tupi.solutions
  • Products
  • About
  • News
  • For Interpreters
  • For Agencies
  • Trust Centre
  • Contact
Log In
  • Products
  • About
  • News
  • For Interpreters
  • For Agencies
  • Trust Centre
  • Contact
Log In

Data Processing Agreement

Standard terms · Version 1.3 · Effective 20 September 2026

These are the standard data processing terms on which Tupi Solutions Limited processes personal data on behalf of an Agency. They are published, not negotiated, and apply identically to every Agency. They take effect when an Agency accepts them in an Agency Agreement Schedule, and they form part of the agreement between us.

If you are evaluating Tupi and need these terms signed as a standalone document, the same text is available as a countersigned agreement on request from info@tupi.solutions.

1. What these terms cover

1.1 “Tupi”, “we”, “us” means Tupi Solutions Limited, company number 17220183, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.

1.2 “Agency”, “you” means the organisation identified in the Agency Agreement Schedule that accepts these terms.

1.3 “Software” means the TupiEx mobile application and the TupiNow and TupiManage web applications.

1.4 “Agency Data” means personal data we process on your behalf in providing the Software.

1.5 UK GDPR, DPA 2018, controller, processor, personal data, processing, data subject and personal data breach carry the meanings given in the UK General Data Protection Regulation and the Data Protection Act 2018.

1.6 These terms are part of the agreement under which we provide the Software (the Services Agreement). Where the two conflict on the processing of personal data, these terms prevail.

2. Who is controller and who is processor

2.1 For Agency Data, you are the controller and we are the processor. This covers everything entered into or generated within the Software in the course of your business, interpreter records, bookings and assignments, job sheets, expenses, invoices, rates and client records.

2.2 We are an independent controller for a separate and narrow set of processing: operating and securing the Software, managing your account and billing contact, service communications, and improving the Software using aggregated or anonymised data. Our Privacy Notice governs that processing, not these terms.

2.3 Where an individual uses the free core functionality of TupiEx for their own purposes rather than on your instruction, we are the controller of that use.

3. Our obligations

We shall:

3.1 Process only on your documented instructions, including as to transfers outside the UK, unless we are required to do otherwise by law, in which case we will tell you before processing, unless the law forbids it. The Services Agreement, these terms, and your configuration and use of the Software together constitute your documented instructions.

3.2 Tell you if an instruction looks unlawful. We will notify you immediately if, in our opinion, an instruction infringes data protection law.

3.3 Impose confidentiality on every person authorised to process Agency Data, by contract or by statutory duty.

3.4 Apply the security measures in Annex B, appropriate to the risk, in accordance with Article 32 UK GDPR. We may update those measures provided the level of protection is not reduced.

3.5 Engage sub-processors only under clause 4.

3.6 Help you answer data subjects. Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as possible, in responding to requests to exercise data subject rights. If a data subject contacts us directly about Agency Data we will not answer substantively; we will refer them to you and tell you promptly.

3.7 Help you with security, breaches and impact assessments under Articles 32 to 36 UK GDPR, taking into account the nature of the processing and the information available to us.

3.8 Return or delete Agency Data at the end of the Services, under clause 8.

3.9 Show our working. Make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits under clause 9.

4. Sub-processors

4.1 You give us general written authorisation to engage sub-processors, subject to this clause.

4.2 Our sub-processors are listed in Annex C and maintained on our published sub-processor page. That page is the authoritative list.

4.3 We will give at least 30 days’ notice before adding or replacing a sub-processor, by updating the published list and notifying the contact you nominate in the Schedule.

4.4 You may object on reasonable data protection grounds within that period. We will discuss it in good faith. If we cannot resolve it, you may terminate the affected Services on written notice without penalty, save for fees already incurred.

4.5 We will impose on each sub-processor, by written contract, data protection obligations materially equivalent to these terms, and we remain fully liable to you for each sub-processor’s performance.

4.6 An accounting package you connect is not our sub-processor. Where you connect your own accounting package (Intuit QuickBooks, Sage Accounting or FreeAgent), that connection is your instruction, made under your own agreement with that provider. See clause 10.4.

5. Where your data goes

5.1 We host and process Agency Data in the United Kingdom. Inbound email receiving operates in Ireland, which is covered by UK adequacy regulations.

5.2 We will not transfer Agency Data outside the UK except to a country covered by UK adequacy regulations, or under an appropriate Article 46 safeguard (the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses), with a transfer risk assessment where one is required.

5.3 We will give you details of the safeguards applying to any transfer on request.

5.4 The current position for each sub-processor is in Annex C.

6. If there is a breach

6.1 We will notify you without undue delay and within 24 hours of becoming aware of a personal data breach affecting Agency Data, using the security contact in your Schedule.

6.2 We will tell you, so far as we know it: what happened, the categories and approximate number of data subjects and records affected, the likely consequences, what we have done or propose to do, and who to speak to. Where we cannot provide everything at once we will follow up without undue further delay.

6.3 We will take reasonable steps to contain and remediate, and will not make any public statement identifying you without your written consent unless the law requires it.

6.4 Notifying the Information Commissioner’s Office and affected data subjects is your responsibility as controller.

7. Data subject rights

7.1 The Software gives you self-service access to Agency Data sufficient to answer most access, rectification and portability requests without involving us.

7.2 Where you do need us, we will respond within 5 working days of a written request, and in any event in time for you to meet your statutory deadline.

7.3 That assistance is free, except that we may charge reasonable costs for requests that are manifestly unfounded, excessive or repetitive.

8. Ending the service

8.1 On termination or expiry you may export Agency Data through the Software for 30 days.

8.2 After that, and at your written election, we will delete or return Agency Data within 90 days and delete existing copies, unless the law requires us to keep them.

8.3 Backups. Agency Data may remain in encrypted backups after deletion under clause 8.2 until those backups expire. Backups are taken daily and retained for 21 days, so a backup copy persists for up to 21 days. We will not restore or otherwise process backup copies except to recover the service, and we delete them when their retention period expires.

8.4 We will certify deletion in writing on request.

9. Audit

9.1 We will make available, on written request and no more than once in any 12-month period, the information reasonably necessary to demonstrate compliance with these terms.

9.2 We may satisfy clause 9.1 with a current third-party certification, independent assessment report, or completed security questionnaire, where that addresses your reasonable enquiries.

9.3 Where that is genuinely insufficient, you may audit on 30 days’ written notice, in business hours, subject to reasonable confidentiality undertakings, without unreasonable disruption, and no more than once a year, unless a personal data breach has occurred or a regulator requires it. Each party bears its own costs.

9.4 Nothing here requires us to disclose information that would compromise the security or confidentiality of another customer’s data.

10. Your obligations

You warrant and undertake that:

10.1 Lawful basis. You have a lawful basis under Article 6 UK GDPR for all personal data you enter into or generate through the Software, and your instructions comply with data protection law.

10.2 People who are not users. You have a lawful basis for personal data you record about people who do not use the Software, in particular the person an interpreting assignment is for, and you have given them the privacy information required by Articles 13 and 14, or can rely on an exemption.

10.3 Special category and criminal offence data. Where what you record reveals special category data under Article 9, including where the context of an assignment reveals health data, or relates to criminal convictions and offences under Article 10, including where you record the legal category of a matter, you have identified an appropriate condition under Schedule 1 DPA 2018 and, where required, maintain an appropriate policy document.

10.4 Accounting packages you connect. Where you connect an accounting package: the connection is your instruction to us; you contract directly with that provider and are responsible for that relationship, including any transfer of personal data outside the UK and any data residency position you rely on; and you have satisfied yourself as to what is transmitted, having been told by us that invoice line descriptions may carry the booking context you recorded, including the name of the person the assignment is for and, where you record it, the legal category of the matter, and that where the package accepts attachments, the supporting documents go with the invoice or bill: job sheets and receipts, and an interpreter’s own invoice.

10.5 Your own users. You are responsible for managing your users’ accounts, for the accuracy of what you enter, for setting appropriate access levels, and for withdrawing access promptly when someone no longer needs it.

10.6 Retention. You have decided appropriate retention periods for Agency Data and will instruct us accordingly.

11. General

11.1 Liability under these terms is subject to the limitations and exclusions in the Terms of Service. Liability arising from a breach of these terms falls within the cap in clause 12.3 of those Terms (the total Fees paid or payable in the six months before the event giving rise to the claim), except for the categories that clause 12.1 leaves unlimited.

11.2 Term. These terms take effect when you accept them and continue while we process Agency Data.

11.3 Changes to these terms. We may update these standard terms. Where a change is material, meaning it reduces our obligations, reduces the protection given to Agency Data, or materially changes your rights, we will give you at least 30 days’ written notice before it takes effect, and you may terminate the affected Services without penalty if you do not accept it. Non-material changes, such as correcting an error or clarifying wording, take effect on publication. Every version is dated and archived, and superseded versions remain available on request.

11.4 Changes in law. We will negotiate in good faith any amendment required by a change in data protection law or regulatory guidance.

11.5 Governing law. These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.


Annex A: Details of the processing

Subject matter. Provision of the Software to the Agency for managing language interpreting and translation services.

Duration. The term of the Services Agreement, plus the periods in clause 8.

Nature and purpose. Hosting, storage, retrieval, organisation, transmission and deletion of Agency Data for: interpreter records and onboarding; scheduling and availability; booking and assignment; call and assignment records; job sheet and expense submission and approval; rate cards and pricing; invoicing to the Agency’s clients, and self-billing or receipt of interpreter invoices; notification by email and SMS; and AI-assisted document extraction and email classification as described in our Privacy Notice.

Categories of data subject

CategoryNotes
Interpreters and candidate interpretersEngaged by, or applying to, the Agency
Agency staff and administratorsUsers of TupiManage
The Agency’s client organisations’ staffRequestors and bookers using TupiNow
People an assignment is forEnd users, data subjects who never use the Software and have no relationship with Tupi

Categories of personal data

Interpreters. Name, trading name, postal address, city, postcode, country, email address, telephone numbers, profile photograph, transport mode, languages, qualifications and qualification levels, security clearances, availability and time off, contact devices including telephone, SIP and mobile identifiers, performance feedback and ratings, account status.

Interpreter financial and identity data. Business type, company registration number, VAT number, Unique Taxpayer Reference, National Insurance number, and bank details (account holder name, bank, sort code, account number).

Interpreter documents. Files uploaded as evidence, which may include identity documents, right-to-work documents, qualification certificates and background-check results. These may constitute special category or criminal offence data.

Agency and client organisation contacts. Name, role, email address, telephone number, organisational unit, procurement and finance contacts, invoice addresses, billing references.

Bookings and assignments. Date, time, duration, language, service type, assignment address and geographic coordinates, client reference, organisation and unit, requestor name, booking instructions, and free-text notes recorded by interpreters or administrators.

People an assignment is for. Where the Agency’s configuration collects them: name, gender, date of birth, and the legal category of the matter. The Agency decides which of these fields it collects.

Job sheets and expenses. Submitted start and end times, travel and total minutes, mileage, expense categories and amounts, VAT treatment, uploaded receipts and supplier invoices, and figures extracted from those documents by automated means.

Financial records. Invoices, line items and entries, amounts, payment records.

Feedback. Ratings and free-text comments about an interpreter’s performance.

Special category and criminal offence data

Both arise in ordinary use of the Software:

  • Criminal offence data (Article 10): where the Agency records the legal category of a matter, and where interpreter background-check documents are uploaded.
  • Special category data (Article 9): where an assignment’s context reveals health data, for example a booking recorded against a named person in a healthcare setting.

We process both only as processor, on the Agency’s instructions. Clause 10.3 places responsibility for the Article 9 or 10 condition on the Agency.


Annex B: Technical and organisational measures

These are the measures we operate as at the effective date of these terms.

Hosting and location. Amazon Web Services, eu-west-2 (London). Inbound email receiving in eu-west-1 (Ireland).

Encryption in transit. TLS 1.2 minimum, enforced at the content delivery network, with all HTTP redirected to HTTPS. Internal traffic between components stays within a private network.

Encryption at rest. Database instances are encrypted, including the read replica. File storage applies AES-256 server-side encryption.

Network segmentation. Servers sit in a private virtual network with default-deny inbound rules. The application load balancer is internal only. Databases are not publicly accessible. The only internet-facing entry points are the content delivery network and the API gateway. Administrative shell access is restricted by source address.

Access control. Every account is individual. No shared or generic logins. Passwords require a minimum of 12 characters with no maximum, and upper case, lower case and numeric characters. Authentication is rate-limited against brute-force attempts. Role separation between interpreter, client and administrator functions is enforced server-side on every request, not in the interface. Administrative functions require membership of a named administrator group.

Credential management. Application credentials are held in a managed secrets store. Compute resources authenticate with short-lived role-based credentials rather than static access keys. Server access is by cryptographic key; password login is disabled. No system runs on a vendor default credential.

Change control. All infrastructure is version-controlled code. Every change to a network or firewall rule is a reviewable change with an audit trail.

Resilience. Automated database backups taken daily and retained for 21 days, a final snapshot on decommissioning, and versioning on file storage.

Segregation. Agency Data is logically segregated by organisation identity, enforced in the application’s data access layer.


Annex C: Sub-processors

Sub-processorPurposeLocationTransfer basis
Amazon Web ServicesHosting, compute, database, file storage, authentication, email sending and receiving, messaging, secrets management, and AI extraction of figures from job sheets, receipts and supplier invoices and classification of interpreter email replies (via Amazon Bedrock)United Kingdom; inbound email receiving in IrelandUK domestic / EEA adequacy
Google (Google Cloud EMEA Limited)Google Workspace, company email, through which correspondence with the Agency and its users is receivedContracted in Ireland; onward processing under Google’s Cloud Data Processing AddendumEEA adequacy for the contracted entity; SCCs and UK Addendum for onward transfer
MintlyValidation of interpreter bank account detailsUnited KingdomUK domestic
VoIPstudioTelephony: carrying on-demand interpreting calls taken in the browser, and sending SMS verification codes to phone numbersUnited KingdomUK domestic

Not sub-processors.

  • Google Maps Platform: used for address verification and journey estimation for assignment locations. Only an address or map coordinates is sent, no name, booking reference or other identifier, so no personal data is disclosed, which is why it is not listed as a sub-processor. Included here for transparency.
  • Anthropic: used only in our UAT and development environments, and only ever with non-real test data. No Agency Data is sent to it, so it is not a sub-processor. All AI processing in the live service runs on Amazon Bedrock, under the Amazon Web Services entry above.
  • Accounting packages the Agency connects (Intuit QuickBooks, Sage Accounting or FreeAgent). Your own processor, under your own agreement. See clauses 4.6 and 10.4.
  • Xero: our own accounting records. Processes our billing contact for you, for which we are controller, not Agency Data.
  • Twilio: present in our configuration but not currently engaged. If we engage it, we will update Annex C under clause 4.3 first.

Version history

VersionEffectiveChange
1.019 August 2026First publication.
1.114 September 2026Annex C: VoIPstudio added as a sub-processor, after notice to agencies under clause 4.3.
1.215 September 2026Clauses 4.6 and 10.4 and Annex C: Sage Accounting and FreeAgent named alongside Intuit QuickBooks as accounting packages an Agency can connect, and clause 10.4 now also says that supporting documents are sent where the package accepts them. A clarification; no obligation changes.
1.320 September 2026Clause 8.3 and Annex B: backups described as they actually run, daily with 21-day retention, in place of a weekly cycle with three generations. The 21-day outer limit is unchanged and is now set in infrastructure as code. A correction; no obligation changes.
tupi.solutions

The technology behind the interpreters.

System status ↗ (opens in a new tab)

Products

  • TupiEX Now in beta
  • TupiNow Now in beta
  • TupiManage Available now
  • All capabilities

Company

  • About
  • News
  • Contact
  • For Interpreters
  • For Agencies
  • Trust Centre

Legal

  • Agreements
  • Privacy Notice
  • Cookie Policy
  • Sub-processors
  • Data Processing (DPA)
  • Acceptable Use

© 2026 Tupi Solutions Limited. All rights reserved.

tupi.solutions builds software for interpreting agencies. We do not provide interpreting services.

Tupi Solutions Limited is registered in England and Wales, company number 17220183. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.