Data Processing Agreement
TPSCheck.uk - Data Processing Agreement
Last Updated: 11 February 2026
Effective Date: 11 February 2026
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (“Agreement”) between Visian Systems Limited (trading as TPSCheck) (“Processor”, “we”, “us”) and the customer using our Service (“Controller”, “you”, “Customer”).
This DPA reflects the parties’ commitment to comply with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, and other applicable data protection laws when the Processor processes Personal Data on behalf of the Controller.
By using the TPSCheck Service, you agree to this DPA. This DPA supplements and is incorporated into our Terms of Service.
2. Definitions
In this DPA:
“Controller” means the natural or legal person which determines the purposes and means of processing Personal Data.
“Data Protection Laws” means the UK GDPR, the Data Protection Act 2018, PECR, and any other applicable UK data protection legislation.
“Data Subject” means an identified or identifiable natural person whose Personal Data is processed.
“Personal Data” means any information relating to an identified or identifiable natural person.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
“Processing” means any operation performed on Personal Data, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
“Processor” means a natural or legal person which processes Personal Data on behalf of the Controller.
“Service” means the TPSCheck TPS/CTPS checking API and related services.
“Sub-processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
3. Scope and Roles
3.1 Controller and Processor Relationship
When you submit telephone numbers to the TPSCheck API for TPS/CTPS checking:
- You are the Controller (or acting on behalf of a Controller) for the telephone numbers submitted
- TPSCheck is the Processor processing those telephone numbers on your behalf
3.2 Scope of Processing
This DPA applies to the processing of telephone numbers and any associated Personal Data submitted through the Service for the purpose of TPS/CTPS compliance checking.
3.3 TPSCheck as Controller
TPSCheck acts as a Controller for:
- Your account information
- Payment and billing data
- Usage logs and analytics
- Communications with you
Such processing is governed by our Privacy Policy, not this DPA.
4. Details of Processing
4.1 Subject Matter
Processing of telephone numbers to determine TPS/CTPS registration status and return telephone line intelligence.
4.2 Duration
Processing occurs for the duration of your use of the Service. Individual telephone numbers are processed in real-time. For plans that include audit logs (Pro, Business, and Enterprise), telephone numbers and check results are retained in audit logs for the duration specified by the Customer’s plan tier (90 days to 24 months). For Free and PAYG plans, telephone numbers are not retained after processing is complete.
4.3 Nature of Processing
- Receipt of telephone numbers via API request
- Validation and normalisation of telephone number format
- Query against TPS/CTPS registers
- Retrieval of line type, carrier, and geographic data
- Return of results via API response
- Generation of aggregated usage statistics (no Personal Data retained)
4.4 Purpose of Processing
To enable the Controller to check telephone numbers against UK TPS and CTPS registers for telemarketing compliance purposes under PECR.
4.5 Categories of Data Subjects
- Individuals whose telephone numbers are submitted for checking (typically consumers or business contacts)
4.6 Types of Personal Data
- Telephone numbers (mobile and landline)
- Associated metadata: line type, carrier, geographic location (derived from number, not the individual)
5. Controller Obligations
5.1 Lawful Basis
The Controller warrants that:
(a) It has a lawful basis under UK GDPR for submitting telephone numbers to the Service;
(b) Where required, it has obtained appropriate consent or established another lawful basis for processing;
(c) It has provided appropriate privacy notices to Data Subjects regarding TPS checking activities.
5.2 Instructions
The Controller’s instructions to the Processor are to process Personal Data only as necessary to provide the Service, as described in Section 4 and the Agreement.
5.3 Compliance
The Controller is responsible for:
(a) Ensuring its use of the Service complies with Data Protection Laws;
(b) Responding to Data Subject rights requests relating to telephone numbers it has submitted;
(c) Assessing the adequacy of the Processor’s security measures for the Controller’s purposes;
(d) Using TPS/CTPS check results in compliance with PECR and other applicable laws.
6. Processor Obligations
6.1 Processing Instructions
The Processor shall:
(a) Process Personal Data only on documented instructions from the Controller, unless required by law;
(b) Immediately inform the Controller if, in the Processor’s opinion, an instruction infringes Data Protection Laws;
(c) Not process Personal Data for any purpose other than providing the Service.
6.2 Confidentiality
The Processor shall:
(a) Ensure that persons authorised to process Personal Data are subject to confidentiality obligations;
(b) Take reasonable steps to ensure the reliability of staff with access to Personal Data;
(c) Limit access to Personal Data to those who need it to perform the Service.
6.3 Security Measures
The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
Technical Measures:
(a) Encryption of Personal Data in transit using TLS 1.2 or higher;
(b) Encryption of Personal Data at rest where stored;
(c) Access controls and authentication mechanisms;
(d) Regular testing of security measures;
(e) Logging and monitoring of access to systems;
(f) Network security measures including firewalls and intrusion detection;
(g) Regular security patching and vulnerability management.
Organisational Measures:
(a) Information security policies and procedures;
(b) Staff training on data protection and security;
(c) Access management based on least privilege principle;
(d) Incident response procedures;
(e) Regular security assessments and audits.
6.4 Data Minimisation
The Processor shall:
(a) Not retain telephone numbers beyond the audit log retention period applicable to the Customer’s plan (or, for plans without audit logs, not retain telephone numbers after processing is complete);
(b) Process only the minimum Personal Data necessary to provide the Service;
(c) Not create databases or profiles from telephone numbers submitted.
6.5 Sub-processing
(a) The Controller provides general authorisation for the Processor to engage Sub-processors, subject to the requirements of this Section;
(b) The Processor shall maintain a list of Sub-processors, available at https://tpscheck.uk/sub-processors or upon request;
(c) The Processor shall give the Controller prior notice of any intended addition or replacement of Sub-processors, allowing reasonable time to object;
(d) The Controller may object to a new Sub-processor on reasonable grounds. If the objection cannot be resolved, the Controller may terminate the affected Service;
(e) The Processor shall ensure Sub-processors are bound by data protection obligations no less protective than this DPA;
(f) The Processor remains liable for the acts and omissions of its Sub-processors.
Current Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Infrastructure hosting | UK/EEA |
| Stripe | Payment processing | UK/EEA/US |
6.6 Data Subject Rights
(a) The Processor shall promptly notify the Controller of any request received directly from a Data Subject regarding their Personal Data;
(b) The Processor shall not respond to such requests except on documented instructions from the Controller or as required by law;
(c) The Processor shall provide reasonable assistance to the Controller in responding to Data Subject requests, considering the nature of processing and information available.
6.7 Data Protection Impact Assessments
The Processor shall provide reasonable assistance to the Controller with data protection impact assessments and prior consultations with supervisory authorities, where required by Data Protection Laws, taking into account the nature of processing and information available.
6.8 Personal Data Breach
(a) The Processor shall notify the Controller without undue delay, and in any event within 24 hours, upon becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA;
(b) Such notification shall include, to the extent available:
- Description of the nature of the breach
- Categories and approximate number of Data Subjects affected
- Categories and approximate number of Personal Data records affected
- Name and contact details of the Processor’s data protection contact
- Likely consequences of the breach
- Measures taken or proposed to address the breach
(c) The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach;
(d) The Processor shall document all Personal Data Breaches, including facts, effects, and remedial actions taken.
6.9 Deletion and Return
Upon termination of the Agreement:
(a) The Processor shall delete Personal Data processed under this DPA unless required by law to retain it;
(b) For plans with audit log retention, the Controller may export all audit log data prior to termination. Any retained data will be deleted at the end of the applicable retention period or within 30 days of termination, whichever is sooner;
(c) The Processor shall provide written confirmation of deletion upon request.
6.10 Audit Rights
(a) The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA;
(b) The Controller may conduct audits, including inspections, either directly or through a third-party auditor, subject to:
- Reasonable advance notice (minimum 30 days, except in case of suspected breach)
- Execution of appropriate confidentiality agreements
- Audits being conducted during normal business hours with minimal disruption
- The Controller bearing its own audit costs
(c) The Processor may satisfy audit requirements by providing:
- Relevant third-party certifications (e.g., ISO 27001, SOC 2)
- Results of penetration tests or security assessments
- Completed security questionnaires
- Other documentation demonstrating compliance
7. International Transfers
7.1 Location of Processing
The Processor processes Personal Data primarily within the United Kingdom and European Economic Area.
7.2 Transfers Outside UK/EEA
Where Personal Data is transferred to a country outside the UK and EEA that does not have an adequacy decision:
(a) The Processor shall ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the UK ICO
- Binding Corporate Rules where applicable
- Other approved transfer mechanisms
(b) The Processor shall provide details of any such transfers and safeguards upon request.
7.3 Supplementary Measures
Where required, the Processor shall implement supplementary technical and organisational measures to ensure the transferred data remains protected.
8. Liability and Indemnification
8.1 Liability
Each party’s liability under this DPA is subject to the limitations set out in the Agreement.
8.2 Allocation
(a) The Controller is liable for any losses arising from processing that is not in accordance with this DPA or Data Protection Laws, to the extent caused by the Controller’s instructions or breach;
(b) The Processor is liable for any losses arising from processing that is not in accordance with this DPA or Data Protection Laws, to the extent caused by the Processor’s actions or omissions.
9. Term and Termination
9.1 Term
This DPA shall remain in effect for the duration of the Agreement.
9.2 Survival
Provisions of this DPA that by their nature should survive termination (including confidentiality, audit rights for a reasonable period, and deletion obligations) shall survive.
9.3 Termination for Breach
Either party may terminate the Agreement if the other party materially breaches this DPA and fails to remedy the breach within 30 days of notice.
10. General Provisions
10.1 Precedence
In the event of conflict between this DPA and the Agreement, this DPA shall prevail regarding data protection matters.
10.2 Amendments
We may update this DPA to reflect changes in Data Protection Laws or our practices. Material changes will be notified in accordance with the Agreement.
10.3 Governing Law
This DPA is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction over disputes arising from this DPA.
10.4 Severability
If any provision of this DPA is found invalid or unenforceable, the remaining provisions shall continue in full force and effect.
11. Contact
For questions about this DPA or to exercise rights under it:
Visian Systems Limited (trading as TPSCheck) Email: privacy@tpscheck.uk Post: Data Protection, Visian Systems Limited, Stapeley House, London Road, Stapeley, Nantwich CW5 7JW, United Kingdom
Annex A: Technical and Organisational Security Measures
The Processor implements the following security measures:
1. Access Control
- Role-based access control (RBAC)
- Multi-factor authentication for administrative access
- Unique user accounts (no shared credentials)
- Automatic session timeout
- Regular access reviews
2. Encryption
- TLS 1.2+ for data in transit
- AES-256 encryption for data at rest
- Secure key management practices
3. Network Security
- Firewalls and network segmentation
- Intrusion detection and prevention systems
- DDoS protection
- Regular vulnerability scanning
4. Application Security
- Secure development lifecycle (SDLC)
- Code reviews and security testing
- Input validation and output encoding
- Protection against common vulnerabilities (OWASP Top 10)
5. Infrastructure Security
- Hosted in ISO 27001 certified data centres
- Physical access controls
- Environmental controls (fire suppression, climate control)
- Redundant power and connectivity
6. Monitoring and Logging
- Centralised logging
- Security event monitoring
- Alerting for suspicious activity
- Log retention for security analysis
7. Incident Response
- Documented incident response plan
- Designated incident response team
- Regular incident response testing
- Post-incident reviews
8. Business Continuity
- Regular backups
- Disaster recovery planning
- Redundant infrastructure
- Tested recovery procedures
9. Personnel Security
- Background checks where appropriate
- Confidentiality agreements
- Security awareness training
- Disciplinary procedures for policy violations
10. Vendor Management
- Security assessments of Sub-processors
- Contractual security requirements
- Regular vendor reviews
Annex B: Sub-processors
The Controller has authorised the use of the following Sub-processors:
| Name | Processing Activities | Location | Safeguards |
|---|---|---|---|
| Amazon Web Services (AWS) | Infrastructure hosting, data storage | UK/EEA | DPA, ISO 27001, SOC 2 |
| Stripe | Payment processing | UK/EEA/US | PCI DSS Level 1, DPA, SCCs |
| HelpScout | Customer support platform | US (EU data processing) | DPA, SOC 2 |
An up-to-date list is maintained at: https://tpscheck.uk/sub-processors
To be notified of Sub-processor changes, contact: privacy@tpscheck.uk
By using the TPSCheck Service, you acknowledge and agree to this Data Processing Agreement.