing. We operate only within the instructions provided by the client controller and do not use client data for any purpose beyond the contracted service.
Information we collect
Information you provide directly
- Full name and job title
- Company name and business address
- Work email address and telephone number
- Enquiry details and correspondence
- Information submitted through website forms
- Booking and scheduling information
- Content of emails, messages and calls with us
Information collected automatically
- IP address and approximate location
- Browser type, version and language
- Device type and operating system
- Pages visited and navigation paths
- Session duration and click behaviour
- Referral source and campaign identifiers
- Cookie identifiers and analytics data
Information from third parties
- Business contact data from CRM and outreach platforms
- Publicly available professional information (LinkedIn, company registries)
- Referral and partner introductions
- Calendly booking data when you schedule a call
- Analytics platform data (where enabled)
We primarily process business contact data. We do not seek to collect special category personal data (as defined by UK GDPR Article 9) through our website or standard business communications.
How we use your information
Responding to website enquiries, emails and booking requests
Legitimate interests — responding to business enquiries
Managing contracts, scoping work, onboarding clients and delivering outsourcing services
Performance of a contract; legitimate interests
Maintaining and improving client relationships, account management, service reviews
Legitimate interests — managing ongoing business relationships
Meeting statutory obligations, record-keeping, responding to lawful requests from authorities
Legal obligation; legal claims
Analysing how visitors use our website to improve content, navigation and performance
Legitimate interests — improving our website
Protecting our systems, detecting unauthorised access and preventing fraudulent activity
Legitimate interests — protecting our business and clients
Sending information about our services to business contacts where permitted
Legitimate interests (B2B); consent where required by PECR
Our lawful bases for processing
Every processing activity requires a lawful basis under UK GDPR. We rely on the following:
Legitimate interests
The basis we rely on most frequently for business-to-business activities — responding to enquiries, managing relationships, improving our services and protecting our systems. We carry out a legitimate interests assessment (LIA) for each activity to confirm that our interests are not overridden by your rights and freedoms.
Performance of a contract
Where we are processing data in order to fulfil a contract with you or to take steps at your request before entering into a contract — including scoping, onboarding and delivering services.
Legal obligation
Where we are required to process personal data to comply with a statutory or regulatory duty, including financial record-keeping obligations, anti-money laundering requirements and responses to lawful authority requests.
Consent
Where we rely on consent — primarily for direct marketing to individual consumers or sole traders under PECR — we will collect it clearly and separately, and you may withdraw it at any time without detriment.
Marketing communications
We may send information about our services to business contacts where we have a legitimate interest in doing so and where those communications are relevant to your business. Under the Privacy and Electronic Communications Regulations (PECR), we observe the corporate subscriber exemption for B2B email marketing where it applies.
Every marketing communication we send includes a clear and functional unsubscribe mechanism. You may also opt out at any time by contacting us directly at hello@savarisolutions.com. We will act on your request promptly and without condition.
We do not purchase third-party marketing lists. We do not use personal information obtained for one purpose to send unrelated marketing communications.
Who we share your data with
We do not sell personal information. We share it only where necessary and with appropriate safeguards in place.
Employees and delivery teams
Personnel who need access to your information to respond to your enquiry or deliver the contracted service. All staff are subject to confidentiality obligations and data protection training.
Technology and cloud providers
The platforms we use to operate our business — CRM, communication, scheduling, cloud infrastructure and collaboration tools. We use Data Processing Agreements with all sub-processors.
Professional advisers
Solicitors, accountants and other advisers where necessary for legal, financial or regulatory purposes, each subject to their own professional confidentiality obligations.
Regulators and authorities
Where we are legally required to disclose information to a regulator, law enforcement body or court. We will notify you where legally permitted to do so.
We never sell personal data. We never share personal information with third parties for their own marketing purposes. Sharing with sub-processors is governed by written agreements that impose obligations equivalent to those we carry ourselves.
International data transfers
Savari’s client-facing teams are based in the United Kingdom. Our delivery operations are located in Nairobi, Kenya. Personal data processed as part of service delivery may therefore be transferred to and processed in Kenya, a country outside the United Kingdom.
Kenya is not currently the subject of a UK adequacy decision. Where personal data is transferred to Kenya in connection with service delivery, we rely on the following safeguards:
Data Processing Agreements
All client accounts governed by a DPA that specifies the lawful basis, processing instructions, security requirements and sub-processor obligations applicable to that transfer.
International Data Transfer Agreements
Where required, we execute UK IDTAs (or their approved equivalents) to provide appropriate safeguards for personal data transferred outside the UK.
Contractual controls
All personnel with access to client data are bound by confidentiality obligations, access restrictions and data handling procedures agreed and documented before any data transfer takes place.
Transfer impact assessment
We assess the legal landscape of the destination country to confirm that the agreed safeguards are effective in practice, and document that assessment for each client engagement where a transfer occurs.
We are transparent with clients about where data will be processed and the safeguards in place. Prospective clients may request sight of our transfer impact assessment and standard DPA before entering into a contract.
Client confidentiality provisions
When Savari acts as a data processor on behalf of a client, we are bound by specific obligations that go beyond those set out in this Privacy Policy. The following commitments apply to every client engagement involving personal data:
Processing only on instruction
We process personal data solely in accordance with documented client instructions. We do not use client data for any purpose other than the delivery of the contracted service.
Confidentiality of personnel
Every member of staff with access to client data is subject to a binding confidentiality obligation. This applies to all delivery, management and support personnel.
Sub-processor management
We maintain an up-to-date sub-processor list. We notify clients of any intended change to sub-processor arrangements in advance, giving them the opportunity to object.
Breach notification
In the event of a personal data breach affecting client data, we notify the client controller without undue delay, providing sufficient information to enable them to meet their own notification obligations.
Audit rights
We cooperate with reasonable client audit requests and provide information necessary to demonstrate compliance with applicable data protection obligations.
Return and deletion
At the end of an engagement, we return or securely delete client data in accordance with the terms of the applicable DPA and any instructions provided by the client controller.
Information security and organisational controls
We implement appropriate technical and organisational measures designed to protect personal data against accidental loss, unauthorised disclosure or unlawful processing. Our approach includes:
Access controls
Role-based access permissions ensure that personnel access only the data necessary for their specific function. Access rights are reviewed and withdrawn promptly when no longer required.
Authentication
Multi-factor authentication is applied to systems and platforms holding personal data wherever technically feasible.
Encryption
Personal data transmitted over public networks is encrypted. We apply encryption at rest where risk assessment indicates it is appropriate.
Infrastructure
We use established cloud infrastructure providers with their own security certifications and contractual commitments. We do not operate on-premise servers for the storage of client personal data.
Confidentiality obligations
All personnel are subject to binding confidentiality agreements. Data handling procedures are communicated during onboarding and reinforced through ongoing training.
Security reviews
We conduct periodic reviews of our security measures and update them in response to new risks, threats or changes to the processing environment.
No system can be guaranteed completely secure. Where a personal data breach occurs, we follow documented incident response procedures and fulfil applicable notification obligations under UK GDPR.
How long we keep your data
We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, meet our legal obligations and defend against potential claims. The following schedule sets out our standard retention periods.
2 years from last contact
Legitimate interests in managing business relationships and following up on enquiries
7 years from contract end
Legal obligation — financial record-keeping and limitation periods for contractual claims
As specified in the DPA
Governed by client instructions; data returned or deleted at contract end
Until opt-out or 3 years of inactivity
Legitimate interests in B2B marketing; suppression lists maintained indefinitely
Up to 26 months
Legitimate interests in website improvement; data aggregated where possible
12 months
Legitimate interests in security monitoring and incident investigation
As required by law
Legal obligation
Where personal data is no longer required, we delete or anonymise it in a manner designed to prevent reconstruction.
Your rights under UK GDPR
Subject to applicable law and exemptions, you have the following rights in relation to personal data we hold about you. We will respond to all rights requests within one calendar month, extended where permitted by law for complex or numerous requests.
Right of access
Request a copy of the personal data we hold about you and information about how we use it.
Right to rectification
Request that inaccurate or incomplete personal data about you is corrected without undue delay.
Right to erasure
Request deletion of personal data where there is no longer a legitimate reason to hold it, subject to legal retention obligations.
Right to restrict processing
Request that we limit how we use your personal data in certain circumstances, for example while a rectification request is resolved.
Right to portability
Receive a copy of data you have provided to us in a structured, commonly used and machine-readable format, where technically feasible.
Right to object
Object to processing carried out on the basis of legitimate interests, including direct marketing. We will stop processing unless we have compelling legitimate grounds.
Right to withdraw consent
Withdraw consent at any time where processing is consent-based. Withdrawal does not affect the lawfulness of processing before withdrawal.
Right to complain
Lodge a complaint with the Information Commissioner’s Office (ICO) if you are not satisfied with how we have handled your personal data.
To exercise any of these rights, contact us at hello@savarisolutions.com. We may need to verify your identity before processing the request. We will not charge a fee for reasonable requests.
Cookies and website analytics
Our website uses cookies and similar technologies to support functionality, measure performance and improve your experience. A cookie is a small text file placed on your device when you visit a website.
Strictly necessary cookies
Required for the website to function. These cannot be disabled as they enable core functionality such as page delivery and security. No consent is required for these.
Analytics cookies
Used to understand how visitors interact with the website — pages visited, session duration, referral source. This data is aggregated and used to improve content and navigation. We obtain consent for analytics cookies where required by PECR.
Third-party cookies
Embedded tools such as Calendly may set their own cookies when you interact with them. These are governed by the relevant third party’s privacy policy. We minimise third-party cookie use wherever possible.
You can manage or disable cookies through your browser settings. Disabling cookies may affect website functionality. Where we use a consent management platform, your preferences will be recorded and honoured on subsequent visits.
Third-party websites
Our website may contain links to third-party websites, including social media platforms, reference sources and technology partners. This Privacy Policy applies only to our website. We are not responsible for the privacy practices or content of any third-party site, and we encourage you to read the privacy policy of any site you visit via a link from our pages.
Where we embed third-party tools — such as Calendly for appointment scheduling — those tools are governed by the relevant provider’s own privacy policy. We select tools that meet our data protection expectations and include them in our sub-processor register.
Children’s privacy
Our services are designed for and directed at businesses and business professionals. They are not intended for, and we do not knowingly collect personal information from, children under the age of 16.
If you believe that a child has provided personal information to us without appropriate consent, please contact us at hello@savarisolutions.com and we will take prompt steps to delete that information.
Changes to this policy
We review this Privacy Policy periodically and update it to reflect changes in our processing activities, legal requirements or regulatory guidance. The date of the most recent revision is shown at the top of this page.
Where a change is material, we will take reasonable steps to bring it to your attention — for example by updating the date prominently or, where we have your contact details and the change affects you directly, by notifying you directly. Continued engagement with our website or services after an update constitutes acknowledgement of the revised Policy.
We recommend checking this page periodically if you interact with us on an ongoing basis.
Questions and complaint rights
If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or have a concern about how we have handled your personal information, please contact us in the first instance:
Savari Solutions Ltd
Email: hello@savarisolutions.com
Website: savarisolutions.com
We aim to respond to all data protection enquiries within 10 working days. For formal rights requests, we will respond within one calendar month of receiving sufficient information to process your request.
If you are not satisfied with our response, or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the United Kingdom Information Commissioner’s Office:
Information Commissioner’s Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113
The ICO is the UK’s independent supervisory authority for data protection.
Have a question about how we handle data?
We’re happy to discuss our data processing practices before you engage with us — ask on the call or send us an email.