Privacy Policy

Updated April 2026

Data Protection and Information Security

Lime Blue Solutions Ltd services bring us into contact with personal information about people. To ensure that all those using and working in the company can do so with confidence, we adhere to the Data Protection Act 2018.

This document helps to ensure that we have followed the agreed company procedures, which regulate when and how an individual's "personal data" may be obtained, used, disclosed and generally processed. It applies to computerised processing of personal data and paper-based files and records.

To comply with the law, information is collected and used fairly, stored securely and not disclosed to any other person unlawfully. To do this, Lime Blue Solutions Limited staff comply with the Data Protection principles and subsequent GDPR regulations. In summary, these state that personal data shall be:

  • Processed fairly, lawfully and in a transparent manner
  • Obtained for specified, explicit and legitimate purpose and not further processed
  • Adequate, relevant and limited to what is necessary in relation to the purpose for which it is processed
  • Accurate and, where necessary, kept up to date
  • Kept for no longer than is deemed necessary for the specific purpose
  • Processed in accordance with the data subject's rights
  • Protected by appropriate security
  • Not transferred to a third country or an international organisation if the provisions of the GDPR are not complied with (under the 8th principle we can transfer information for travel & event purposes to a third party overseas providing we have the individual's consent)

This privacy policy covers the following points:

  • What kind of information do we collect; the ways we collect it and why
  • How we use information we collect
  • With whom we share information we collect
  • How you can access, amend, and delete information we collect from you
  • What kinds of security we use to protect information you provide

Before using the Lime Blue Solutions Limited website or communicating with us – and particularly before providing personally identifiable information to us – you should read this entire policy. Use of our website or communicating with us constitutes your agreement to the terms of this policy. If the terms of this policy are not acceptable to you, do not provide any personally identifiable information to us. You can also contact us at enquiries@limebluesolutions.com.


How We Collect Information

We collect information from you in two ways: actively and passively. Active information collection refers to instances in which we gather information from you when you fill it in and send it to us, such as by completing a contact form on our website or event registration site. Active information includes both personally identifiable information (e.g., your full name or information that is unique to you). Passive information collection refers to instances in which we collect information from you that you have not actively provided (see below for a summary of our passive information collection methods).

Types of Active Information Collection

(a) Website Contact Form
If you wish to get in contact to find out more about our services, we ask you to complete a contact form that asks for the following information: full name, email address, phone number and any optional details you wish to disclose about your enquiry.

(b) Event Registration
If you are attending a Lime Blue Solutions Ltd event and are required to register via a registration site, we will ask for the following information: full name, email address, job title, company name, telephone number, dietary requirements and any other data required for the event purposes. (For client registration sites, please ask for a copy of our full policy and refer to the section called ‘Data Processing on Behalf of a Client’.)

Types of Passive Information Collection

Personal information will also be collected automatically via our website www.limebluesolutions.com, as well as any online registration systems and websites we create for client events:

(a) Cookies and IP Addresses
Our company website is created using Wix.com and our event registration sites are created using EventsCase.com.

The development software uses several third-party tracking services that use cookies, IP addresses, location, browser and operating system data to track non-personally identifiable information about visitors to the Site in the aggregate, like Google Analytics or Zopim. We have no access or control of these third-party tracking utilities.

The sites sometimes link the information we store in cookies to any Personally Identifiable Information you submit while on a Site in order to improve the Site and to deliver a better and more personalised service.

The Sites use both session ID cookies and persistent cookies. We use session cookies to make it easier for you to navigate a Site. A session ID cookie expires when you close your browser. A persistent cookie remains on your hard drive for an extended period. You can remove persistent cookies by following directions provided in your Internet browser's "help" file.

For registration sites only – we set a persistent cookie to remember your login details, so you don't have to enter it more than once. Persistent cookies also enable us to track and target the interests of our users to enhance the experience on our Site.

You may refuse to accept cookies by activating the settings on your browser which allow you to refuse the setting of cookies. However, if you select this setting your ability to access certain areas of our Site may be limited. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you log on to our Site.

(b) Personal Data Storage and Security – Wix.com
Wix can store your site-visitors' data in several locations.

Your site-visitors' personal information may be stored in data centres located in the United States of America, Ireland, South Korea, Taiwan and Israel. We may use other jurisdictions as necessary for the proper delivery of our services and/or as may be required by law.

Wix is a global company that respects the laws of the jurisdictions it operates within. The processing of the User Customer Data may take place within the territory of the European Union, Israel or a third country, territory, or one or more specified sectors within that third country, of which the European Commission has decided that it ensures an adequate level of protection.

(c) Personal Data Storage and Security – Eventscase.com
Our third-party internet provider stores data at Amazon Ireland, always inside of the European Union.

The AWS environment that hosts our third-party services maintains multiple certifications for its data centres, including ISO 27001 compliance, PCI Certification, and SOC reports. For more information about their certification and compliance, please visit the AWS security website and the AWS compliance website.

Customer data is encrypted at rest (AWS RDS Encryption – AES-256).

If you would like more information on our third-party registration platform partner, please refer to their privacy policy at: eventscase.com/pages/privacy

How We Collect Information Through Other Channels

We collect information from you when you call us, when you send emails, when we meet with you in person and when you communicate with us via social media.


How Do We Use the Information

The data we process about you will only be used and disclosed in accordance with this policy or as specifically disclosed to you at the time you provide the information.

We will process it in the following ways:

(a) To respond to your requests, it will be accessed by our internal staff and carefully selected third parties while providing quotes that you request for our services.

(b) If you have previously asked us for a quote or confirmed an event or design project with us, we will send you company and services updates and relevant marketing news to the email or postal address you have provided to us. You can unsubscribe at any time – see the ‘Unsubscribing’ section below for more information.


Unsubscribing

On all our marketing communications to you we will include a way for you to unsubscribe from any future communications.

Should you wish to unsubscribe from marketing communications via email, you may opt out by sending an email to enquiries@limebluesolutions.com writing ‘unsubscribe’ in the title, or by replying to a specific email campaign and writing ‘unsubscribe’ in the title.

Should you wish to unsubscribe from marketing communications via postal mail, you can contact us by email at enquiries@limebluesolutions.com (please write "unsubscribe" in the subject line and provide each postal address you would like us to remove), or by post at Lime Blue Solutions Ltd, London House, Lower Road, Cookham, Berkshire, SL6 9EH.

Access to Your Personal Data

We provide you with reasonable access to your personal information to correct errors or delete the information you have provided. If you wish to correct or delete your personally identifiable information, please contact us by email at enquiries@limebluesolutions.com or by post at Lime Blue Solutions Ltd, London House, Lower Road, Cookham, Berkshire, SL6 9EH.


Legal Basis for Processing Personal Data

Under the UK General Data Protection Regulation (UK GDPR), we rely on the following lawful bases for processing your personal data:

1. Contractual Necessity

We process your personal data where it is necessary to perform a contract with you, or to take steps at your request prior to entering a contract. This includes:

  • Delivering event and design services
  • Managing event registrations and delegate information
  • Communicating with you regarding enquiries, quotes, and ongoing projects

2. Legitimate Interests

We may process your personal data where it is necessary for our legitimate business interests, if these are not overridden by your rights and freedoms. These interests include:

  • Managing and developing our business relationships
  • Responding to enquiries and providing relevant information about our services
  • Improving our services, websites, and client experience
  • Maintaining internal records and administrative processes

Where we rely on legitimate interests, we ensure that our processing is proportionate and respects your privacy rights.

3. Consent

We rely on your consent to process your personal data in certain situations, including:

  • Sending you marketing communications where required by law
  • Collecting optional information (such as dietary requirements or preferences where not essential to the service)

You have the right to withdraw your consent at any time (see "Your Data Protection Rights" section).

4. Legal Obligation

We may process your personal data where it is necessary for compliance with a legal obligation to which we are subject. This includes:

  • Maintaining financial records for accounting and tax purposes
  • Complying with regulatory or legal requirements

5. Vital Interests (Where Applicable)

In rare circumstances, we may process personal data to protect an individual's vital interests, for example in the case of a medical emergency during an event.

Special Category Data

In limited circumstances, we may process special category data (such as dietary requirements or accessibility needs) where this is necessary for the delivery of an event or service. In such cases, we will rely on your explicit consent or another lawful basis permitted under UK GDPR.


Data Processing on Behalf of a Client

We process data for clients to fulfil our contractual responsibilities while delivering our services:

  • All Lime Blue Solutions Limited contracts will include terms and conditions adhering to the GDPR regulations, and therefore information given to us by clients can be processed for the purposes of the contract or SLA. When a client supplies us with delegate details, we will not require individual consent to pass delegate data to third parties and sub-data processors (i.e. destination management companies, flight companies etc.) but will require the client to confirm they have already received this consent from their delegates. We ensure that within client contracts and SLA agreements the client has confirmed the following sentence: "the data controller has taken all reasonable steps to make data passed to us compliant under GDPR regulations and all applicable laws".
  • We use third-party software called EventsCase to create event registration websites and event apps. If further information is required from delegates in addition to the previous point, we set up a fair processing notice on the site/app, which is in line with the end client's privacy policy.
  • Registration websites and apps in EventsCase can only be accessed by Lime Blue staff who are working on that event, either having full access to the site/app or parts of it, and these will be agreed with the client at the point of signing the contract. Full administration rights and thus access to all registration sites is only held by Lime Blue administrators.
  • When clients send us personal information on their delegates, we ensure these spreadsheets have been password protected. Passwords are sent to us separately – preferably by WhatsApp, text or phone call.
  • We ensure all documents we create in the process of the event which contain delegate information are password protected. We use GDPR-compliant password protocol. Only individuals working on an event, the Company Directors, Senior Account Directors and the Lime Blue Solutions Limited Data Protection Manager will have access to these passwords (which they need for crisis management purposes).
  • Prior to travelling to an event – we make sure all delegate data is only put onto a secure online platform such as OneDrive or Google Drive. Access to this data is invite only.
  • Prior to returning from an event – any documents that have been put on a desktop during the event are deleted from desktops before travel.
  • After each event, relevant documents such as signed contracts and signed SLAs are stored on our Microsoft 365 SharePoint, and kept for a period of six years. No paper documents are saved.
  • All medium to high risk personal information (such as date of birth, postal address, passport information etc.) gathered for a specific event is shredded on-site at our offices (if printed) and deleted from all computers, servers and online share points post-event, and on completion of all invoicing and subsequent payment.
  • We delete all emails that contain personal information from any staff inboxes, sent items, files and deleted folders.
  • All client and supplier invoices will be kept by the Lime Blue Solutions Limited Accounts Department for a period of six years.
  • All other personally identifiable information deemed low risk which is held on individuals as part of the event (i.e. registration names, event planners) shall be kept on the Microsoft 365 SharePoint, in password-protected files, for a maximum of 5 years, after which it will be deleted if we are no longer working with that client.
  • Client registration website pages are deleted, and the websites set to 'unpublished', within 2 weeks past the last day of the event. We keep a record of the number of registrations only.
    • If an app has been used, we request the external supplier to remove it from the App Store within 2 weeks of returning from the event, unless the client has a series of events.
  • When venue sourcing for a client, we will keep emails from clients, venue proposals and venue confirmations. Once the event has taken place and commission invoices paid, all invoices will be kept by our accounts department and event information on the Microsoft 365 SharePoint, but no other paper files will be kept.
  • Any design files that contain personally identifiable information will be kept in a password-protected folder. Only the Company Directors, Senior Account Directors and the Lime Blue Solutions Limited Data Protection Manager will have access to these passwords.

Data Protection Officer

Lime Blue Solutions Ltd has not appointed a data protection officer, as it is our policy not to collect the following information:

  • Racial or ethnic origin or political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data, or biometric data
  • Data concerning health
  • Data concerning a natural person's sex life or sexual orientation

We have a Data Protection Manager who can be contacted at +44 1628 780211 or ali@limebluesolutions.com.


Lime Blue Solutions Proprietary Database

Throughout the course of our business, we collect data on 3 different types of contacts:

  • Prospects
  • Clients
  • Suppliers

All contacts have the right to ask what information we hold on them on this database.

Prospects

We collect and store information on prospective clients who we believe may have a legitimate business interest in our services. This is usually collected via marketing campaigns, networking events or cold calling.

We collect and store their name, job title, company name, company address, phone number, business mobile, email address and website, and a record of conversations we have had with them. We may also keep a record of what marketing activity we have had with them.

These records are kept for a period of 3 years. If we have had no engagement with the prospect within this time, they are contacted a final time and, if no response, the record is deleted.

Prospect marketing communications must always contain the option to unsubscribe.

Clients

The above information is also collected from any clients that call or email Lime Blue Solutions Limited with a new enquiry. We also keep a record of what enquiries they have made with us, venues we have booked on their behalf, events or design projects we have delivered for them, and any feedback.

This information is kept for 5 years. If we have had no engagement with the client within this time, they are contacted a final time and, if no response, the record is deleted.

All client marketing communications must contain the option to unsubscribe.

Suppliers

The above information is also collected from suppliers for use to facilitate work/projects. This information is kept on the ACT database indefinitely, unless requested to be removed.


Loss of Laptop – Procedure

In the unfortunate event that a company laptop is lost or stolen, the following procedures are followed:

  • A line manager, Company Director or data protection manager is immediately notified – where and when the loss occurred. They will in turn inform the necessary other parties.
  • Our IT provider is requested to change the username and password.
  • Passwords are changed via phone or other means.
  • Lost and found departments are checked if applicable.
  • If stolen, the loss is reported to the police to obtain a crime reference number for insurance purposes. All company laptop serial numbers are kept on record in our Business Continuity Policy for easy access.
  • The line manager makes the client aware that the laptop has been lost, and then explains what precautions have already been taken to protect their data.

General Data Storage and Security Information

At the end of employment (or contract), personnel access to computing and network resources, facilities and secure areas is immediately terminated.

Entry to the Lime Blue Solutions physical office is protected via a locked door. Each time an employee terminates their employment, the door key is returned.

The office premises is alarmed. In the event of the alarm sounding, a nominated team member is called by the monitoring centre, who then responds to and investigates the alarm.

Lime Blue Solutions holds an inventory of assets in the Business Continuity Policy, a copy of which is kept both onsite and offsite. It documents ID, ownership, usage, location and configuration.

Company data is split between an on-premise NAS solution and a Microsoft 365 SharePoint structure.

The networking and telecommunications closet, which contains our NAS drive, is located in its own secure cupboard in our meeting room so no unauthorised access can occur during office hours. This is further protected by a code pad.

We have a UPS which protects the networking equipment and NAS from power surges.

Office 365 accounts are protected via MFA Number Matching, which is enforced via a Conditional Access Policy.

Office 365 data (Mailboxes, OneDrive, SharePoint and Teams) is backed up to Acronis Backup Cloud Storage once a day. This is stored in the UK.

NAS data is backed up to Acronis Backup Cloud Storage three times a day. This is stored in the UK.

Our IT provider holds a network configuration blueprint of the infrastructure and maintains documentation of configuration changes to each system. They also have formally defined policies and practices for performing risk assessments of software and systems.

Laptops and desktops have properly configured anti-malware software – Sentinel One – have Windows Firewall enabled, which denies access to all connections that are not explicitly allowed, and also have patch management in place to ensure the OS is kept up to date.

We also have the Barracuda Email Security and Impersonation Protection mail solution in place to protect us from mail threats.

Our IT provider gives us original passwords for each desktop and laptop, and the operator then changes the password. Passwords must be between 8 and 256 characters and use a combination of at least three of the following: uppercase letters, lowercase letters, numbers, and symbols.

Discs from old computers are removed, wiped and disposed of via Purple Jelly, Lime Blue's dedicated IT company.