
Papillon Translations Ltd
Company number 08991181
Registered office: 167–169 Great Portland Street, 5th Floor, London W1W 5PF
Scope and roles
This policy applies to employees, contractors, translators, interpreters, reviewers, suppliers and systems used to receive, process, store or transmit personal information. Papillon usually acts as processor for client documents and service-user data, following the controller’s documented instructions. It acts as controller for limited business administration such as recruitment, supplier vetting, billing and contact management.
Data-protection principles
- Process personal data lawfully, fairly and transparently for specified purposes.
- Collect and share only what is adequate, relevant and necessary; maintain accuracy and version control.
- Retain information only for the agreed contractual or legal period and securely delete or return it afterwards.
- Protect confidentiality, integrity and availability through proportionate technical and organisational measures.
- Maintain accountability evidence including policies, training, contracts, risk assessments, DPIAs, access reviews, audit logs and incident records.
Security controls
- Least-privilege access, unique accounts, role-based permissions and timely removal of access.
- MFA for administrative and sensitive systems where supported; TLS 1.2+ in transit and encryption at rest where platform capability permits.
- Approved secure transfer routes, managed devices, patching, screen locks, endpoint protection, backups and restoration checks.
- Contractual confidentiality and data-handling requirements for suppliers and linguists, with location and access controls proportionate to the assignment.
- No client data in unauthorised consumer AI, personal email or unapproved storage services.
Special-category data, rights and incidents
Health, social-care, safeguarding, justice and other special-category information is restricted to authorised need-to-know personnel. For sensitive public-sector work, Papillon’s default is UK processing; any approved overseas processing must satisfy client instructions and applicable UK transfer safeguards.
Papillon supports client controllers with access, rectification, restriction, deletion, audit and incident enquiries. Suspected personal-data breaches must be reported immediately. As processor, Papillon informs the relevant controller without undue delay and supports assessment and notification; for data it controls, Papillon assesses notification duties under applicable law.
Assurance
Papillon follows ISO/IEC 27001-aligned principles and maintains NHS Data Security and Protection Toolkit assurance. These statements describe alignment and assurance controls; they do not claim ISO 27001 certification.
Standards and reference points
External guidance informs this policy. Links open the authoritative publisher’s current material.
Need this policy another way?
For an accessible copy, client assurance question or concern under this policy, contact Stephen Kent, Managing Director. Do not send sensitive client or service-user information by ordinary email.
stevekent@papillontranslations.com ↗