Compliance & security

Consent-safe, audit-ready

In most of this category compliance is a badge in a footer. For the teams we work with in financial services, healthcare, and enterprise technology, it is the first question procurement asks.

This page answers that question in full.

01 · Certifications

What we are certified for

ISO/IEC 27001:2022Certificate 305025061778IS

KAT-i INFOTECH PRIVATE LIMITED holds a certification to ISO/IEC 27001:2022 for its information security management system. The standard requires risk assessment, access control, incident management, business continuity, and continuous improvement, audited independently rather than self-declared. What the certificate actually covers in our business is the certified scope, which we quote in full below rather than paraphrase into something broader.

Certified scope, verbatimProvision of information security management system related to custom B2B list research, marketing information research, data enhancement and sales intelligence.
Certificate number
305025061778IS
Certified entity
KAT-i INFOTECH PRIVATE LIMITED
Standard
ISO/IEC 27001:2022, Information Security Management System
Certifying body
QRO Certification LLP
Accreditation
EGAC, CAB number 011905. EGAC is a signatory to the IAF Multilateral Recognition Arrangement, which is what makes this certificate readable by a procurement team anywhere.
Statement of Applicability
Version 1.0, dated 25 November 2024
Certified on
17 June 2025
Valid until
16 June 2028, subject to annual surveillance audit
Surveillance
First surveillance audit completed 16 June 2026. Second due 16 June 2027.
Verify at
qrocert.org

Read the scope, not the badge. Publishing the number is the point. Take it to QRO Certification LLP, confirm the scope and the current status, and treat anything we say about security as unproven until you have. Accredited certification means the auditor was itself audited, which is the whole difference between a certificate and a logo in a footer.

GDPR compliance

We set stringent rules for how we research, gather, process, and protect personal data. Those rules are documented, tested, and subject to internal review, and the sections below set out what they require in practice.

Where this page describes a control, you should be able to check it. Where it describes a limit, we have said so plainly rather than left it out.

02 · The laws that apply

Which regimes reach us, and what we do about each

KAT-i is an Indian company researching data about people in more than 145 countries, for clients based mainly in the United Kingdom, Europe, the United States and Asia Pacific. Several regimes therefore apply at once, and they do not all say the same thing.

What follows is our position on each, stated plainly. Where a regime does not currently apply to us we say so rather than staying silent, because silence is what a procurement team has to chase.

RegimeWhereOur position
EU GDPREuropean UnionApplies. We process as controller for research we initiate and as processor for client-directed work, with the basis for each set out in the agreement.
UK GDPR and Data Protection Act 2018United KingdomApplies as a separate instrument from EU GDPR. Same obligations, separately observed.
PECRUnited KingdomApplies to electronic marketing. Corporate subscribers and individual subscribers are handled differently. See below.
CAN-SPAMUnited StatesApplies to commercial email. Accurate headers, a physical postal address in every message, and opt-outs honoured within ten business days.
DPDP Act 2023IndiaApplies to us directly. We are an Indian data fiduciary and are implementing the obligations ahead of the enforcement dates.
CASLCanadaApplies to any message sent to a Canadian address. We treat Canada as an express consent market. See below.
CCPA and CPRACaliforniaThe statutory thresholds do not currently apply to KAT-i. Californian data is handled to the same standard regardless. See below.

2.1United Kingdom, and why corporate and individual subscribers are separated

Under PECR, the electronic mail rule does not apply to corporate subscribers, which means consent is not required to email a named person at a limited company, a limited liability partnership or a Scottish partnership. Sole traders and unincorporated partnerships are treated as individuals, and consent or a soft opt-in is required for them.

Because the two sit side by side in any real UK list, we record entity type as a field on United Kingdom records. It means a client can tell, record by record, which basis applies rather than assuming one basis covers the file. UK GDPR applies on top of PECR in both cases: a lawful basis, privacy information, and an absolute right to object to direct marketing that we honour without argument.

2.2Canada, and why we do not rely on the published address exemption

CASL permits commercial email on the basis of express consent, or on a narrower implied basis where the recipient has themselves conspicuously published the electronic address and the message is relevant to their role. The Federal Court of Appeal has interpreted that implied basis strictly: the sender carries the burden of proof, third party directories do not establish publication, and a job title alone does not establish relevance.

We therefore treat Canada as an express consent market. Where a client wants Canadian contacts for outreach, our opt-in service runs alongside the research, exactly as it does for Europe: consent captured by telephone, date-stamped, and voice-recorded for eighteen months. Where Canadian contacts are commissioned for account mapping or market research rather than for emailing, no commercial electronic message is sent and CASL does not arise.

2.3California, and the position on the thresholds

The CCPA exemption for business to business contact data expired at the end of 2022, so professional contact details are personal information in California in the same way as any other personal data. The Act applies to a business that operates in California and meets at least one of three thresholds: gross annual revenue above 26.625 million US dollars, buying, selling or sharing the personal information of 100,000 or more California residents or households in a year, or deriving half or more of its annual revenue from selling or sharing California residents' personal information.

KAT-i meets none of the three, by a wide margin rather than a narrow one. The data broker registration requirement under the Delete Act attaches to businesses covered by the Act, so it does not attach to us either. We monitor the volume of Californian records on a rolling twelve month basis and will register before the threshold is reached rather than after, should the position change.

Where a client is itself a covered business, we accept the CCPA obligations passed down in their data processing agreement as a matter of contract, whatever our own statutory position.

2.4Representatives in the European Union and the United Kingdom

Article 27 of both the EU and the UK GDPR requires a controller established outside those territories to appoint a representative within them. Our representatives are:

EU representative
To be confirmed: name and address of the appointed Article 27 representative in the European Union
UK representative
To be confirmed: name and address of the appointed Article 27 representative in the United Kingdom

Being straight about this one. Both appointments are in progress at the time of writing and this page will name them as soon as they are in place. A supervisory authority or an individual exercising their rights should meanwhile contact us directly at compliance@kat-i.com, and we will respond within the statutory period.

2.5What we do not claim

We do not claim certification against any privacy standard beyond those listed in the previous section. Our ISO/IEC 27001:2022 certificate covers the scope printed on it and nothing wider, and we do not present it as certification of privacy compliance, which it is not. We do not describe ourselves as compliant with a law where the work behind that word is still under way, and where that is the case this page says so. We do not hold ourselves out as offering legal advice to clients about their own obligations.

03 · Data governance

How we handle data

Data ownership

On delivery, the data is your property. We do not resell it or add it to a shared pool, and we do not operate a shared pool. Our own copy is deleted after the 75-day guarantee period.

No persistent database

There is no product database. Nothing is aggregated, nothing is resold, and no historical archive accumulates. Client data is retained only for the 75-day guarantee period and then deleted. Consent recordings are held for eighteen months because a consent record that cannot be produced is worthless.

This is not a policy exception. It is how we are built, and it changes the shape of the risk you take on by working with us: there is no aggregated archive to breach, to subpoena, or to leak, because none is ever assembled.

What we do hold is narrow and time-limited, and it is set out in full below rather than described in a phrase.

Data storage and deletion

During the research and verification period, data is processed on secure Microsoft, Box.com, and Google Workspace business systems, listed with their safeguards in section 04. Once a list is completed, telephone-verified, and delivered, our copy is deleted from active systems at the end of the guarantee period.

Access control

Work happens on company-issued equipment only. Nothing is stored on personal devices. Teams are segmented so that no individual sees a complete client dataset.

Access to client data is restricted to the research and verification team assigned to the project. No third-party contractors or offshore brokers have access. Access is logged and reviewed.

Encryption

Data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted on every system that holds client data.

What we holdHow longThen
Active project dataDuration of verification and delivery, plus the 75-day guarantee periodSecurely deleted from active systems
BackupsOperational recovery onlyPurged on the backup cycle
Opt-in voice recordings18 months from the date of consentPurged
Aggregated contact databaseNot heldNever assembled
04 · Research and consent

How we source and verify data lawfully

What we process

Business contact information only: names, job titles, work email addresses, work phone numbers, and company details. We do not collect consumer data, sensitive personal data, or special category data.

Under the GDPR, business contact data is personal data. We treat it as such, and we would be cautious of any supplier who tells you otherwise.

Lawful basis

For most B2B contact research we rely on legitimate interest under Article 6(1)(f), balanced against the rights of the data subject. For email marketing into Europe we seek explicit consent under Article 6(1)(a), captured by telephone and confirmed by email.

What we do not do

  • We do not scrape personal data from social media or consumer platforms
  • We do not purchase lists with unclear provenance
  • We do not infer consent from silence or inactivity
  • We do not process special category data or sensitive personal data
  • We do not retain client data beyond the guarantee period
05 · Sub-processors

Who else touches your data

We do not outsource research or verification to third-party data brokers. All research and all telephone verification is performed by our own teams. The sub-processors below are used for infrastructure and communication only.

Sub-processorPurposeSafeguard
MicrosoftSecure file storage and communicationStandard Contractual Clauses where required
Box.comSecure file transferStandard Contractual Clauses where required
Google WorkspaceEmail and document collaborationStandard Contractual Clauses where required

A full and current list of sub-processors is available on request, and is updated whenever a new sub-processor is engaged. If your agreement requires notice before we add one, say so at contracting and we will write it in.

06 · Security measures

How we protect data

Physical security

Our offices maintain controlled access. Workstations are locked when unattended. No client data is stored on personal devices.

Logical security

  • Multi-factor authentication on all systems
  • Role-based access control, so researchers see only the projects they are assigned to
  • Enforced password policy
  • Anti-malware and endpoint protection on all devices

Network security

  • Firewall-protected network perimeter
  • VPN required for remote access
  • Regular vulnerability scanning and patching

Incident response

In the event of a suspected data breach:

  1. Containment within 24 hours.
  2. Assessment and documentation within 72 hours.
  3. Notification to affected clients without undue delay.
  4. Notification to supervisory authorities within 72 hours where the GDPR requires it.

Our incident response plan is tested annually.

07 · Audit and verification

How you can check any of this

A compliance page that cannot be tested is a marketing page. Each claim above has a way to check it.

Certificate verification

Certificate 305025061778IS, issued to KAT-i INFOTECH PRIVATE LIMITED by QRO Certification LLP under EGAC accreditation. Verify it at qrocert.org, or ask us for a PDF copy and check that against the body's own record. We would rather you did that than take the badge at face value.

Consent record retrieval

For any opt-in contact we deliver, the voice-recorded consent file can be retrieved and shared on request for eighteen months from the date of consent. If your regulatory position requires a defined retrieval turnaround, raise it at the briefing stage and we will agree one in writing rather than leave it to goodwill.

Source trail

We maintain a source trail for every record through the research process. If you need provenance for specific records, particularly for a compliance review, ask and we will provide what we hold.

Client audit

We accommodate reasonable client audit requests relating to data handling and security controls, subject to a mutual non-disclosure agreement.

08 · Data subject rights

Rights we respect and facilitate

Under the GDPR, a data subject has the right to:

  • Access: to know what data we hold about them
  • Rectification: to have inaccurate data corrected
  • Erasure: to request deletion, the right to be forgotten
  • Restriction: to limit how their data is processed
  • Portability: to receive their data in a structured format
  • Objection: to object to processing based on legitimate interest

We honour all valid subject access requests within 30 days. Requests should be directed to the compliance contact in section 09.

09 · International transfers

Where the work actually happens

Our research and verification teams work from our offices in San Francisco, Pune, and Kolkata. Personal data researched for a European client is therefore processed outside the EEA during the research and verification period. We would rather state that plainly than let you discover it in a due diligence questionnaire.

Where a transfer requires a safeguard under Chapter V of the GDPR, we put one in place, including Standard Contractual Clauses with the sub-processors listed in section 04. We do not transfer personal data to a party that cannot meet an adequate standard of protection.

The transfer mechanism that applies to your engagement is set out in the data processing agreement we sign with you, so that it is a contractual commitment rather than a claim on a web page. If your legal team wants to review it before contracting, ask and we will send it.

10 · Who to speak to

Compliance contacts

Data protection and compliance

Subject access requests, lawful basis questions, sub-processor notices, and data processing agreements.

compliance@kat-i.com

Security incidents

Suspected breaches or security concerns relating to data we hold or have delivered. Mark the subject line urgent.

compliance@kat-i.com

By telephone

For anything on this page that is faster spoken than written.

+1 628 600 9607United States
+44 20 3769 6479United Kingdom
+91 628 942 3558India
+91 877 709 5698India

Before you contract

If procurement needs the certificate, the sub-processor list, or the data processing agreement in advance, ask and we will send them.

Get in touch →

11 · Document history

Version and review

VersionDateChanges
1.0August 2026Initial publication

This page is reviewed annually, and whenever a significant change to our compliance posture occurs. If you are relying on it for a vendor assessment and want to be told when it changes, ask and we will add you to the notification list.

Send it to your legal team

If there is a question on this page we have not answered, it is probably one worth asking. Tell us what your review needs and we will answer it directly rather than point you at a policy.