Legal

Privacy Policy

How TPSClear handles personal data, including the UK phone numbers we screen on behalf of our customers, whether they call the API directly or use a native CRM integration.

Last updated: 3 August 2026.

1. Who we are

TPSClear is a UK Telephone Preference Service (TPS) and Corporate TPS (CTPS) list-cleaning service operated by Voll Studios Ltd, a company registered in England and Wales (company number 09302803, registered office 5 Brayford Square, London, England, E1 0SG). Voll Studios Ltd is registered with the Information Commissioner's Office under registration number ZC135838. In this policy "TPSClear", "we", "us" and "our" refer to Voll Studios Ltd in our capacity as operator of the TPSClear service.

For privacy queries, contact us at privacy@tpsclear.co.uk.

2. The service this policy covers

TPSClear is delivered in two ways:

  • REST API. A direct screening interface used by customers building TPS/CTPS compliance into their own systems.
  • Native CRM integrations. Marketplace applications for HubSpot (live), with Salesforce, Microsoft Dynamics 365, Pipedrive, Zoho CRM and Capsule CRM in build. These call the API on the customer's behalf and write verdicts back to CRM records.

This policy applies to all of them and to the marketing site at tpsclear.co.uk.

3. Roles under UK GDPR

Customer data submitted for screening (CRM records or API request payloads): the customer (the organisation or individual that holds a TPSClear account) is the data controller. TPSClear is the data processor, processing this data on the customer's documented instructions to perform the screening service. A Data Processing Agreement (DPA) covers this relationship; see section 12.

Marketing-site visitors and account holders: for example, anyone who emails us, submits a form on the site, or opens a TPSClear account. TPSClear is the data controller.

4. What data we process

4.1 Customer data (as processor)

Across both the API and CRM integrations:

  • UK phone numbers submitted for screening. We normalise these to E.164, query the TPS and CTPS registers, and return a verdict.
  • The screening verdict returned or written back: TPS-listed, CTPS-listed, Clean, Not a valid UK number, or Unknown, with a timestamp.
  • Account identifiers required to authenticate the request: CRM-side OAuth tokens, API keys, customer account IDs.
  • Optional metadata the customer chooses to send with API calls, for example a request reference for the customer's own audit trail.

We do not require, request, or rely on names, email addresses, or other personal data attached to the phone numbers being screened. The screening operation works on the number alone.

4.2 Account holder and marketing-site visitor data (as controller)

  • Email address, name, organisation and any message content sent to us.
  • Account information when an account is created or a CRM app is installed: account ID, billing contact, and acceptance records for these terms and the DPA.
  • Operational telemetry: request timestamps, error logs, usage counts. We do not log phone numbers alongside this telemetry.
  • Standard server logs (IP address, user agent) retained for security and abuse-prevention purposes.

5. Why we process it (lawful bases under UK GDPR)

  • Contract. To deliver the TPSClear screening service to customers and account holders.
  • Legitimate interests. To secure the service, prevent abuse, improve performance, monitor usage against fair limits, and respond to support enquiries. We balance these interests against your rights.
  • Legal obligation. Where we are required by law to retain records or respond to lawful requests.

6. Sub-processors

We do not sell or share customer data with third parties for marketing purposes. We share data only with sub-processors who help us run the service:

  • Vercel Inc. (United States; serves UK and EU traffic from EU edge and function regions): application hosting, serverless API execution, and privacy-friendly web analytics.
  • Supabase, Inc. (managed Postgres in an EU region): database hosting for the screening result cache, screening audit records, account metadata, OAuth installation records, and per-portal screening configuration.
  • Selectabase Ltd (United Kingdom): licensed TPS/CTPS screening provider performing register lookups, as one of our licensed data partners.
  • Data8 Ltd (United Kingdom): licensed data partner for TPS/CTPS register data, where this partner performs the lookup.
  • Stripe, Inc. (and Stripe Payments Europe Ltd): payment processing and subscription billing. Stripe handles billing details only; no screening data.
  • Resend, Inc. (United States): transactional email for account and service notifications; no screening data.
  • Cloudflare, Inc.: DNS and email routing for the tpsclear.co.uk domain.
  • Google (Google Ireland Ltd, Google Workspace): business email for support and privacy correspondence.

The HubSpot platform is not a TPSClear sub-processor: for HubSpot-integration customers, the TPSClear app runs inside your own HubSpot portal, which is your own CRM environment under your own agreement with HubSpot.

A current list of sub-processors with locations and transfer mechanisms is published at tpsclear.co.uk/subprocessors. We require sub-processors to provide appropriate security and data-protection commitments, and we notify active customers at least 30 days before adding or replacing a sub-processor.

7. International transfers

Some sub-processors may process data outside the United Kingdom and the European Economic Area. Where they do, we rely on UK-approved transfer mechanisms, including the UK International Data Transfer Addendum and equivalent Standard Contractual Clauses, to safeguard the data.

8. Retention

  • Screening verdicts written to a customer's CRM remain on the customer's records for as long as the customer keeps them; their retention is under the customer's control.
  • Screening audit log. Each API screening request produces an audit record, referenced by the X-Request-Id returned in the response, containing the request id, the numbers screened, and the verdicts. Audit records are retained for 12 months, then deleted. We keep them to support dispute resolution and to give customers billing and compliance evidence for each screen.
  • Screening result cache. A definitive verdict is cached against the screened number so that repeat screenings of the same number within 28 days do not incur a fresh billed register lookup (TPS registrations become enforceable after 28 days, so a verdict is safe to reuse within that window). Cached verdicts are deleted no later than 60 days after the underlying check.
  • Platform operational logs (Vercel function invocation logs, error traces, request metadata) are retained per our hosting platform's defaults, typically around 30 days for production deployments. Phone numbers are not written to these error and telemetry logs.
  • Operational telemetry (timestamps, error codes, usage counts) is retained for up to 12 months, then deleted or fully anonymised.
  • Customer account records are retained for as long as the account is active, plus 12 months after closure for legitimate-interest record-keeping, unless a longer period is required by law.

9. Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to certain types of processing;
  • data portability where applicable;
  • lodge a complaint with the Information Commissioner's Office (ico.org.uk) if you believe we have not handled your data properly.

To exercise any of these rights, email privacy@tpsclear.co.uk. For data we process on behalf of a customer (CRM records or API submissions), please direct requests to the customer who is the controller; we will assist as the processor.

10. Cookies and analytics

The TPSClear marketing site does not set marketing or advertising cookies. Strictly necessary cookies may be set for session, security, and load-balancing purposes by our hosting provider.

We use Google Analytics 4 to understand aggregate site usage (which pages get visited, what country traffic comes from, which referrers send visits). Google Analytics is loaded with UK GDPR consent mode set to denied by default, so it does not set tracking cookies on your device unless you explicitly consent in future via a banner we may introduce. Until then, Google receives cookieless modelled pings only, which contain no identifiers we could use to recognise you across visits. IP addresses sent to Google Analytics are anonymised at collection. You can opt out of Google Analytics in any browser by enabling Do Not Track or installing the official Google Analytics opt-out browser add-on.

11. Security

We protect data with industry-standard measures: encryption in transit (TLS 1.2 or higher), encryption at rest for the configuration and OAuth-token records we hold in our hosted database, scoped API keys, role-based access controls, and principle-of-least-privilege practices for staff. No system is perfectly secure; we will notify affected customers and the ICO of any qualifying data breach in line with UK GDPR requirements (within 72 hours of becoming aware, where applicable).

12. Data Processing Agreement

For customers who require a separate written DPA in addition to these terms, a TPSClear DPA is available on request. The DPA covers the standard UK GDPR processor obligations: processing on documented instructions, confidentiality, security measures, sub-processor controls, assistance with data-subject requests, breach notification, and return or deletion of data on termination.

13. Changes to this policy

We may update this policy from time to time. Material changes will be announced on this page and, where appropriate, by direct communication to active customers. The "Last updated" date at the top of the page reflects the most recent change.

14. Contact

Email privacy@tpsclear.co.uk or write to Voll Studios Ltd at the registered address above.

Back to home