Region-aware data handling,
by default.
Vytrix Data operates a security-led data practice with region-specific processes for the jurisdictions most clients work in. We're careful where we need to be — and clear about what is, and isn't, our responsibility versus yours.
A clear word on certification.
Vytrix Data operates security-led processes aligned with widely-used frameworks. We do not, on this page, claim any formal regulatory certification. Where a campaign or contract requires audited evidence of a specific control framework, we provide it under NDA on request — not by badge.
One global default isn't a strategy.
Each region has its own approach to lawful processing, marketing consent and data subject rights. We apply the right one for the region a record belongs to — not the region a campaign happens to run from.
European Union
Legitimate-interest assessment recorded for B2B contact data. Subject access & erasure requests honoured within statutory timelines. No special-category data processed.
United Kingdom
PECR-aware practice for B2B email and phone. Corporate-subscriber rules respected. Live ICO opt-out service cross-referenced for UK telephone outreach.
United States
US business email lists handled with CAN-SPAM identification, opt-out and header-accuracy controls in mind. State-level rules considered for California (CCPA-aware) and Virginia.
India
Aligned with the Digital Personal Data Protection Act, 2023. B2B identifiers treated as personal data, with consent and notice obligations passed through in customer contracts.
Middle East
UAE PDPL, KSA PDPL and broader GCC frameworks considered. Local trade-licence data treated as commercial-public information, with free-zone flags surfaced.
Asia Pacific
Singapore PDPA, Australia Privacy Act, Japan APPI considered. Region-specific opt-out checks run per campaign before any export is released.
The seven things we hold to.
These principles apply across every region, every package and every customer engagement. Where a regulation requires more, the region-specific layer on top still applies.
Region-specific handling, not a single global default.
Every record carries a jurisdiction tag at ingest. Suppression, retention and consent rules are applied per record, not per customer. We document why a record is processable for the use you've briefed for.
Active suppression & opt-out management.
We maintain a global suppression list of email addresses, phone numbers and domains. Opt-out requests received directly, or supplied by you, are honoured within seven working days and never resurface in future deliveries.
Secure transfer & storage.
Deliveries use encrypted SFTP, signed S3 URLs, or HTTPS-only API endpoints. Customer files and Vytrix exports are encrypted at rest using AES-256. Access is role-based and reviewed quarterly by our security lead.
Data minimisation by brief.
We only collect, store and supply the fields a customer has explicitly briefed for. Optional fields (e.g. mobile phone) require explicit opt-in per contract. Bonus fields are not added "because we can".
Customer usage responsibility, framed up front.
Vytrix supplies data. How that data is used in a campaign is the customer's controllership obligation. We make this explicit in every SOW, and we provide guidance on regional marketing rules — but the campaign-level lawful-basis sits with you.
GDPR-aware processes for EU & UK records.
For EU and UK contact records we operate a legitimate-interest framework with documented assessments, retention windows of 24 months by default, and a route for data subjects to be removed without going through the original customer.
CAN-SPAM-aware practice for US email marketing.
For US email campaigns drawing on Vytrix data, we provide guidance on header accuracy, identification, physical-address and opt-out requirements as defined under CAN-SPAM. Campaign-level execution remains the customer's responsibility.
Your record. Your call.
If you've received outreach using Vytrix-supplied data and would like your contact details removed from our inventory, we'll action it within seven working days. You can also request a copy of the data we hold on you.
- No fee for opt-out, suppression or subject access requests.
- Requests can be made by you directly — not only via the marketer who contacted you.
- Once suppressed, your identifiers are retained on the suppression list to prevent re-appearance.
- For India records we follow the rights granted under the DPDP Act, 2023.
Data Governance, Vytrix Data
For DSARs, opt-out, suppression or compliance questions, contact our data governance function in Hyderabad. We typically respond within one working day.
+91 40 6824 9100
Vytrix Data Private Limited
Level 8, Tower B, Cyber Pearl
HITEC City, Madhapur
Hyderabad, Telangana 500081
India
Need our DPA, SOC questionnaire or DPIA pack?
Our standard data processing addendum, security questionnaire responses and DPIA-ready documentation are available under NDA. Ask your sales contact, or write to legal@vytrixdata.com.