Security & compliance

What happens to your data

Written plainly, for the person who has to sign it off. If your procurement team needs something not covered here, ask — we would rather answer than have you guess.

The essentials

Who you are contracting with

Sowrav Chowdhury, trading as The Data Collection, based in Chattogram, Bangladesh. That is the name that appears on the NDA and on any agreement.

NDA before anything moves

We sign an NDA on request, before you share a single record. Ask in your first message and it will be with you the same day.

Deletion after approval

Your data is deleted after project approval. We do not retain copies, we do not build a database from client work, and nothing is ever resold.

Data handling

Client data is worked on in isolated project folders, accessible only to the team members assigned to that project. Files are transferred through the channel you choose — your own cloud storage, a shared drive you control, or encrypted email attachment.

We do not move client data onto personal devices. We do not use client records for testing, demonstrations or portfolio examples unless you have given written permission, and the before/after examples on this website use synthetic data written for the purpose.

Retention and deletion

Working files are deleted once you approve the delivery. Where a project has a support window we retain the final deliverable for the duration of that window and delete it at the end. If you need a different retention period — longer for continuity, or immediate deletion on handover — say so at the scoping stage and we will follow it.

Sub-processors

Some verification work requires third-party services. These are the tools that may process contact data during a project:

  • ZeroBounce — email verification and deliverability scoring
  • NeverBounce — secondary email verification
  • Apollo and Hunter.io — contact discovery and enrichment
  • LinkedIn Sales Navigator — prospect research
  • Clearbit and Lusha — firmographic enrichment

If your policy prohibits any of these, tell us at scoping. We can usually work around a specific tool, though it may affect turnaround.

GDPR position

Where we process personal data of EU or UK data subjects on your behalf, we act as a processor and you remain the controller. We will sign a Data Processing Agreement on request. We process only on your documented instructions, we do not transfer data to any party outside the sub-processor list above without telling you, and we assist with data subject requests relating to work we have done for you.

We describe this as GDPR-compliant processes rather than certification. There is no such thing as a GDPR certificate for a processor of our size — what matters is the DPA, the sub-processor list and the deletion policy, all of which are above.

Access control

Where you give us direct access to a live system — a CRM user account, for instance — we ask for the minimum permission level that allows the work, a named account rather than a shared login, and we ask you to revoke it at project close. We will remind you if you forget.

What we do not claim

We are not ISO 27001 certified and we do not hold a SOC 2 report. We are a ten-person specialist team, and buying either would be misleading rather than meaningful at our size. What we can offer is a signed NDA, a signed DPA, a documented deletion policy, a named legal signatory and a named point of contact. If your procurement process requires a formal certification, we would rather tell you now than waste your time.

Questions

Security questionnaires are welcome. Send them to contact@thedatacollection.com and we will complete them — usually within two business days.

Need the paperwork first?

Ask for the NDA and DPA in your first message and we’ll send both before you share anything.

Last reviewed · We review every page quarterly for accuracy.

Get a free assessment WhatsApp