Privacy Policy
IMPORTANT: this privacy policy is a starter template. Before publishing, fill in your company details and have it reviewed by a solicitor.
This policy describes how Spotlight Publishing ("we", "us") collects and processes personal data of visitors to this website, in line with the UK GDPR and Data Protection Act 2018.
1. Data controller. The controller of your personal data is Spotlight Publishing, [Registered office]. For any data-related question contact us at team@spotlight-publishing.com.
2. What we collect. We collect: (a) information you submit through the contact form (name, email, message); (b) email and language preference when you subscribe to the newsletter; (c) information needed to process course and event purchases; (d) basic server logs (IP, user-agent) used only for security and rate limiting; (e) analytics data only after you opt in via the cookie banner.
3. Purposes and legal bases. We process data to: (a) respond to enquiries (Art. 6(1)(b) — pre-contract); (b) deliver the newsletter (Art. 6(1)(a) — double opt-in consent); (c) fulfil course purchases (Art. 6(1)(b) — contract); (d) keep the system secure (Art. 6(1)(f) — legitimate interest); (e) measure traffic (Art. 6(1)(a) — consent).
4. Retention. Enquiries: 24 months. Newsletter subscriptions: until you unsubscribe + 30-day archive. Transaction records: 6 years for HMRC requirements. Server logs: 90 days.
5. Your rights. You may request access, rectification, erasure, restriction, portability, and object to processing. You may also withdraw consent at any time. File requests at team@spotlight-publishing.com; we respond within 30 days.
6. ICO complaints. You may lodge a complaint with the Information Commissioner's Office (ico.org.uk).
7. Cookies. The site uses only strictly-necessary cookies without consent. Analytics and marketing cookies load only after you opt in via the banner.
8. Changes. The current version is published on this page. We announce material changes 14 days in advance by email to newsletter subscribers.