What we build

UK data rules, and how few hours of the working day an automation team shares

Wobble works from Karachi and has no United Kingdom office. The useful version of this page is not a claim about presence. It is the working day arithmetic, the rules that shape what gets built, and the one thing UK buyers ask for that remote suppliers routinely get wrong.

Four to five hours of real overlap, and where they fall

Hiring an AI automation agency in the United Kingdom does not require the agency to be in the United Kingdom. What it requires is a shared working window, a named person who answers, and a build that treats UK data and marketing consent rules as design inputs rather than paperwork added at the end. Wobble works from Karachi and shares four to five hours of the UK day.

Karachi is UTC+5 and does not observe daylight saving. London runs four hours behind through British Summer Time and five hours behind in winter. A Karachi day ending at six in the evening covers the London morning through to the early afternoon, which is four to five hours of genuinely shared working time.

That is a materially better position than most offshore arrangements, and being specific about it changes what is reasonable to expect. A same-day answer to a question raised at nine in London is realistic. A same-day answer to a question raised at four in the afternoon London time is not, and pretending otherwise builds a small disappointment into every week.

The pattern that works is a UK morning used for anything that needs discussion, and the Karachi evening used for the work that came out of it, so answers are waiting when London opens the next day. Used properly the gap becomes a shift handover rather than a delay.

UK data rules are a design input, not a clause in the contract

A UK business handling personal data sits under UK GDPR alongside the Data Protection Act, with the Information Commissioner's Office as regulator. Nothing here is legal advice and your own adviser should confirm what applies to your situation. What is useful from an automation supplier is how the framework changes what gets built.

Three things change concretely. Every automated process needs a stated lawful basis for using the personal data it touches, and having had the data for years is not one of them. A supplier processing personal data on your behalf works under written processor terms, and moving personal data outside the UK requires an approved transfer mechanism, for which the ICO publishes templates.

And a person can ask what you hold about them and ask you to delete it, which means the system has to be able to find every copy of one individual's data and remove it.

The third point is the one that quietly rules out careless design. If customer records end up spread across a spreadsheet, an automation tool's execution history, a document store an assistant reads from and three message logs, answering a deletion request becomes an archaeology project with a deadline attached. Deciding at build time where the single record of a person lives costs an afternoon. Reconstructing it later costs considerably more.

The question that tests a design

Ask any supplier to walk through exactly what happens when a customer asks to be deleted. A considered design answers with a list of places and a process. A weak one answers with reassurance and the word compliant.

Marketing consent rules change how outbound gets built

Alongside data protection, the UK has separate rules covering electronic marketing, which is where email and SMS campaigns live. In plain terms you need an appropriate consent position for what you send, you identify yourself clearly, and you provide a working way to stop. The detail differs between individuals and business contacts, and your adviser should confirm which position applies to your lists.

Building for that means consent is a stored field with a timestamp and a source, attached to the person rather than assumed from the list they arrived on. A purchased spreadsheet with no provenance cannot be messaged, and no amount of clever automation changes that.

It also means the stop path has to run through the automation rather than around it. The standard failure is a person opting out in one channel while a different workflow, reading a different table, keeps them in a sequence somewhere else. That is a design fault rather than bad luck, and it is worth asking a supplier how they prevent it before the first campaign rather than after the complaint.

The named person, which UK buyers ask for and rarely get

The most consistent request from UK clients working with an outside supplier is a person, by name, who knows the account and answers. Not a shared inbox. Not a rotating queue. Not an account manager who takes the question away, asks somebody technical, and comes back the next day with an approximation of the answer.

It is a reasonable request and it should be written into the arrangement rather than promised on a call: who that person is, which hours they cover stated in UK time, what the response window is, and who covers when they are on leave.

A supplier who cannot name that person on the first call is probably running a pool, and a pool means explaining your business again every few weeks to somebody new. The cost of that is invisible on an invoice and considerable in practice.

Which channels actually reach UK customers

Build for where your customers already are rather than for the channel a supplier finds interesting. In the UK, email and SMS still carry most business-to-customer messaging, and the phone still matters for higher-value services. WhatsApp is used heavily in personal life and is growing for business contact, but it is not the default the way it is in Pakistan, and an automation designed around it can end up automating a channel your customers do not use with you.

One platform detail is worth knowing if WhatsApp voice comes up in a proposal. Meta excludes a specific list of countries from business-initiated WhatsApp calling, currently the United States, Canada, Egypt, Vietnam and Nigeria, and the United Kingdom is not among them. Availability is Meta's decision and can change, so it should be verified against current documentation rather than taken from any agency page, including this one.

The underlying point holds whatever the platform does next. Look at where enquiries currently arrive and where replies currently come from, automate that first, then test a second channel deliberately and measure it.

When this arrangement does not fit

If your organisation's own policy requires personal data to stay within the UK and never be accessed from outside it, a team working from Karachi is the wrong shape for the parts of the system that touch that data. That is a policy decision rather than a technical obstacle, and it is better established in week one.

If you are buying through a procurement framework that only permits suppliers already listed on it, fit is irrelevant until that is resolved. Check it before anybody writes a proposal.

If the work requires somebody on site, or staff who have been through a vetting process your sector requires, hire for that locally and use a remote team for the parts that genuinely do not need a body in the room.

And if nobody internally can spend a few hours a week for the first month, wait until they can. The map of how work actually moves cannot be produced without your people, wherever the supplier sits.

The named person who answers, and what the deletion question does to a build

This page says a UK buyer needs a named person who answers, so here they are. Moiz Khan owns automation architecture and decides what gets built and how it runs. Haad owns growth and client solutions and takes the first conversation. Ibrahim owns build and workflows and trains your team as each piece lands. Ali owns marketing and sales. Wobble is based in Karachi, bills month to month rather than annually, and is answerable for what it operates across 25 engagements in six countries. Month to month is the practical answer to the risk a UK buyer is actually weighing, which is being stuck with a supplier in another jurisdiction.

The audit takes the first week and on a UK engagement its most useful output is the answer to the deletion question: a written list of every place one person's data lives, and the process for removing it from each. One named system is live inside a fortnight. Processor terms and the transfer mechanism are settled in that first week rather than at signature, because a build that has to be redesigned around a transfer mechanism in month two is a build that was started too early.

Every workflow is labelled before you approve it. Anything published in your name, any change to advertising spend, any pricing decision and any serious complaint wait for human approval, and an automated workflow that meets something outside its scope hands it to a person with the record attached. Across a four to five hour overlap that rule earns more than it would locally, because a workflow improvising at nine in the evening Karachi time has nobody in London awake to catch it until the morning.

Ownership is the other half of the same protection. The accounts are in your name, the workflows and credentials sit under your logins, and the record of where personal data lives is a document you hold rather than a reassurance you were given, so you own the system and the deletion path stays walkable if the arrangement ends. A UK business with an in-house developer can build the first automation itself, and where that person will still own it next year that is the better answer. The harder thing to keep internally is the single record of a person, decided at build time, holding across every tool that touches them.

Common questions

How do UK data protection rules apply when the build team is outside the UK?

The framework is UK GDPR alongside the Data Protection Act, with the ICO as regulator, and your own adviser should confirm the detail. In practice a supplier processing personal data for you works under written processor terms, and moving personal data outside the UK needs an approved transfer mechanism. The ICO publishes templates for that.

How many hours a day will we overlap with a Karachi team?

Four to five. Karachi is four hours ahead of London through British Summer Time and five ahead in winter, so a Karachi day ending at six in the evening covers the London morning into early afternoon. Questions raised in the London morning can be answered the same day. Questions raised at four in the afternoon usually cannot.

Can we have one named person rather than a ticket queue?

Yes, and it should be written into the arrangement rather than promised verbally: the person's name, the hours they cover stated in UK time, the response window, and who covers their leave. A supplier who cannot name that person on the first call is likely running a pool, which means re-explaining your business every few weeks.

Do the marketing consent rules change how outbound automation is built?

Substantially. Consent becomes a stored field with a timestamp and a source rather than an assumption, every outbound workflow reads one suppression list before sending, and sender identification lives inside the templates. The common failure is somebody opting out in one channel while another workflow keeps sending because it reads a different table.

Is WhatsApp the right channel for UK customers?

Often not as the first channel. Email, SMS and the phone still carry most UK business-to-customer contact, and WhatsApp, while widely used personally, is not the default business channel it is in Pakistan. Look at where your enquiries actually arrive today, automate that, then test a second channel deliberately rather than by assumption.

When is a remote overseas partner the wrong choice for a UK organisation?

When policy requires personal data to stay in the UK and never be accessed from outside it, when you buy through a framework that only permits listed suppliers, when the role needs sector vetting or physical presence, or when nobody internally can give the first month a few hours a week. The last one sinks projects regardless of where the supplier sits.

See where this applies to your business

The AI Readiness Call is a short, free conversation about where automation would actually pay back in your business. The call is free. The diagnosis is not.

Book AI Readiness Call