
Updated April 2026
Lime Blue Solutions Ltd services bring us into contact with personal information about people. To ensure that all those using and working in the company can do so with confidence, we adhere to the Data Protection Act 2018.
This document helps to ensure that we have followed the agreed company procedures, which regulate when and how an individual's "personal data" may be obtained, used, disclosed and generally processed. It applies to computerised processing of personal data and paper-based files and records.
To comply with the law, information is collected and used fairly, stored securely and not disclosed to any other person unlawfully. To do this, Lime Blue Solutions Limited staff comply with the Data Protection principles and subsequent GDPR regulations. In summary, these state that personal data shall be:
This privacy policy covers the following points:
Before using the Lime Blue Solutions Limited website or communicating with us – and particularly before providing personally identifiable information to us – you should read this entire policy. Use of our website or communicating with us constitutes your agreement to the terms of this policy. If the terms of this policy are not acceptable to you, do not provide any personally identifiable information to us. You can also contact us at enquiries@limebluesolutions.com.
We collect information from you in two ways: actively and passively. Active information collection refers to instances in which we gather information from you when you fill it in and send it to us, such as by completing a contact form on our website or event registration site. Active information includes both personally identifiable information (e.g., your full name or information that is unique to you). Passive information collection refers to instances in which we collect information from you that you have not actively provided (see below for a summary of our passive information collection methods).
(a) Website Contact Form
If you wish to get in contact to find out more about our services, we ask you to complete a contact form that asks for the following information: full name, email address, phone number and any optional details you wish to disclose about your enquiry.
(b) Event Registration
If you are attending a Lime Blue Solutions Ltd event and are required to register via a registration site, we will ask for the following information: full name, email address, job title, company name, telephone number, dietary requirements and any other data required for the event purposes. (For client registration sites, please ask for a copy of our full policy and refer to the section called ‘Data Processing on Behalf of a Client’.)
Personal information will also be collected automatically via our website www.limebluesolutions.com, as well as any online registration systems and websites we create for client events:
(a) Cookies and IP Addresses
Our company website is created using Wix.com and our event registration sites are created using EventsCase.com.
The development software uses several third-party tracking services that use cookies, IP addresses, location, browser and operating system data to track non-personally identifiable information about visitors to the Site in the aggregate, like Google Analytics or Zopim. We have no access or control of these third-party tracking utilities.
The sites sometimes link the information we store in cookies to any Personally Identifiable Information you submit while on a Site in order to improve the Site and to deliver a better and more personalised service.
The Sites use both session ID cookies and persistent cookies. We use session cookies to make it easier for you to navigate a Site. A session ID cookie expires when you close your browser. A persistent cookie remains on your hard drive for an extended period. You can remove persistent cookies by following directions provided in your Internet browser's "help" file.
For registration sites only – we set a persistent cookie to remember your login details, so you don't have to enter it more than once. Persistent cookies also enable us to track and target the interests of our users to enhance the experience on our Site.
You may refuse to accept cookies by activating the settings on your browser which allow you to refuse the setting of cookies. However, if you select this setting your ability to access certain areas of our Site may be limited. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you log on to our Site.
(b) Personal Data Storage and Security – Wix.com
Wix can store your site-visitors' data in several locations.
Your site-visitors' personal information may be stored in data centres located in the United States of America, Ireland, South Korea, Taiwan and Israel. We may use other jurisdictions as necessary for the proper delivery of our services and/or as may be required by law.
Wix is a global company that respects the laws of the jurisdictions it operates within. The processing of the User Customer Data may take place within the territory of the European Union, Israel or a third country, territory, or one or more specified sectors within that third country, of which the European Commission has decided that it ensures an adequate level of protection.
(c) Personal Data Storage and Security – Eventscase.com
Our third-party internet provider stores data at Amazon Ireland, always inside of the European Union.
The AWS environment that hosts our third-party services maintains multiple certifications for its data centres, including ISO 27001 compliance, PCI Certification, and SOC reports. For more information about their certification and compliance, please visit the AWS security website and the AWS compliance website.
Customer data is encrypted at rest (AWS RDS Encryption – AES-256).
If you would like more information on our third-party registration platform partner, please refer to their privacy policy at: eventscase.com/pages/privacy
We collect information from you when you call us, when you send emails, when we meet with you in person and when you communicate with us via social media.
The data we process about you will only be used and disclosed in accordance with this policy or as specifically disclosed to you at the time you provide the information.
We will process it in the following ways:
(a) To respond to your requests, it will be accessed by our internal staff and carefully selected third parties while providing quotes that you request for our services.
(b) If you have previously asked us for a quote or confirmed an event or design project with us, we will send you company and services updates and relevant marketing news to the email or postal address you have provided to us. You can unsubscribe at any time – see the ‘Unsubscribing’ section below for more information.
On all our marketing communications to you we will include a way for you to unsubscribe from any future communications.
Should you wish to unsubscribe from marketing communications via email, you may opt out by sending an email to enquiries@limebluesolutions.com writing ‘unsubscribe’ in the title, or by replying to a specific email campaign and writing ‘unsubscribe’ in the title.
Should you wish to unsubscribe from marketing communications via postal mail, you can contact us by email at enquiries@limebluesolutions.com (please write "unsubscribe" in the subject line and provide each postal address you would like us to remove), or by post at Lime Blue Solutions Ltd, London House, Lower Road, Cookham, Berkshire, SL6 9EH.
We provide you with reasonable access to your personal information to correct errors or delete the information you have provided. If you wish to correct or delete your personally identifiable information, please contact us by email at enquiries@limebluesolutions.com or by post at Lime Blue Solutions Ltd, London House, Lower Road, Cookham, Berkshire, SL6 9EH.
Under the UK General Data Protection Regulation (UK GDPR), we rely on the following lawful bases for processing your personal data:
We process your personal data where it is necessary to perform a contract with you, or to take steps at your request prior to entering a contract. This includes:
We may process your personal data where it is necessary for our legitimate business interests, if these are not overridden by your rights and freedoms. These interests include:
Where we rely on legitimate interests, we ensure that our processing is proportionate and respects your privacy rights.
We rely on your consent to process your personal data in certain situations, including:
You have the right to withdraw your consent at any time (see "Your Data Protection Rights" section).
We may process your personal data where it is necessary for compliance with a legal obligation to which we are subject. This includes:
In rare circumstances, we may process personal data to protect an individual's vital interests, for example in the case of a medical emergency during an event.
In limited circumstances, we may process special category data (such as dietary requirements or accessibility needs) where this is necessary for the delivery of an event or service. In such cases, we will rely on your explicit consent or another lawful basis permitted under UK GDPR.
We process data for clients to fulfil our contractual responsibilities while delivering our services:
Lime Blue Solutions Ltd has not appointed a data protection officer, as it is our policy not to collect the following information:
We have a Data Protection Manager who can be contacted at +44 1628 780211 or ali@limebluesolutions.com.
Throughout the course of our business, we collect data on 3 different types of contacts:
All contacts have the right to ask what information we hold on them on this database.
We collect and store information on prospective clients who we believe may have a legitimate business interest in our services. This is usually collected via marketing campaigns, networking events or cold calling.
We collect and store their name, job title, company name, company address, phone number, business mobile, email address and website, and a record of conversations we have had with them. We may also keep a record of what marketing activity we have had with them.
These records are kept for a period of 3 years. If we have had no engagement with the prospect within this time, they are contacted a final time and, if no response, the record is deleted.
Prospect marketing communications must always contain the option to unsubscribe.
The above information is also collected from any clients that call or email Lime Blue Solutions Limited with a new enquiry. We also keep a record of what enquiries they have made with us, venues we have booked on their behalf, events or design projects we have delivered for them, and any feedback.
This information is kept for 5 years. If we have had no engagement with the client within this time, they are contacted a final time and, if no response, the record is deleted.
All client marketing communications must contain the option to unsubscribe.
The above information is also collected from suppliers for use to facilitate work/projects. This information is kept on the ACT database indefinitely, unless requested to be removed.
In the unfortunate event that a company laptop is lost or stolen, the following procedures are followed:
At the end of employment (or contract), personnel access to computing and network resources, facilities and secure areas is immediately terminated.
Entry to the Lime Blue Solutions physical office is protected via a locked door. Each time an employee terminates their employment, the door key is returned.
The office premises is alarmed. In the event of the alarm sounding, a nominated team member is called by the monitoring centre, who then responds to and investigates the alarm.
Lime Blue Solutions holds an inventory of assets in the Business Continuity Policy, a copy of which is kept both onsite and offsite. It documents ID, ownership, usage, location and configuration.
Company data is split between an on-premise NAS solution and a Microsoft 365 SharePoint structure.
The networking and telecommunications closet, which contains our NAS drive, is located in its own secure cupboard in our meeting room so no unauthorised access can occur during office hours. This is further protected by a code pad.
We have a UPS which protects the networking equipment and NAS from power surges.
Office 365 accounts are protected via MFA Number Matching, which is enforced via a Conditional Access Policy.
Office 365 data (Mailboxes, OneDrive, SharePoint and Teams) is backed up to Acronis Backup Cloud Storage once a day. This is stored in the UK.
NAS data is backed up to Acronis Backup Cloud Storage three times a day. This is stored in the UK.
Our IT provider holds a network configuration blueprint of the infrastructure and maintains documentation of configuration changes to each system. They also have formally defined policies and practices for performing risk assessments of software and systems.
Laptops and desktops have properly configured anti-malware software – Sentinel One – have Windows Firewall enabled, which denies access to all connections that are not explicitly allowed, and also have patch management in place to ensure the OS is kept up to date.
We also have the Barracuda Email Security and Impersonation Protection mail solution in place to protect us from mail threats.
Our IT provider gives us original passwords for each desktop and laptop, and the operator then changes the password. Passwords must be between 8 and 256 characters and use a combination of at least three of the following: uppercase letters, lowercase letters, numbers, and symbols.
Discs from old computers are removed, wiped and disposed of via Purple Jelly, Lime Blue's dedicated IT company.