Privacy Notice
This Privacy Notice explains how InSignLanguage Ltd ("InSignLanguage", "we", "us", "our") collects, uses, shares and protects personal data. It is written to meet our obligations under the UK General
England & Wales
InSignLanguage Ltd — last updated 13 June 2026 — version 1.1
This Privacy Notice explains how InSignLanguage Ltd ("InSignLanguage", "we", "us", "our") collects, uses, shares and protects personal data. It is written to meet our obligations under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
If you have any questions about this notice, or about how we handle your information, please contact us using the details in section 14.
1. Who we are
InSignLanguage Ltd is a British Sign Language (BSL) interpreting and translation business. We arrange and deliver in-person interpreting, Video Remote Interpreting (VRI), Video Relay Service (VRS), translation and Deaf-awareness training to clients across the UK, including individuals using Access to Work (AtW).
Company name
InSignLanguage Ltd
Registered office
26 Domum Road, Portsmouth, PO2 0QZ, United Kingdom
Companies House number
10943637 · VAT registration number GB 298 6629 31
ICO registration number
ZC163713
Data protection contact
support@insignlanguage.co.uk
Website
https://www.insignlanguage.co.uk
We are the data controller for personal data we collect about visitors to our website, our clients, the Deaf and hard-of-hearing service-users we work with, our interpreter network, our employees and our suppliers. Where we deliver interpreting on behalf of an organisation (for example an NHS trust, a local authority or an employer using Access to Work), that organisation is normally the data controller and InSignLanguage acts as its data processor. In those cases the client's own privacy notice will also apply.
2. Scope of this notice
This notice applies to:
visitors to insignlanguage.co.uk and our official social-media channels;
clients, prospects and enquirers (individuals or organisations);
Deaf, Deafblind, hard-of-hearing and hearing service-users for whom we provide interpreting;
self-employed interpreters and translators in our network;
employees, directors, partners and contracted staff;
complainants, witnesses and others whose data we receive when handling complaints, safeguarding concerns or incidents.
3. The personal data we collect
We collect only the personal data we need for each activity. The table below summarises the categories of data we hold and where we get it from.
Category
Examples
Typical source
Identity and contact data
name, job title, employer, email, phone, postal address
you, your employer, our clients
Booking and assignment data
date, time, location or video link, subject matter, language pair, format (in-person/VRI/VRS), special requirements, free-text notes
clients, service-users
Service-user data
name and contact details, communication preferences, accessibility requirements
client, AtW user, service-user
Financial data
purchase orders, billing references, bank details (interpreters and suppliers)
you, our clients
Practitioner data
NRCPD/RBSLI/SLRPDC registration, qualifications, CPD, insurance, right-to-work evidence, DBS/PVG/Access NI outcomes, bank details, availability
interpreter, regulator, DBS umbrella body
Employment data
personnel file, pay, pension, sickness/absence, occupational health, equality monitoring
employee, payroll provider, occupational health
Website and marketing data
IP address, device/browser data, cookie identifiers, pages visited, referrers, enquiry content, marketing preferences
your device, our analytics and CRM tools
Call data (VRI/VRS)
the audio and video stream of a call, signed and spoken content, chat messages, call metadata, recordings (where enabled)
the participants and the video platform
Complaints, safeguarding and incident data
complaint narratives, investigation notes, outcomes, breach records
complainant, staff, interpreters, authorities
Calls and bookings will often involve special category data (such as information about your health, disability, race, religion, sex life or sexual orientation) and may occasionally involve criminal-justice data (for example court appointments). We process this only with an additional lawful condition under Article 9 UK GDPR or Schedule 1 of the Data Protection Act 2018, as set out in section 5.
4. Why we use your data and our lawful basis
We process personal data only when we have a lawful basis to do so. Our processing activities, and the lawful basis we rely on for each, are summarised below. This mirrors our internal Record of Processing Activities (ROPA), which we maintain under Article 30 UK GDPR.
4.1 Client booking and assignment management
To receive, schedule, allocate and deliver interpreting assignments, including confirmations, reminders, cancellations and assignment-related correspondence.
Contract (Art. 6(1)(b)) — performance of the booking contract.
Legal obligation (Art. 6(1)(c)) — accessibility duties under the Equality Act 2010.
Legitimate interests (Art. 6(1)(f)) — administering the booking workflow and contacting the requester.
4.2 Interpreter and freelance practitioner records
To recruit, vet, contract, allocate, pay and manage qualified BSL interpreters and translators.
Contract (Art. 6(1)(b)) — service contract with the practitioner.
Legal obligation (Art. 6(1)(c)) — tax, anti-money-laundering, right to work, safeguarding and professional regulatory checks.
Legitimate interests (Art. 6(1)(f)) — quality assurance, allocation and dispute handling.
4.3 Employees, directors, partners and contracted staff
To employ, pay, manage and develop our people.
Contract (Art. 6(1)(b)) — contract of employment / partnership.
Legal obligation (Art. 6(1)(c)) — tax, NI, pensions, statutory leave, health and safety.
Legitimate interests (Art. 6(1)(f)) — staff administration and business management.
Consent (Art. 6(1)(a)) — discretionary uses such as photographs in marketing.
4.4 Website, marketing, enquiries and CRM
To operate our website, respond to enquiries, send marketing communications and analyse aggregated site usage.
Consent (Art. 6(1)(a)) — non-essential cookies and email marketing to individual subscribers (PECR reg. 22).
Legitimate interests (Art. 6(1)(f)) — responding to enquiries and the "soft opt-in" to business contacts where the conditions in PECR reg. 22(3) are met.
Contract (Art. 6(1)(b)) — pre-contract steps where an enquiry leads to a quote.
You can unsubscribe from marketing at any time via the link in any marketing email, or by contacting us.
4.5 Video Remote Interpreting (VRI), Video Relay Service (VRS) and recordings
To deliver live interpreting via video, and — only where appropriate — to record calls for the limited purposes of quality assurance, complaint handling, safeguarding or, where notified, internal product development.
Live delivery — Contract (Art. 6(1)(b)) and Legal obligation (Art. 6(1)(c)).
Recording for quality assurance or product development — Legitimate interests (Art. 6(1)(f)), supported by a documented Legitimate Interests Assessment (LIA), with prominent notice and opt-out controls; or consent (Art. 6(1)(a)) where required.
Safeguarding / legal — Legal obligation (Art. 6(1)(c)) and Vital interests (Art. 6(1)(d)).
Recordings are not used to identify or profile end users beyond the purposes set out in this notice.
4.6 Finance, accounting and tax
To raise invoices, pay suppliers and interpreters, maintain statutory accounts and respond to audits.
Contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) — Companies Act 2006, VAT Act 1994, ITEPA 2003; Legitimate interests (Art. 6(1)(f)) — credit control.
4.7 Complaints, safeguarding and incident management
To investigate complaints, manage safeguarding concerns, handle data-protection incidents and respond to data-subject rights requests.
Legal obligation (Art. 6(1)(c)) — UK GDPR Articles 12–22 and 33–34 and safeguarding statutes.
Legitimate interests (Art. 6(1)(f)) — resolving complaints.
Vital interests (Art. 6(1)(d)) — safeguarding emergencies.
5. Special category data and criminal-conviction data
Some of our processing inevitably involves special category data (health, disability, ethnicity, religion, sex life and similar) or criminal-conviction data. Where it does, we additionally rely on one or more of the following conditions:
Article 9(2)(b) / DPA 2018 Sch.1 Pt.1 §1 — employment, social security and social protection (for example Access to Work, sickness absence, reasonable adjustments).
Article 9(2)(c) — vital interests where the data subject cannot give consent.
Article 9(2)(f) — legal claims and judicial acts.
Article 9(2)(g) / DPA 2018 Sch.1 Pt.2 §6 — statutory and government purposes.
Article 9(2)(g) / DPA 2018 Sch.1 Pt.2 §8 — equality of opportunity or treatment.
DPA 2018 Sch.1 Pt.2 §10 — preventing or detecting unlawful acts.
DPA 2018 Sch.1 Pt.2 §18 — safeguarding of children and individuals at risk.
We maintain an Appropriate Policy Document (APD) for processing under Schedule 1 of the Data Protection Act 2018 and a Legitimate Interests Assessment for processing relying on legitimate interests. Copies are available on request.
6. Who we share your data with
We share personal data only where we have a lawful reason. The categories of recipient are:
the assigned interpreter(s) and other parties on a call or at an assignment;
the client organisation who booked the service;
our sub-processors (see section 7), including our booking platform, video platform, cloud storage, email and CRM providers;
HMRC, our pension provider, our occupational health provider and our auditors;
our accountants, lawyers, insurers and other professional advisers;
regulators (including the Information Commissioner's Office and the DBS), and the police, courts or safeguarding authorities, where we are legally required to do so;
debt-recovery agents (only if necessary).
We do not sell personal data, and we do not share data with advertisers for behavioural advertising.
7. Sub-processors
We engage a small number of carefully selected suppliers ("sub-processors") to help us run our service. Every sub-processor is bound by a written contract that meets Article 28 UK GDPR. We carry out due diligence before onboarding any new sub-processor.
A current list is published at insignlanguage.co.uk/sub-processors and updated when our supplier base changes. Typical categories include:
booking platform provider;
video / VRI / VRS platform provider;
cloud storage and file-sharing;
Microsoft 365 for email, calendar and productivity;
accounting and payroll provider;
CRM and email-marketing provider;
website host; Google — Google Analytics, Google advertising/marketing tools and YouTube embeds;
DBS umbrella body;
occupational-health provider;
external legal and accountancy advisers.
8. International transfers
We are a UK business and we prefer UK or EEA hosting wherever possible. Some of our suppliers (in particular for video, productivity and analytics) process data in the European Economic Area or the United States.
Where we transfer personal data outside the UK we rely, in order of preference, on:
UK adequacy regulations (currently in place for the EEA, the US through the UK Data Bridge for certified organisations under the Data Privacy Framework, and other adequate jurisdictions);
the UK International Data Transfer Agreement (IDTA); or
the UK Addendum to the EU Standard Contractual Clauses.
Each transfer is supported by a documented Transfer Risk Assessment (TRA) in line with ICO guidance. Copies are available on request.
9. How long we keep your data
We keep personal data only for as long as we need it. Our standard retention periods are:
Record
Retention
Justification
Booking records (active and historic)
Duration of engagement + 7 years
Limitation Act 1980; audit; complaints
Cancellations / no-shows
2 years
Internal QA and dispute handling
Interpreter file (active)
Duration of relationship
Contract administration
Interpreter file (left)
7 years from end of relationship
Limitation Act 1980; references; tax
DBS / safeguarding evidence
Certificate content: 6 months from sight of the certificate, then destroyed. Record of the check (certificate number, date, level, outcome): 7 years
DBS guidance; safeguarding policy
Unsuccessful job applicants
6 months from decision
Defending discrimination claims
Employee personnel file
7 years after end of employment
Limitation Act 1980; references
Payroll & tax records
6 years from end of tax year
HMRC requirements
Pensions auto-enrolment records
6 years (some 4 years)
The Pensions Regulator
Right-to-work evidence
2 years after end of employment
Home Office statutory excuse
Statutory accounting records
6 years from end of accounting year
Companies Act 2006; VAT Act 1994
Website enquiries
24 months from last contact
Legitimate interest; sales follow-up
Marketing list (subscribers)
Until unsubscribe + 2 years suppression
PECR reg. 22
CRM contact records
3 years from last meaningful interaction
Legitimate interest; reviewed annually
VRI/VRS call metadata
24 months
QA, dispute handling
VRI/VRS recordings (QA)
30 days unless live complaint or claim
Data minimisation
VRI/VRS recordings (product development)
90 days, anonymised thereafter where retained
Limited internal R&D purpose
Complaints files
6 years from resolution
Limitation Act 1980
Personal-data breach register
6 years
UK GDPR Art. 33(5)
Safeguarding records
Per statutory guidance (often 25 years where children are involved)
Working Together to Safeguard Children
At the end of the retention period, data is either securely deleted or fully anonymised.
10. Your rights
Under the UK GDPR you have the following rights. We will respond to any request within one calendar month (extendable by up to a further two months for complex requests, in which case we will tell you why). There is normally no charge.
The right to be informed — through this notice and our other privacy information.
The right of access — to receive a copy of the personal data we hold about you.
The right to rectification — to ask us to correct inaccurate or incomplete data.
The right to erasure — to ask us to delete data we no longer need to keep.
The right to restrict processing — to ask us to limit how we use your data in certain circumstances.
The right to data portability — to receive data you gave us in a structured, commonly used, machine-readable format.
The right to object — to processing based on legitimate interests, and to direct marketing at any time.
Rights related to automated decision-making and profiling — we do not make decisions about you using solely automated means.
The right to withdraw consent — where we rely on consent, you can withdraw it at any time.
To exercise a right, please email support@insignlanguage.co.uk with the subject line "Data subject request". We may need to verify your identity. See our Data Subject Rights Request page for more detail.
You also have the right to complain to the Information Commissioner's Office (ICO):
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF 0303 123 1113 https://ico.org.uk
We would, however, appreciate the chance to deal with your concerns directly first — please contact us using the details below.
11. Security
We protect personal data using a combination of technical and organisational measures that we keep under regular review, including:
TLS 1.2+ encryption in transit on all client and staff systems;
encryption at rest on the cloud platforms we use;
pseudonymous booking references in our finance system;
role-based access controls and multi-factor authentication on administrative, HR and payroll systems;
daily / continuous cloud backups, with annual restore testing;
mandatory data-protection induction and annual refresher training;
written confidentiality undertakings in every employee and freelance contract;
supplier due diligence and Article 28 DPAs before any new sub-processor is engaged;
a documented incident-response procedure aligned to the 72-hour ICO reporting deadline under Article 33 UK GDPR;
locked premises, visitor sign-in, locked storage for any paper records, and a clear-desk / clear-screen policy.
12. Cookies
Our website uses a small number of cookies. We only set non-essential cookies after you have given consent through our cookie banner. Full details are in our Cookie Policy.
13. Children
Our services are not directed at children. Where we provide interpreting that involves children (for example in education, health or social-care settings), we do so on behalf of a client organisation under that organisation's lawful basis, and any safeguarding records are handled under section 4.7.
14. Contact and complaints
If you have any questions about this notice or about how we use your information, please contact:
Data Protection Lead InSignLanguage Ltd 26 Domum Road, Portsmouth, PO2 0QZ support@insignlanguage.co.uk
If you are not satisfied with our response, you can complain to the Information Commissioner's Office (see section 10).
15. Changes to this notice
We review this notice at least once a year, and whenever there is a material change to our processing — for example, a new service, a new sub-processor, or a regulatory change. The current version, version number and "last updated" date are always shown at the top of this page. Significant changes will be highlighted on the website for at least 30 days.
This notice is read alongside, and is consistent with, InSignLanguage's internal Record of Processing Activities (ROPA), Information Security Policy (SEC-001), Data Protection & Confidentiality Policy (SEC-002) and Data Retention & Deletion Policy (SEC-003).
Related policies: DBS and Vetting Policy (ISL-LEG-F-E) and the Appropriate Policy Document (ISL-LEG-F-H) cover criminal-offence data; the Remote Interpreting Policy (ISL-LEG-F-F) covers video delivery.
.png)