Answer first: VAConnect places South African professionals for UK, Ireland and Scotland clients. Security is practical: strict NDAs, POPIA compliance with a GDPR-aligned posture, client-owned cloud systems, and LastPass (or an equivalent) so VAs never see raw passwords. We do not claim GDPR certification.
Controls
NDA: every VA signs one; you may add yours. Access: you create and revoke accounts; your CRM, email alias, cloud files, phone number and dialler remain yours. Cloud: files stay in your Drive, SharePoint, Dropbox or OneDrive. Screening: references, skills checks and a 45-minute Boiler Room; 80%+ is required to reach your shortlist. Continuity: SOPs, no passwords in WhatsApp, no parallel CRM.
GDPR for UK and Ireland
We are POPIA compliant and GDPR-aligned in practice. DPAs, UK GDPR clauses and data scope belong on a strategy call with Karen van Zyl. This is not legal advice. We do not lead with HIPAA or other US frameworks.
FAQ
1. Do VAs sign an NDA?
Yes. Every VA signs a strict NDA; you may add a client-specific NDA.
2. Are you GDPR certified?
No. We are POPIA compliant with a GDPR-aligned posture.
3. Who owns systems and the phone number?
You do: accounts, cloud, CRM, email alias, number, dialler and records.
4. How do we share passwords and files?
Use LastPass or an equivalent manager and your cloud.
5. Do you claim HIPAA compliance?
No. This page is GDPR/POPIA-first; discuss required frameworks at discovery.