Legal

GDPR & Data Processing

Last updated: 5 October 2026. Hiring a GDPR compliant offshore agency means knowing who controls the data, where it goes and what's in the contract. Here's how Intelligent Solutions Tech handles each of those.

Our role under GDPR and UK GDPR

Intelligent Solutions Tech is based in DHA Phase 1, Lahore, Pakistan, and works for clients in the European Union, the United Kingdom, the United States, Canada and Australia. The EU GDPR and UK GDPR apply to our work when we handle personal data of people in the EU or UK.

We play two roles. For data collected on our own website (contact form, audit requests, newsletter sign-ups and analytics), we’re the controller, and our privacy policy explains what we do with it. For personal data in your systems that we handle while doing client work, such as CRM contacts, customer emails or order records, we’re your processor and act only on your documented instructions.

What to check when hiring a GDPR compliant offshore agency

Before an agency outside the EU or UK touches your customer data, you should have answers to five questions: Is there a signed data processing agreement? Which sub-processors will see the data? What legal mechanism covers the transfer? Who on their side has access? What happens to the data when the contract ends? The sections below give our answers.

Data processing agreement

We sign a data processing agreement (DPA) with any client whose work involves personal data. It covers the subject matter and duration of processing, the types of data and data subjects, our duty to act only on your instructions, confidentiality of our staff, security measures, use of sub-processors, help with data subject requests, breach notification, and return or deletion of data at the end. We can sign your DPA or provide ours.

To request a DPA, email hassan@intelligentsolutionstech.com.

International transfers

Pakistan doesn’t have an adequacy decision from the European Commission or the UK government. So when personal data moves from the EU or UK to us, we put the European Commission’s Standard Contractual Clauses in place, together with the UK International Data Transfer Addendum for UK data, as part of our DPA. We also assess the transfer and the safeguards around it.

Our own providers, such as Google Workspace, use their own approved transfer mechanisms for data they store.

Sub-processors

We use a short list of sub-processors, such as Google Workspace for email and file storage, and, where your contract allows it, AI services that help process client work, like drafting content or extracting data from documents. We only use AI providers whose business terms say they don’t train their models on customer data.

Your DPA lists the sub-processors for your project. We’ll tell you before adding a new one, and you can object.

How we protect client data

Wherever possible we work inside accounts you own, like your CRM, Google Workspace or hosting, so you control access and can remove it at any time. Access is limited to the people working on your account. Team members are bound by confidentiality terms, and we sign client NDAs on request.

We collect only the data a task needs, avoid copying client data into personal devices or unapproved tools, and use test data when building automations where we can. If we become aware of a personal data breach affecting your data, we’ll notify you without undue delay so you can meet your own reporting duties.

Data subject rights and end of contract

If a person asks you to access, correct, delete or export their data, we’ll help you respond within the legal deadline. If a request reaches us directly about data we process for you, we’ll pass it to you.

When the contract ends, we return or delete your personal data as the DPA says, unless the law requires us to keep some of it.

For questions about GDPR, UK GDPR or this page, email hassan@intelligentsolutionstech.com. See also our cookie policy and terms of service.