Our role
When we deliver services, the client is the owner and controller of its customer data, and DEMGEM acts as its service provider (processor). We handle that data only on the client's documented instructions and for the agreed services, never for our own purposes.
Our commitments
Your data stays yours. We make no claim over client data, scripts or recordings.
Purpose limits. Data is used only for the campaign or process the client has asked us to run.
No sale, no sharing. We do not sell, rent or pass client data to anyone else, except to the extent the law requires.
Need-to-know access. Only executives and supervisors assigned to a client's work can see that client's data.
No copying out. Executives are not permitted to copy, forward, photograph or store client data outside the agreed systems.
Confidentiality. Everyone working on client data is bound by written confidentiality and our code of conduct.
How clients keep control
Scripts and process. The client approves the script and process we follow.
Numbers and technology. Where the client provides its own telephony or masked numbers, calls run on them and we do not collect the customers' raw numbers beyond what the work requires.
Visibility. A shared tracker and day-end reports show what was done, so the client sees outcomes without having to ask.
Recordings. Where calls are recorded, the recordings belong to the client and are used for quality, compliance and dispute resolution as the agreement provides.
Seats. The client sets the number of seats and can add or reduce them with notice.
Security
We apply reasonable safeguards appropriate to the data, including controlled access to systems and trackers, individual accounts for team members, and prompt removal of access when someone leaves a project. Our team coordinates on StaqOn, which keeps instructions, queries and trackers in one controlled workspace.
If something goes wrong
If we become aware of a personal data breach affecting client data, we will tell the client without undue delay and give the information it needs to meet its own legal obligations, and we will help it respond.
Return and deletion
When an engagement ends, or on the client's written request, we return or delete client data from our systems within the period set in the service agreement, except for what the law requires us to keep, and confirm in writing on request.
Law
We work to comply with applicable Indian law on data protection, including the Digital Personal Data Protection Act, 2023 and the rules made under it as they come into force, and with the reasonable requirements of each client's regulator.
Questions
To ask about how we handle data, or to raise a concern, write to hello@demgem.com.