Trust Center
BPO, Digital Factory and UAE corporate services delivered from Dubai by UBTIS — multilingual contact center, custom software, Business Setup, PRO/Visa, Tax/VAT and compliance.
UBTIS Trust Center — Security, Privacy & Compliance
This page describes how UBTIS handles information security, privacy and compliance across BPO, Digital Factory and UAE Corporate Services engagements. Statements below describe UBTIS controls and commitments; platform capabilities (Cloudflare, AWS, Supabase, licensed KYC vendors) are governed by their own certifications; client responsibilities remain with the client.
- Information Security: UBTIS operates its information security program aligned with the ISO/IEC 27001 framework. We describe this posture as "" — not "certified" — because we do not currently hold an active third-party certificate for this operating scope.
- GDPR Compliance: UBTIS acts as a data processor under GDPR (or an equivalent role under UAE PDPL where applicable), with a Data Processing Agreement, SCCs where relevant, and a defined subprocessor list.
- : For engagements that touch payment card data, cardholder-data flows are handled through the client's environment (gateway, IVR pause-and-resume, tokenization). UBTIS does not present itself as a service provider unless a specific engagement is scoped, contracted and certified that way.
- Data Protection & Confidentiality: NDA + MSA + DPA where applicable, per-client data segregation, TLS 1.2+ in transit, encryption at rest where offered by the underlying platform, and return or documented deletion of client data at end of engagement.
- Secure Onboarding & Access Management: Background checks, least-privilege access, MFA on UBTIS-managed accounts, joiner/mover/leaver process, session logging for administrative access.
- SLA & QA Methodology: SLA agreed in writing per engagement; weekly operational reporting; QA scorecard sampled per agent per week; calibration sessions; continuous improvement loop.
- Compliance Commitments: UBTIS supports clients with compliance work inside contracted scope and does not claim regulatory approvals or certificates it does not hold. Any specific certification claim will reference the certificate, its scope and its date.
Contact our security team at contact@ubtis.com for security questionnaires, DPA / SCC requests, subprocessor lists, incident contact or vulnerability reports.