Data Processing

The data, looked after properly.

Limelight Labs · Last updated 13 August 2026 · UK GDPR / EU GDPR

The short version When an Organisation runs its productions on Limelight, the Organisation owns the data and decides what is held - cast profiles, schedules, messages and resources. The platform holds no health data and provides no field for it. Limelight looks after that data as the Organisation's processor, only on its instructions, under this agreement. A small set of data (account login, billing, support, security, diagnostics and feedback) Limelight handles for itself as a controller, governed by the Privacy Policy. We do not monitor or moderate message content. We host on Google Cloud and Stream; the database and server-side functions are held in the United Kingdom, while uploaded files currently live in Google's United States regions under UK-approved transfer safeguards. We use named sub-processors you can object to, and on request we return or delete the data within thirty days. This DPA is designed to meet Article 28 of the UK GDPR.

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the agreement between Limelight and the Organisation under which Limelight provides the Limelight platform and related services (the "Principal Agreement"). It sets out, in plain English but in legally operative terms, how Limelight processes personal data on behalf of the Organisation, and the protections that apply to that data.

Parties

  1. Massingberd Investments Limited, a company registered in England & Wales under company number 15895057, whose registered office is at 73 Massingberd Way, London, England, SW17 6AF, trading as "Limelight Labs" and "Limelight" ("Limelight", "we", "us", or, depending on the role described in clause 3, the "Processor"); and
  2. the customer organisation that has entered into the Principal Agreement (the "Organisation" or, depending on the role described in clause 3, the "Controller").

Each a "party" and together the "parties".

Background

  1. The Organisation uses the Limelight platform to manage musical theatre productions, including cast and production data, schedules, messaging and learning resources.
  2. In providing the platform, Limelight processes personal data. For most of that data - the production data the Organisation uploads and manages - Limelight acts as a processor on the Organisation's behalf. For a limited set of data Limelight handles for its own purposes (account administration, billing, security and product diagnostics), Limelight acts as an independent controller. Clause 3 explains this split.
  3. This DPA records the parties' agreement in respect of the processing where Limelight acts as processor, and is intended to satisfy Article 28 of the UK GDPR.

Effective date: [Effective date]. This DPA takes effect on that date and remains in force for as long as Limelight processes personal data on behalf of the Organisation under the Principal Agreement.

1. Definitions and Interpretation

1.1 In this DPA, the following definitions apply:

  • "Affiliate" means, in relation to a party, any entity that controls, is controlled by, or is under common control with that party, where "control" means the ownership of more than 50% of the voting interests or the power to direct the management of the entity.
  • "Data Protection Laws" means all laws and regulations applicable to the processing of personal data under this DPA, including the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and, where and to the extent it applies to a given processing activity, the EU GDPR, in each case as amended, replaced or superseded from time to time.
  • "UK GDPR" means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.
  • "EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
  • "Controller", "processor", "data subject", "personal data", "special category data" (data concerning a person's health and other categories listed in Article 9), "processing", "personal data breach" and "supervisory authority" each have the meaning given in the UK GDPR.
  • "Controller Personal Data" means the personal data that Limelight processes on behalf of, and under the instructions of, the Organisation under the Principal Agreement, as further described in Schedule 1.
  • "Documented Instructions" means the Organisation's instructions to Limelight in respect of the processing of Controller Personal Data, comprising this DPA (including the Schedules), the Principal Agreement, the Organisation's lawful use and configuration of the platform, and any further written instructions the Organisation gives from time to time.
  • "Effective Date" means the effective date stated in the preamble, or, if none is stated, the date on which the Organisation first enters into the Principal Agreement.
  • "Services" means the Limelight platform and related services provided by Limelight to the Organisation under the Principal Agreement. Where the Principal Agreement defines this or an equivalent term, that definition applies.
  • "Sub-processor" means any third party (including any Affiliate of Limelight) engaged by Limelight to process Controller Personal Data on Limelight's behalf.
  • "UK IDTA" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018. References in this DPA to the UK IDTA include, where the parties so agree, the UK Addendum to the EU SCCs, being the alternative UK transfer route issued by the Information Commissioner.
  • "EU SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision 2021/914.
  • "Restricted Transfer" means a transfer of Controller Personal Data to a country or territory not benefiting from an adequacy decision or adequacy regulations under the relevant Data Protection Laws.
  • "Privacy Policy" means Limelight's published privacy policy at limelightlabs.co.uk/privacy, as updated from time to time, which describes the data Limelight handles as a controller in its own right.

1.2 Terms used but not defined in this DPA have the meaning given in the Principal Agreement.

1.3 References to a statute or statutory provision include that statute or provision as amended, extended or re-enacted. References to "writing" include email.

1.4 The Schedules form part of this DPA.

2. Subject Matter, Duration and Precedence

2.1 Subject matter and duration. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Schedule 1. The processing continues for the duration of the Principal Agreement and for any further period during which Limelight retains Controller Personal Data in accordance with clause 9.

2.2 This DPA prevails. This DPA forms part of the Principal Agreement. If there is any conflict or inconsistency between this DPA and any other part of the Principal Agreement on a matter concerning the processing of personal data, this DPA prevails. The order of precedence in clause 13.10 applies within this DPA.

2.3 No reduction of statutory rights. Nothing in this DPA relieves Limelight of, or limits, any obligation that the UK GDPR imposes directly on a processor. Where any provision of this DPA is more favourable to Limelight than the UK GDPR requires, that provision does not override the mandatory processor obligations in Article 28(3).

3. Roles of the Parties

3.1 The Organisation is the Controller of the Controller Personal Data described in Schedule 1 (cast and production profiles, schedules, messages, content and resources). The Organisation determines the purposes and means of that processing.

3.2 Limelight is the Processor of the Controller Personal Data and processes it only on the Organisation's behalf and on its Documented Instructions, in accordance with clause 4.

3.3 No processing for Limelight's own purposes. Limelight shall not process Controller Personal Data for any purpose other than providing the Services on the Organisation's Documented Instructions, shall not sell it, and shall not combine it with, or use it to derive, any other data set except as instructed by the Organisation or as required by law. In particular, Limelight's own administration, security, abuse-prevention, product-diagnostics and feedback activities described in clause 3.4 operate on the Limelight-controller data identified there and on aggregated or pseudonymised technical signals, and are not used to build profiles of the Organisation's users (including child users).

3.4 Limelight is an independent Controller for a limited set of data that it determines the purposes and means for, namely:

  • account administration and login/authentication details;
  • billing and the handling of support enquiries;
  • security, abuse prevention and the integrity of the platform, operating on technical and account-level signals (which are pseudonymised or aggregated where practicable) rather than on the substantive content of Controller Personal Data; and
  • product diagnostics and usage analytics, including crash reports, app performance data and in-app analytics of feature usage; and
  • feedback, research and product improvement, comprising survey responses, interview responses and other feedback provided voluntarily by the Organisation or its users, which Limelight collects and uses for its own purpose of improving and developing the platform.

This DPA does not govern Limelight's processing of that data as a controller; that processing is governed by Limelight's Privacy Policy, which provides the Article 13/14 transparency information for it, and Limelight is independently responsible for it under Data Protection Laws. Where any single data field is used by Limelight both to provide the Services to the Organisation (processor) and for Limelight's own administration, security or diagnostics (controller), each party is responsible only for the processing it carries out in its respective role, and Limelight's controller-role use does not extend to processing Controller Personal Data for its own purposes (see clause 3.3).

3.5 The parties do not consider this arrangement to create joint controllership within the meaning of Article 26 of the UK GDPR, as neither party jointly determines with the other the purposes and means of any processing.

4. Processor Obligations

Where Limelight acts as Processor, it shall comply with the following, which reflect Article 28(3)(a) to (h) of the UK GDPR.

4.1 Processing only on documented instructions (Art 28(3)(a))

Limelight shall process Controller Personal Data only on the Documented Instructions of the Organisation, including with regard to transfers to a third country, unless required to do otherwise by the law of the United Kingdom (or other applicable Data Protection Law) to which Limelight is directly subject. If Limelight is so required, it shall inform the Organisation of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest. Where Limelight or a Sub-processor receives a legally binding request from a public authority (including a foreign government) for disclosure of Controller Personal Data, Limelight shall, to the extent legally permitted, notify the Organisation, review the legality of the request, and consider available lawful means to challenge any request that appears unlawful, overbroad or disproportionate, pursuing them where reasonably practicable and proportionate.

4.2 Unlawful instructions

If Limelight reasonably considers that an instruction infringes Data Protection Laws, it shall promptly inform the Organisation and, where practicable, allow a reasonable opportunity for the Organisation to confirm, amend or withdraw the instruction before Limelight suspends the affected processing. Limelight may suspend immediately, without liability for that suspension, only where continuing to process would expose either party to legal liability or a security risk.

4.3 Confidentiality of personnel (Art 28(3)(b))

Limelight shall ensure that persons authorised to process Controller Personal Data are subject to an appropriate duty of confidentiality (whether contractual or statutory) and process the data only as instructed, and that access is limited to those who need it to provide the Services. The confidentiality obligations in this clause 4.3 survive termination or expiry of this DPA and continue for so long as the relevant personnel retain access to, or knowledge of, Controller Personal Data.

4.4 Security (Art 28(3)(c) / Art 32)

Limelight shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects. The measures in place as at the Effective Date are set out in Schedule 3. Limelight may update those measures from time to time provided that the measures at all times remain appropriate to the risk and no less protective overall than those in place at the Effective Date, and shall notify the Organisation of any material change.

4.5 Sub-processors (Art 28(3)(d) / Art 28(2) and (4))

Limelight shall engage sub-processors only in accordance with clause 5.

4.6 Assisting with data-subject rights (Art 28(3)(e))

Taking into account the nature of the processing, Limelight shall assist the Organisation by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Organisation's obligation to respond to requests by data subjects exercising their rights under Chapter III of the UK GDPR. Clause 7 sets out how this works in practice.

4.7 Assisting with security, breach notification and DPIAs (Art 28(3)(f) / Arts 32-36)

Taking into account the nature of the processing and the information available to it, Limelight shall provide reasonable assistance to the Organisation in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR (security of processing, personal data breach notification, data protection impact assessments, and prior consultation). Clauses 6 and 7 set out how this works in practice.

4.8 Return or deletion at the end (Art 28(3)(g))

At the choice of the Organisation, Limelight shall delete or return all Controller Personal Data at the end of the provision of the Services, and delete existing copies, in accordance with clause 9.

4.9 Information and audits (Art 28(3)(h))

Limelight shall make available to the Organisation all information necessary to demonstrate compliance with the obligations in Article 28, and allow for and contribute to audits, in accordance with clause 10.

4.10 Records of processing (Art 30(2))

Limelight shall maintain a record of the categories of processing carried out on behalf of the Organisation as required by Article 30(2) of the UK GDPR, and shall make that record available to the Organisation or a supervisory authority on reasonable request.

4.11 No monitoring or moderation of content

Limelight does not monitor, screen, moderate or proactively review the content of messages, newsfeed posts or other user-generated content. Server-side retention and timestamping support after-the-fact disclosure on the Organisation's request; they are not a live moderation or safeguarding-oversight service. The Organisation remains responsible for supervising its users and for safeguarding (see clause 12).

5. Sub-processing

5.1 General authorisation. The Organisation gives Limelight general written authorisation to engage sub-processors to process Controller Personal Data, subject to this clause 5. The sub-processors engaged as at the Effective Date are listed in Schedule 2, and the Organisation authorises them.

5.2 Notice of changes. Limelight shall give the Organisation at least fourteen (14) days' prior written notice before adding or replacing a sub-processor, identifying the sub-processor, the services it will provide and the location of processing, except where a sub-processor must be added or replaced urgently for security, legal or continuity reasons, in which case Limelight shall give as much prior notice as is reasonably practicable and, where prior notice is not practicable, shall notify the Organisation promptly after the change takes effect. Notice may be given by email to the Organisation's nominated contact, or by updating Limelight's published list of sub-processors and notifying the Organisation by email that it has been updated. Limelight shall update Schedule 2 (or its published list) to reflect any change.

5.3 Engagement following notice. Limelight may engage the sub-processor concerned, and transfer Controller Personal Data to it, once the notice period in clause 5.2 has expired or, in the urgent cases described in clause 5.2, immediately. An objection under clause 5.4 does not suspend or prevent the engagement of the sub-processor; the remedy for an unresolved objection is that set out in clause 5.4.

5.4 Right to object. The Organisation may object to the addition or replacement of a sub-processor on reasonable data-protection grounds by written notice given within fourteen (14) days of the notice under clause 5.2. If no objection is given within that period, the change is deemed approved. Where an objection is given, the parties shall work together in good faith to resolve it, and Limelight may propose additional safeguards or measures to address the grounds of objection. If the objection cannot be resolved within a reasonable period, the Organisation may, as its sole and exclusive remedy, terminate the Principal Agreement on written notice; on such termination Limelight shall refund any prepaid fees covering the period after termination, and the Organisation remains liable for fees accrued up to termination.

5.5 Flow-down of terms. Where Limelight engages a sub-processor, it shall do so under a written contract that imposes data-protection obligations that are the same as, or no less protective than, those set out in this DPA, and in particular meet the requirements of Article 28(3) and (4). In particular the sub-processor shall be bound by appropriate confidentiality, security and transfer obligations. On the Organisation's reasonable written request, Limelight shall provide a copy of the relevant data-protection terms of a sub-processor's contract (which may be redacted to remove commercial terms).

5.6 Continuing liability. Where a sub-processor fails to fulfil its data-protection obligations, Limelight remains fully liable to the Organisation for the performance of that sub-processor's obligations, to the same extent as if Limelight had performed them itself, subject to the limitations in clause 11.

6. Personal Data Breaches

6.1 Limelight shall notify the Organisation without undue delay, and in any event such as to allow the Organisation to meet its own notification obligations under Article 33(1) of the UK GDPR, after becoming aware of a personal data breach affecting Controller Personal Data. Where reasonably practicable, Limelight shall provide that notification within twenty-four (24) hours, and in any event within seventy-two (72) hours, of becoming aware. For these purposes, Limelight "becomes aware" when its security or engineering function has a reasonable degree of certainty that a security incident has occurred that has led to a personal data breach.

6.2 The notification shall include, to the extent known and as it becomes available (Limelight may provide information in phases), the information the Organisation reasonably needs to meet its own breach-notification obligations, including:

  • a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects and records concerned;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach and mitigate its effects; and
  • a contact point for further information.

6.3 Limelight shall take reasonable steps to investigate, contain and remediate the breach, and shall cooperate with the Organisation and provide reasonable assistance in connection with any notification the Organisation must make to a supervisory authority or affected data subjects.

6.4 Limelight shall keep, and make available to the Organisation on reasonable request, a record of all personal data breaches affecting Controller Personal Data, including the facts relating to the breach, its effects and the remedial action taken.

6.5 Limelight's notification of a breach is not, and shall not be construed as, an acknowledgement of fault or liability.

7. Data-Subject Requests and DPIA Assistance

7.1 Data-subject requests. If Limelight receives a request from a data subject in respect of Controller Personal Data, it shall not respond directly (other than to acknowledge receipt or to direct the data subject to the Organisation, unless legally required to respond), and shall promptly forward the request to the Organisation.

7.2 Taking into account the nature of the processing, Limelight shall provide reasonable assistance, by appropriate technical and organisational measures and insofar as possible, to enable the Organisation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability and objection). The platform provides self-service tools that allow the Organisation to access, correct, export and delete much of the Controller Personal Data directly; the Organisation shall use those tools in the first instance.

7.3 DPIA and prior consultation. Taking into account the nature of the processing and the information available to it, Limelight shall provide reasonable assistance to the Organisation with data protection impact assessments and any prior consultation with the supervisory authority, in each case relating to the processing carried out by Limelight on the Organisation's behalf.

7.4 Charges. Assistance that the UK GDPR requires Limelight to provide, and that is within the scope of the standard Services, will be provided at no additional charge. Where the Organisation's requests for assistance are manifestly unfounded, excessive or repetitive, or require effort materially beyond that contemplated by the standard Services, Limelight may charge a reasonable fee based on its actual costs, having first notified the Organisation and given it the opportunity to withdraw or revise the request.

8. International Transfers

8.1 The Organisation acknowledges that, as at the Effective Date, Controller Personal Data is processed as set out in Schedule 2: the database and server-side functions are hosted in the United Kingdom (Google's europe-west2 London region), whilst file storage is currently hosted in Google's United States regions (us-central1), and chat messaging uses the Stream region stated in Schedule 2. Where the Organisation is established in the United Kingdom, no Restricted Transfer takes place between the parties; Restricted Transfers occur at sub-processor level. Processing in the UK or EEA (which benefits from UK adequacy) is not a Restricted Transfer; processing in the United States is a Restricted Transfer covered by the safeguards in clause 8.2 and Schedule 4.

8.2 Limelight shall ensure that each Restricted Transfer (including the United States hosting of file storage, and the delivery of push notifications via Apple's and Google's global infrastructure) is covered by an appropriate safeguard under Data Protection Laws, being: (a) the recipient's current certification under the UK Extension to the EU-US Data Privacy Framework (the "UK-US Data Bridge"), for transfers to the United States; (b) the UK IDTA and/or the EU SCCs entered into between Limelight (or the relevant sub-processor) and the recipient, supplemented where necessary; or (c) another lawful transfer mechanism, in each case as described in Schedule 4 and together with supplementary measures including encryption in transit and at rest.

8.3 If a safeguard relied on for a Restricted Transfer is invalidated, suspended or replaced, Limelight shall implement (or shall procure that the relevant sub-processor implements) an alternative lawful transfer mechanism and any supplementary measures reasonably required, and the parties shall cooperate in good faith to that end.

8.4 Limelight shall, on reasonable request, provide the Organisation with information about any Restricted Transfer and the safeguards applied to it.

9. Return and Deletion of Data

9.1 On termination or expiry of the Principal Agreement, or on the Organisation's earlier written request, Limelight shall, at the Organisation's choice, return and/or delete the Controller Personal Data, and delete existing copies, except to the extent that retention is required by law. To give effect to this, on termination or expiry Limelight shall provide a grace period of thirty (30) days during which the Organisation may export or retrieve the Controller Personal Data and make its return-or-delete election. Where return is elected, Limelight shall return the data in a commonly-used, machine-readable format. Limelight shall delete the live Controller Personal Data within thirty (30) days of the Organisation's election or, if no election is made, within thirty (30) days of the end of the grace period.

9.2 Standard deletion window. Where the Organisation or a user deletes an account, or requests deletion, Limelight shall delete the relevant Controller Personal Data within thirty (30) days, except where retention is legally required or where data is held in routine backups that are overwritten on a rolling cycle (in which case the backup copies are deleted on that cycle, which shall be no longer than thirty (30) days, and are protected from active use in the meantime). This is consistent with the deletion commitment in the Privacy Policy.

9.3 Chat messages. Chat message content is processed through the sub-processor Stream and, while an account is active, is retained server-side under Stream's default retention configuration (which Limelight controls at the application level) to support production messaging and safeguarding auditability. On account deletion or a deletion request under clause 9.2, Limelight removes the Stream user and marks that user's messages as deleted in shared channels within the same thirty (30) day window; the underlying message content is then purged in line with Stream's retention configuration. Where a specific message must be preserved, this is done only on the documented instruction of the Organisation's nominated contact (such as its safeguarding lead), or where required by a legal obligation; in that case Limelight preserves only that specific message, for no longer than necessary and subject to periodic review, and records the reason, the retention period and a review date. Any such preservation is carried out on the Organisation's behalf as controller and not at Limelight's own initiative.

9.4 Certification. At the Organisation's written request, Limelight shall provide written certification that it has deleted the Controller Personal Data in accordance with this clause 9. Such certification satisfies Limelight's deletion obligations under this DPA in respect of the data certified.

9.5 Where Limelight retains any Controller Personal Data because the law requires it, Limelight shall retain it only for as long as the law requires, shall protect it from any further processing other than that required by law, and shall keep it secure.

10. Audit and Demonstrating Compliance

10.1 Limelight shall make available to the Organisation, on reasonable written request, the information reasonably necessary to demonstrate compliance with Article 28 and this DPA. On reasonable written request and subject to an appropriate confidentiality undertaking, Limelight shall provide the Organisation with its then-current third-party audit reports and certifications (for example SOC 2 and/or ISO 27001 reports) held by Limelight or its sub-processors.

10.2 Third-party reports first. The Organisation agrees that, in the first instance, Limelight may satisfy its obligation to make available information and to allow for and contribute to audits by providing the third-party audit reports, certifications and summaries described in clause 10.1. The Organisation shall accept such reports as sufficient where they reasonably address the subject matter of the request.

10.3 On-site / direct audits. Where the third-party reports do not reasonably address the Organisation's compliance verification needs, the Organisation (or a mandated independent auditor who is not a competitor of Limelight and who is bound by confidentiality) may carry out an audit of Limelight's processing of Controller Personal Data, subject to the following, which the parties agree are reasonable:

  • audits are limited to once in any twelve (12) month period (except where required by a supervisory authority, or following a personal data breach affecting the Organisation's data);
  • the Organisation must give at least thirty (30) days' prior written notice;
  • audits take place during normal business hours, must not unreasonably disrupt Limelight's operations, and must respect the security and confidentiality of Limelight's other customers;
  • the auditor and the Organisation are bound by appropriate confidentiality obligations;
  • the scope is limited to information and systems relevant to the processing of the Organisation's Controller Personal Data; and
  • the Organisation bears its own and Limelight's reasonable costs of the audit, save where (i) the audit reveals a material breach by Limelight of this DPA, or (ii) the audit is required by a supervisory authority, in which cases Limelight bears its own costs.

10.4 Limelight shall contribute to and cooperate with such audits and inspections as required by Article 28(3)(h). Nothing in this clause limits any audit or inspection right the Organisation has under Article 28(3)(h), or that a supervisory authority requires. This clause does not require Limelight to provide access to data, systems or information of its other customers, or to information the disclosure of which would breach a legal or confidentiality obligation or compromise security.

11. Liability and Indemnity

11.1 Liability cap. Subject to clauses 11.2 and 11.6, each party's total aggregate liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is subject to, and counts towards, the limitations and exclusions of liability set out in the Principal Agreement. Where the Principal Agreement caps liability by reference to fees paid, that same cap applies to liability under this DPA, and liability under the Principal Agreement and this DPA is aggregated, so that the cap is not multiplied by the existence of this DPA.

11.2 Data-protection super-cap. Notwithstanding clause 11.1, each party's aggregate liability for breach of its data-protection obligations under this DPA shall not exceed the greater of (a) 125% of the fees paid or payable by the Organisation under the Principal Agreement in the twelve (12) months preceding the event giving rise to the claim, or (b) £10,000. This super-cap is mutual, applies in place of (and is not cumulative with) the general cap in clause 11.1 for data-protection liability, and does not apply to the matters in clause 11.6.

11.3 Each party's liability under or in connection with this DPA is limited to direct losses. Neither party is liable for indirect, special or consequential loss, or for loss of profit, revenue, goodwill or anticipated savings, except to the extent such exclusion is not permitted by law.

11.4 Controller indemnity. The Organisation shall indemnify and hold harmless Limelight against all losses, claims, damages, costs and reasonable expenses that Limelight incurs arising out of or in connection with:

  • the Organisation's instructions, where Limelight has acted in accordance with them, including any instruction that infringes Data Protection Laws;
  • the Organisation's failure to establish or maintain a lawful basis for the processing, including its failure to obtain any necessary consent (parental or guardian consent for children, and an Article 9 condition for any special category data it enters in breach of clause 12.1);
  • the Organisation's failure to provide required privacy notices or information to data subjects; or
  • the Organisation's other breach of clause 12 or of Data Protection Laws in its capacity as Controller,

except to the extent the loss arises from Limelight's own breach of this DPA or its own negligence, and except for any regulatory fine imposed on Limelight for Limelight's own infringement. The Organisation's indemnity obligations under this clause 11.4 are not subject to the limitations in clauses 11.1 to 11.3. The indemnity is conditional on Limelight giving the Organisation prompt written notice of the relevant claim, not admitting or settling it without the Organisation's prior written consent (not to be unreasonably withheld), allowing the Organisation to have conduct of its defence and settlement (with Limelight's reasonable input), and taking reasonable steps to mitigate its loss.

11.5 Processor indemnity. Limelight shall indemnify and hold harmless the Organisation against all losses, claims, damages, costs and reasonable expenses that the Organisation incurs arising out of or in connection with Limelight's breach of this DPA or its processing of Controller Personal Data otherwise than in accordance with the Organisation's lawful Documented Instructions, except for any regulatory fine imposed on the Organisation for the Organisation's own infringement. The same notice, conduct and mitigation conditions in clause 11.4 apply, with the parties reversed. This indemnity is subject to clause 11.2.

11.6 Carve-outs. Nothing in this DPA limits or excludes either party's liability for death or personal injury caused by its negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be limited or excluded.

11.7 Article 82. This clause 11 does not affect any data subject's right to compensation under Article 82 of the UK GDPR, or the allocation of liability between controllers and processors under Article 82 as between the parties and a supervisory authority. As between the parties, liability shall be borne in proportion to each party's responsibility for the damage under Article 82(5), save that the indemnities in clauses 11.4 and 11.5 shall apply to losses arising from the matters listed in those clauses regardless of such proportionate split.

12. Controller Responsibilities and Warranties

12.1 The Organisation warrants and undertakes that:

  • Lawful basis and notices. It has, and will maintain, a valid lawful basis under Article 6 of the UK GDPR for all Controller Personal Data it provides to or processes through the platform, and has given all privacy notices and information to data subjects required by Data Protection Laws.
  • Special category and criminal offence data. The parties do not intend that special category personal data, or personal data relating to criminal convictions and offences, will be processed through the platform, and the platform provides no field for such data. The Organisation shall not intentionally upload or enter such data, and shall not instruct Limelight to process it, unless the parties have first agreed in writing the applicable purposes, lawful basis, Article 9 (or Article 10) condition and appropriate safeguards. The parties acknowledge that, because the platform carries free-text fields, messages and uploaded files whose content Limelight neither specifies nor monitors (clause 4.11), such data could be included incidentally; any such content is processed by Limelight solely as part of its general hosting instruction under this DPA, and the Organisation remains the Controller responsible for it, including for any Article 9 or Article 10 condition required. If either party becomes aware that special category or criminal offence data has been included on the platform, it shall inform the other without undue delay, and Limelight shall cooperate with the Organisation, on its documented instructions, to restrict, delete or otherwise appropriately deal with that data in accordance with Data Protection Laws.
  • Children. Where Controller Personal Data relates to children (users under 18), it is responsible for the safeguarding of those children, in line with Limelight's published safeguarding materials. For users below the age at which a child can consent to information society services (13 in the UK under section 9 of the Data Protection Act 2018), the Organisation must obtain and evidence appropriate parental or guardian consent, and carry out any age-verification, before the user accesses the platform. Limelight does not direct its service at children independently of the Organisation.
  • Lawful instructions. Its instructions to Limelight regarding the processing of Controller Personal Data are and will remain lawful and within the scope of the Principal Agreement.
  • Accuracy and authority. It has the authority to provide the Controller Personal Data to Limelight, and to authorise the processing described in this DPA, including the engagement of sub-processors and the international transfers in clause 8 and Schedule 4.

12.2 The Organisation is responsible for the acts and omissions of its own authorised users (including teachers, directors, student leaders and administrators) in their use of the platform, and for supervising its users. As noted in clause 4.11, Limelight does not monitor or moderate content and the platform is not a safeguarding-oversight service.

13. General

13.1 Variation. No variation of this DPA is effective unless in writing and signed by or on behalf of each party, except that Limelight may update Schedule 2 (sub-processors) under the mechanism in clause 5, and may update Schedule 3 (security measures) under clause 4.4 provided protection is not reduced below the floor stated there.

13.2 Severance. If any provision of this DPA is held to be invalid or unenforceable, it shall be modified to the minimum extent necessary to make it valid and enforceable, or, if that is not possible, severed; the remaining provisions continue in full force.

13.3 No third-party rights. Except as set out in clause 13.4, a person who is not a party to this DPA has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms.

13.4 Data subjects. Where Data Protection Laws confer directly enforceable rights on data subjects as third-party beneficiaries, those rights are preserved to the extent the law requires.

13.5 Survival. Clauses 4.3 (confidentiality), 6.4 (breach records), 9 (return and deletion), 10 (audit), 11 (liability and indemnity) and 12 (controller warranties), together with any other provision that by its nature is intended to survive, continue in force after termination or expiry of this DPA.

13.6 Notices. Legal notices under this DPA (including breach notifications, sub-processor objections and termination notices) must be in writing and sent to the other party's nominated contact. For Limelight, that contact is the data protection contact in clause 13.8. For the Organisation, it is the contact stated in the Principal Agreement or otherwise notified to Limelight. Notice by email is valid and is deemed received on the next business day after sending, absent a delivery failure.

13.7 Assignment. Neither party may assign or novate this DPA except in accordance with the assignment provisions of the Principal Agreement; where the Principal Agreement is validly assigned or novated, this DPA transfers with it.

13.8 Data protection contact. Limelight has not appointed a statutory Data Protection Officer under Article 37, having assessed that it is not required to do so; Limelight will keep that assessment under review and document it. Its data protection contact is Dom Conte, who can be reached at dom@limelightlabs.co.uk. The Organisation should direct data-protection queries, sub-processor objections and audit requests to that contact.

13.9 Governing law and jurisdiction. This DPA and any dispute or claim arising out of or in connection with it (including non-contractual disputes or claims) are governed by the law of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.

13.10 Order of precedence. In the event of conflict, the following order of precedence applies: (a) the body of this DPA; (b) the Schedules to this DPA; (c) the remainder of the Principal Agreement; and (d) the Privacy Policy.

13.11 Counterparts and electronic execution. This DPA may be executed in counterparts, each of which is an original and which together form one agreement, and may be signed electronically.

13.12 Signature. By entering into the Principal Agreement, or by signing below, each party agrees to this DPA.

For Massingberd Investments Limited (Processor)For the Organisation (Controller)
Name: [Signatory name]Name: [Organisation signatory name]
Title: [Signatory title, e.g. Director]Title: [Organisation signatory title]
Date: [Date]Date: [Date]

Schedule 1 - Details of Processing

Categories of data subjects

  • Students / cast members, including children under 18 and children under 13 (the latter requiring appropriate parental or guardian consent obtained by the Organisation).
  • Student leaders / lead cast.
  • Teachers / tutors / directors.
  • Organisation administrators (org admins).
  • Super admins (founder-level; audit-only, by request).

Categories of personal data

CategoryDetail
Account informationName, email address, password (stored securely and hashed by the authentication provider), profile photo, short bio, and the Organisation and show(s) the user belongs to. (Account and authentication details are handled by Limelight as an independent controller per clause 3.4; this row is included for completeness of the data inventory rather than as data processed solely under the Organisation's instructions.)
Cast and production profile dataPhone number, date of birth, gender, emergency contact details (name, phone number and relationship), and costume measurements (height, chest, waist, hips, inseam, head circumference and shoe size). Optional; held on behalf of and under the instructions of the Organisation. Where these fields (including body measurements and date of birth) relate to children, the Organisation is responsible for ensuring their collection is necessary and age-appropriate.
Content provided by usersChat messages, newsfeed posts, comments, personal annotations and bookmarks, and any images, audio recordings or files uploaded.
Diagnostic and usage dataCrash reports and app performance data (such as load times); in-app analytics (which screens/features are used and the user's role). (Note: where processed for Limelight's own diagnostics and analytics, this is handled by Limelight as an independent controller - see clause 3.4.)
Device dataDevice model, operating system version, app version, a unique installation identifier and a push notification token.
Device permissions dataCamera and photo library access (profile photos and image uploads), microphone access (audio uploads), Face ID / Touch ID (on-device app unlock only; biometric data never leaves the device), and location access (used only to display venue locations on a map). Each permission is used only when granted by the user and only for the invoked feature. The platform does not collect or store any user's real-time location; venue locations are addresses entered by administrators.

Special category personal data (Article 9)

None intended. The platform provides no field for special category data, and the parties do not intend it to be processed through the platform. Limelight does not solicit, structure or knowingly process special category data on any Organisation's behalf. The platform does carry free-text fields, messages and uploaded files whose content Limelight neither specifies nor monitors (clause 4.11); any such content included there is processed by Limelight solely as part of its general hosting instruction under this DPA, and clause 12.1 governs responsibility for it and its remediation.

Nature and purpose of processing

The provision of the Limelight platform for the management of musical theatre productions, including: hosting and storing cast and production profiles; scheduling rehearsals and performances; real-time messaging and a newsfeed within shows; distribution of learning resources (audio, PDF and other files); display of venue locations on a map; delivery of push notifications; and the storage, organisation, retrieval, transmission, return and deletion of the above data on the Organisation's instructions. Limelight does not monitor or moderate the content of messages or posts (see clause 4.11).

Duration of processing

For the duration of the Principal Agreement and any subsequent retention period permitted or required under clause 9. Personal data is kept while the account is active, plus a reasonable period thereafter to comply with legal obligations, resolve disputes and enforce agreements; on account deletion or a deletion request, data is deleted within thirty (30) days, except where retention is legally required.

Schedule 2 - Approved Sub-processors

The following sub-processors are approved as at the Effective Date. Changes are notified and may be objected to under clause 5. Each sub-processor relies on its own transfer safeguards (such as a current UK-US Data Bridge certification, the EU SCCs and/or the UK IDTA) for any onward transfers, which Limelight will summarise on request under clause 8.4.

Sub-processorPurposeLocationCertifications
Google (Firebase / Google Cloud) Authentication, database (Cloud Firestore), file storage, cloud functions, crash reporting (Crashlytics), performance monitoring, and push notification delivery (Firebase Cloud Messaging). United Kingdom for the database and cloud functions (Cloud Firestore, europe-west2 London); United States (us-central1) for file storage, under the safeguards in clause 8.2 and Schedule 4. ISO 27001 and SOC 1/2/3 (among others).
Stream (getstream.io) Real-time chat messaging within shows; processes message content and related metadata. Retention is managed via Stream Chat with the default configuration applied at the application level (see clause 9.3). United Kingdom / EEA (Stream EU data residency). SOC 2 Type II and ISO 27001 certified.
Apple Delivery of push notifications via the Apple Push Notification service (APNs). Apple receives a push notification token and the notification payload for delivery only; push notifications preview message text, so the payload may include limited message content. Payloads are encrypted in transit and held by Apple only for the purposes of delivery; individual users can disable message previews on their own device in iOS notification settings. Global (Apple Push Notification service). Any transfer is covered by appropriate safeguards (see Schedule 4). See Apple's published compliance documentation (including ISO 27001 and SOC 2 reports for relevant services).
Google Maps Display of venue locations on a map where an Organisation has added venue addresses. Map display only, using venue addresses the Organisation enters. Any transfer is covered by appropriate safeguards (see Google row). Covered by Google's ISO 27001 and SOC 1/2/3 certifications (see Google row).

Schedule 3 - Technical and Organisational Security Measures (Article 32)

The measures below are in place as at the Effective Date and map to Article 32(1)(a) to (d) of the UK GDPR. Limelight may update them under clause 4.4 provided protection remains appropriate to the risk and no less protective overall than at the Effective Date.

AreaMeasure
Encryption in transitData in transit is encrypted using TLS (TLS 1.2 or above everywhere).
Encryption at restData at rest is encrypted by the cloud provider (Google Cloud) as standard.
Access control (RBAC)Role-based access control with permissions enforced server-side at the database layer (Firestore security rules), not just in the UI.
Scoped roles and least privilegeFive distinct scoped roles (Student, Student leader, Teacher, Org admin, Super admin). Access is limited to authorised personnel of Limelight and the Organisation, on a need-to-know basis.
Tenant data isolationEach Organisation's data is logically segregated, and access is scoped to the Organisation and show(s) a user belongs to, enforced by the server-side security rules.
Multi-factor authenticationMulti-factor authentication is enabled for administrative and privileged access to the production environment and provider consoles.
Access loggingAdministrative and privileged access to production systems is logged via the cloud provider's audit logging and is available for review.
Credential protectionPasswords are hashed and never stored in plain text.
Resilience and availabilitySystems are hosted on managed cloud infrastructure; data is replicated across multiple zones within the hosting region, protecting durability and availability against hardware failure and physical incident.
Restoration and backupsThe database is backed up automatically every day, with backups retained for seven days, and point-in-time recovery is enabled, allowing the database to be restored to any point in the preceding seven days. Uploaded files are versioned, with previous versions retained for thirty days. Backups are encrypted and subject to access controls; backup copies are purged on a rolling cycle of no more than thirty days, consistent with clause 9.2.
Vulnerability and patch managementDependencies and infrastructure are kept up to date, with security patches applied on a regular cadence and promptly for high-severity issues.
Regular testing and evaluationFirestore security rules are tested against the role model on every release, and Limelight reviews and evaluates the effectiveness of its security measures on a regular basis.
Personnel securityAccess to Controller Personal Data is limited to authorised personnel bound by confidentiality obligations.
Sub-processor assuranceCore infrastructure sub-processors hold recognised certifications (ISO 27001, SOC 2 - see Schedule 2).
Vulnerability / responsible disclosureA responsible disclosure process is in place (email dom@limelightlabs.co.uk).
Auditability of messagingServer-side timestamping and retention of chat messages support after-the-fact disclosure; manual disclosure / retrieval assistance is available to the Organisation's safeguarding leads on request. This is not a live monitoring or moderation service (see clause 4.11).

Schedule 4 - Transfer Safeguards

(a) Controller Personal Data is processed by the sub-processors in the locations listed in Schedule 2: the database is hosted in the United Kingdom; server-side functions are hosted in the United Kingdom; file storage is currently hosted in the United States; and push notifications are delivered via Apple's and Google's global infrastructure. Where the Organisation is established in the United Kingdom, no Restricted Transfer takes place between the parties; Restricted Transfers are effected at sub-processor level. Processing in the UK or the EEA (which benefits from UK adequacy regulations) does not involve a Restricted Transfer.

(b) The specific safeguard relied on for each Restricted Transfer as at the Effective Date is as follows:

  • Google - file storage (United States, us-central1) and Android push delivery via Firebase Cloud Messaging: Google LLC holds a current certification under the UK Extension to the EU-US Data Privacy Framework (the UK-US Data Bridge) covering the services in use; in addition, the EU SCCs and the UK Addendum are incorporated into Google's Firebase Data Processing and Security Terms and apply as a fallback if that certification ceases to be available.
  • Stream - chat messaging: no Restricted Transfer arises, as processing is confined to the United Kingdom / EEA.
  • Apple - delivery of push notifications via the Apple Push Notification service: Apple does not make an Article 46 transfer instrument available for APNs. The data transferred is limited to a device push token and the notification payload (which may include limited message content), is encrypted in transit and is held by Apple only transiently for the purposes of delivery. Limelight relies on the necessity of the transfer for delivering notifications requested by the user, together with the technical and organisational measures described in Schedules 2 and 3, and the Organisation, having been informed of this position, authorises the transfer under clause 12.1 (accuracy and authority). Message previews may be disabled by any user on their own device in iOS notification settings.

In each case, supplementary measures include encryption in transit and at rest.

(c) Limelight shall keep the safeguards relied on for each Restricted Transfer under review and shall, on the Organisation's reasonable request under clause 8.4, identify and summarise the safeguard applied to any given transfer.

(d) If a safeguard ceases to provide a lawful basis for a Restricted Transfer, clause 8.3 applies.