TaskCentrix Africa — Privacy Policy

Effective Date: August 12, 2026 | Last Updated: August 12, 2026

Section 1

1. Introduction

TaskCentrix Africa ("TaskCentrix," "we," "us," or "our") is a business process outsourcing (BPO) delivery provider operating across various African countries. This Privacy Policy explains how we collect, use, disclose, and safeguard information in the course of our operations, including:

  • Our corporate website and digital properties;
  • Our recruitment, hiring, and employment activities;
  • Delivery of contact centre and BPO services on behalf of our clients.

TaskCentrix operates in two distinct capacities with respect to personal data, and the rules that apply differ depending on which capacity is engaged:

CapacityWhen it appliesWhat it means
Data ControllerOur website visitors, job applicants, employees/agents, vendors, and corporate contactsWe determine why and how this data is processed, and this Policy governs that processing directly.
Data ProcessorEnd-customer data belonging to our clients (e.g., a client's customers who contact us via voice, WhatsApp, email, chat, or ticketing)We process this data only on the documented instructions of our clients, under a signed Data Processing Agreement (DPA). This Policy does not override those instructions. If you are an end-customer of one of our clients, please refer to that client's privacy policy; you may contact us as described in Section 12 and we will route your request to the relevant client.
Section 2

2. Information We Collect

2.1 As a Controller (our own operations)

  • Website visitors: IP address, browser/device type, pages visited, referral source, and cookies (see Section 8).
  • Job applicants: name, contact details, CV/resume, work history, education, references, national ID/passport details where required for background checks, and interview notes.
  • Employees and agents: identity and contact information, employment and payroll records, bank details, tax and statutory registration numbers, performance data, and — where legally required for HR administration — limited health information (e.g., medical certificates for leave).
  • Clients, vendors, and partners: business contact details, contract and billing information.

2.2 As a Processor (on behalf of clients)

When delivering contact centre and BPO services, we may process categories of personal data belonging to our clients' customers, which can include: names, contact details, account or transaction information, call recordings, chat/WhatsApp transcripts, email correspondence, and support ticket content. The specific categories, purposes, and retention periods for this data are defined by each client's instructions and the applicable DPA, not by this Policy.

Section 3

3. How We Use Information

We use personal data we control for purposes including:

  • Operating and improving our website and communications;
  • Recruiting, hiring, onboarding, and managing our workforce;
  • Administering payroll, benefits, and statutory compliance;
  • Managing client, vendor, and partner relationships and contracts;
  • Complying with legal, tax, and regulatory obligations in each jurisdiction we operate in;
  • Protecting the security of our systems and premises (e.g., CCTV at delivery centres, access logs, network monitoring).

Where we act as a processor, data is used strictly for the purposes instructed by the relevant client (e.g., delivering customer support, fulfilling a transaction, resolving a ticket) and for no other purpose.

Section 4

4. Legal Bases for Processing

Depending on the jurisdiction and context, we rely on one or more of the following legal bases, consistent with applicable data protection laws in the countries where we operate:

  • Consent — where you have given clear permission (e.g., marketing communications, cookies);
  • Contractual necessity — to perform an employment contract, client agreement, or vendor arrangement;
  • Legal obligation — to comply with tax, labour, immigration, or regulatory requirements;
  • Legitimate interests — for business administration, fraud prevention, and system security, balanced against your rights; and
  • Client instruction— where we act as a processor, our basis for processing is the client's own legal basis and documented instruction.
Section 5

5. Data Sharing and Disclosure

We may share personal data with:

  • Clients — where we are delivering outsourced services on their behalf;
  • Service providers — IT hosting, workforce management, payroll, and telephony/CX platform providers, under confidentiality and data protection terms;
  • Regulators and authorities — where required by law, court order, or to protect vital interests;
  • Professional advisors — legal, audit, and compliance advisors, under confidentiality obligations.
Notice: We do not sell personal data.
Section 6

6. International and Cross-Border Data Transfers

Given our multi-country footprint, personal data may be transferred between the various jurisdictions in which we operate, as well as to service providers located outside these countries. Where such transfers occur, we take steps required by applicable law — such as standard contractual clauses, adequacy assessments, or explicit consent — to ensure the data remains protected to a comparable standard. Client data processed on a client's instruction is transferred only as authorized by the applicable DPA.

Section 7

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, including to satisfy legal, accounting, or reporting obligations. Retention periods vary by category:

  • Job applicant data: typically retained for 12 months after a recruitment process closes, unless you consent to longer retention for consideration in future opportunities;
  • Employee records: retained for the duration of employment plus 7 years, in line with common statutory record-keeping requirements for tax, labour, and payroll purposes;
  • Client end-customer data (as processor): retained per the applicable client DPA, and deleted or returned to the client within 30 days of the end of the engagement, unless a longer period is contractually required;
  • Website/cookie data: as described in Section 8.
Section 8

8. Cookies and Website Tracking

Our website uses cookies and similar technologies to operate core functionality, understand site usage, and (where enabled) support analytics. You can control cookies through your browser settings; disabling certain cookies may affect site functionality.

CategoryPurposeTypical Duration
Strictly NecessaryEnable core site functionality (navigation, security, load balancing)Session, up to 24 hours
Analytics/PerformanceUnderstand site usage and improve performance (e.g., Google Analytics-type tools)Up to 13 months
FunctionalRemember preferences (e.g., language, region)Up to 12 months
MarketingTrack effectiveness of campaigns and content, where enabledUp to 12 months

Where required by local law, we present a cookie consent banner on first visit allowing you to accept or reject non-essential categories.

Section 9

9. Data Security

We implement technical and organizational measures appropriate to the sensitivity of the data we handle, including access controls, encryption in transit, network monitoring, physical security at delivery centres, staff confidentiality obligations, and vendor due diligence. Call recordings and chat transcripts processed on behalf of clients are secured in line with the applicable client's security requirements and our internal information security policies.

No system is completely secure, and we cannot guarantee absolute security of information transmitted to us.

Section 10

10. Your Rights

Subject to the law of your jurisdiction, you may have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request deletion of your data, subject to legal retention requirements;
  • Object to or restrict certain processing;
  • Withdraw consent where processing is based on consent;
  • Lodge a complaint with your local data protection authority (e.g., the Office of the Data Protection Commissioner in Kenya).
End-Customer Notice: If you are an end-customer of one of our BPO clients, please direct data rights requests to that client in the first instance, as they are the data controller. We will assist our clients in responding to such requests as required by the applicable DPA.
Section 11

11. Children's Privacy

Our services are not directed at children, and we do not knowingly collect personal data from children without appropriate parental or guardian consent, except where incidentally processed as part of a client's customer base and governed by that client's own policies.

Section 12

12. Contact Us

For questions about this Privacy Policy or to exercise your data rights:

TaskCentrix Africa

Data Protection Contact: Data Protection Officer

Email: [email protected]

If your enquiry relates to a specific client's service, please also let's know the client/brand involved so we can route your request appropriately.

Section 13

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements across the markets we operate in. We will post the updated version on this page with a revised "Last Updated" date. Material changes will be communicated through appropriate channels (e.g., website notice, email to registered users).