Overhead view of a team around a wooden table covered with laptops, tablets and notebooks, two people shaking hands in the middle.
Security & Compliance

Your customers’ data, protected like our own

Outsourcing support means trusting a partner with your customers’ accounts, their conversations and sometimes their money. ClearLine acts as a processor under a written data processing agreement, keeps card data out of our environment by design, and discloses every sub-processor before it is engaged — never after.

Why it matters to you

Security isn't our paperwork — it's your protection

Behind every control is a concrete outcome for your business and your customers. Here's what our controls buy you.

Your data stays protected

Advisors work in locked-down environments with role-based, least-privilege access, provisioned at hire and revoked the day someone leaves — so customer data is only ever seen by the people who need it.

Every advisor screened before access

Identity, right to work and criminal-record checks are completed before an advisor is given access to any client system, re-run on the cycle a regulated programme requires — and we pay for them, never the applicant.

Privacy by design

GDPR- and CCPA-ready processes for consent and data-subject requests, PCI-aware handling on payment-adjacent queues, and the DPA your compliance team needs — signed before we go live.

The people behind the promise

Credentials our teams hold

Great security starts with trained people. Every check below is run by us, at our cost, before an advisor touches your queue.

BGVVerified

Background verification

Accredited screening provider

Every advisor is screened before their first shift: identity, right to work, employment history and a criminal-record check appropriate to the jurisdiction. Programmes in regulated sectors get enhanced screening and re-screening on the cycle the client's regulator requires. We pay for this. An applicant is never asked to buy their own check.

Run before the first shift, not after it, and paid for by us — an applicant is never asked to buy their own check. Regulated programmes get enhanced screening on the cycle the client's regulator requires.

SEC-AWVerified

Security & data-handling training

ClearLine CX internal programme

Phishing, social engineering, clean-desk discipline, device handling and what to do the moment something looks wrong. Delivered before system access is granted, refreshed annually, and repeated immediately after any incident. Completion is recorded against the advisor's file and is auditable by the client.

Completed before system access is granted rather than during the first week, refreshed annually, and repeated immediately after any incident.

PCI-AWVerified

PCI DSS awareness

Aligned to PCI DSS v4.0 requirement 12.6

Advisors on payment-adjacent queues are trained on cardholder-data handling, pause-and-resume recording, and the rule that card numbers are never written into a ticket, a chat window or a notepad. VERIFY: this describes training aligned to the standard, not a certification of the company — do not describe ClearLine as 'PCI certified' unless and until a QSA has attested it.

Required on any queue where a customer might read a card number aloud. Note this is training aligned to the standard — it is not a QSA attestation of the company.

LANG-B2Verified

Language proficiency assessment

CEFR-aligned internal assessment

Written and spoken assessment in each language the advisor will work in, marked against CEFR descriptors, with a bar of B2 for general queues and C1 for regulated or technical ones. Assessed by us, at our cost, before assignment — a self-declared language on a CV is not evidence.

Assessed by us in each language the advisor will work in, to CEFR descriptors. A language listed on a CV is not evidence.

PRODVerified

Client product certification

Client-approved training programme

Each programme has a product test built with the client. Advisors take live contacts only after passing it, and re-take it when the product changes materially. The pass mark and the content are the client's to set — they are the ones whose customers hear the answers.

The client sets the content and the pass mark, because it is their customers who hear the answers. No live contacts until it is passed.

Standards & controls

The standards we hold ourselves to

Beyond our people's training, these are the regulatory obligations we work under and the internal controls we operate before any customer data reaches us.

SOC2

SOC 2 control practices

AICPA Trust Services Criteria

Access control, change management, monitoring and incident response are run against the Trust Services Criteria for security and confidentiality. VERIFY before publishing any claim of a completed Type I or Type II report — say 'aligned to' until an auditor's report exists.

PCI

PCI DSS handling

PCI Security Standards Council, DSS v4.0

Card data is kept out of our environment by design: pause-and-resume on recordings, no card numbers in tickets or chat transcripts, and payment steps handed to the client's own payment page wherever possible. VERIFY before claiming compliance validated by a QSA.

GDPR

GDPR & UK GDPR

Regulation (EU) 2016/679

We act as a processor for client personal data under a written data processing agreement: documented lawful basis, defined retention, subject-access and erasure requests handled to statutory deadlines, and sub-processors disclosed before they are engaged.

HIPAA

HIPAA administrative safeguards

45 CFR Parts 160 and 164

For healthcare administration programmes only. Protected health information is handled under written administrative, physical and technical safeguards, with a Business Associate Agreement signed before a programme goes live. ClearLine performs no clinical function and gives no clinical advice.

TCPA

TCPA & outbound consent

47 U.S.C. § 227 and FCC rules

Outbound campaigns run against consent records checked before dialling, with do-not-call suppression, calling-window rules applied to the customer's local time, and recording disclosure per jurisdiction. Where a client cannot evidence consent, we do not dial.

A trained team

Great support starts with great people. Build your career with us.

We hire for empathy and potential, then invest in paid training and real supervision — so our advisors can handle difficult conversations with care and confidence. If that sounds like you, there’s a place for you here.

Five smiling contact-centre advisors wearing headsets, standing together beside an office window.

Outsource support without compromising on security

Every programme we run carries the full weight of our controls behind it. Tell us what you need — we'll show you exactly how your customers' data stays protected.