Policies and Agreements
Business Continuity Policy
Last updated: 20 August 2026
Review date: 20 August 2027
1. Purpose
Localscript is operated by one person. The obvious question is what happens to your recordings if something happens to me.
This document answers it with scenarios and timescales rather than a management structure. It is the policy referred to at clause 3.4 of the Localscript Data Processing Agreement and at section 13 of the Localscript Information Security Policy, and it is what makes the "standing written instructions" promised in that clause real.
In scope: transcription and anonymisation services, and the client data held while delivering them.
Out of scope: nothing. There is one service and one person delivering it.
Owner: Montagu Franks, Director.
2. What matters most, in order
Not everything needs to recover at the same speed. In priority order:
- Your data stays protected. A disruption must never become a data breach. Nothing in this plan trades security for speed.
- You get your data back, or it is destroyed. Whichever you choose — but you are never left not knowing where your recordings are.
- You find out promptly. So you can go elsewhere while your deadline is still achievable.
- The work gets finished. Last, deliberately. A missed deadline is recoverable. A lost or exposed recording is not.
Data protection does not lapse during a disruption. Every obligation in the Data Processing Agreement — no transfers outside the UK, no sub-processors, no access by anyone other than the named individual, 30-day deletion — applies in full during an incident. An emergency is not a justification for handing your audio to somebody else.
3. Scenarios and recovery times
| Scenario | You are told within | Your data back within | Processing resumes within |
|---|---|---|---|
| Processing machine fails or is stolen | 1 working day | 1 working day | 5 working days |
| Short illness — under a week | 1 working day | On request | On recovery |
| Extended illness — over a week | 1 working day | 2 working days | Uncertain — you are released |
| Incapacity or death | 5 working days | See section 6 | Not applicable |
| Home or premises unavailable | 1 working day | 2 working days | 5 working days |
| Loss of internet or power | Same day if a deadline is affected | — | Ordinarily same day |
| Email or website provider fails | Same day | — | Immediately — see section 7 |
These are targets I hold myself to, not contractual guarantees. Where I cannot meet one, I say so at the time rather than let a deadline pass silently.
4. Hardware failure or theft
Immediate. Treated as a security incident under section 12 of the Information Security Policy. Affected clients are notified within 24 hours. A stolen machine is reported to the police, and the crime reference given to any client who asks.
Why theft is not automatically a breach. The processing machine is fully encrypted at rest, with authentication required at boot. A thief has an expensive brick, not a set of interviews. This is the single most important reason full-disk encryption is non-negotiable rather than good practice — it converts the most likely incident into an inconvenience.
Recovery. Client data is restored from encrypted backup held on removable media in the UK. Returning your files needs only a working computer and the backup — one working day. Rebuilding the full processing environment takes longer, because the operating system, pipeline, dependencies and model weights all have to be reinstalled and several gigabytes re-downloaded — five working days.
If your deadline cannot survive five days, I tell you on day one and release you.
5. Illness
Short — under a week. Deadlines are reassessed and you are told immediately if yours is at risk. Most single-file work absorbs a few days without consequence.
Extended — over a week, or open-ended. You are told within one working day of it becoming clear. Your recordings are returned or destroyed at your election within two working days. I do not hold work hoping to recover in time. Clause 13.3 of the Terms and Conditions commits me to saying so promptly and releasing you rather than holding the work, and this is where that applies.
There is no second operator to hand the work to, and introducing one without your written authorisation would breach clause 3.3 of the Data Processing Agreement. That is a real limitation of a single-operator service, and it is the trade for knowing exactly who has heard your recording.
6. Incapacity or death
The scenario nobody asks about directly and everybody thinks about.
Standing written instructions are held with my instructions to my executors and with a nominated contact. They are sufficient to give effect to clause 3.4 of the Data Processing Agreement without that person needing to read, open or understand any client file.
On becoming aware, the nominated contact will:
- Notify every active client, from a client list held with the instructions, within 5 working days.
- Notify the Information Commissioner's Office of the cessation.
- Carry out secure destruction of all client recordings, transcripts, logs and keys, and issue a Certificate of Erasure to each affected client.
Destruction, not return, is the default — and that is deliberate. Returning your data would require someone to decrypt and access it, which is precisely what clause 3.3 forbids without your written authorisation. Destruction requires no such access: the encryption keys and the media are destroyed without anything being opened or read.
This is why clause 4.4 of the Terms and Conditions asks you to keep your own copy of every recording. In this scenario, your copy is the one that survives. Mine is designed not to.
If you would prefer return rather than destruction, say so in writing at the outset and it is recorded against your engagement. Return then requires a person you nominate and authorise, on terms you set.
What the nominated contact does not have. No routine access to the processing machine, to client data, or to any working account. They hold sealed instructions, a contact list, and the authority to act on them. They cannot read a transcript, and are not asked to.
7. Supplier and infrastructure failure
The architecture makes most of this uneventful, because almost nothing depends on a supplier.
- Processing depends on no external service. An internet outage does not stop transcription — it only delays transfer and delivery. This is a direct benefit of the local-first design, not a coincidence.
- Email runs on Microsoft Exchange Online. Outages are ordinarily short. Where one affects a deadline, I contact affected clients by another route.
- Website and booking are convenience only. Neither holds client data and neither is needed to deliver work. If both vanished tomorrow, every live engagement would continue.
- Power. The processing machine is a laptop with an internal battery, so a domestic outage does not terminate a run or corrupt working files.
- Premises. Where home is unavailable, work moves to alternative premises within the United Kingdom that meet section 5 of the Information Security Policy. Client data is not processed in cafés, libraries, co-working spaces or in transit, and that restriction does not relax in a disruption.
8. Communicating during an incident
- Affected clients are contacted directly, not left to discover it from a status page. There is no status page.
- Notification says what has happened, what it means for their deadline, and what their options are — including going elsewhere.
- Security incidents follow the 24-hour notification commitment at clause 3.2(e) of the Data Processing Agreement, which is separate from and faster than the timescales in section 3.
- A client list sufficient to make these contacts is held with the standing instructions, in encrypted form, containing names and email addresses only — no participant data.
9. Testing
A plan never tested is a plan that does not work.
- Restore test — monthly. A backup is restored and verified, per section 9 of the Information Security Policy.
- Rebuild test — annually. The processing environment is rebuilt from scratch and timed, to check that the five-day figure in section 3 is still true rather than aspirational.
- Instruction review — annually. The standing instructions and client list are checked with the nominated contact for accuracy and accessibility.
- After every incident. What happened, what worked, what changed as a result.
Where a test shows a target cannot be met, the target in this document is corrected rather than the test repeated until it passes.
10. What I do not promise
- No 24/7 availability. Working hours are Monday to Friday. There is no out-of-hours cover.
- No hot standby. There is no second machine ready to run, and no second operator.
- No guarantee your deadline survives. Some disruptions will cost you time. The commitment is that you find out early enough to act, not that it never happens.
- No independent certification. This plan is not audited or externally validated.
A one-person service cannot offer what a hundred-transcriber operation can on availability. It offers something different: one named person, no pool, no offshore handoff, and a plan that says what will actually happen rather than who would convene to decide.
11. Document control
| Version | Date | Amendments |
|---|---|---|
| 1.0 | 20 August 2026 | First issue |
Reviewed annually, and additionally after any incident, any change to the processing setup or backup arrangement, any change to the nominated contact, and any annual rebuild test that returns a different figure.
Questions about this document? Email {{ contactEmail }}.