Customer information needed for insurance applications may be entered into the Zards CRM by authorized staff and shared with the relevant licensed producer or carrier. Payment identifiers and health fields are encrypted in application storage, masked by default, and revealed only through a role-scoped, logged action. Public inquiry forms must not be used to send payment, identity or medical details.
Calls may be recorded for quality assurance and compliance. Recordings are restricted by role, assignment and workflow stage, reviewed for script and disclosure adherence, and retained only as long as required for training, dispute resolution, and legal obligations.
All employees handle customer data under confidentiality obligations. Selling, copying, or removing customer data from company systems is prohibited and grounds for termination and legal action. Staff are trained on do-not-call handling, consent, and data handling at onboarding.
Customer data is shared only with: (a) the licensed insurance producers and carriers needed to complete a requested quote or policy, and (b) infrastructure providers (hosting, email, telephony, advertising measurement) acting on our instructions. We do not sell customer data.
Lead and sales records are retained for operational, tax, and regulatory purposes, then deleted or anonymized. Verified deletion requests from data subjects are honored within 30 days wherever no legal retention duty applies.
Suspected data incidents are contained immediately, investigated by management, and — where legally required or where risk to individuals is material — affected parties and partners are notified without undue delay, along with remediation steps taken.
Security questions or reports: admin@zardsbpo.com · Zards BPO, Office 4A, 1st Floor, Imran Plaza, F-10, Islamabad, Pakistan.