Powering revenue teams in 190+ countriessales@vytrixdata.com+91 40 6824 9100
Home/Compliance

Region-aware data handling,
by default.

Vytrix Data operates a security-led data practice with region-specific processes for the jurisdictions most clients work in. We're careful where we need to be — and clear about what is, and isn't, our responsibility versus yours.

GDPR-awareUK-GDPR-awareCAN-SPAM-awareDPDP-aware (India)PDPL-aware (UAE / SA)
!

A clear word on certification.

Vytrix Data operates security-led processes aligned with widely-used frameworks. We do not, on this page, claim any formal regulatory certification. Where a campaign or contract requires audited evidence of a specific control framework, we provide it under NDA on request — not by badge.

Region-specific handling

One global default isn't a strategy.

Each region has its own approach to lawful processing, marketing consent and data subject rights. We apply the right one for the region a record belongs to — not the region a campaign happens to run from.

EU / EEA · GDPR-aware

European Union

Legitimate-interest assessment recorded for B2B contact data. Subject access & erasure requests honoured within statutory timelines. No special-category data processed.

UK · UK-GDPR-aware

United Kingdom

PECR-aware practice for B2B email and phone. Corporate-subscriber rules respected. Live ICO opt-out service cross-referenced for UK telephone outreach.

US · CAN-SPAM-aware

United States

US business email lists handled with CAN-SPAM identification, opt-out and header-accuracy controls in mind. State-level rules considered for California (CCPA-aware) and Virginia.

India · DPDP-aware

India

Aligned with the Digital Personal Data Protection Act, 2023. B2B identifiers treated as personal data, with consent and notice obligations passed through in customer contracts.

GCC · PDPL-aware

Middle East

UAE PDPL, KSA PDPL and broader GCC frameworks considered. Local trade-licence data treated as commercial-public information, with free-zone flags surfaced.

APAC · local-aware

Asia Pacific

Singapore PDPA, Australia Privacy Act, Japan APPI considered. Region-specific opt-out checks run per campaign before any export is released.

Core principles

The seven things we hold to.

These principles apply across every region, every package and every customer engagement. Where a regulation requires more, the region-specific layer on top still applies.

PRINCIPLE 01

Region-specific handling, not a single global default.

Every record carries a jurisdiction tag at ingest. Suppression, retention and consent rules are applied per record, not per customer. We document why a record is processable for the use you've briefed for.

PRINCIPLE 02

Active suppression & opt-out management.

We maintain a global suppression list of email addresses, phone numbers and domains. Opt-out requests received directly, or supplied by you, are honoured within seven working days and never resurface in future deliveries.

PRINCIPLE 03

Secure transfer & storage.

Deliveries use encrypted SFTP, signed S3 URLs, or HTTPS-only API endpoints. Customer files and Vytrix exports are encrypted at rest using AES-256. Access is role-based and reviewed quarterly by our security lead.

PRINCIPLE 04

Data minimisation by brief.

We only collect, store and supply the fields a customer has explicitly briefed for. Optional fields (e.g. mobile phone) require explicit opt-in per contract. Bonus fields are not added "because we can".

PRINCIPLE 05

Customer usage responsibility, framed up front.

Vytrix supplies data. How that data is used in a campaign is the customer's controllership obligation. We make this explicit in every SOW, and we provide guidance on regional marketing rules — but the campaign-level lawful-basis sits with you.

PRINCIPLE 06

GDPR-aware processes for EU & UK records.

For EU and UK contact records we operate a legitimate-interest framework with documented assessments, retention windows of 24 months by default, and a route for data subjects to be removed without going through the original customer.

PRINCIPLE 07

CAN-SPAM-aware practice for US email marketing.

For US email campaigns drawing on Vytrix data, we provide guidance on header accuracy, identification, physical-address and opt-out requirements as defined under CAN-SPAM. Campaign-level execution remains the customer's responsibility.

Subject access & opt-out

Your record. Your call.

If you've received outreach using Vytrix-supplied data and would like your contact details removed from our inventory, we'll action it within seven working days. You can also request a copy of the data we hold on you.

  • No fee for opt-out, suppression or subject access requests.
  • Requests can be made by you directly — not only via the marketer who contacted you.
  • Once suppressed, your identifiers are retained on the suppression list to prevent re-appearance.
  • For India records we follow the rights granted under the DPDP Act, 2023.

Submit an opt-out request →

Reach the data protection lead

Data Governance, Vytrix Data

For DSARs, opt-out, suppression or compliance questions, contact our data governance function in Hyderabad. We typically respond within one working day.


privacy@vytrixdata.com
+91 40 6824 9100

Vytrix Data Private Limited
Level 8, Tower B, Cyber Pearl
HITEC City, Madhapur
Hyderabad, Telangana 500081
India
Procurement & legal teams

Need our DPA, SOC questionnaire or DPIA pack?

Our standard data processing addendum, security questionnaire responses and DPIA-ready documentation are available under NDA. Ask your sales contact, or write to legal@vytrixdata.com.