1. Purpose
This privacy notice explains how Vivid Starr Ltd handles personal data for its own business purposes and the rights individuals have in relation to that data.
2. Scope
This notice applies to personal data Vivid Starr Ltd handles as a controller in connection with enquiries, website use, client and supplier relationships, business administration, consultancy delivery, meetings, finance, security and business development.
It does not replace a client’s privacy notice where Vivid Starr processes personal data on that client’s behalf. In those circumstances, the client is normally the controller and determines the purposes and lawful basis for the processing.
3. Our commitment
Vivid Starr Ltd is committed to being clear about how it collects, uses, shares, stores and protects personal data, and to handling it in accordance with the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations and other applicable data-protection law.
4. The notice
4.1 Who we are
| Field | Detail |
|---|---|
| Organisation | Vivid Starr Ltd, trading as Vivid Starr |
| Company number | 15722054 |
| Registered office | Hassets, Stockton Avenue, Fleet GU51 4NP, United Kingdom |
| ICO registration | ZB797976 |
| Contact for privacy matters | privacy@vividstarr.com |
Vivid Starr Ltd is the controller for the personal data described in this notice.
4.2 Personal data we collect
Depending on how you interact with us, we may collect and use:
- your name, job title and organisation;
- business contact details;
- enquiry, correspondence and relationship-management records;
- information contained in contracts, statements of work and client project records;
- supplier, contractor and associate information;
- billing, payment and accounting information;
- meeting notes and communications;
- authorised meeting recordings, transcripts and related outputs where Vivid Starr determines the purpose of the processing;
- information provided during consultancy work;
- security, access and incident records relating to our systems and services;
- your internet protocol address;
- the date and time of a website visit;
- the pages and resources requested;
- referring website or source;
- browser, device and operating-system information;
- approximate location derived from an internet protocol address;
- cookie, session or similar identifiers where used;
- website navigation, interaction and repeat-visit information;
- an organisation or network inferred from an internet protocol address or related information; and
- information used to associate a website visit with an organisation or, where reasonably supported by other lawfully held information, a known business contact.
An internet protocol address or inferred organisation does not necessarily establish the identity of the individual who visited the website. Vivid Starr will not describe a visitor as an identified person unless there is a reasonable and lawful basis for making that association.
Most personal data is provided directly by you or collected automatically when your browser or device communicates with our website.
We may also receive business contact, website-visitor or engagement information from other sources, including:
- referrals and introductions;
- clients, prime contractors, delivery partners and associates;
- website hosting, security, analytics and visitor-identification providers; and
- publicly available professional or organisational sources where relevant to understanding a business enquiry or relationship.
Vivid Starr does not deliberately seek special-category or criminal-offence data for its own business purposes. However, a communication, meeting or authorised recording may incidentally contain sensitive information that a participant chooses to disclose. We do not use recordings, transcripts or website-visitor information to infer sensitive characteristics.
Where Vivid Starr processes information on a client’s instructions, the client is responsible for identifying the applicable lawful basis, providing appropriate privacy information and giving Vivid Starr lawful processing instructions.
4.3 How we use personal data and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Operating, delivering and troubleshooting the website | Legitimate interests |
| Maintaining website and network security, detecting misuse and investigating incidents | Legitimate interests; legal obligation where applicable |
| Measuring website traffic, visits, navigation and use | Legitimate interests where the processing is necessary and proportionate; consent where required for the technology used |
| Understanding which organisations appear to have visited the website | Legitimate interests in understanding business interest and developing services |
| Associating a website visit with a known business contact where there is a reasonable and lawful basis | Legitimate interests; consent where required for the technology used |
| Responding to enquiries and taking steps requested before entering into a contract | Steps taken at your request before entering into a contract; legitimate interests where the enquiry concerns an organisation |
| Establishing and managing client relationships | Contract where you are personally party to the contract; otherwise legitimate interests |
| Providing management, IT, security and data-protection consultancy | Contract where applicable; legitimate interests |
| Managing suppliers, contractors and associates | Contract; legitimate interests |
| Recording, transcribing or analysing an authorised meeting for an identified business purpose | Contract or legitimate interests, depending on the relationship and purpose |
| Invoicing and maintaining accounting and tax records | Legal obligation; contract |
| Maintaining business records and professional relationships | Legitimate interests |
| Developing Vivid Starr’s services and responding to business opportunities | Legitimate interests |
| Protecting our systems, information and operations | Legitimate interests; legal obligation where applicable |
| Meeting legal, regulatory, contractual and tax requirements | Legal obligation; contract; legitimate interests where applicable |
| Establishing, exercising or defending legal rights | Legitimate interests; legal obligation where applicable |
Where we rely on legitimate interests, those interests include:
- operating and protecting the website and business;
- maintaining website and information security;
- detecting misuse and investigating incidents;
- understanding how the website is accessed and used;
- understanding interest in Vivid Starr’s services;
- identifying organisations that may be interested in those services;
- managing professional relationships;
- providing and improving services;
- responding to opportunities and enquiries; and
- maintaining appropriate business records.
We consider whether the processing is necessary and proportionate and balance these interests against the rights and interests of the individuals concerned.
We will complete and retain an appropriate legitimate-interests assessment for website analytics and visitor-identification processing before those activities begin.
Where consent is required under the Privacy and Electronic Communications Regulations for a cookie, script, tag, device identifier or similar technology, the technology will not be used until valid consent has been obtained.
We do not currently send marketing communications. If this changes, we will identify the applicable lawful basis, comply with applicable direct-marketing rules, provide any required choices or consent mechanism, and update this notice.
4.4 When information is required
Some information is needed so that we can respond to an enquiry, enter into or perform a contract, meet a legal obligation, issue or pay an invoice, or provide agreed services.
If required information is not provided, we may be unable to enter into or perform the relevant contract, respond fully to the request, or meet the applicable legal or business requirement.
Website technical information, including an internet protocol address, is normally communicated automatically when a device requests a website resource. Some optional analytics or visitor-identification processing may be disabled or refused through the choices made available on the website.
4.5 Sharing personal data
Where necessary for the purposes described in this notice, we may share personal data with:
- website hosting, content-delivery and security providers;
- website analytics and visitor-identification providers;
- cloud and IT service providers, including Microsoft;
- finance and accounting providers, including Intuit and QuickBooks;
- approved AI service providers, including OpenAI and Anthropic, where their use is permitted by our policies and appropriate for the information involved;
- professional advisers;
- contractors, associates and delivery partners supporting authorised work;
- clients and prime contractors where necessary to manage or deliver an engagement;
- security, support and recovery providers; and
- public authorities, courts or regulators where required or permitted by law.
These organisations may act as processors, independent controllers or joint participants in delivering a service, depending on the circumstances.
We limit sharing to what is necessary for the relevant purpose and do not sell personal data.
The specific website analytics and visitor-identification providers will be named in this notice or an associated cookie notice before their technologies are enabled.
4.6 International transfers
Some of our service providers may process or allow access to personal data outside the United Kingdom.
Where a restricted international transfer takes place, we use a transfer mechanism permitted by UK data-protection law. Depending on the destination and provider, this may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission’s Standard Contractual Clauses; or
- another lawful transfer mechanism or exception where applicable.
Where required, we also assess whether the transfer mechanism provides appropriate protection in the circumstances.
You can contact privacy@vividstarr.com for further information about the safeguards applying to a particular transfer or how to obtain a copy of them.
4.7 How long we keep personal data
We keep personal data only for as long as it is needed for the purpose for which it is held, taking account of legal, accounting, contractual, client, security and legitimate business requirements.
Our standard positions include:
- raw website access and security logs are retained for up to 90 days;
- relevant security information may be retained for longer where needed to investigate an incident, protect legal rights or meet a legal obligation;
- website analytics and visitor-identification information is retained for up to 12 months unless a shorter period is configured;
- information lawfully incorporated into a genuine business-contact or client record follows the retention period for that record rather than the website analytics period;
- statutory accounts and tax records are normally retained for six years from the end of the relevant accounting period;
- client contracts and statements of work are normally retained for six years after the engagement ends;
- business correspondence is normally retained for six years where it may be needed as a business or contractual record;
- client project information is returned or securely deleted at the end of the engagement unless the agreement, a legal requirement or an approved hold requires otherwise;
- enquiry, contact and relationship information is retained only while it remains reasonably necessary for the relevant business purpose; and
- meeting recordings, transcripts and related outputs are retained according to their purpose, the applicable engagement arrangements and our retention requirements.
We may retain particular information for longer where required by law, a contract, a formal hold or the need to establish, exercise or defend legal rights.
When personal data is no longer required, it is securely deleted or disposed of in accordance with our Records Retention and Disposal Policy.
4.8 Website data and tracking technologies
Our website and its hosting infrastructure collect the technical information needed to receive and respond to requests, maintain security, diagnose faults and operate the site. This may include internet protocol addresses, timestamps, requested pages, browser information and server-log data.
We may also use analytics technologies to understand website traffic, repeat visits, navigation and interaction.
We may use internet protocol addresses and related information to infer which organisation or network appears to have accessed the site. Where reasonably supported by other lawfully held information, we may associate a visit with a known business contact. We will not represent an inference as certain identification when the available information does not support that conclusion.
Essential cookies or equivalent technologies may be used where necessary to provide or secure the website.
Analytics, visitor-identification or similar technologies that store information on, or access information from, a visitor’s device will be used only where:
- valid consent has been obtained; or
- a specific legal exception applies and all conditions of that exception, including any required information and objection mechanism, have been met.
Where consent is required, non-essential technologies will remain disabled until the visitor makes a choice. Refusing or withdrawing consent will not prevent access to the main website content.
The website will provide appropriate information and controls for managing or withdrawing choices. Withdrawal of consent will not affect processing that took place lawfully before consent was withdrawn.
The actual cookies, scripts, tags and providers used, together with their purposes and durations, will be documented before the relevant technology is enabled.
4.9 How we protect personal data
We apply practical and proportionate technical and organisational controls. These include access controls, multi-factor authentication, device and drive encryption, approved-service requirements, supplier review, recovery arrangements and incident-response procedures.
No method of storage or transmission can guarantee absolute security, but we review our controls in proportion to the nature of the information and the risks involved.
4.10 Your rights
Depending on the circumstances and the lawful basis for the processing, you may have the right to:
- request access to your personal data;
- ask us to correct inaccurate or incomplete information;
- ask us to erase your personal data;
- ask us to restrict how your personal data is used;
- receive certain personal data in a portable format;
- object to particular processing;
- withdraw consent where processing is based on consent; and
- exercise rights relating to solely automated decision-making and profiling.
These rights do not apply in every circumstance. We will explain the position if an exemption or limitation applies.
To exercise a right, contact privacy@vividstarr.com. We may need to verify your identity before acting on the request.
We will respond without undue delay and normally within one month. Where permitted by law, this period may be extended for a complex request or multiple requests. If an extension is necessary, we will tell you within the first month.
If Vivid Starr is processing your personal data on behalf of a client, we may need to refer your request to that client as the controller.
Your right to object
You have the right to object to processing based on legitimate interests, including website analytics and visitor-identification processing.
If you object, we will stop the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
If personal data is used for direct marketing, you have the right to object at any time. We will stop using your personal data for that purpose when you object.
You can object by contacting privacy@vividstarr.com or by using any website objection or preference control made available for the relevant processing.
4.11 Automated decision-making
Vivid Starr does not make decisions about individuals based solely on automated processing, including profiling, that produce legal or similarly significant effects.
Website analytics or visitor-identification information may help Vivid Starr understand apparent business interest, but it will not be used to make solely automated decisions producing legal or similarly significant effects.
AI tools may assist with authorised business and consultancy activities, but their use is subject to appropriate purpose, access, information-handling and human-oversight controls.
4.12 Complaints
If you are concerned about how we have handled your personal data, please contact us at privacy@vividstarr.com.
We will:
- provide a way for you to make a data-protection complaint;
- acknowledge receipt within 30 days;
- take appropriate steps to investigate and respond without undue delay;
- keep you appropriately informed while the complaint is being considered; and
- tell you the outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection:
Contacting us first does not affect your right to complain to the ICO.
4.13 Changes to this notice
We review this notice at least annually and whenever our processing, suppliers, systems or legal obligations change materially.
This version was approved on 8 September 2026. The publication date will be recorded when it is made available on the Vivid Starr website.
5. Roles and responsibilities
The Director maintains and approves this notice, ensures that it reflects Vivid Starr’s actual processing activities, and oversees the handling of rights requests and data-protection complaints.
Personnel, contractors and associates must provide accurate privacy information and handle personal data consistently with this notice.
Suppliers must meet the contractual, security and data-protection requirements applicable to the services they provide.
6. Related documents
- Data Protection Policy
- Information Security Policy
- Supplier and Associate Security Policy
- Records Retention and Disposal Policy
- AI Acceptable Use Policy
- Data Classification and Handling Policy
- Client Confidentiality and Data Segregation Policy
- Incident Response Procedure
7. Review cycle
This notice is reviewed at least annually, or sooner following a significant change to the business, processing activities, systems, suppliers, legal requirements or risk profile.
8. Approval and document control
| Field | Detail |
|---|---|
| Document title | Privacy Notice |
| Organisation | Vivid Starr Ltd, company number 15722054 |
| Owner | Director |
| Approver | Director |
| Version | 1.0 |
| Status | Approved for publication |
| Approval and effective date | 8 September 2026 |
| Publication date | Pending website publication |
| Review date | 8 September 2027 |
| Classification | Public |
| Public repository copy | policies/public/03-privacy-notice.md (controlled mirror) |
| Related documents | See section 6 |
9. Definitions
| Term | Definition |
|---|---|
| Personal data | Information relating to an identified or identifiable person. |
| Controller | A person or organisation that determines the purposes and means of processing personal data. |
| Processor | A person or organisation that processes personal data on behalf of a controller. |
| Processing | Any operation performed on personal data, including collection, use, storage, sharing, deletion or alteration. |
| Lawful basis | A recognised legal basis for processing personal data. |
| Online identifier | Information that may distinguish a person or device online, including an internet protocol address, cookie identifier or similar identifier. |
| Special-category data | Personal data given additional protection under data-protection law, including information about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetics, biometrics used for identification, sex life or sexual orientation. |