Information Assets Security Control
Information Security & Data Protection Policy
Security-oriented
Policy Statement
TeleSky Limited is committed to protecting the confidentiality, integrity, availability, and privacy of all information entrusted to us by our clients, customers, employees, partners, and other stakeholders.
As a provider of Business Process Outsourcing (BPO), Contact Centre, Customer Experience, Digital Services, and Information Technology Solutions, we recognize that information is one of our most valuable assets. Protecting that information is fundamental to maintaining customer trust, meeting contractual obligations, and complying with applicable legal and regulatory requirements.
TeleSky operates an Information Security Management System (ISMS) based on ISO/IEC 27001:2022 and continuously improves its information security controls through risk management, monitoring, internal audits, management reviews, and continual improvement.
ISO 27001 : 2022
Document Number: TS-ISMS-POL-001
Version: 1.0
Classification: Public
Effective Date: June 26, 2026
Review Date: Annually
Approved By: Board of Directors
Information Security is Key
Policy
Information Security Objectives
TeleSky is committed to achieving the following measurable objectives:
- Maintain zero confirmed unauthorized disclosure of confidential customer information.
- Achieve 100% compliance with applicable legal, regulatory and contractual information security requirements.
- Maintain CRM, telephony and customer service platform availability of at least 99.5%.
- Achieve 100% completion of mandatory Information Security and Data Protection training by all personnel annually.
- Apply critical security patches within 72 hours of release or risk assessment.
- Detect, investigate and respond to all critical security incidents within 24 hours.
- Conduct annual ISMS internal audits and management reviews.
- Continuously improve ISMS effectiveness through risk assessments and corrective actions.
Compliance
TeleSky complies with applicable laws and regulations including:
- ISO/IEC 27001:2022
- ISO/IEC 27701
- EU General Data Protection Regulation (GDPR)
- Kenya Data Protection Act, 2019
- Kenya Data Protection (General) Regulations
- Computer Misuse and Cybercrimes Act
- Employment Act
- Client contractual security requirements
Other applicable international privacy regulations where services are provided.
Data Protection Commitment
TeleSky processes personal data lawfully, fairly and transparently. We are committed to:
- Collecting only necessary information.
- Processing personal data for legitimate business purposes.
- Maintaining data accuracy.
- Protecting data using appropriate technical and organizational measures.
- Retaining information only as long as necessary.
- Respecting the rights of data subjects.
- Securely disposing of information when no longer required.
Where required by law, TeleSky enters into Data Processing Agreements with clients and third-party processors.
Information Classification
Classification | Description |
Public | Information approved for public disclosure |
Internal | Business information intended for internal use only |
Confidential | Sensitive business information requiring restricted access |
Highly Confidential | Client data, financial information, passwords, authentication credentials, personal information and regulated information requiring the highest level of protection |
Call Recording
Where permitted by law or client agreement:
- Calls may be recorded for quality assurance, compliance, training and dispute resolution.
- Recordings are protected using encryption and strict access controls.
- Access is limited to authorized Quality Assurance and Management personnel.
- Customer Verification: Customer authentication shall be performed using approved Know Your Customer (KYC) procedures before disclosure of confidential information.
Endpoint Security: All company devices shall:
- Run approved antivirus and endpoint protection.
- Receive regular security updates.
- Use encrypted storage where appropriate.
Be centrally managed.
- Remote Working: Employees working remotely shall:
- Use company-approved devices where applicable.
- Connect through secure VPN services.
- Protect confidential information from unauthorized viewing.
- Follow the same security standards applicable within TeleSky offices.
Incident Management
Any employee who suspects or discovers:
- Phishing attempts,
- Malware,
- Unauthorized system access,
- loss or theft of devices,
- Accidental disclosure of information,
- Ransomware,
- Data breaches,
- Suspicious activity
must immediately report the incident through TeleSky’s Information Security Incident Reporting process. All incidents shall be investigated, documented and managed according to the organization’s Incident Response Procedures. Where legally required, personal data breaches shall be reported to the relevant supervisory authority and affected individuals within applicable regulatory timelines.
Continual Improvement
TeleSky is committed to continually improving its Information Security Management System through:
- Risk assessments
- Internal audits
- Penetration testing
- Vulnerability assessments
- Management reviews
- Corrective and preventive actions
- Security performance measurement
- Lessons learned from incidents
Contact
For questions regarding this policy or the protection of personal information, please contact:
Information Security Manager
TeleSky Limited
Email: tech@telesky.co.ke
Approval
Version | Date | Approved By |
1.0 | June 26, 2026 | Board of Directors |
Purpose
Scope
Principles
TeleSky operates according to the following security principles
Confidentiality: Information shall only be accessible to authorized individuals with a legitimate business need
Integrity: Information shall be protected against unauthorized modification, destruction or corruption
Availability: Critical systems and information shall remain available to authorized users whenever required
Accountability: Every employee is personally responsible for protecting company and customer information
Privacy by Design: Privacy and data protection requirements shall be incorporated into all systems, products and business processes from inception.
Least Privilege: Access rights shall be limited to the minimum necessary to perform assigned duties
Zero Trust: No user, device or application shall be automatically trusted regardless of network location.