Data Security & Compliance
Quotara maintains a security and privacy framework designed to support the secure delivery of outsourced customer experience, sales development, back-office, and operational services.
Our approach is based on data minimisation, controlled access, least-privilege principles, client-controlled systems, limited retention, and clear accountability for the handling of customer and business information.
Where Quotara processes information on behalf of a client, our personnel are expected to access only the systems and information required to perform the agreed service. Client data is not used for Quotara’s own independent purposes.
Security requirements may be supplemented by client-specific controls, contractual obligations, operating procedures, or regulatory requirements applicable to the relevant market or engagement.
Data Handling Model
Quotara’s preferred operating model is for customer information to remain within client-owned or client-approved systems.
Our teams typically access customer records through platforms such as CRM systems, customer support platforms, ticketing systems, dialers, email environments, live chat applications, order management systems, and other systems approved by the client.
Quotara does not maintain an independent customer database containing information obtained through client engagements for its own use.
Customer information should not be downloaded, exported, copied, or stored outside approved systems unless there is a defined operational requirement and the activity has been appropriately authorised.
Where temporary information is required to complete a task, the information should be limited to what is operationally necessary and removed when it is no longer required.
Data Retention
Quotara operates on a data-minimisation and limited-retention basis.
For customer calls, chats, emails, and similar interactions, Quotara does not ordinarily maintain a separate permanent copy of the customer information exchanged during the interaction.
Once the operational requirement has been completed, temporary notes, working information, or locally retained customer information are expected to be deleted or securely disposed of where retention is not otherwise required.
Information retained within a client’s CRM, helpdesk, dialer, call-recording platform, chat system, email environment, or other client-approved system remains subject to the client’s applicable retention policies, system configuration, and contractual requirements.
Where requested, Quotara can implement client-specific retention and deletion requirements as part of the agreed operating model.
Personally Identifiable Information
Access to personally identifiable information, or PII, is limited to personnel with a legitimate operational requirement.
Controls may include:
- Individual user credentials
- Role-based access
- Least-privilege permissions
- Multi-factor authentication
- Controlled system provisioning
- Access revocation during offboarding or role changes
- Restrictions on downloading and local storage
- Restrictions on unauthorised screenshots, copying, or data extraction
- Client-defined access requirements
Personnel are expected to use customer information only for the purpose for which access has been provided.
Access to sensitive information may be further restricted based on the nature of the client, the information involved, and the applicable regulatory or contractual requirements.
Client System Access
Where practicable, Quotara operates directly within the client’s existing technology environment rather than transferring customer information into separate Quotara-controlled systems.
Client platforms remain the system of record unless otherwise agreed.
This model allows clients to retain control over areas including:
- User permissions
- Data retention
- Customer records
- Platform configuration
- Authentication requirements
- Audit logs
- Recording policies
- Deletion requirements
Quotara personnel are provided access only to the applications and functionality required for their assigned responsibilities.
Access Control and Least Privilege
System access is assigned according to operational role and business need.
Quotara applies a least-privilege approach under which personnel should receive no greater level of access than is reasonably required to perform their responsibilities.
Where supported by the applicable client environment, controls may include:
- Unique user accounts
- Role-based permissions
- Multi-factor authentication
- Password controls
- Session timeouts
- Automatic screen locking
- Access logging
- Supervisory controls
- Periodic access review
Access should be removed or amended where an individual changes role, leaves an account, leaves the organisation, or no longer requires the relevant system.
Multi-Factor Authentication
Quotara supports the use of multi-factor authentication for access to client systems where the functionality is available or required by the client.
MFA is particularly appropriate for environments containing customer information, financial data, administrative functionality, or other sensitive business information.
Client-specific authentication requirements can be incorporated into the account onboarding and access-management process.
Endpoint and Device Controls
Devices used to access client systems are expected to meet the security requirements applicable to the relevant engagement.
Depending on the client environment and risk profile, controls may include:
- Password-protected devices
- Automatic screen locking
- Operating-system patching
- Antivirus and malware protection
- Endpoint protection
- Restricted administrative privileges
- Restrictions on removable media
- Browser and application controls
- Device monitoring
- Mobile Device Management
- Remote Monitoring and Management
- Restrictions on local storage
Enhanced endpoint controls may be introduced where required by a client or where personnel have access to sensitive or regulated information.
Personal Devices
Client information should not be stored on personal devices unless expressly approved as part of the agreed operating model.
Personnel may be restricted from:
- Downloading customer files
- Saving customer information locally
- Transferring information to personal email
- Using unauthorised cloud-storage services
- Copying information to personal messaging applications
- Using removable storage devices
- Photographing customer information
- Otherwise moving information outside the approved environment
Client-specific restrictions may be implemented where stronger controls are required.
Clean Desk and Secure Workspace
Quotara may apply clean-desk and controlled-workspace requirements for personnel handling sensitive, confidential, financial, or customer information.
Depending on the engagement, controls may restrict access to:
- Mobile phones
- Cameras
- Personal laptops
- External storage devices
- Paper
- Notebooks
- Pens
- Other unauthorised recording or storage methods
Printing of customer information should be avoided unless specifically required and authorised.
Any temporary physical records containing customer information should be securely disposed of once the operational requirement has ended.
Work From Home and Remote Delivery
Where personnel perform services remotely, the same confidentiality, access-control, and data-handling requirements continue to apply.
Remote-delivery controls may include:
- Approved devices
- Individual system credentials
- MFA
- Automatic screen locking
- Endpoint protection
- Restricted downloading
- Secure connectivity requirements
- Private workspace requirements
- Restrictions on unauthorised individuals viewing client systems
- Local-storage restrictions
- MDM or RMM controls where required
Remote access may be approved, restricted, or prohibited depending on the client’s requirements, the role being performed, and the sensitivity of the information involved.
Non-compliance with applicable security requirements may result in removal of system access or removal from the relevant client account.
GDPR and UK GDPR
For engagements involving personal data subject to the European Union General Data Protection Regulation or UK GDPR, Quotara seeks to support the applicable data-protection obligations associated with the services it provides.
Where Quotara processes personal data on behalf of a client and does not determine the independent purposes for which that data is used, Quotara would generally operate in the capacity of a data processor, with the client acting as the relevant controller.
Our approach is aligned to principles including:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
Where required, data-processing obligations, confidentiality requirements, international-transfer provisions, or other client-specific privacy requirements can be documented contractually.
Australian Privacy Requirements
For services involving Australian clients or Australian customer information, Quotara seeks to support applicable requirements under the Privacy Act 1988 and the Australian Privacy Principles.
Relevant controls may address:
- Collection and use of personal information
- Access to personal information
- Disclosure
- Information security
- Data quality
- Data minimisation
- Correction
- Retention and disposal
- Cross-border access or processing
Quotara delivers services internationally. As a result, authorised personnel may access client systems from Pakistan or other approved delivery locations.
Where customer information is accessed outside Australia, the applicable access locations should be disclosed to the client and appropriate contractual, operational, and technical controls agreed as required.
United States Privacy Requirements
Quotara supports organisations operating across the United States and recognises that privacy and data-protection obligations vary by jurisdiction and by the nature of the information being processed.
Where applicable, Quotara may act as a service provider, contractor, or processor on behalf of its client.
Quotara does not use client customer information to establish independent marketing databases, sell customer information, or independently determine unrelated purposes for which customer information is processed.
Client-specific requirements relating to applicable U.S. federal or state privacy laws can be incorporated into the relevant operating and contractual framework.
Payment Card Information and PCI DSS
Quotara’s preferred approach is to minimise access to payment-card information wherever operationally possible.
Where a customer transaction requires payment-card information, personnel should use the client’s approved payment environment or payment provider rather than independently storing or retaining cardholder information.
Unless specifically authorised and required for the applicable service, Quotara personnel should not record or retain:
- Full payment-card numbers
- Card verification values
- PIN information
- Sensitive authentication data
- Other unnecessary cardholder information
Where a client requires personnel to operate within a PCI DSS-regulated environment, the applicable controls, responsibilities, technology requirements, and operating procedures should be agreed prior to service commencement.
These may include:
- Restricted system access
- Individual credentials
- MFA
- Controlled workspaces
- Restrictions on paper and writing materials
- Recording restrictions
- Restrictions on local storage
- Approved payment platforms
- Security and privacy training
Quotara can work within client-controlled environments and apply agreed controls designed to minimise exposure to cardholder information.
Financial Information
Some client engagements may require limited access to financial information, including bank details, reimbursement information, invoice data, payment status, or similar records.
Access to this information should be restricted to authorised personnel with a defined business requirement.
Financial information should remain within the approved client system wherever practicable and should not be separately retained by Quotara once the operational purpose has been completed.
Additional restrictions can be applied for accounts involving financial or other sensitive information.
Customer Conversations
Quotara personnel may interact with customers through channels including email, live chat, telephone, webform, SMS, social media, or other client-approved communication channels.
PII contained within those conversations should be accessed only where necessary to resolve the customer interaction or complete the relevant process.
Quotara does not ordinarily maintain a separate permanent repository of customer conversation content.
Where chats, tickets, emails, calls, or recordings remain within a client or approved third-party platform, the applicable platform and client retention rules continue to apply.
Temporary information created outside those systems should be removed when no longer operationally required.
Call Recordings
Where calls are recorded, recording must occur through a client-approved or otherwise authorised platform and remain subject to the applicable legal, consent, notification, and retention requirements.
Recordings may be used for authorised purposes such as:
- Quality assurance
- Training
- Compliance
- Performance review
- Dispute resolution
- Customer-service investigation
Quotara’s preferred model is for recordings to remain within the approved platform rather than being separately downloaded or retained.
Confidentiality
Personnel with access to client systems or information are subject to confidentiality obligations appropriate to their roles.
Confidential information may include:
- Customer information
- Personally identifiable information
- Commercial information
- Internal client documentation
- Financial information
- Intellectual property
- Credentials
- Operating procedures
- Other non-public information
Unauthorised access, disclosure, duplication, or use of confidential information is prohibited.
Confidentiality obligations may continue following removal from an account or termination of employment or engagement.
Security Awareness and Training
Personnel may receive security, privacy, and client-specific training appropriate to their roles.
Training may cover:
- Confidentiality
- PII handling
- Password security
- MFA
- Phishing and social engineering
- Secure system access
- Clean-desk practices
- Customer privacy
- Financial information
- Incident reporting
- Data retention
- Client-specific operating requirements
Additional training may be introduced where required by the client, contract, market, or information classification.
Security Incident Management
Personnel are expected to escalate suspected or confirmed information-security incidents promptly.
Examples may include:
- Unauthorised system access
- Compromised credentials
- Phishing
- Malware
- Accidental disclosure
- Unauthorised downloading
- Loss of information
- Lost or stolen equipment
- Inappropriate access to customer information
Where an incident involves client systems or client information, Quotara will seek to investigate, contain, and escalate the matter through the agreed client-notification process.
Notification requirements, responsible contacts, escalation paths, and any contractual notification timeframes may be defined for individual client engagements.
Data Location and Cross-Border Access
Quotara’s service-delivery model may involve access to client systems from Pakistan and other approved locations.
The location in which client data is technically stored will generally depend on the client’s underlying platforms and infrastructure.
Quotara does not independently relocate client customer information solely as a consequence of personnel accessing an approved cloud-based client platform.
Where required, Quotara can disclose the locations from which client data will be accessed or processed as part of the onboarding and security-review process.
Any restrictions relating to data residency or permitted access locations should be identified prior to commencement of service.
Third-Party and Subprocessor Access
Where a third party, affiliated entity, technology provider, or subcontractor requires access to client information in connection with service delivery, the requirement should be disclosed and appropriately controlled.
Third-party access should be limited to the purpose for which the third party has been engaged and subject to appropriate contractual and security obligations.
For client engagements requiring formal subprocessor disclosure, Quotara can provide information regarding the relevant entity, location, service performed, and nature of data access.
Offboarding and Access Removal
When an individual leaves a client account or no longer requires access to a client environment, applicable system access should be removed or amended.
Account offboarding may include:
- Revoking CRM access
- Disabling communication-platform access
- Removing email or helpdesk permissions
- Revoking shared-resource access
- Removing local temporary files
- Confirming return or disposal of client information
- Removing client-specific credentials
Where an engagement ends, Quotara does not ordinarily retain client customer databases for continued use.
Any required return, deletion, or retention of information will be managed in accordance with the applicable contract, client instruction, and legal requirement.
Client-Specific Security Controls
Quotara recognises that security requirements differ by client, market, industry, system, and data classification.
Prior to implementation, client requirements can be reviewed across areas including:
- Access control
- Approved work locations
- Device standards
- MDM and RMM
- MFA
- PII handling
- Local-storage restrictions
- Data residency
- Clean-desk requirements
- Call recording
- Financial information
- Payment information
- Incident notification
- Retention and deletion
- Workforce screening
- Security reporting
Where a client requirement exceeds Quotara’s standard operating model, the requirement, dependency, control, and implementation approach should be agreed before access to the relevant information is provided.
Security and Compliance Enquiries
Clients may request additional information regarding Quotara’s security controls, privacy practices, delivery locations, remote-working model, data-handling procedures, or client-specific compliance requirements.
Where required as part of procurement or due diligence, Quotara can participate in security questionnaires and provide supporting documentation relevant to the proposed scope of service.