+254 709 370 000
hello@telesky.co.ke

Information Assets Security Control

 

Information Security & Data Protection Policy

Security-oriented

Policy Statement

TeleSky Limited is committed to protecting the confidentiality, integrity, availability, and privacy of all information entrusted to us by our clients, customers, employees, partners, and other stakeholders.

As a provider of Business Process Outsourcing (BPO), Contact Centre, Customer Experience, Digital Services, and Information Technology Solutions, we recognize that information is one of our most valuable assets. Protecting that information is fundamental to maintaining customer trust, meeting contractual obligations, and complying with applicable legal and regulatory requirements.

TeleSky operates an Information Security Management System (ISMS) based on ISO/IEC 27001:2022 and continuously improves its information security controls through risk management, monitoring, internal audits, management reviews, and continual improvement.

ISO 27001 : 2022

Document Number: TS-ISMS-POL-001

Version: 1.0

Classification: Public

Effective Date: June 26, 2026

Review Date: Annually

Approved By: Board of Directors 

Information Security is Key

Policy

Information Security Objectives

TeleSky is committed to achieving the following measurable objectives:

  • Maintain zero confirmed unauthorized disclosure of confidential customer information.
  • Achieve 100% compliance with applicable legal, regulatory and contractual information security requirements.
  • Maintain CRM, telephony and customer service platform availability of at least 99.5%.
  • Achieve 100% completion of mandatory Information Security and Data Protection training by all personnel annually.
  • Apply critical security patches within 72 hours of release or risk assessment.
  • Detect, investigate and respond to all critical security incidents within 24 hours.
  • Conduct annual ISMS internal audits and management reviews.
  • Continuously improve ISMS effectiveness through risk assessments and corrective actions.

Compliance

TeleSky complies with applicable laws and regulations including:

  • ISO/IEC 27001:2022
  • ISO/IEC 27701
  • EU General Data Protection Regulation (GDPR)
  • Kenya Data Protection Act, 2019
  • Kenya Data Protection (General) Regulations
  • Computer Misuse and Cybercrimes Act
  • Employment Act
  • Client contractual security requirements

Other applicable international privacy regulations where services are provided.

Data Protection Commitment

TeleSky processes personal data lawfully, fairly and transparently. We are committed to:

  • Collecting only necessary information.
  • Processing personal data for legitimate business purposes.
  • Maintaining data accuracy.
  • Protecting data using appropriate technical and organizational measures.
  • Retaining information only as long as necessary.
  • Respecting the rights of data subjects.
  • Securely disposing of information when no longer required.

Where required by law, TeleSky enters into Data Processing Agreements with clients and third-party processors.

Information Classification

Classification

Description

Public

Information approved for public disclosure

Internal

Business information intended for internal use only

Confidential

Sensitive business information requiring restricted access

Highly Confidential

Client data, financial information, passwords, authentication credentials, personal information and regulated information requiring the highest level of protection

Call Recording

Where permitted by law or client agreement:

  • Calls may be recorded for quality assurance, compliance, training and dispute resolution.
  • Recordings are protected using encryption and strict access controls.
  • Access is limited to authorized Quality Assurance and Management personnel.
  • Customer Verification: Customer authentication shall be performed using approved Know Your Customer (KYC) procedures before disclosure of confidential information.

Endpoint Security: All company devices shall:

  • Run approved antivirus and endpoint protection.
  • Receive regular security updates.
  • Use encrypted storage where appropriate.

Be centrally managed.

  • Remote Working: Employees working remotely shall:
  • Use company-approved devices where applicable.
  • Connect through secure VPN services.
  • Protect confidential information from unauthorized viewing.
  • Follow the same security standards applicable within TeleSky offices.

Incident Management

Any employee who suspects or discovers:

  • Phishing attempts,
  • Malware,
  • Unauthorized system access,
  • loss or theft of devices,
  • Accidental disclosure of information,
  • Ransomware,
  • Data breaches,
  • Suspicious activity

must immediately report the incident through TeleSky’s Information Security Incident Reporting process. All incidents shall be investigated, documented and managed according to the organization’s Incident Response Procedures. Where legally required, personal data breaches shall be reported to the relevant supervisory authority and affected individuals within applicable regulatory timelines.

Continual Improvement

TeleSky is committed to continually improving its Information Security Management System through:

  • Risk assessments
  • Internal audits
  • Penetration testing
  • Vulnerability assessments
  • Management reviews
  • Corrective and preventive actions
  • Security performance measurement
  • Lessons learned from incidents

 

Contact

For questions regarding this policy or the protection of personal information, please contact:

Information Security Manager
TeleSky Limited

Email: tech@telesky.co.ke

Approval

Version

Date

Approved By

1.0

June 26, 2026

Board of Directors 

Purpose

This policy establishes the principles governing the protection of information assets and personal data processed by TeleSky Limited. The policy aims to: • Protect Confidentiality, Integrity and Availability (CIA) of information. • Protect customer and employee personal data. • Prevent unauthorized access, disclosure, alteration or destruction of information. • Reduce cyber security risks. • Support business continuity. • Comply with applicable legal, contractual and regulatory obligations. • Promote a culture of information security throughout the organization.

Scope

This policy applies to: • All employees • Directors • Temporary staff • Contact Centre Agents • Consultants • Contractors • Vendors • Business partners • Interns • Third-party service providers It applies to all information assets including: • Customer information • Client information • Employee records • Personally Identifiable Information (PII) • Sensitive Personal Data • Voice recordings • Emails • CRM systems • Cloud platforms • Network infrastructure • Servers • End-user devices • Mobile devices • Physical documents • Data stored or processed on behalf of clients.

Principles

TeleSky operates according to the following security principles

Confidentiality: Information shall only be accessible to authorized individuals with a legitimate business need

IntegrityInformation shall be protected against unauthorized modification, destruction or corruption

 Availability: Critical systems and information shall remain available to authorized users whenever required

Accountability: Every employee is personally responsible for protecting company and customer information

Privacy by Design: Privacy and data protection requirements shall be incorporated into all systems, products and business processes from inception.

 Least Privilege: Access rights shall be limited to the minimum necessary to perform assigned duties

 Zero Trust: No user, device or application shall be automatically trusted regardless of network location.

Access Control

TeleSky implements robust access control measures including: Role-Based Access Control (RBAC) Multi-Factor Authentication (MFA) Strong password requirements Least Privilege Periodic access reviews Immediate removal of access following employee separation Secure remote access controls Session timeout controls Sharing user accounts or passwords is strictly prohibited.

Contact Centre Security Controls

Clean Desk and Clean Screen. Employees shall: Lock computers whenever leaving their workstations. Secure confidential documents. Remove sensitive information from desks after each shift. Dispose of confidential documents securely.

Physical Security

TeleSky protects its facilities through: Biometric access control Visitor registration Visitor escorts CCTV surveillance Server room access restrictions Environmental monitoring Secure equipment disposal Emergency preparedness measures

Third-Party Security

All suppliers, contractors and business partners handling TeleSky or client information shall: Meet contractual security requirements. Sign confidentiality agreements where appropriate. Undergo security due diligence where applicable. Comply with applicable privacy laws.

Business Continuity

TeleSky maintains Business Continuity and Disaster Recovery plans designed to: Minimize service interruption. Protect critical customer operations. Ensure timely recovery of systems. Regularly test recovery capabilities.

Security Awareness

All employees shall receive regular Information Security and Data Protection training covering: Cybersecurity awareness Password security Social engineering Phishing GDPR Kenya Data Protection Act Secure handling of customer information Acceptable Use Incident reporting Training effectiveness shall be regularly evaluated.

Employee Responsibilities

Every employee is responsible for: Protecting customer information. Following all security procedures. Maintaining confidentiality. Reporting suspected security incidents immediately. Completing mandatory security training. Complying with this policy and related procedures.

Monitoring and Audit

TeleSky reserves the right to monitor systems, networks and business applications to: Protect customer information. Detect cyber threats. Ensure compliance. Investigate suspected misuse. Monitoring is conducted in accordance with applicable privacy legislation. Internal and external audits are conducted periodically to verify compliance with the Information Security Management System.

Policy Violations

Violation of this policy may result in: Disciplinary action, Suspension of system access, Contract termination, Civil proceedings, Criminal prosecution where applicable