White-label managed delivery·Multilingual customer experience·Back-office operations·Dedicated, shared and overflow teams·You keep the client·Responsibilities in writing·White-label managed delivery·Multilingual customer experience·Back-office operations·Dedicated, shared and overflow teams·You keep the client·Responsibilities in writing·

What we hold, why we hold it, and what you can ask of us.

How DefrilexCX collects, uses, shares and protects personal information across defrilexcx.com, our talent network and our email programmes. It is written to be read rather than skimmed past, and every statement in it describes what we actually do. Effective 11 September 2026, last updated 11 September 2026.

This version supersedes the version of 11 August 2026.

01who we are and what this covers
Privacy

Sometimes we decide, sometimes we are instructed.

Defrilex LLC, a Florida limited liability company trading as DefrilexCX (“DefrilexCX”, “we”, “us”, “our”), provides managed multilingual customer operations to business process outsourcers (BPOs) and enterprises — customer support, contact centre, technical support, back-office processing and applied AI workflows, delivered by teams we source, credential and operate.

This policy covers defrilexcx.com, our talent network, our email programmes, and the DefrilexCX Marketplace at app.defrilexcx.com where you use it. Defrilex LLC operates more than one brand website, and each one publishes its own copy of this policy. This copy is the one that governs defrilexcx.com. It sits alongside our Terms of Service, which set out the rules for using the site itself.

The two roles we play

Data protection law separates two things: deciding why personal data is handled, and handling it because someone else told you to. The first role is called Controller, the second Processor. We occupy both, in different situations, and which one applies decides who you should go to when you want something done about your data.

  • 01ControllerFor website visitors, business prospects, mailing list subscribers and members of our talent network. We chose what to collect and why, so you exercise your rights directly against us and we answer you directly.
  • 02ProcessorFor personal data we handle on behalf of a client — above all, information about the client’s own end customers that arises when our teams handle a customer interaction on the client’s behalf. We act on that client’s documented instructions and nothing else. If you are one of those end customers, the client is your first point of contact, and we support them in answering you.
02whose data we process
Privacy

Five groups of people. Find yourself here.

Five groups of people appear in this policy. Find yourself here, then read the rest with that group in mind.

  • 01Website visitorsAnyone browsing defrilexcx.com.
  • 02Business prospects and clientsProfessionals who enquire about our services, request documentation, run a pilot, or manage a live client account.
  • 03TalentMultilingual customer-service and support agents, technical and sales support, and back-office professionals who apply to join our network, or who are already members of it.
  • 04SubscribersPeople who signed up for job alerts or network updates.
  • 05Client end customersIndividuals — customers, callers, claimants — who contact a client’s service and are helped by our teams. We handle this data as a Processor for the client.
03what we collect
Privacy

What we hold depends on why you came to us.

Who you areWhat we collect
Website visitorsServer logs needed for security and performance — IP address, user agent, pages requested, timestamps. No advertising or analytics trackers run on this site.
Business prospects and clientsName, work email, company, role, and whatever you choose to tell us in an enquiry, a capacity check request or a documentation request. For active clients, contract, scheduling and billing records.
TalentName, contact details, country, languages, proficiency, experience, certifications, availability and working setup. Background check results where a role requires one and you consent. Payment details needed to pay you.
SubscribersEmail address, name, which lists you belong to, subscription status, and delivery logs such as bounces and complaints.
Client end customersThe content of customer interactions our teams handle on the client’s behalf — calls, chats, emails and tickets — together with any recordings, transcripts or case notes the client requires. This can include payment details, health information or other sensitive categories.
Recorded customer interactions

Handling customer interactions for clients is our core service, so it is worth being blunt about what happens to them. Our teams take calls, chats, emails and tickets on a client’s behalf. Those interactions are recorded, transcribed or stored where the client requires it — for quality assurance, training, dispute resolution and regulatory compliance. The client is the Controller for that material. We act as Processor on the client’s documented instructions, and the client sets the retention period.

If you want access to a recording of your own interaction, or you want it deleted, approach the client whose service you were using. They hold the decision, and we will assist them in answering you.

Our agents remain bound by confidentiality. They are required to work in a private, secure environment where the conversation cannot be overheard, they may not store customer data on personal devices, and they may not make their own recordings outside the client’s approved systems. Where interactions involve payment details or other sensitive categories, additional handling restrictions apply under the client contract.

Sensitive information

We do not ask website visitors or business prospects for sensitive personal information, and you should not send it to us through a web form. Where sensitive information does reach us — health information disclosed during a customer interaction on a healthcare programme, or a background check result for a talent application — we use it only for the purpose it was provided for, and we disclose it to no one else except as set out in section 08.

04how we use it
Privacy

Delivery, matching and payment. Nothing sold to anyone.

We use personal information to:

  • 01 Provide, operate and improve our customer-operations, back-office and staffing services
  • 02 Match talent to client programmes on language, credentials and availability
  • 03 Respond to enquiries and manage client and talent relationships
  • 04 Send job alerts and network updates to the people who asked for them
  • 05 Process payments to talent and invoice clients
  • 06 Vet and credential talent, including background checks where a role requires one
  • 07 Secure our systems, prevent fraud and abuse, and investigate incidents
  • 08 Comply with legal, tax and regulatory obligations

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not buy, rent or scrape contact lists. We have never done any of these things, and this policy would have to change before we could.

Automated decision-making

Matching talent to assignments is assisted by automated ranking on objective criteria such as language, certification and availability. No decision that materially affects a person — acceptance into the network, engagement for an assignment, removal from one — is made by automated means alone. A person reviews the shortlist and decides. If you believe a decision about you was made automatically, ask us and a human being will review it.

06cookies and tracking
Privacy

No banner, because there is nothing to consent to.

This is the shortest section in this policy, and deliberately so.

defrilexcx.com sets no cookies at all. There is no advertising pixel, no analytics tag, no tag manager, no session replay and no third-party tracker on this website. That is why no cookie banner has interrupted your reading — there is nothing to consent to.

The one piece of browser storage this site uses is a single sessionStorage entry that remembers which job listing you came from, so an application carries the right context with it. It is deleted the moment you close the tab, it never leaves your browser, and it holds no personal data.

Fonts

The typefaces on this site are loaded from Google’s font service. That is a request to a third party, so your IP address and browser user-agent reach Google each time a page loads. The font service sets no cookie, it is not a tracker, and nothing about you comes back to us from it — but it is still a disclosure to Google that you did not choose to make, so it belongs in this section. We are moving to self-hosted font files to remove the request.

The Marketplace platform

The Marketplace at app.defrilexcx.com uses strictly necessary cookies to keep you signed in, hold your session together and protect against cross-site request forgery. Those cookies cannot be switched off, because the platform cannot authenticate you without them. The Marketplace runs no advertising or analytics cookies either.

You can block or delete cookies in your browser settings. Doing so changes nothing on this website, because there is nothing here to block. It will stop you signing in to the Marketplace.

07email, consent and unsubscribing
Privacy

Double opt-in to get in, one click to get out.

We email job alerts and network updates to people who joined our talent network or subscribed on defrilexcx.com. Public signups use double opt-in: you confirm your address by clicking a link in a confirmation email, and until you do, we send you nothing else.

Every marketing email carries a one-click unsubscribe link and the postal address of our head office. Unsubscribing takes effect immediately — not within the ten business days the law allows us, which is a window we have no use for.

When you unsubscribe, or when your address hard-bounces, we add it to a suppression list. We keep that list indefinitely, because deleting it is exactly how companies end up emailing people who already asked them to stop. The list holds the minimum needed to recognise your address and keep it out of every send, and it is used for nothing else. It is never a marketing list.

Operational messages are different from marketing. Assignment details, payment notifications, security alerts and notices about changes to this policy are part of the service you have with us, so unsubscribing from job alerts does not switch them off. If you want to leave the network altogether, tell us and we will close your profile.

08who we share data with
Privacy

Named providers, and the people who handle the conversation.

We share personal information with the service providers that help us operate. Each one is bound by a written agreement that limits it to processing on our instructions, and none of them may use your data for their own purposes.

ProviderPurposeLocation
Hetzner Online GmbHMailing list and infrastructure hostingFinland
Amazon Web Services (SES)Transactional and bulk email deliveryUnited States
RailwayApplication hosting for the MarketplaceUnited States
Microsoft 365 & Google WorkspaceEmail, productivity and internal collaborationUnited States
Checkr, Inc.Background checks and vetting, where a role requires one and the person consentsUnited States
Wise and PayPalPayments to talentUnited States and European Union
Our agent network

Delivering a customer-operations service necessarily means a person handles the conversation. There is no way around that, so we state it plainly: our vetted customer-service and support agents, technical and sales support, and back-office professionals act as our subprocessors when they handle client and end-customer information. They are bound by written confidentiality and data protection obligations that survive the end of their engagement, they may not store end-customer data on personal devices or make their own recordings outside the client’s approved systems, and they must work in a private, secure environment.

Other disclosures
  • 01ClientsWhere you are engaged on a client programme, we pass the client the professional information it needs to credential and schedule you.
  • 02Professional advisersLawyers, accountants, auditors and insurers, each under a duty of confidentiality.
  • 03Legal and safetyWhere the law, a court order or a valid request from a public authority requires it, or where disclosure is necessary to protect the rights, safety or property of any person.
  • 04Corporate transactionsIn a merger, acquisition, financing or sale of assets, personal information can transfer as part of the transaction. We will tell you, and the protections in this policy continue to apply to the data that moves.

We update this list when our providers change. Clients under a Data Processing Agreement receive advance notice of any new subprocessor and may object, on the terms set out in that agreement.

09international transfers
Privacy

Standard Contractual Clauses, and no badge we have not earned.

We are established in the United States and our network spans many countries, so personal information crosses borders, including into the United States.

Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies. We carry out transfer impact assessments where they are required, and we document the outcome.

Some of our United States providers are self-certified under the EU–US Data Privacy Framework and its UK and Swiss extensions. Where a provider holds a current certification, Defrilex may rely on that certification for transfers to that provider. Defrilex LLC does not itself claim Data Privacy Framework certification, and relies on Standard Contractual Clauses for transfers to itself.

You can ask for a copy of the safeguards that apply to your data. Write to us at the address in section 15 and we will send it.

10how long we keep data
Privacy

Every category has a clock, and here is what each one reads.

DataRetention period
Talent profilesThe duration of your membership in the network, plus three years, so we can answer credentialing queries and disputes about past assignments.
Unsuccessful applicationsTwelve months from the decision, unless you ask us to keep your profile on file for future openings.
Client and contract recordsSeven years after the last service, for tax, audit and limitation-period purposes.
Business prospect recordsTwo years after our last meaningful contact with you.
Mailing list membershipUntil you unsubscribe.
Suppression listIndefinitely, so that we keep honouring your opt-out. See section 07.
Server and security logsTwelve months.
Customer interaction records and recordingsRetained for the period set by the client’s contract, and returned or deleted at the end of the engagement. The client sets that period, not us.

Where the law obliges us to keep something longer — a tax record, or data covered by a litigation hold — we keep it for as long as that obligation lasts and delete it when the obligation ends.

11your rights
Privacy

The same core rights, wherever you happen to live.

Which rights you hold by law depends on where you live. We extend the core rights — access, correction and deletion — to everyone, wherever you are, because operating two standards is how mistakes happen.

  • 01 Access a copy of the personal information we hold about you
  • 02 Correct anything that is inaccurate or incomplete
  • 03 Delete your information, subject to the obligations that require us to keep some of it
  • 04 Port your data to another provider in a structured, machine-readable format
  • 05 Object to or restrict processing, including processing based on legitimate interests
  • 06 Withdraw consent at any time, where the processing rests on consent
  • 07 Limit the use of sensitive personal information to what is necessary to deliver the service
  • 08 Opt out of sale or sharing. We sell nothing and share nothing for cross-context behavioural advertising, so there is nothing to opt out of — the right still stands, and we will honour any request made under it
  • 09 Not be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or give you a lesser standard of service because you asked
How to exercise them

Write to privacy@defrilex.com with “Privacy request” in the subject line. You can also reach us through our enquiry page or at the postal address in section 15.

We acknowledge every request within ten days and respond substantively within thirty days. Where a US state statute allows forty-five days and your request is genuinely complex, we use the longer period and we tell you that we are doing so, before the thirty days are up.

We verify your identity before acting on a request, and ask only for what is necessary to do it. An authorised agent can submit a request for you with written proof of authority.

Global Privacy Control

We honour the Global Privacy Control signal. Because we neither sell nor share personal information, the signal changes nothing about how we treat you. It is respected all the same, and we would rather recognise it than argue about whether we have to.

Complaints

If you are unhappy with how we have handled your information, tell us first and we will try to put it right. You also have the right to complain to a supervisory authority, and you do not need our permission to do it.

  • 01European Economic AreaThe data protection authority where you live, where you work, or where the issue arose.
  • 02United KingdomThe Information Commissioner’s Office.
  • 03BrazilThe Autoridade Nacional de Proteção de Dados.
  • 04United StatesYour state Attorney General, where your state provides that route.
12security
Privacy

What we do to prevent it, and what we do when it happens anyway.

We apply technical and organisational measures proportionate to the risk: encryption of data in transit and at rest, role-based access control granted on a least-privilege basis, multi-factor authentication on staff and administrative accounts, and monitoring of our networks and applications. Confidentiality and security obligations are written into every contract and flow down to everyone who handles data on our behalf.

Talent must work in a private, secure environment, may not make their own recordings outside the client’s approved systems, and may not store end-customer information on personal devices.

No system is perfectly secure, and any company that tells you otherwise is overselling. What we can promise is what we do when something goes wrong. If a breach affects your personal information, we notify you and the relevant regulators within the timeframes the law sets. Where we are acting as a Processor, we notify the client without undue delay so the client can meet its own obligations.

If you think you have found a vulnerability in our systems, report it to privacy@defrilex.com. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before disclosing it.

13children
Privacy

Adults only, with one honest exception.

Our services and our talent network are for adults aged eighteen and over. This website is not directed at children, and we do not knowingly collect personal information from anyone under eighteen. If you believe a child has given us personal information, contact us and we will delete it.

A customer interaction can involve a minor — a child named on a family account, for instance. That information belongs to the client as Controller. It is handled under the client’s instructions and the Data Processing Agreement we hold with them, and the client is the right place to direct any request about it.

14changes to this policy
Privacy

Thirty days of notice, and a dated version you can point to.

We update this policy when our practices change or the law does. The effective date at the top of this page always names the version you are reading.

Where a change materially affects your rights or how we use your information, we give at least thirty days’ notice before it takes effect — by email to subscribers and network members, and by prominent notice on this website. Where a change needs your consent, we ask for it rather than assume it.

This policy supersedes the version of 11 August 2026. Previous versions are available on request. Changes to the rules for using the site are handled separately in our Terms of Service.

15how to contact us
Privacy

One address, one inbox, one telephone number.

For any privacy question, or to exercise a right under section 11:

Defrilex LLC
12000 Biscayne Blvd, Suite 205
Miami, FL 33181
United States

Email privacy@defrilex.com
Telephone +1 (888) 982-0561
Online contact DefrilexCX

If you are a client exercising rights on behalf of your own data subjects, route the request through your account manager so we can handle it under the Data Processing Agreement we hold with you. That keeps the record straight on both sides.

Issued by

FRITZ GERALD ZEPHIRIN

Defrilex LLC

11 September 2026