Confidentiality, Data Protection and AI Prohibition Agreement


Confidentiality, Data Protection and AI Prohibition Agreement

For Transcribers

Version created: 3rd September 2026, review date 3rd September 2027 - Security classification – CONFIDENTIAL

Between

(1) TP Transcription Limited, trading as University Transcriptions, of Ty Brith, Llandegla Road, Mold CH7 4QX (the Company); and

(2) the Contractor.

Background

The Contractor may receive highly sensitive recordings, transcripts, personal data and commercial information while providing transcription or related services. The Company is willing to provide access only on the basis of the protections in this Agreement.

The parties agree as follows.

1. Definitions

1.1 In this Agreement:

Applicable Data Protection Law means all data protection and privacy law applying to the services, including the UK GDPR, the Data Protection Act 2018 and any legislation amending, replacing or supplementing them.

Client means any client or prospective client of the Company and any person on whose behalf that client acts.

Confidential Information means all non-public information relating to the Company, a Client, an assignment or any identifiable person, whether oral, visual, written, digital or in any other form.

Losses means all losses, liabilities, damages, compensation, claims, demands, actions, fines or penalties to the extent lawfully recoverable, and all costs and expenses including legal, professional, forensic, investigation, notification, remediation and regulatory-response costs.

Protected Material means every audio or video recording, transcript, draft, extract, note, screenshot, image, document, personal data, credential and other file or information supplied, accessed or created in connection with work for the Company.

Prohibited AI Use has the meaning in clause 5.

1.2 Confidential Information includes Protected Material; client identities and instructions; the existence and subject matter of assignments; research data; personal, special category and criminal offence data; Company systems, policies, rates and methods; and any information marked confidential or evidently confidential by its nature.

2. Core confidentiality undertaking

2.1 The Contractor must keep Confidential Information strictly confidential during and after the relationship with the Company and must protect it using at least the same care used for the Contractor's own most sensitive information and in all cases reasonable care.

2.2 The Contractor may access and use Confidential Information only to perform the specific work authorised by the Company and only to the minimum extent necessary.

2.3 The Contractor must not disclose, release, publish, transmit, display, play, discuss, copy, distribute, license, sell or otherwise make Confidential Information available to any third party without the Company's express prior written permission.

2.4 Third party includes family members, friends, colleagues, other contractors, other clients, online groups, social media, software or platform providers, cloud-storage or file-transfer providers, transcription services, AI providers and any other person or system not expressly authorised.

2.5 The Contractor must not use Protected Material for a portfolio, example, training, teaching, testing, research, benchmarking, product development, publicity, discussion or personal purpose, even if it has been anonymised, edited or excerpted.

2.6 The Contractor must not contact a Client, recording participant, research participant, data subject or any other person identified in Protected Material unless expressly instructed in writing by the Company.

3. Limited exceptions and compelled disclosure

3.1 The obligations do not apply to information the Contractor proves: was lawfully known without restriction before disclosure; becomes public other than through breach; is received lawfully from a third party without a duty of confidence; or is independently developed without use of Confidential Information.

3.2 If disclosure is required by law, court order or regulator, the Contractor must, so far as legally permitted, give the Company prompt written notice before disclosure, disclose only the minimum legally required and reasonably assist the Company to seek confidential treatment or other protection.

3.3 Nothing permits disclosure merely because the Contractor believes a recording is harmless, already partly public, anonymised or unlikely to identify anyone.

3.4 Nothing in this Agreement prevents a protected disclosure under applicable whistleblowing law, reporting suspected crime to the police or an appropriate authority, cooperating with a regulator acting within its powers, or obtaining confidential legal advice. The Contractor must disclose only what is reasonably necessary and, where legally permitted, notify the Company in advance.

4. Data protection and restricted processing

4.1 The Contractor acknowledges that the Company may be a controller or a processor for a Client. The Contractor will act only as the Company's processor or authorised sub-processor for personal data and will process it only on the Company's documented instructions.

4.2 The permitted processing is secure receipt, authorised download, playback, human transcription, formatting, time stamping, authorised quality checking, secure return and deletion for the assigned work. No other purpose is authorised.

4.3 The Contractor must comply with Applicable Data Protection Law, keep personal data accurate where responsible for transcription, minimise copies, apply the security controls in Schedule 2 and not access or transfer personal data outside the United Kingdom without express prior written permission and a lawful transfer mechanism.

4.4 No other person may access Protected Material unless the Company has authorised that person in writing and the person has signed obligations no less protective than this Agreement. The Contractor remains liable for every authorised person's acts and omissions.

4.5 The Contractor must promptly assist with data subject rights, data protection impact assessments, security enquiries, Client or regulator enquiries, breach notification, audits and proof of compliance, and must immediately forward any request or complaint without responding unless instructed.

4.6 If the Contractor determines a new purpose or processes outside instructions, the Contractor bears responsibility for that processing and may become a controller under Applicable Data Protection Law.

4.7 Schedule 1 describes the subject matter, duration, nature and purpose of processing, the types of personal data and data subjects, and the Company's rights and instructions.

5. Absolute prohibition on AI and automated transcription

5.1 The Contractor must not carry out, attempt, permit or procure any Prohibited AI Use and warrants that all transcription supplied as human transcription is produced by a human without Prohibited AI Use.

5.2 Prohibited AI Use means submitting, uploading, transmitting, pasting, playing, dictating, exposing or otherwise making Protected Material available to, or processing it with, any artificial intelligence, machine-learning or automated content-processing system, whether online, cloud-based, locally installed, built into another product, free or paid.

5.3 It includes automated speech recognition, automatic transcription, generative AI, large language models, chatbots, AI writing or editing assistants, AI translation, summarisation, paraphrasing, speaker analysis, content generation and any system that retains, learns from, trains on, analyses or sends Protected Material to a third party.

5.4 It applies to recordings, video, transcripts, drafts, extracts, single sentences, names, screenshots, prompts, queries and anonymised or pseudonymised versions. Ordinary offline word-processing, non-AI spellchecking and playback software are permitted only if they do not transmit Protected Material externally.

5.5 No exception arises because a supplier promises encryption, confidentiality, UK hosting, deletion or no model training. Use is permitted only where the Company gives express prior written approval identifying the tool, purpose, assignment and conditions.

5.6 The Contractor must disable automatic AI, cloud transcription and content-analysis features and, on request, certify human production and provide reasonable information about the software and process used.

6. Suspected or confirmed AI use

6.1 If the Company has reasonable grounds to suspect Prohibited AI Use, it may immediately suspend access and work, preserve or withhold fees relating to affected work pending investigation, require preservation and disclosure of relevant records, and notify a Client or regulator where reasonably necessary. The Contractor must cooperate fully.

6.2 Any Prohibited AI Use is a material and irremediable breach, whether deliberate, reckless or inadvertent. If it is admitted or established on the balance of probabilities, the Company may terminate the Contractor's engagement immediately, reject affected work, require repayment of fees paid for it, require secure deletion and take any protective or legal action available.

6.3 The Contractor is liable for and must indemnify and keep indemnified the Company on demand against all Losses, howsoever caused or incurred, arising out of or in connection with Prohibited AI Use. This expressly includes: data protection breach and incident-response costs; forensic investigation; re-transcription and quality-review costs; Client refunds, credits and compensation; claims by Clients and data subjects; legal and professional fees; increased insurance costs; ICO and other regulator investigation, response, notification, enforcement and defence costs; administrative fines and penalties to the extent lawfully recoverable; loss, suspension, termination or non-renewal of any contract; and loss of revenue, profit, business, opportunity, goodwill or reputation.

6.4 The indemnity in clause 6.3 applies to direct, indirect and consequential Losses, whether or not foreseeable at the date of this Agreement, is unlimited and is not subject to a limitation or exclusion in any other agreement. It survives completion and termination.

7. Security incidents and breach response

7.1 The Contractor must notify the Company without undue delay and in any event within two hours after becoming aware of any actual or suspected loss, unauthorised access, disclosure, alteration, corruption, malware event, credential compromise, misdirection, Prohibited AI Use or inability to account for Protected Material.

7.2 The first notification must not be delayed for investigation. It must contain all then-known details of affected material and people, timing, systems and recipients, likely consequences, containment and a follow-up contact.

7.3 The Contractor must contain the incident, preserve evidence and logs, follow reasonable directions, give continuing updates and assist fully with investigation, recovery, notifications, claims and Client, insurer, ICO or other regulator enquiries.

7.4 The Contractor must not conceal or minimise an incident, delete evidence, make a public statement, contact affected people or notify a regulator or Client without the Company's written approval unless law requires it.

8. Return, deletion and certification

8.1 On completion, termination or request, the Contractor must immediately stop using and, at the Company's choice, securely return or delete all Protected Material and copies, including drafts, extracts, temporary files, downloads, caches, recycle-bin copies, backups and printouts.

8.2 If immediate deletion from an encrypted backup is technically impossible, the copy must be put beyond use, remain protected and be deleted at the next normal cycle. It must not be restored except for disaster recovery and must be deleted again immediately if restored.

8.3 The Contractor must confirm return or deletion in writing if requested and disclose any copy that cannot lawfully be deleted, the legal basis, location, safeguards and retention period.

9. Monitoring, records and audit

9.1 The Contractor must keep sufficient records to demonstrate compliance, including authorised devices and software, access and deletion records, approved substitutes and incidents, without retaining Protected Material longer than authorised.

9.2 The Contractor must provide information reasonably requested and allow proportionate audits or inspections by the Company, a Client or appointed auditor on reasonable notice, or immediately after a suspected breach. Audits will be limited to systems, records and locations relevant to Company work and conducted so far as practicable to minimise unnecessary intrusion.

9.3 The Contractor must promptly remedy any reasonable security or compliance finding at the Contractor's cost.

10. Remedies and liability

10.1 The Contractor acknowledges that unauthorised disclosure may cause harm not adequately compensated by damages. The Company may seek an injunction, delivery up, deletion, specific performance or other equitable relief in addition to damages and indemnities.

10.2 The Contractor must indemnify the Company against Losses arising from breach of this Agreement by the Contractor or any person for whom the Contractor is responsible. The specific AI indemnity in clause 6 is additional and prevails if wider.

10.3 Nothing limits liability for fraud, fraudulent misrepresentation, wilful misconduct or any liability that cannot lawfully be limited.

11. Duration and general terms

11.1 This Agreement begins on the Effective Date. Trade secrets remain protected indefinitely. Other Confidential Information remains protected until it lawfully enters the public domain through no breach. Personal data remains protected for as long as it is held. Clauses on AI, incidents, deletion, audit, remedies, liability and governing law survive termination.

11.2 No intellectual property right or other licence is granted except the limited right to use Protected Material to perform authorised work.

11.3 This Agreement is the entire agreement on confidentiality, data handling and Prohibited AI Use, but it operates alongside any services agreement. If terms conflict, the provision giving greater protection to Protected Material and personal data prevails.

11.4 A variation or waiver must be in writing and signed or expressly agreed by authorised representatives. Delay in exercising a right is not a waiver.

11.5 If a provision is invalid or unenforceable, it will be modified to the minimum extent necessary and the rest continues. The Contractor may not assign this Agreement.

11.6 A person who is not a party has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce this Agreement.

11.7 This Agreement and any non-contractual dispute are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction.

Schedule 1 - Details of processing

Subject matter: Access to and handling of recordings and associated materials for human transcription and closely related authorised work.

Duration: For the term of each authorised assignment and only until return or secure deletion is required under the Company's instructions.

Nature and purpose: Secure receipt, authorised download, playback, manual transcription, formatting, time stamping, authorised quality checking, secure return and deletion. No analytics, training, profiling, independent research or AI processing.

Types of personal data: Names, contact and identity details; voices and images; employment, education, financial and research information; opinions and interview responses; device or file metadata; and any other information contained in recordings or source documents.

Special category and criminal offence data: Assignments may contain health, disability, racial or ethnic origin, religion, political opinions, trade union membership, sex life or sexual orientation, genetic or biometric information, allegations, convictions, court, police or safeguarding information.

Categories of data subject: Clients and their personnel; research participants; interviewees; students; academics; patients; service users; children or vulnerable people; witnesses; legal professionals; parties to proceedings; suspects; victims; employees; job candidates; customers and other persons mentioned in source material.

Company rights and instructions: The Company or its upstream Client determines the purpose and essential means, may issue documented instructions, verify compliance, authorise or refuse sub-processing, require assistance, audit relevant processing and require return or deletion.

Schedule 2 - Minimum information security requirements

  • use only devices and user accounts controlled by the Contractor and protected by a strong unique password or passphrase, automatic screen locking and, where available, multi-factor authentication;
  • use a currently supported operating system, promptly apply security updates, maintain active anti-malware protection and use a firewall;
  • use full-disk encryption on every device or storage medium containing Protected Material;
  • work in a private environment, use headphones where others may overhear, and prevent family members, household members and other unauthorised persons from seeing or hearing Protected Material;
  • access and transfer Protected Material only through methods approved by the Company, and never through a personal email account, consumer messaging service, unapproved file-transfer site or social-media platform;
  • disable or prevent unapproved cloud synchronisation, cloud backup, voice assistant, screen capture, telemetry or other external transmission of Protected Material;
  • store only the minimum material needed for the Assignment, never use a shared or public computer, and never copy material to an unencrypted portable drive;
  • not print Protected Material unless the Company gives prior written permission; any authorised printout must be kept locked away and securely shredded when no longer required;
  • keep credentials confidential, report any suspected credential compromise immediately and never allow another person to use the Contractor's access;
  • keep the work area, equipment and files physically secure and take reasonable precautions against theft, loss, accidental disclosure, malware and unauthorised access; and
  • securely delete all local and temporary copies, downloads, caches, recycle-bin copies and authorised backups when instructed, and confirm deletion in writing if requested.

The obligations in clauses 2 to 9 and Schedule 2 are minimum standards. The Contractor must also comply with any assignment-specific security instruction and promptly implement any reasonable security measure required by the Company or an upstream client.

By signing, the parties enter into this Agreement and the Contractor gives the undertakings set out above.

Leave this empty:

Signature arrow sign here

Signed by Anna Gresty TP Transcription Limited
Signed On: 3rd September 2026


Signature Certificate
Document name: Confidentiality, Data Protection and AI Prohibition Agreement
lock iconUnique Document ID: 3181841a89794ff068e7462be30daa482d4897f1
Timestamp Audit
3rd September 2026 3:03 pm BSTConfidentiality, Data Protection and AI Prohibition Agreement Uploaded by Anna Gresty - anna.gresty@tptranscription.co.uk IP 82.71.118.30
3rd September 2026 3:07 pm BST Document owner anna@tptranscription.co.uk has handed over this document to anna.gresty@tptranscription.co.uk 2026-09-03 15:07:50 - 82.71.118.30