← Back to Tupolis

Policies & Legal

Last updated: 3 September 2026

Operator: People Building Ltd Company number: 06969239 Address: 15 Queensway, Hemel Hempstead, Hertfordshire, HP1 1LS, United Kingdom Email: info@peoplebuilding.co.uk ICO registration: Z2203181

1. Purpose

Tupolis depends on third-party technologies for hosting, delivery, security, development and embedded content. The exact production provider register must be maintained internally and this notice must match reality.

2. Roles

People Building may act as controller. A supplier may act as processor, independent controller or in another role depending on what it does. The legal role is determined by the actual processing, not merely by calling every supplier a processor.

3. Infrastructure and email

Tupolis may use Amazon Web Services, including EC2 or related services, and Amazon SES for hosting/computing and transactional email delivery.

4. Security/network services

Cloudflare may be used for DNS, delivery, traffic management and security functions.

5. Development

GitHub may be used for source-code management/development. Development tools do not automatically have permission to receive live user data.

6. Error monitoring and diagnostics

A production error-monitoring/diagnostics provider may be used. The exact provider must be verified before it is named publicly. Diagnostic collection should minimise personal/sensitive information.

7. YouTube/Google

Tupolis may embed YouTube content. Google/YouTube may process information when content is loaded or used. Tupolis login is separate from Google/YouTube login. Cookie/consent behaviour must be implemented consistently with the Cookie Policy.

8. Payments and programme sales

Tupolis does not currently operate a standalone subscription checkout. Programme purchases may occur externally using services such as Stripe, PayPal or Keap/Infusionsoft. Where Tupolis links members to external upgrade or purchase pages, those providers may act independently for payment processing and customer management.

9. Future AI

The future AI provider is undecided. Before launch People Building must review contracts, provider data use/training, retention, security, processing locations, subprocessors and international transfers, and update this notice.

10. Children

Third-party sharing involving child information should be minimised, high privacy by default, and supported by due diligence appropriate to the child's best interests.

11. Practitioner uploads

Restricted practitioner uploads must not be treated as a general client-record storage facility. Provider access should remain limited to what is needed to operate/support the service.

12. Contracts, transfers and minimisation

Where required, appropriate processing contracts and international-transfer safeguards should be used. Send each provider only the information reasonably needed for its service.

13. Development/test data

Use artificial, anonymised or appropriately pseudonymised test data where reasonably practicable. Live data should be used in development only when genuinely necessary and appropriately protected.

14. Provider register

Maintain an internal register recording provider, purpose, role, data categories, contract/DPA, processing location, transfer mechanism, subprocessors, retention, security review and review date.

← All policies