In most of this category compliance is a badge in a footer. For the teams we work with in financial services, healthcare, and enterprise technology, it is the first question procurement asks.
This page answers that question in full.
KAT-i INFOTECH PRIVATE LIMITED holds a certification to ISO/IEC 27001:2022 for its information security management system. The standard requires risk assessment, access control, incident management, business continuity, and continuous improvement, audited independently rather than self-declared. What the certificate actually covers in our business is the certified scope, which we quote in full below rather than paraphrase into something broader.
Certified scope, verbatimProvision of information security management system related to custom B2B list research, marketing information research, data enhancement and sales intelligence.
Read the scope, not the badge. Publishing the number is the point. Take it to QRO Certification LLP, confirm the scope and the current status, and treat anything we say about security as unproven until you have. Accredited certification means the auditor was itself audited, which is the whole difference between a certificate and a logo in a footer.
We set stringent rules for how we research, gather, process, and protect personal data. Those rules are documented, tested, and subject to internal review, and the sections below set out what they require in practice.
Where this page describes a control, you should be able to check it. Where it describes a limit, we have said so plainly rather than left it out.
KAT-i is an Indian company researching data about people in more than 145 countries, for clients based mainly in the United Kingdom, Europe, the United States and Asia Pacific. Several regimes therefore apply at once, and they do not all say the same thing.
What follows is our position on each, stated plainly. Where a regime does not currently apply to us we say so rather than staying silent, because silence is what a procurement team has to chase.
| Regime | Where | Our position |
|---|---|---|
| EU GDPR | European Union | Applies. We process as controller for research we initiate and as processor for client-directed work, with the basis for each set out in the agreement. |
| UK GDPR and Data Protection Act 2018 | United Kingdom | Applies as a separate instrument from EU GDPR. Same obligations, separately observed. |
| PECR | United Kingdom | Applies to electronic marketing. Corporate subscribers and individual subscribers are handled differently. See below. |
| CAN-SPAM | United States | Applies to commercial email. Accurate headers, a physical postal address in every message, and opt-outs honoured within ten business days. |
| DPDP Act 2023 | India | Applies to us directly. We are an Indian data fiduciary and are implementing the obligations ahead of the enforcement dates. |
| CASL | Canada | Applies to any message sent to a Canadian address. We treat Canada as an express consent market. See below. |
| CCPA and CPRA | California | The statutory thresholds do not currently apply to KAT-i. Californian data is handled to the same standard regardless. See below. |
Under PECR, the electronic mail rule does not apply to corporate subscribers, which means consent is not required to email a named person at a limited company, a limited liability partnership or a Scottish partnership. Sole traders and unincorporated partnerships are treated as individuals, and consent or a soft opt-in is required for them.
Because the two sit side by side in any real UK list, we record entity type as a field on United Kingdom records. It means a client can tell, record by record, which basis applies rather than assuming one basis covers the file. UK GDPR applies on top of PECR in both cases: a lawful basis, privacy information, and an absolute right to object to direct marketing that we honour without argument.
CASL permits commercial email on the basis of express consent, or on a narrower implied basis where the recipient has themselves conspicuously published the electronic address and the message is relevant to their role. The Federal Court of Appeal has interpreted that implied basis strictly: the sender carries the burden of proof, third party directories do not establish publication, and a job title alone does not establish relevance.
We therefore treat Canada as an express consent market. Where a client wants Canadian contacts for outreach, our opt-in service runs alongside the research, exactly as it does for Europe: consent captured by telephone, date-stamped, and voice-recorded for eighteen months. Where Canadian contacts are commissioned for account mapping or market research rather than for emailing, no commercial electronic message is sent and CASL does not arise.
The CCPA exemption for business to business contact data expired at the end of 2022, so professional contact details are personal information in California in the same way as any other personal data. The Act applies to a business that operates in California and meets at least one of three thresholds: gross annual revenue above 26.625 million US dollars, buying, selling or sharing the personal information of 100,000 or more California residents or households in a year, or deriving half or more of its annual revenue from selling or sharing California residents' personal information.
KAT-i meets none of the three, by a wide margin rather than a narrow one. The data broker registration requirement under the Delete Act attaches to businesses covered by the Act, so it does not attach to us either. We monitor the volume of Californian records on a rolling twelve month basis and will register before the threshold is reached rather than after, should the position change.
Where a client is itself a covered business, we accept the CCPA obligations passed down in their data processing agreement as a matter of contract, whatever our own statutory position.
Article 27 of both the EU and the UK GDPR requires a controller established outside those territories to appoint a representative within them. Our representatives are:
Being straight about this one. Both appointments are in progress at the time of writing and this page will name them as soon as they are in place. A supervisory authority or an individual exercising their rights should meanwhile contact us directly at compliance@kat-i.com, and we will respond within the statutory period.
We do not claim certification against any privacy standard beyond those listed in the previous section. Our ISO/IEC 27001:2022 certificate covers the scope printed on it and nothing wider, and we do not present it as certification of privacy compliance, which it is not. We do not describe ourselves as compliant with a law where the work behind that word is still under way, and where that is the case this page says so. We do not hold ourselves out as offering legal advice to clients about their own obligations.
On delivery, the data is your property. We do not resell it or add it to a shared pool, and we do not operate a shared pool. Our own copy is deleted after the 75-day guarantee period.
There is no product database. Nothing is aggregated, nothing is resold, and no historical archive accumulates. Client data is retained only for the 75-day guarantee period and then deleted. Consent recordings are held for eighteen months because a consent record that cannot be produced is worthless.
This is not a policy exception. It is how we are built, and it changes the shape of the risk you take on by working with us: there is no aggregated archive to breach, to subpoena, or to leak, because none is ever assembled.
What we do hold is narrow and time-limited, and it is set out in full below rather than described in a phrase.
During the research and verification period, data is processed on secure Microsoft, Box.com, and Google Workspace business systems, listed with their safeguards in section 04. Once a list is completed, telephone-verified, and delivered, our copy is deleted from active systems at the end of the guarantee period.
Work happens on company-issued equipment only. Nothing is stored on personal devices. Teams are segmented so that no individual sees a complete client dataset.
Access to client data is restricted to the research and verification team assigned to the project. No third-party contractors or offshore brokers have access. Access is logged and reviewed.
Data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted on every system that holds client data.
| What we hold | How long | Then |
|---|---|---|
| Active project data | Duration of verification and delivery, plus the 75-day guarantee period | Securely deleted from active systems |
| Backups | Operational recovery only | Purged on the backup cycle |
| Opt-in voice recordings | 18 months from the date of consent | Purged |
| Aggregated contact database | Not held | Never assembled |
Business contact information only: names, job titles, work email addresses, work phone numbers, and company details. We do not collect consumer data, sensitive personal data, or special category data.
Under the GDPR, business contact data is personal data. We treat it as such, and we would be cautious of any supplier who tells you otherwise.
For most B2B contact research we rely on legitimate interest under Article 6(1)(f), balanced against the rights of the data subject. For email marketing into Europe we seek explicit consent under Article 6(1)(a), captured by telephone and confirmed by email.
Where consent is required, every element below is part of the process rather than a summary of it. Consent that the person did not understand is not consent.
What this costs us, and why we do it anyway. Marking a record as no answer after twelve attempts loses us contacts on every campaign. It is also the reason the consents we do deliver survive the scrutiny of a compliance officer who asks where the permission came from.
We do not outsource research or verification to third-party data brokers. All research and all telephone verification is performed by our own teams. The sub-processors below are used for infrastructure and communication only.
| Sub-processor | Purpose | Safeguard |
|---|---|---|
| Microsoft | Secure file storage and communication | Standard Contractual Clauses where required |
| Box.com | Secure file transfer | Standard Contractual Clauses where required |
| Google Workspace | Email and document collaboration | Standard Contractual Clauses where required |
A full and current list of sub-processors is available on request, and is updated whenever a new sub-processor is engaged. If your agreement requires notice before we add one, say so at contracting and we will write it in.
Our offices maintain controlled access. Workstations are locked when unattended. No client data is stored on personal devices.
In the event of a suspected data breach:
Our incident response plan is tested annually.
A compliance page that cannot be tested is a marketing page. Each claim above has a way to check it.
Certificate 305025061778IS, issued to KAT-i INFOTECH PRIVATE LIMITED by QRO Certification LLP under EGAC accreditation. Verify it at qrocert.org, or ask us for a PDF copy and check that against the body's own record. We would rather you did that than take the badge at face value.
For any opt-in contact we deliver, the voice-recorded consent file can be retrieved and shared on request for eighteen months from the date of consent. If your regulatory position requires a defined retrieval turnaround, raise it at the briefing stage and we will agree one in writing rather than leave it to goodwill.
We maintain a source trail for every record through the research process. If you need provenance for specific records, particularly for a compliance review, ask and we will provide what we hold.
We accommodate reasonable client audit requests relating to data handling and security controls, subject to a mutual non-disclosure agreement.
Under the GDPR, a data subject has the right to:
We honour all valid subject access requests within 30 days. Requests should be directed to the compliance contact in section 09.
Our research and verification teams work from our offices in San Francisco, Pune, and Kolkata. Personal data researched for a European client is therefore processed outside the EEA during the research and verification period. We would rather state that plainly than let you discover it in a due diligence questionnaire.
Where a transfer requires a safeguard under Chapter V of the GDPR, we put one in place, including Standard Contractual Clauses with the sub-processors listed in section 04. We do not transfer personal data to a party that cannot meet an adequate standard of protection.
The transfer mechanism that applies to your engagement is set out in the data processing agreement we sign with you, so that it is a contractual commitment rather than a claim on a web page. If your legal team wants to review it before contracting, ask and we will send it.
Subject access requests, lawful basis questions, sub-processor notices, and data processing agreements.
Suspected breaches or security concerns relating to data we hold or have delivered. Mark the subject line urgent.
For anything on this page that is faster spoken than written.
+1 628 600 9607United States
+44 20 3769 6479United Kingdom
+91 628 942 3558India
+91 877 709 5698India
If procurement needs the certificate, the sub-processor list, or the data processing agreement in advance, ask and we will send them.
| Version | Date | Changes |
|---|---|---|
| 1.0 | August 2026 | Initial publication |
This page is reviewed annually, and whenever a significant change to our compliance posture occurs. If you are relying on it for a vendor assessment and want to be told when it changes, ask and we will add you to the notification list.
If there is a question on this page we have not answered, it is probably one worth asking. Tell us what your review needs and we will answer it directly rather than point you at a policy.
Before anything is stored
This site sets nothing on your device unless you say yes. We would like to set one cookie that tells us which pages are read, so we know what to write next. Nothing is shared with advertisers, and we do not run ads. What this means.