This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the agreement between Limelight and the Organisation under which Limelight provides the Limelight platform and related services (the "Principal Agreement"). It sets out, in plain English but in legally operative terms, how Limelight processes personal data on behalf of the Organisation, and the protections that apply to that data.
Each a "party" and together the "parties".
Effective date: [Effective date]. This DPA takes effect on that date and remains in force for as long as Limelight processes personal data on behalf of the Organisation under the Principal Agreement.
1.1 In this DPA, the following definitions apply:
1.2 Terms used but not defined in this DPA have the meaning given in the Principal Agreement.
1.3 References to a statute or statutory provision include that statute or provision as amended, extended or re-enacted. References to "writing" include email.
1.4 The Schedules form part of this DPA.
2.1 Subject matter and duration. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Schedule 1. The processing continues for the duration of the Principal Agreement and for any further period during which Limelight retains Controller Personal Data in accordance with clause 9.
2.2 This DPA prevails. This DPA forms part of the Principal Agreement. If there is any conflict or inconsistency between this DPA and any other part of the Principal Agreement on a matter concerning the processing of personal data, this DPA prevails. The order of precedence in clause 13.10 applies within this DPA.
2.3 No reduction of statutory rights. Nothing in this DPA relieves Limelight of, or limits, any obligation that the UK GDPR imposes directly on a processor. Where any provision of this DPA is more favourable to Limelight than the UK GDPR requires, that provision does not override the mandatory processor obligations in Article 28(3).
3.1 The Organisation is the Controller of the Controller Personal Data described in Schedule 1 (cast and production profiles, schedules, messages, content, resources and any special category health data). The Organisation determines the purposes and means of that processing.
3.2 Limelight is the Processor of the Controller Personal Data and processes it only on the Organisation's behalf and on its Documented Instructions, in accordance with clause 4.
3.3 No processing for Limelight's own purposes. Limelight shall not process Controller Personal Data for any purpose other than providing the Services on the Organisation's Documented Instructions, shall not sell it, and shall not combine it with, or use it to derive, any other data set except as instructed by the Organisation or as required by law. In particular, Limelight's own administration, security, abuse-prevention and product-diagnostics activities described in clause 3.4 operate on the Limelight-controller data identified there and on aggregated or pseudonymised technical signals, and are not used to build profiles of the Organisation's users (including child users).
3.4 Limelight is an independent Controller for a limited set of data that it determines the purposes and means for, namely:
This DPA does not govern Limelight's processing of that data as a controller; that processing is governed by Limelight's Privacy Policy, which provides the Article 13/14 transparency information for it, and Limelight is independently responsible for it under Data Protection Laws. Where any single data field is used by Limelight both to provide the Services to the Organisation (processor) and for Limelight's own administration, security or diagnostics (controller), each party is responsible only for the processing it carries out in its respective role, and Limelight's controller-role use does not extend to processing Controller Personal Data for its own purposes (see clause 3.3).
3.5 The parties do not consider this arrangement to create joint controllership within the meaning of Article 26 of the UK GDPR, as neither party jointly determines with the other the purposes and means of any processing.
Where Limelight acts as Processor, it shall comply with the following, which reflect Article 28(3)(a) to (h) of the UK GDPR.
Limelight shall process Controller Personal Data only on the Documented Instructions of the Organisation, including with regard to transfers to a third country, unless required to do otherwise by the law of the United Kingdom (or other applicable Data Protection Law) to which Limelight is directly subject. If Limelight is so required, it shall inform the Organisation of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest. Where Limelight or a Sub-processor receives a legally binding request from a public authority (including a foreign government) for disclosure of Controller Personal Data, Limelight shall, to the extent legally permitted, notify the Organisation, shall review the legality of the request, and shall challenge any request that is unlawful, overbroad or disproportionate.
If Limelight reasonably considers that an instruction infringes Data Protection Laws, it shall promptly inform the Organisation and, where practicable, allow a reasonable opportunity for the Organisation to confirm, amend or withdraw the instruction before Limelight suspends the affected processing. Limelight may suspend immediately, and without liability for that suspension, only where continuing to process would expose either party to legal liability or a security risk; otherwise it may suspend (without liability for that suspension) once the opportunity above has been given and the instruction has not been resolved. Limelight is not obliged to carry out legal research to police the Organisation's instructions; this duty applies to infringements that are apparent to Limelight.
Limelight shall ensure that persons authorised to process Controller Personal Data are subject to an appropriate duty of confidentiality (whether contractual or statutory) and process the data only as instructed, and that access is limited to those who need it to provide the Services. The confidentiality obligations in this clause 4.3 survive termination or expiry of this DPA and continue for so long as the relevant personnel retain access to, or knowledge of, Controller Personal Data.
Limelight shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects. The measures in place as at the Effective Date are set out in Schedule 3. Limelight may update those measures from time to time provided that the measures at all times remain appropriate to the risk and no less protective overall than those in place at the Effective Date, and shall notify the Organisation of any material change.
Limelight shall engage sub-processors only in accordance with clause 5.
Taking into account the nature of the processing, Limelight shall assist the Organisation by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Organisation's obligation to respond to requests by data subjects exercising their rights under Chapter III of the UK GDPR. Clause 7 sets out how this works in practice.
Taking into account the nature of the processing and the information available to it, Limelight shall provide reasonable assistance to the Organisation in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR (security of processing, personal data breach notification, data protection impact assessments, and prior consultation). Clauses 6 and 7 set out how this works in practice.
At the choice of the Organisation, Limelight shall delete or return all Controller Personal Data at the end of the provision of the Services, and delete existing copies, in accordance with clause 9.
Limelight shall make available to the Organisation all information necessary to demonstrate compliance with the obligations in Article 28, and allow for and contribute to audits, in accordance with clause 10.
Limelight shall maintain a record of the categories of processing carried out on behalf of the Organisation as required by Article 30(2) of the UK GDPR, and shall make that record available to the Organisation or a supervisory authority on reasonable request.
Limelight does not monitor, screen, moderate or proactively review the content of messages, newsfeed posts or other user-generated content. Server-side retention and timestamping support after-the-fact disclosure on the Organisation's request; they are not a live moderation or safeguarding-oversight service. The Organisation remains responsible for supervising its users and for safeguarding (see clause 12).
5.1 General authorisation. The Organisation gives Limelight general written authorisation to engage sub-processors to process Controller Personal Data, subject to this clause 5. The sub-processors engaged as at the Effective Date are listed in Schedule 2, and the Organisation authorises them.
5.2 Notice of changes. Limelight shall give the Organisation at least thirty (30) days' prior notice before adding or replacing a sub-processor, so as to give the Organisation the opportunity to object, except where a sub-processor must be replaced urgently for security, legal or continuity reasons, in which case Limelight shall give as much notice as is reasonably practicable. Notice may be given by email to the Organisation's nominated contact, by updating Schedule 2 (or an online sub-processor list referenced in it) with a subscription/notification option, or through the platform.
5.3 No onboarding during objection period. Limelight shall not transfer Controller Personal Data to a proposed new sub-processor until the objection period in clause 5.2 has expired without objection, or any objection raised has been resolved.
5.4 Right to object. The Organisation may object to a new sub-processor on reasonable data-protection grounds by giving written notice within the notice period. The parties shall work together in good faith to resolve the objection, and Limelight shall use reasonable endeavours to avoid using the objected-to sub-processor for that Organisation's Controller Personal Data. If they cannot resolve it within a reasonable period, the Organisation may, as its sole and exclusive remedy, terminate the affected part of the Services (and the corresponding part of the Principal Agreement) on written notice, without penalty; on such termination Limelight shall refund any prepaid fees for the terminated portion of the Services covering the period after termination, and the Organisation remains liable for fees accrued up to termination.
5.5 Flow-down of terms. Where Limelight engages a sub-processor, it shall do so under a written contract that imposes data-protection obligations that are the same as, or no less protective than, those set out in this DPA, and in particular meet the requirements of Article 28(3) and (4). In particular the sub-processor shall be bound by appropriate confidentiality, security and transfer obligations. On the Organisation's reasonable written request, Limelight shall provide a copy of the relevant data-protection terms of a sub-processor's contract (which may be redacted to remove commercial terms).
5.6 Continuing liability. Where a sub-processor fails to fulfil its data-protection obligations, Limelight remains fully liable to the Organisation for the performance of that sub-processor's obligations, to the same extent as if Limelight had performed them itself, subject to the limitations in clause 11.
6.1 Limelight shall notify the Organisation without undue delay, and in any event such as to allow the Organisation to meet its own notification obligations under Article 33(1) of the UK GDPR, after becoming aware of a personal data breach affecting Controller Personal Data. Limelight will use reasonable endeavours to provide that notification within seventy-two (72) hours of becoming aware. For these purposes, Limelight "becomes aware" when its security or engineering function has a reasonable degree of certainty that a security incident has occurred that has led to a personal data breach.
6.2 The notification shall include, to the extent known and as it becomes available (Limelight may provide information in phases), the information the Organisation reasonably needs to meet its own breach-notification obligations, including:
6.3 Limelight shall take reasonable steps to investigate, contain and remediate the breach, and shall cooperate with the Organisation and provide reasonable assistance in connection with any notification the Organisation must make to a supervisory authority or affected data subjects.
6.4 Limelight shall keep, and make available to the Organisation on reasonable request, a record of all personal data breaches affecting Controller Personal Data, including the facts relating to the breach, its effects and the remedial action taken.
6.5 Limelight's notification of a breach is not, and shall not be construed as, an acknowledgement of fault or liability.
7.1 Data-subject requests. If Limelight receives a request from a data subject in respect of Controller Personal Data, it shall not respond directly (other than to acknowledge receipt or to direct the data subject to the Organisation, unless legally required to respond), and shall promptly forward the request to the Organisation.
7.2 Taking into account the nature of the processing, Limelight shall provide reasonable assistance, by appropriate technical and organisational measures and insofar as possible, to enable the Organisation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability and objection). The platform provides self-service tools that allow the Organisation to access, correct, export and delete much of the Controller Personal Data directly; the Organisation shall use those tools in the first instance.
7.3 DPIA and prior consultation. Taking into account the nature of the processing and the information available to it, Limelight shall provide reasonable assistance to the Organisation with data protection impact assessments and any prior consultation with the supervisory authority, in each case relating to the processing carried out by Limelight on the Organisation's behalf.
7.4 Charges. Assistance that the UK GDPR requires Limelight to provide, and that is within the scope of the standard Services, will be provided at no additional charge. Where the Organisation's requests for assistance are manifestly unfounded, excessive or repetitive, or require effort materially beyond that contemplated by the standard Services, Limelight may charge a reasonable fee based on its actual costs, having first notified the Organisation and given it the opportunity to withdraw or revise the request.
8.1 The Organisation acknowledges that, as at the Effective Date, Controller Personal Data is processed in the United Kingdom, using the UK (and, for some services, EEA) regions of Limelight's hosting sub-processors (in particular Google/Firebase and Stream), as set out in Schedule 2. The EEA benefits from UK adequacy, so processing in those regions is not a Restricted Transfer.
8.2 Where a Restricted Transfer of Controller Personal Data takes place, the parties shall ensure it is subject to an appropriate transfer mechanism under Data Protection Laws, namely the UK IDTA and/or the EU SCCs (as supplemented where necessary), or another lawful transfer mechanism. The applicable mechanism is described in Schedule 4.
8.3 To the extent the EU SCCs and/or UK IDTA apply to transfers under this DPA, they are incorporated by reference, the relevant modules and options being those set out in Schedule 4, and this DPA together with its Schedules populates the information they require. If a transfer mechanism is invalidated or replaced, the parties shall work together in good faith to put in place an alternative lawful mechanism.
8.4 Residual transfers. Where any limited transfer of Controller Personal Data outside the United Kingdom or EEA does occur (for example, delivery of push notifications via Apple's global infrastructure, or a support tool), Limelight relies on an appropriate safeguard for that transfer (such as the UK IDTA, the EU SCCs, or the recipient's adequacy status), together with supplementary measures including encryption of data in transit and at rest. Limelight shall, on reasonable request, provide the Organisation with information about any such transfer and the safeguards and supplementary measures applied.
9.1 On termination or expiry of the Principal Agreement, or on the Organisation's earlier written request, Limelight shall, at the Organisation's choice, return and/or delete the Controller Personal Data, and delete existing copies, except to the extent that retention is required by law. To give effect to this, on termination or expiry Limelight shall provide a grace period of thirty (30) days during which the Organisation may export or retrieve the Controller Personal Data and make its return-or-delete election. Where return is elected, Limelight shall return the data in a commonly-used, machine-readable format. Limelight shall delete the live Controller Personal Data within thirty (30) days of the Organisation's election or, if no election is made, within thirty (30) days of the end of the grace period.
9.2 Standard deletion window. Where the Organisation or a user deletes an account, or requests deletion, Limelight shall delete the relevant Controller Personal Data within thirty (30) days, except where retention is legally required or where data is held in routine backups that are overwritten on a rolling cycle (in which case the backup copies are deleted on that cycle, which shall be no longer than thirty (30) days, and are protected from active use in the meantime). This is consistent with the deletion commitment in the Privacy Policy.
9.3 Chat messages. Chat message content is processed through the sub-processor Stream and, while an account is active, is retained server-side under Stream's default retention configuration (which Limelight controls at the application level) to support production messaging and safeguarding auditability. On account deletion or a deletion request under clause 9.2, Limelight removes the Stream user and marks that user's messages as deleted in shared channels within the same thirty (30) day window; the underlying message content is then purged in line with Stream's retention configuration. Where a specific message must be preserved, this is done only on the documented instruction of the Organisation's safeguarding lead, or where required by a legal obligation; in that case Limelight manually preserves only that specific message, for no longer than necessary for the safeguarding or legal purpose and subject to periodic review, and records the reason, the retention period and a review date. Any such preservation is carried out on the Organisation's behalf as controller and not at Limelight's own initiative.
9.4 Certification. At the Organisation's written request, Limelight shall provide written certification that it has deleted the Controller Personal Data in accordance with this clause 9. Such certification satisfies Limelight's deletion obligations under this DPA in respect of the data certified.
9.5 Where Limelight retains any Controller Personal Data because the law requires it, Limelight shall retain it only for as long as the law requires, shall protect it from any further processing other than that required by law, and shall keep it secure.
10.1 Limelight shall make available to the Organisation, on reasonable written request, the information reasonably necessary to demonstrate compliance with Article 28 and this DPA. On reasonable written request and subject to an appropriate confidentiality undertaking, Limelight shall provide the Organisation with its then-current third-party audit reports and certifications (for example SOC 2 and/or ISO 27001 reports) held by Limelight or its sub-processors.
10.2 Third-party reports first. The Organisation agrees that, in the first instance, Limelight may satisfy its obligation to make available information and to allow for and contribute to audits by providing the third-party audit reports, certifications and summaries described in clause 10.1. The Organisation shall accept such reports as sufficient where they reasonably address the subject matter of the request.
10.3 On-site / direct audits. Where the third-party reports do not reasonably address the Organisation's compliance verification needs, the Organisation (or a mandated independent auditor who is not a competitor of Limelight and who is bound by confidentiality) may carry out an audit of Limelight's processing of Controller Personal Data, subject to the following, which the parties agree are reasonable:
10.4 Limelight shall contribute to and cooperate with such audits and inspections as required by Article 28(3)(h). Nothing in this clause limits any audit or inspection right the Organisation has under Article 28(3)(h), or that a supervisory authority requires. This clause does not require Limelight to provide access to data, systems or information of its other customers, or to information the disclosure of which would breach a legal or confidentiality obligation or compromise security.
11.1 Liability cap. Subject to clauses 11.2 and 11.6, each party's total aggregate liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is subject to, and counts towards, the limitations and exclusions of liability set out in the Principal Agreement. Where the Principal Agreement caps liability by reference to fees paid, that same cap applies to liability under this DPA, and liability under the Principal Agreement and this DPA is aggregated, so that the cap is not multiplied by the existence of this DPA.
11.2 Data-protection super-cap. Notwithstanding clause 11.1, each party's aggregate liability for breach of its data-protection obligations under this DPA shall not exceed the greater of (a) 125% of the fees paid or payable by the Organisation under the Principal Agreement in the twelve (12) months preceding the event giving rise to the claim, or (b) £10,000. This super-cap is mutual, applies in place of (and is not cumulative with) the general cap in clause 11.1 for data-protection liability, and does not apply to the matters in clause 11.6.
11.3 Each party's liability under or in connection with this DPA is limited to direct losses. Neither party is liable for indirect, special or consequential loss, or for loss of profit, revenue, goodwill or anticipated savings, except to the extent such exclusion is not permitted by law.
11.4 Controller indemnity. The Organisation shall indemnify and hold harmless Limelight against all losses, claims, damages, costs and reasonable expenses that Limelight incurs arising out of or in connection with:
except to the extent the loss arises from Limelight's own breach of this DPA or its own negligence, and except for any regulatory fine imposed on Limelight for Limelight's own infringement. The Organisation's indemnity obligations under this clause 11.4 are not subject to the limitations in clauses 11.1 to 11.3. The indemnity is conditional on Limelight giving the Organisation prompt written notice of the relevant claim, not admitting or settling it without the Organisation's prior written consent (not to be unreasonably withheld), allowing the Organisation to have conduct of its defence and settlement (with Limelight's reasonable input), and taking reasonable steps to mitigate its loss.
11.5 Processor indemnity. Limelight shall indemnify and hold harmless the Organisation against all losses, claims, damages, costs and reasonable expenses that the Organisation incurs arising out of or in connection with Limelight's breach of this DPA or its processing of Controller Personal Data otherwise than in accordance with the Organisation's lawful Documented Instructions, except for any regulatory fine imposed on the Organisation for the Organisation's own infringement. The same notice, conduct and mitigation conditions in clause 11.4 apply, with the parties reversed. This indemnity is subject to clause 11.2.
11.6 Carve-outs. Nothing in this DPA limits or excludes either party's liability for death or personal injury caused by its negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be limited or excluded.
11.7 Article 82. This clause 11 does not affect any data subject's right to compensation under Article 82 of the UK GDPR, or the allocation of liability between controllers and processors under Article 82 as between the parties and a supervisory authority. As between the parties, liability shall be borne in proportion to each party's responsibility for the damage under Article 82(5), save that the indemnities in clauses 11.4 and 11.5 shall apply to losses arising from the matters listed in those clauses regardless of such proportionate split.
12.1 The Organisation warrants and undertakes that:
12.2 The Organisation is responsible for the acts and omissions of its own authorised users (including teachers, directors, student leaders and administrators) in their use of the platform, and for supervising its users. As noted in clause 4.11, Limelight does not monitor or moderate content and the platform is not a safeguarding-oversight service.
13.1 Variation. No variation of this DPA is effective unless in writing and signed by or on behalf of each party, except that Limelight may update Schedule 2 (sub-processors) under the mechanism in clause 5, and may update Schedule 3 (security measures) under clause 4.4 provided protection is not reduced below the floor stated there.
13.2 Severance. If any provision of this DPA is held to be invalid or unenforceable, it shall be modified to the minimum extent necessary to make it valid and enforceable, or, if that is not possible, severed; the remaining provisions continue in full force.
13.3 No third-party rights. Except as set out in clause 13.4, a person who is not a party to this DPA has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms.
13.4 Data subjects. Where Data Protection Laws (including any incorporated EU SCCs or UK IDTA) confer directly enforceable rights on data subjects as third-party beneficiaries, those rights are preserved to the extent the law requires.
13.5 Survival. Clauses 4.3 (confidentiality), 6 (breach records), 9 (return and deletion), 10 (audit), 11 (liability and indemnity) and 12 (controller warranties), together with any other provision that by its nature is intended to survive, continue in force after termination or expiry of this DPA.
13.6 Notices. Legal notices under this DPA (including breach notifications, sub-processor objections and termination notices) must be in writing and sent to the other party's nominated contact. For Limelight, that contact is the data protection contact in clause 13.8. For the Organisation, it is the contact stated in the Principal Agreement or otherwise notified to Limelight. Notice by email is valid and is deemed received on the next business day after sending, absent a delivery failure.
13.7 Assignment. Neither party may assign or novate this DPA except in accordance with the assignment provisions of the Principal Agreement; where the Principal Agreement is validly assigned or novated, this DPA transfers with it.
13.8 Data protection contact. Limelight has not appointed a statutory Data Protection Officer under Article 37, having assessed that it is not required to do so; Limelight will keep that assessment under review and document it. Its data protection contact is Dom Conte, who can be reached at dom@limelightlabs.co.uk. The Organisation should direct data-protection queries, sub-processor objections and audit requests to that contact.
13.9 Governing law and jurisdiction. This DPA and any dispute or claim arising out of or in connection with it (including non-contractual disputes or claims) are governed by the law of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales, save that this does not limit the jurisdiction conferred by any incorporated EU SCCs.
13.10 Order of precedence. In the event of conflict, the following order of precedence applies: (a) any applicable EU SCCs or UK IDTA (Schedule 4); (b) the body of this DPA; (c) the Schedules to this DPA; (d) the remainder of the Principal Agreement; and (e) the Privacy Policy.
13.11 Counterparts and electronic execution. This DPA may be executed in counterparts, each of which is an original and which together form one agreement, and may be signed electronically.
13.12 Signature. By entering into the Principal Agreement, or by signing below, each party agrees to this DPA.
| For Massingberd Investments Limited (Processor) | For the Organisation (Controller) |
|---|---|
| Name: [Signatory name] | Name: [Organisation signatory name] |
| Title: [Signatory title, e.g. Director] | Title: [Organisation signatory title] |
| Date: [Date] | Date: [Date] |
| Category | Detail |
|---|---|
| Account information | Name, email address, password (stored securely and hashed by the authentication provider), profile photo, short bio, and the Organisation and show(s) the user belongs to. (Account and authentication details are handled by Limelight as an independent controller per clause 3.4; this row is included for completeness of the data inventory rather than as data processed solely under the Organisation's instructions.) |
| Cast and production profile data | Phone number, date of birth, gender, emergency contact details (name, phone number and relationship), costume measurements (height, chest, waist, hips, inseam, head circumference and shoe size) and any special requirements. Optional; held on behalf of and under the instructions of the Organisation. Where these fields (including body measurements and date of birth) relate to children, the Organisation is responsible for ensuring their collection is necessary and age-appropriate. |
| Content provided by users | Chat messages, newsfeed posts, comments, personal annotations and bookmarks, and any images, audio recordings or files uploaded. |
| Diagnostic and usage data | Crash reports and app performance data (such as load times); in-app analytics (which screens/features are used) where enabled in future. (Note: where processed for Limelight's own diagnostics, this is handled by Limelight as an independent controller - see clause 3.4.) |
| Device data | Device model, operating system version, app version, a unique installation identifier and a push notification token. |
| Device permissions data | Camera, microphone, photo library, Face ID / Touch ID and location access, used only when granted and only for the invoked feature. |
| Category | Detail and conditions |
|---|---|
| Health information | Medical conditions and allergies, recorded by some Organisations to keep performers safe during rehearsals and performances. Optional; held on behalf of the Organisation. The Organisation is responsible for obtaining the appropriate Article 9 lawful basis - most commonly the explicit consent of the performer, or of a parent or guardian for performers under 18, or another applicable Article 9 condition (see clause 12). |
The provision of the Limelight platform for the management of musical theatre productions, including: hosting and storing cast and production profiles; scheduling rehearsals and performances; real-time messaging and a newsfeed within shows; distribution of learning resources (audio, PDF and other files); display of venue locations on a map; delivery of push notifications; and the storage, organisation, retrieval, transmission, return and deletion of the above data on the Organisation's instructions. Limelight does not monitor or moderate the content of messages or posts (see clause 4.11).
For the duration of the Principal Agreement and any subsequent retention period permitted or required under clause 9. Personal data is kept while the account is active, plus a reasonable period thereafter to comply with legal obligations, resolve disputes and enforce agreements; on account deletion or a deletion request, data is deleted within thirty (30) days, except where retention is legally required.
The following sub-processors are approved as at the Effective Date. Changes are notified and may be objected to under clause 5. Each sub-processor relies on its own transfer safeguards (such as the EU SCCs and/or UK IDTA) for any onward transfers, which Limelight will summarise on request under clause 8.4.
| Sub-processor | Purpose | Location | Certifications |
|---|---|---|---|
| Google (Firebase / Google Cloud) | Authentication, database (Cloud Firestore), file storage, cloud functions, crash reporting (Crashlytics), performance monitoring, and push notification delivery (Firebase Cloud Messaging). | United Kingdom (Google's UK / EEA regions, e.g. europe-west2 London). | ISO 27001 and SOC 1/2/3 (among others). |
| Stream (getstream.io) | Real-time chat messaging within shows; processes message content and related metadata. Retention is managed via Stream Chat with the default configuration applied at the application level (see clause 9.3). | United Kingdom / EEA (Stream EU data residency). | SOC 2 Type II and ISO 27001 certified. |
| Apple | Delivery of push notifications via the Apple Push Notification service (APNs). Apple receives a push notification token and message payload metadata for delivery only. | Global (Apple Push Notification service); receives a push token and delivery metadata only. Any transfer is covered by appropriate safeguards (see Schedule 4). | See Apple's published compliance documentation (including ISO 27001 and SOC 2 reports for relevant services). |
| Google Maps | Display of venue locations on a map where an Organisation has added venue addresses. | Map display only, using venue addresses the Organisation enters. Any transfer is covered by appropriate safeguards (see Google row). | Covered by Google's ISO 27001 and SOC 1/2/3 certifications (see Google row). |
The measures below are in place as at the Effective Date and map to Article 32(1)(a) to (d) of the UK GDPR. Limelight may update them under clause 4.4 provided protection remains appropriate to the risk and no less protective overall than at the Effective Date.
| Area | Measure |
|---|---|
| Encryption in transit | Data in transit is encrypted using TLS (TLS 1.2 or above everywhere). |
| Encryption at rest | Data at rest is encrypted by the cloud provider (Google Cloud) as standard. |
| Access control (RBAC) | Role-based access control with permissions enforced server-side at the database layer (Firestore security rules), not just in the UI. |
| Scoped roles and least privilege | Five distinct scoped roles (Student, Student leader, Teacher, Org admin, Super admin). Access is limited to authorised personnel of Limelight and the Organisation, on a need-to-know basis. |
| Tenant data isolation | Each Organisation's data is logically segregated, and access is scoped to the Organisation and show(s) a user belongs to, enforced by the server-side security rules. |
| Multi-factor authentication | Multi-factor authentication is required for administrative and privileged access to the production environment and provider consoles. |
| Access logging and monitoring | Administrative and privileged access to production systems is logged and monitored via the cloud provider's audit logging. |
| Credential protection | Passwords are hashed and never stored in plain text. |
| Confidentiality, integrity and availability | Systems are hosted on managed cloud infrastructure providing resilience and high availability, supporting the ongoing confidentiality, integrity, availability and resilience of processing systems and services. |
| Restoration and resilience | Data is backed up by the cloud provider; backups are encrypted and subject to access controls, enabling restoration of availability and access to data in a timely manner after an incident (target restoration measured in hours to a small number of days depending on scope). |
| Vulnerability and patch management | Dependencies and infrastructure are kept up to date, with security patches applied on a regular cadence and promptly for high-severity issues. |
| Regular testing and evaluation | Firestore security rules are tested against the role model on every release, and Limelight reviews and evaluates the effectiveness of its security measures on a regular basis. |
| Personnel security and training | Personnel with access to Controller Personal Data are bound by confidentiality obligations and receive data protection and security awareness guidance. |
| Sub-processor assurance | Core infrastructure sub-processors hold recognised certifications (ISO 27001, SOC 2 - see Schedule 2). |
| Vulnerability / responsible disclosure | A responsible disclosure process is in place (email dom@limelightlabs.co.uk). |
| Auditability of messaging | Server-side timestamping and retention of chat messages support after-the-fact disclosure; manual disclosure / retrieval assistance is available to the Organisation's safeguarding leads on request. This is not a live monitoring or moderation service (see clause 4.11). |
4.1 As at the Effective Date, Controller Personal Data is processed in the United Kingdom (and, for some services, the EEA, which benefits from UK adequacy) by the sub-processors listed in Schedule 2. The core hosting of Controller Personal Data therefore does not involve a Restricted Transfer.
4.2 Where a Restricted Transfer occurs, the following mechanism applies:
4.3 The information required to populate the SCCs / IDTA (parties, categories of data subject and data, nature and purpose, duration, sub-processors, and security measures) is set out in this DPA and Schedules 1 to 3, which the parties agree are incorporated into the relevant Annexes (Annex I and Annex II of the EU SCCs) and Tables (the IDTA appendix information). Where the SCCs / IDTA require the identity of the importer's data protection contact, this is the contact in clause 13.8. Where a Sub-processor's own SCCs or IDTA govern an onward transfer, those clauses are relied on for that transfer, and Limelight will identify and summarise them on request under clause 8.4.
4.4 Where a residual transfer outside the UK / EEA occurs (see clause 8.4), Limelight relies on the safeguards and supplementary measures described in clause 8.4. If a transfer mechanism ceases to provide a lawful basis for transfer, the parties shall co-operate in good faith to implement an alternative lawful mechanism and any supplementary measures reasonably required.