Skip to content

PodLot Studios Ltd. GDPR Compliance Policy

Last Updated: 15/03/2025

1. Introduction

PodLot Studios Ltd. ("PodLot") is committed to compliance with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018. This policy outlines how we collect, process, store, and protect personal data for clients using our podcast facilitation services.

2. Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Contractual Necessity: To fulfill service agreements (e.g., recording sessions, billing).
  • Consent: For marketing communications and sharing client content publicly.
  • Legitimate Interests: Improving services, fraud prevention, and promoting our business.

3. Data We Collect

CategoryExamplesPurpose
Client DataName, email, phone number, billing addressService delivery, payment processing
Content DataRecorded audio/video files, show notesProduction, editing, and distribution
Technical DataIP address, device type, browserWebsite functionality, analytics
Marketing DataConsent preferences, campaign engagementPromotional emails, social media ads

4. Data Subject Rights

Clients have the right to:

  1. Access: Request a copy of their personal data.
  2. Rectification: Correct inaccurate/incomplete data.
  3. Erasure: Request deletion (e.g., after account termination).
  4. Portability: Receive data in a machine-readable format.
  5. Withdraw Consent: Opt out of marketing or content sharing.

To exercise rights, email gdpr@podlot.co.uk. We respond within 30 days.

5. Data Sharing & Third Parties

  • Service Providers: Data is shared with:
    • Payment processors (Stripe, PayPal) for transactions.
    • Cloud storage (Firebase, AWS) for content hosting.
    • Email platforms (Mailchimp) for communications.
  • Legal Obligations: Disclosed only if required by law (e.g., court orders).

6. Data Security

  • Encryption: All data transmitted via SSL/TLS; files encrypted at rest (AES-256).
  • Access Controls: Role-based permissions limit staff access to sensitive data.
  • Audits: Annual penetration testing and GDPR compliance reviews.

7. Data Retention

Data TypeRetention Period
Client account data6 years post-termination (HMRC compliance)
Audio/video recordings12 months post-project completion
Marketing dataUntil consent is withdrawn

8. Cookies & Tracking

  • Essential Cookies: Session management, login functionality.
  • Analytics Cookies: Google Analytics (anonymized IPs, opt-out available).
  • Marketing Cookies: Facebook Pixel (only with explicit consent).

9. International Data Transfers

Data may be transferred outside the UK/EEA to partners with:

  • Adequacy Decisions (e.g., EU-US Data Privacy Framework).
  • Standard Contractual Clauses (SCCs) for non-adequate countries.

10. Data Breach Protocol

  • Notification: Reported to the ICO within 72 hours if risk exists.
  • Communication: Affected clients notified via email if breach poses high risk.

11. Updates to This Policy

Changes will be posted on our website. Material updates (e.g., new data uses) will be emailed to clients.

12. Contact Us

Data Protection Officer: [Pending]

Email: gdpr@podlot.co.uk

Postal Address: [Upon Request]

Podcast-Specific Compliance Notes

  1. Content Licensing: Clients consent to public use of their content (e.g., social media clips) via opt-in during onboarding.
  2. Guest Releases: Clients must obtain GDPR-compliant consent from podcast guests before sharing recordings with PodLot.
  3. Children's Data: We do not knowingly process data from individuals under 16 without parental consent.