Who are we
Spotlight Studios is an online Digital & Cloud Services provider operated by Spotlight Studios Ltd, a company registered in England and Wales (“we,” “us,” “our,” “Spotlight” and “Spotlight Studios”). Find out more about our Services by navigating our website. As an organisation that processes business-related data, Spotlight Studios has determined “Legitimate Interests” as the most suitable lawful ground for the processing of data for the purposes of our marketing and sales activities. We have carried out a Legitimate Interests Assessment (LIA) to balance our interests against the rights of the individuals concerned, and we keep this assessment under review.
We are registered with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection.
The role we play in respect of your data
Depending on the relationship, Spotlight Studios acts in one of two capacities under UK data protection law:
- As a data controller: when we decide how and why personal data is processed. This applies to the personal data we collect about our Clients, Potential Clients and Website Visitors for our own purposes (for example, marketing, invoicing, account management and support). The sections below headed “Privacy for our Clients” and “Privacy for our Potential Clients and Website Visitors” describe this processing.
- As a data processor: when we process personal data on behalf of, and under the instructions of, a Client. This applies where we host, build or maintain systems for a Client and, through that work, have access to personal data relating to the Client’s own customers or end-users. The section below headed “Personal data we process on behalf of our Clients” describes this processing.
Privacy for our Clients
This section applies to the Personal Information we collect and process from a Client, Potential Client or Website Visitor. If you are not an active Client, the Potential Clients and Website Visitors section of this policy may be more applicable to you and your data. In this section, “you” and “your” refer to Clients.
The Information we Collect
The information you provide to us during any engagement may be considered Personal Information about you, your organisation and your employees. Personal Information is often, but not exclusively, provided to us when you request a quotation, complete a form on our website, sign up for our services, consult with our customer service team, send us an email, raise a support ticket, provide login credentials, or communicate with us in any other way.
We will let you know prior to collection whether the provision of the Personal Information we are collecting is compulsory or may be provided on a voluntary basis, and the consequences, if any, of not providing the information. By providing us with this information, you agree to it being collected, used and disclosed as described in our Terms of Service and in this privacy policy.
Login Credentials: We will often require login credentials to websites and third-party websites to perform integrations. If you are unable to provide credentials in a secure way (i.e. through your own password manager), Spotlight Studios requests that you use our secure form; we will then add these credentials to our password manager. Additional security on our account includes dual-factor authentication and a secret key. This key has 128 bits of entropy, and combining that with our passwords makes it infeasible to guess no matter how much money or computing power an attacker has available.
The Use of Personal Information
We may use the information we collect about you through our Services or other sources for a variety of reasons, including:
- To provide quotations
- To invoice and collect money owed to us
- To send account activity messages such as password resets, payment reminders or alerts
- To effectively manage your account and expectations
- To provide customer support
- To enforce compliance with our Terms of Service
- To meet legal requirements
- To provide essential information to external representatives and advisors, including lawyers and accountants, to help us comply with legal, accounting or security requirements
- To prosecute and/or defend any legal proceedings
- To respond to lawful requests by public authorities
- To analyse data
- To provide suggestions to you
- To improve our services: We may combine your information with other sources of information we obtain about you, which may include but are not limited to social media profiles. This is done to serve you specifically so we can deliver a product or service according to your preferences, or for advertising or targeting purposes in accordance with this privacy policy. Where we combine your Personal Information with other information, we treat it as, and apply all of the safeguards in this privacy policy applicable to, Personal Information.
- Other purposes: To carry out other legitimate business purposes, as well as other lawful purposes about which we will notify you.
Personal data we process on behalf of our Clients
Where Spotlight Studios hosts, builds or maintains websites, applications or other systems on behalf of a Client, we may have access to personal data relating to that Client’s own customers, users or contacts (“End-User Data”). In respect of End-User Data:
- The Client is the data controller and Spotlight Studios is the data processor.
- We process End-User Data only on the documented instructions of the Client, and not for our own purposes.
- We apply appropriate technical and organisational security measures to protect End-User Data against unauthorised access, loss or disclosure.
- We engage sub-processors (for example, hosting and infrastructure providers) only where permitted, and require them to offer equivalent data protection safeguards.
- We assist the Client in responding to requests from data subjects and in meeting the Client’s own obligations regarding security, breach notification and data protection impact assessments.
- On termination of our services, we return or securely delete End-User Data in accordance with the Client’s instructions, save where retention is required by law.
The specific terms governing this processing are set out in a Data Processing Agreement (DPA) entered into between Spotlight Studios and the Client, as required by Article 28 of the UK GDPR. Where a conflict arises between this privacy policy and the DPA in respect of End-User Data, the DPA prevails. If you are an end-user of a Client’s service and wish to exercise your data protection rights, please contact the relevant Client (the data controller) in the first instance; we will support them in responding to your request.
Privacy for our Potential Clients and Website Visitors
This section applies to Personal Information that we collect and process through our Websites and in the usual course of our business. Examples may include activity in association with events, networking opportunities or sales and marketing activities. In this section, “you” and “your” refer to Potential Clients and Website Visitors.
- To optimise and maintain our Websites
- To send you information for marketing purposes, in accordance with your marketing preferences
- To provide quotations
- For recruitment purposes if you have applied for a role with Spotlight Studios
- To respond to your online inquiries and requests
- To improve the navigation and content of our Websites
- To process transactions and to set up a new online account
- To identify any server problems or other IT or network issues
- To analyse data about site usage to better understand the preferences of our Potential Clients and Website Visitors
- To carry out research and development to improve our products and services
- To carry out other legitimate business purposes, as well as other lawful purposes
Cookies, Analytics & Tracking
We and our partners may use various technologies to collect and store information when you use our Services, which may include cookies and similar tracking technologies such as pixels and web beacons. For example, we use web beacons in the emails we send. These track certain behaviour, such as whether an email sent through the Services was delivered and opened and whether links within it were clicked. They also allow us to collect information such as the recipient’s IP address, browser and email client type. We use this information to measure the performance of email campaigns and to enhance the effectiveness of our Services.
To improve your experience on our site, we may use ‘cookies’. Cookies are an industry standard and most major websites use them. A cookie is a small text file that our site may place on your computer as a tool to remember your preferences. You may refuse the use of cookies by selecting the appropriate settings on your browser; however, please note that if you do this you may not be able to use the full functionality of this website.
Google Analytics: Our website uses Google Analytics, a service which transmits website traffic data to Google servers, which may be located in the United States. Google Analytics does not identify individual users or associate your IP address with any other data held by Google. Where personal data is transferred outside the UK through this service, the transfer is protected by appropriate safeguards, including the UK International Data Transfer Addendum and/or reliance on the UK Government’s adequacy regulations for the United States (the UK Extension to the EU–US Data Privacy Framework), as applicable. We use reports provided by Google Analytics to help us understand website traffic and webpage usage.
Spotlight Studios uses a third-party tool integrated with Google Analytics to translate anonymous IP data into business-level information. This provides us with a business name and lookup, which we use to determine a legitimate business interest in the services viewed on our website. No personal information is obtained by Spotlight Studios at this stage, but we may use this information to establish connections on social media channels such as LinkedIn.
Social media platforms and widgets
Our Websites include reviews and social media features, such as the Facebook Like button. These features may collect information about your IP address and which page you are visiting on our Website, and they may set a cookie to ensure the feature functions properly.
Links to third-party websites
Our Websites include links to other websites whose privacy practices may differ from ours. If you submit Personal Information to any of those sites, your information is governed by their privacy policies. We encourage you to read carefully the privacy policy of any website you visit.
Data Security & Breach Notification
We take the security of personal data seriously and maintain appropriate technical and organisational measures to protect it, including access controls, encryption in transit, dual-factor authentication and secure credential storage. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where we act as a processor for a Client, we will notify the affected Client without undue delay so that they can meet their own notification obligations.
Other Data Protection Rights
PECR (Privacy and Electronic Communications Regulations)
We primarily focus our B2B data acquisition around businesses, as they are classed as “corporate subscribers” under PECR if they are a corporate body with separate legal status (e.g. companies, limited liability partnerships, Scottish partnerships, and some government bodies). However, sole traders and other types of partnerships are classed as “individual subscribers” and PECR treats them the same as individuals. In general the marketing rules in PECR apply equally to corporate and individual subscribers. The main difference is that the rule on marketing by electronic mail (e.g. email or text message) does not apply to corporate subscribers.
If we are not sure whether a business is a corporate subscriber, we ensure that we have their consent to receive our electronic mail (unless we are contacting previous customers about our own similar products and we offered them an opt-out when they gave us their details).
The PECR rule on direct marketing by electronic mail does not apply to corporate subscribers. This means we can send B2B direct marketing emails or texts to a corporate body without consent under PECR. However, we will comply with the regulations by:
- not disguising or concealing our identity; and
- providing a valid address for the business to opt out or unsubscribe from our messages.
Unless otherwise requested, we keep your details on a ‘do not email or text’ list so that we can screen any new B2B direct marketing lists against it.
Where we process personal data for direct marketing purposes, even in a business context, the UK GDPR applies (see below).
GDPR
When we acquire personal data and intend to send you direct marketing messages, we will inform you of this along with a lawful basis under the UK GDPR for the processing.
So, when does the UK GDPR apply to business-to-business marketing?
The UK GDPR applies to the processing of personal data. If we can identify an individual, either directly or indirectly, it constitutes personal data even if they are acting in their business capacity.
For example, we will be processing personal data if:
- we have the name and number of a business contact on file; or
- the email address we are using to communicate with the business identifies an individual (e.g. initials.lastname@company.com).
IMPORTANT: If we do not know the name of the person we are sending direct marketing to at a business, then we are not processing personal data and the UK GDPR does not apply to that marketing — for example, if we address direct marketing by post simply to ‘the IT department’ or by emailing ‘info@company.com’.
Right to be Informed
If your personal data (i.e. name and direct company email) has been sourced publicly or via a third party, you will receive the following information when we add you to our database:
- The name and contact details of our organisation.
- The name and contact details of our representative (if applicable).
- The contact details of our data protection officer (if applicable).
- The purposes of the processing.
- The lawful basis for the processing.
- The legitimate interests for the processing (if applicable).
- The categories of personal data obtained (if the personal data is not obtained from the individual it relates to).
- The recipients or categories of recipients of the personal data.
- The details of transfers of the personal data to any third countries or international organisations (if applicable).
- The retention periods for the personal data.
- The rights available to individuals in respect of the processing.
- The right to withdraw consent (if applicable).
- The right to lodge a complaint with a supervisory authority.
- The source of the personal data (if the personal data is not obtained from the individual it relates to).
- Whether individuals are under a statutory or contractual obligation to provide the personal data (if applicable, and if collected from the individual it relates to).
- The existence of automated decision-making, including profiling (if applicable).
To ensure our compliance:
☐ We display our telephone number when making direct marketing calls to businesses.
☐ If we are not sure whether a business is a corporate subscriber, we ensure that we have their consent to receive our electronic mail (unless contacting previous customers about our own similar products, and we offered them an opt-out when they gave us their details).
☐ If we are processing personal data of our business contacts, we ensure that we have a lawful basis to do so.
☐ We tell our business contacts if we want to use their personal data for direct marketing purposes.
☐ We screen against our suppression lists and ‘do not contact’ lists before sending any direct marketing to businesses.
☐ We act on withdrawals of consent from businesses and business contacts.
☐ We do not send direct marketing to any business or business contact that has asked us not to.
Data Retention
Spotlight Studios records all personal data in a GDPR-compliant CRM system. We have a compliance module for full accountability and traceability of every record, alongside the ability to update contact preferences and opt in or out of communications. Our team continually cleanse the data held within the CRM, completing a full cleanse cycle at least once every 24 months. Records found to be out of date or no longer relevant are placed into a deletion queue and securely purged periodically throughout the year.
We retain personal data only for as long as necessary for the purposes for which it was collected, as set out below:
- Client account and contract records: for the duration of the engagement and for up to 6 years after it ends, to meet legal, accounting and tax obligations.
- Invoicing and financial records: 6 years, in line with HMRC requirements.
- Marketing and prospect data: until you opt out or object, or until 24 months have elapsed since your last engagement or interaction with us, whichever is sooner.
- Support tickets and correspondence: up to 3 years after resolution.
- Login credentials: for the duration of the engagement, then securely deleted on completion or termination.
- End-User Data processed on behalf of Clients: in accordance with the relevant Client’s instructions and the applicable Data Processing Agreement.
Children’s Privacy
Our service is intended for businesses and is not directed at children under the age of 18. We do not knowingly collect or maintain information about anyone under the age of 18 for our own purposes. If we become aware that we have inadvertently collected such information as a controller, we will delete it.
Some of our Clients operate services that involve the personal data of children (for example, in education, childcare, healthcare or activities for young people). Where we host or maintain such services, we may Process children’s personal data on behalf of the Client. In these circumstances the Client is the data controller and Spotlight Studios acts only as a data processor, Processing that data solely on the Client’s instructions and in accordance with the Data Processing Agreement described above. We recognise that children’s personal data merits specific protection, and we apply appropriate technical and organisational security measures to safeguard it. If you are a parent, guardian or child wishing to exercise data protection rights in respect of such data, please contact the relevant Client (the data controller) in the first instance; we will support them in responding to your request.
Data Protection Officer & Supervisory Authority
Spotlight Studios is not currently required by law to appoint a statutory Data Protection Officer. Responsibility for data protection matters rests with our privacy team, who can be reached at privacy@spotlightstudios.co.uk. You also have the right to lodge a complaint with the ICO, the UK’s supervisory authority, at ico.org.uk or by calling 0303 123 1113.
Data Protection Rights
To access, correct, update or request the removal of Personal Information
Spotlight Studios takes reasonable steps to ensure that the data we collect is reliable for its intended use, accurate, complete and up to date. As a Client, you can manage many of your individual account and profile settings within our client portal (https://portal.spotlightstudios.co.uk), or you may contact us directly by phone (0800 689 3652) or by emailing privacy@spotlightstudios.co.uk.
Withdrawal of consent
If Personal Information is collected or processed on the basis of consent, you can withdraw your consent at any time as the data subject. Withdrawing consent will not affect the lawfulness of any processing we carried out prior to your withdrawal, nor will it affect processing of your Personal Information conducted in reliance on lawful grounds other than consent.
The right to complain to a data protection authority
You have the right to lodge a complaint with the ICO (ico.org.uk). For more information, or if you are located outside the UK, please contact your local data protection authority.
Processing a request
We will endeavour to respond to all requests in a timely manner and, in any event, within one month as required by the UK GDPR. Any individual wishing to exercise their data protection rights will need to verify their identity to help us respond efficiently and securely to the request.