This policy explains how Limelight Labs ("we", "us", "our") handles personal data in connection with the Limelight app and website. We wear two hats, and this policy is honest about which is which:
Each category in What data we collect below is marked to show which role we process it in.
Limelight Labs is a trading name of Massingberd Investments Limited, a company registered in England and Wales (company number 15895057), 73 Massingberd Way, London, SW17 6AF. The app serves schools, academies, amateur dramatic societies, community theatre companies and similar production organisations.
We have not appointed a statutory Data Protection Officer (we have assessed that we are not required to), and we keep that under review. Our data protection contact is Dom Conte, dom@limelightlabs.co.uk.
Special category and criminal offence data - not intended. The app provides no fields for special category data (such as information about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, or sexual orientation) or for data about criminal convictions or offences, and it is not intended to be processed through the app. Please do not include it in free-text fields, messages or uploads. If it is included accidentally, we will work with your Organisation to restrict or delete it appropriately.
Where we act as controller:
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, signing you in, and providing the app | Contract (our Terms of Service) |
| Answering your support enquiries | Contract; our legitimate interest in supporting users |
| Keeping the app secure and preventing fraud and abuse | Our legitimate interest in protecting the platform and its users; legal obligation where applicable |
| Diagnostics and analytics - fixing crashes, improving performance, understanding which features are used | Our legitimate interest in operating and improving the app; consent where the law requires it for storing or accessing information on your device |
| Feedback, surveys and interviews - improving and developing our products | Our legitimate interest in developing the app; participation is always voluntary, and consent where we say so at the point of collection |
| Sending push notifications about rehearsals, messages and resources | Consent (you can turn notifications off at any time in your device settings) |
| Complying with the law | Legal obligation |
Any public use we make of feedback is anonymised and aggregated so that neither you nor your Organisation can be identified.
Where we act as processor, we use production data only to provide and support the app for your Organisation, on its instructions. Your Organisation is responsible for its own lawful basis for that data.
We never sell your personal data.
Where your data lives:
Push notifications are delivered through Apple's and Google's global notification infrastructure. The data involved is your device's push token and the notification content, which may include a preview of a message. Payloads are encrypted in transit and held only transiently for delivery. If you would rather message content never appeared in notifications, you can turn off previews in your device's notification settings at any time.
All data is encrypted in transit (TLS 1.2 or above) and at rest.
We keep your data for as long as your account is active. If you delete your account, or ask us to, we delete your personal data within thirty days, except where we are required to keep it for legal reasons. Copies held in routine backups are purged on a rolling cycle of no more than thirty days. If you have contributed posts or comments to a show, your name is removed from them when your account is deleted; the content itself remains unless your Organisation asks us to remove it. Support and billing records are kept for up to six years, in line with UK limitation periods.
Subject to applicable law, you have the right to access your personal data, have inaccurate data corrected, have your data deleted, restrict or object to processing, receive your data in a portable format, and withdraw consent where processing is based on it.
Who to contact depends on the data. For your account, support, diagnostics or feedback data, contact us at dom@limelightlabs.co.uk from your registered email address and we will respond within one calendar month. For cast and production profile data, messages, posts and uploads, your Organisation is the controller - contact your Organisation's administrator or data protection contact; if you send the request to us, we will pass it to your Organisation promptly.
You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
Organisations may only invite users under 18 where their agreement with us expressly permits it, and they are responsible for having appropriate safeguarding arrangements in place and for obtaining any parental or guardian consent required (including for users under 13) before the user signs in. We do not knowingly create accounts for children where these requirements have not been met.
Data in transit is encrypted using TLS; data at rest is encrypted by our cloud provider as standard. Passwords are hashed and never stored in plain text. Access to data is controlled by role-based permissions enforced server-side, limited to what your role and shows require, and administrative access to our production systems is protected by multi-factor authentication and logged. Face ID / Touch ID runs entirely on your device.
For more on how role-based access works in practice, see our safeguarding brief.
The app may contain links to external resources (for example, learning materials). We are not responsible for the content or privacy practices of those third parties.
We update this policy from time to time. If we make material changes we will let you know through the app or by email, and the date at the top shows when it was last revised.
Questions, requests or concerns: dom@limelightlabs.co.uk (data protection contact: Dom Conte). Please write from the email address registered to your account so we can verify it's you.