PRIVACY POLICY

1. Who We Are

Southpaw Dance Productions (“we”, “us”, “our”) is a registered charity based in the United Kingdom. We are the Data Controller, meaning we decide how and why your personal data is used.

Contact details:

Email: info@southpaw.org.uk;

Address: Sheepfolds Stables, Easington Street, Sunderland, SR5 1BA

Data Protection Lead: Executive Director.

2. What Personal Data We Collect

We collect different types of personal data depending on how you interact with us:

  • Contact details — name, email, phone number, address

  • Participant information — attendance, access needs, emergency contacts, demographic data, contact details

  • Audience information - contact details, demographic data

  • Artist, freelancer and subcontractors data — contracts, payment details, access needs, emergency contacts, demographic data, and where appropriate, company data regarding H&S, data protection, etc.

  • Donor and supporter data — donation history, Gift Aid forms. contact details

  • Website and cookie data — IP address, browsing behaviour

  • Photography and video — images captured at events

  • Safeguarding information — where legally required

Some of this may include special category data, such as health or accessibility information, which we only collect with explicit consent or where legally necessary.

HOME mixed-reality application

HOME is a location-based mixed-reality application developed and operated by Southpaw Company for use on Meta Quest headsets as part of a live performance experience.

What information HOME processes

HOME may process limited information required to operate the experience, including:

  • Meta account information: Meta User ID and limited profile information where required to authenticate Meta Platform services and enable the application to function.

  • Multiplayer and session information: temporary device, session and networking information used through Photon Fusion to synchronise participating headsets and the state of the experience.

  • Spatial information: information about the physical environment generated through Meta Quest spatial features, including scene understanding, spatial anchors and positioning information used to align virtual content with the performance space.

  • Camera and QR information: the Quest headset camera may be used to detect designated QR codes or other spatial reference points for calibration and positioning. HOME does not use the headset camera for facial recognition or identification of audience members.

  • Technical information: application, device and diagnostic information may be processed where necessary to operate, test, troubleshoot and maintain the experience.

HOME is not designed to collect names, contact details, payment information or audience profiling information through the application.

How and why we use this information

Information processed by HOME is used only where necessary to provide and operate the mixed-reality experience. This includes:

  • authenticating and initialising Meta Platform functionality;

  • synchronising multiple Quest headsets during a performance;

  • positioning and aligning digital content within the physical venue;

  • identifying designated spatial calibration markers;

  • maintaining application and network stability; and

  • diagnosing technical problems during development, rehearsal and performance.

We do not use information processed by HOME for advertising, behavioural profiling or unrelated marketing purposes.

Spatial and camera information is used to operate the mixed-reality experience and is not intended to be used to identify individual audience members.

Where information is processed through third-party technology used by HOME, such as Meta Platform services or Photon Fusion networking, those services may also process information in accordance with their own privacy

3. How We Use Your Data

We use your personal data to:

  • Deliver events and programmes

  • Communicate with you about opportunities, updates, and events

  • Manage donations and Gift Aid

  • Pay artists, freelancers and subcontractors

  • Evaluate our impact for funders and reporting

  • Ensure safeguarding

  • Improve our website

4. Our Lawful Bases for Processing

We rely on the following lawful bases under UK GDPR:

  • Consent — e.g., joining our mailing list

  • Contract — e.g., working with artists or freelancers

  • Legal obligation — e.g., Gift Aid, safeguarding, employment law

  • Legitimate interests — e.g., running events, evaluating our work.

Where we process special category data, we rely on explicit consent or safeguarding requirements.

5. Sharing Your Data

We only share your data when necessary and with trusted partners, such as:

  • Ticketing platforms

  • Mailing list providers

  • Cloud storage services

  • Accountants or payroll services

  • Funders, usually in anonymised form

We never sell your data.

6. Photography and Filming

We may take photos or videos at our events for marketing, documentation, or reporting.

We will:

  • Display notices at events

  • Seek consent where required (especially for children)

  • Remove images on request where legally appropriate

You can request removal by contacting us.

7. How Long We Keep Your Data

We keep your data only as long as necessary. Typical retention periods include:

  • Mailing list: until you unsubscribe

  • Participant records: 6 years

  • Audience records: 6 years

  • Donor and Gift Aid records: 6 years

  • Contracts and finance: 6 years

  • Safeguarding records: 6 years after case closure

8. Your Rights

You have the right to:

  • Access your data

  • Correct inaccurate data

  • Request deletion

  • Object to certain processing

  • Restrict how your data is used

  • Withdraw consent at any time

  • Data portability (in some cases)

To exercise your rights, contact our Data Protection Lead. If you are unhappy with our response, you can contact the Information Commissioner’s Office (ICO).

9. How We Protect Your Data

We use a range of security measures, including:

  • Multifactor authentication

  • Encryption of devices

  • Role based access controls

  • Secure cloud storage

  • Regular staff training

10. International Transfers

Some of our service providers may store data outside the UK. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses.

11. Updates to This Notice

We review this notice annually or when our data practices change. The latest version will always be available on our website.

Updated 13th June 2026