PRIVACY POLICY
PURPOSE OF THIS PRIVACY POLICY
Stratosphere Ventures Limited respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store, disclose and otherwise process personal data when you:
- visit or use our website;
- contact us or submit an enquiry;
- request, discuss, purchase or receive our services;
- work with us as a client, prospective client, supplier, contractor, collaborator or professional contact;
- participate in consulting, business development, creative, talent, recruitment, photography or portfolio-related activities;
- apply for, discuss or participate in an opportunity facilitated by us;
- communicate with us through email, telephone, video call, social media or another channel; or
- otherwise interact with Stratosphere Ventures Limited.
It also explains your rights under applicable UK data protection law and how you may exercise them.
This Privacy Policy should be read alongside our Cookies Policy, Website Terms and Conditions and any additional privacy information or service-specific terms provided to you.
WHO WE ARE
Stratosphere Ventures Limited is the controller responsible for the personal data covered by this Privacy Policy, except where we expressly state that we are acting solely as a processor on behalf of another organisation.
Our corporate details are:
References in this Privacy Policy to "Stratosphere Ventures", "we", "us" or "our" mean Stratosphere Ventures Limited.
We are not presently required to appoint a statutory Data Protection Officer. Privacy enquiries, rights requests and data protection complaints should be directed to the privacy contact above.
IMPORTANT DEFINITIONS
For the purposes of this Privacy Policy:
- Personal data means information relating to an identified or identifiable living individual.
- Processing includes collecting, recording, organising, storing, consulting, using, disclosing, sharing, restricting, deleting or otherwise handling personal data.
- Special category data includes personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used for identification, health data, and data concerning a person’s sex life or sexual orientation.
- Controller means the person or organisation that determines why and how personal data is processed.
- Processor means a person or organisation that processes personal data on behalf of a controller.
THE PERSONAL DATA WE MAY COLLECT
The personal data we collect depends on your relationship and interaction with us.
4.1Identity and contact information
This may include:
- name;
- title;
- business or trading name;
- job title;
- employer or organisation;
- postal address;
- email address;
- telephone number;
- social media or professional profile details; and
- other contact information you provide.
4.2Enquiry and communications information
This may include:
- information submitted through our contact form;
- the content of emails, messages and correspondence;
- records of telephone or video discussions;
- meeting notes;
- requests, questions, complaints and feedback;
- communication preferences; and
- information you choose to provide when communicating with us.
4.3Client and project information
This may include:
- project briefs;
- commercial objectives;
- business plans and strategies;
- service requirements;
- proposals and quotations;
- contractual records;
- instructions;
- meeting records;
- project correspondence;
- deliverables;
- approvals;
- feedback;
- account information;
- invoicing information; and
- records relating to the administration and performance of our services.
4.4Professional and business information
This may include:
- professional history;
- qualifications;
- experience;
- skills;
- industry sector;
- commercial interests;
- business relationships;
- professional references;
- publicly available professional information; and
- information relevant to evaluating a proposed engagement, introduction, partnership or opportunity.
4.5Talent, recruitment and opportunity information
Where relevant to our services, this may include:
- curriculum vitae or résumé information;
- portfolio materials;
- professional profiles;
- work history;
- skills and experience;
- availability;
- preferences;
- representation status;
- audition, casting or application information;
- photographs, videos or recordings;
- physical or appearance-related information genuinely required for a particular opportunity;
- information supplied by referees or professional contacts; and
- information relevant to assessing suitability for an opportunity.
We do not guarantee any booking, placement, engagement, opportunity, income or commercial outcome.
4.6Photography, creative and portfolio information
This may include:
- booking information;
- creative briefs;
- location and scheduling information;
- photographs, video, audio and other creative material;
- image selections;
- editing instructions;
- licensing information;
- model, contributor or property releases;
- usage permissions;
- correspondence concerning publication or portfolio use; and
- information required to deliver the agreed creative service.
We will not use an individual’s image for unrelated promotional purposes unless we have an appropriate lawful basis and any required permission or contractual authorisation.
4.7Transaction and financial information
This may include:
- billing details;
- payment status;
- transaction records;
- invoices;
- refunds;
- purchase or order history;
- tax-related records; and
- limited payment-related information supplied by a payment provider.
Where payments are processed by an independent payment provider, we may not receive or retain full payment-card details.
4.8Website, device and technical information
This may include:
- internet protocol address;
- browser type and version;
- device type;
- operating system;
- time zone and approximate location;
- pages visited;
- time and date of access;
- referral source;
- navigation and interaction information;
- form-submission information;
- cookie identifiers;
- consent preferences;
- security events;
- diagnostic information; and
- server or application logs.
Further information about cookies and similar technologies appears in our Cookies Policy.
4.9Marketing and preference information
This may include:
- communication preferences;
- marketing consents;
- subscription status;
- areas of professional or commercial interest;
- records of communications sent;
- engagement with communications; and
- opt-out or objection records.
4.10Compliance, dispute and security information
This may include:
- identity-verification information;
- fraud-prevention information;
- records relevant to legal claims;
- complaints;
- alleged misconduct;
- contractual disputes;
- regulatory correspondence;
- security incidents;
- access records; and
- information necessary to establish, exercise or defend legal rights.
4.11Special category and criminal-offence information
We do not ordinarily request special category data or criminal-offence data through our general website enquiry form.
Where this information is genuinely necessary for a particular service, legal obligation, accessibility requirement, safeguarding matter or legal claim, we will process it only where:
- a lawful basis under Article 6 of the UK GDPR applies;
- an additional condition under Article 9 of the UK GDPR applies for special category data;
- any applicable condition under the Data Protection Act 2018 applies;
- the processing is necessary and proportionate; and
- appropriate safeguards are in place.
You should not send special category data, criminal-offence information, financial credentials, passwords or other highly sensitive information through an ordinary website form unless we have specifically requested it and provided an appropriate method.
HOW WE OBTAIN PERSONAL DATA
We may obtain personal data:
- directly from you;
- from someone acting with your authority;
- from a client, employer, representative, agent, collaborator or professional adviser;
- from referees or professional contacts;
- through referrals and introductions;
- from organisations seeking talent, suppliers, consultants, collaborators or commercial partners;
- from publicly accessible sources, including professional websites, company websites, Companies House and professional social media platforms;
- from our website, systems and service providers;
- from analytics, security and communications providers;
- from event organisers or networking contacts; and
- from regulators, public authorities, courts, professional advisers or counterparties where lawful and relevant.
Where we obtain personal data from another source, we will provide the required privacy information within the period required by law unless an applicable exemption applies.
WHY WE PROCESS PERSONAL DATA AND OUR LAWFUL BASES
We process personal data only where we have a lawful basis.
Depending on the circumstances, we may rely on one or more of the following bases:
- Contract: processing is necessary to take steps at your request before entering into a contract or to perform a contract with you.
- Legal obligation: processing is necessary to comply with a legal or regulatory obligation.
- Legitimate interests: processing is necessary for our legitimate interests or those of a third party, except where those interests are overridden by your interests, rights or freedoms.
- Consent: you have freely given a specific, informed and unambiguous indication of consent.
- Vital interests: processing is necessary to protect someone’s life, in the limited circumstances where this applies.
Our principal processing activities are set out below.
6.1Operating and securing our website
Purposes:
- making the website available;
- maintaining functionality;
- processing website forms;
- authenticating authorised access;
- detecting and preventing misuse;
- maintaining security;
- troubleshooting;
- monitoring performance; and
- preserving system integrity.
Lawful bases:
- our legitimate interests in operating a secure and effective website;
- performance of a contract or steps requested before a contract, where relevant;
- legal obligation, where applicable; and
- consent where required for a particular cookie or technology.
6.2Responding to enquiries
Purposes:
- receiving and assessing enquiries;
- responding to questions;
- understanding requirements;
- arranging meetings;
- preparing proposals or quotations;
- determining whether we can provide services; and
- maintaining an appropriate record of communications.
Lawful bases:
- steps requested before entering into a contract;
- performance of a contract;
- our legitimate interests in responding to enquiries and developing legitimate business relationships; and
- legal obligation where relevant.
6.3Providing consulting and business-development services
Purposes:
- client onboarding;
- scoping and managing projects;
- providing strategic, consulting and business-development services;
- producing deliverables;
- administering the client relationship;
- managing communications;
- invoicing;
- resolving issues; and
- maintaining professional and commercial records.
Lawful bases:
- contract;
- legal obligation; and
- our legitimate interests in operating, administering and protecting our business.
6.4Talent, recruitment, creative and opportunity-related activities
Purposes:
- receiving and maintaining professional profiles;
- assessing suitability;
- discussing or identifying opportunities;
- facilitating introductions;
- communicating with prospective clients, collaborators or opportunity providers;
- arranging bookings or engagements;
- supporting portfolio development;
- administering related services; and
- maintaining records of introductions, submissions and outcomes.
Lawful bases:
- contract;
- steps requested before entering into a contract;
- our legitimate interests in providing and developing these services; and
- consent where the law or the circumstances require it.
Where information is to be disclosed to a third party for an opportunity, we will consider the nature of the service, your reasonable expectations, applicable contractual arrangements and whether consent or another lawful basis is required.
6.5Photography and portfolio-building services
Purposes:
- arranging and delivering shoots;
- managing locations, schedules and creative requirements;
- producing, editing and delivering content;
- administering selections and galleries;
- managing usage rights and licences;
- obtaining and recording releases or permissions;
- providing support; and
- retaining appropriate contractual and licensing records.
Lawful bases:
- contract;
- steps requested before entering into a contract;
- legal obligation;
- legitimate interests; and
- consent where required.
6.6Payments, accounting and business administration
Purposes:
- processing payments;
- issuing invoices;
- collecting debts;
- administering refunds;
- maintaining financial records;
- preparing accounts;
- preventing fraud; and
- meeting tax, accounting and legal obligations.
Lawful bases:
- contract;
- legal obligation; and
- legitimate interests in administering our business and recovering sums lawfully due.
6.7Marketing and business communications
Purposes:
- sending relevant service information;
- communicating business updates;
- managing professional relationships;
- measuring communication effectiveness;
- maintaining suppression records; and
- promoting our services where lawful.
Lawful bases:
- consent where required;
- our legitimate interests in promoting and developing our business, particularly in a business-to-business context; and
- compliance with applicable direct-marketing and electronic-communications law.
You may opt out of marketing at any time. We may retain limited suppression information to ensure that we respect an opt-out.
6.8Legal, regulatory, complaints and dispute management
Purposes:
- complying with legal and regulatory duties;
- responding to lawful requests;
- handling complaints;
- investigating alleged breaches;
- obtaining legal advice;
- establishing, exercising or defending legal claims;
- enforcing contracts;
- protecting our rights, property and business; and
- cooperating with courts, regulators and authorities.
Lawful bases:
- legal obligation;
- legitimate interests;
- contract; and
- where relevant, the legal-claims conditions applicable to special category data.
OUR LEGITIMATE INTERESTS
Where we rely on legitimate interests, those interests may include:
- operating and developing our business;
- providing responsive and effective services;
- maintaining client and professional relationships;
- identifying appropriate commercial, creative or professional opportunities;
- protecting website and system security;
- preventing fraud, misuse and unlawful activity;
- maintaining accurate business records;
- improving our services and website;
- protecting confidential information and intellectual property;
- recovering debts;
- obtaining professional advice;
- managing complaints and disputes; and
- establishing, exercising or defending legal rights.
Before relying on legitimate interests, we consider whether the processing is necessary, whether there is a less intrusive means of achieving the purpose, and whether your rights or interests override ours.
You may object to processing based on legitimate interests as explained in section 14.
WHEN YOU MUST PROVIDE PERSONAL DATA
In some circumstances, personal data is required:
- to respond meaningfully to an enquiry;
- to take steps at your request before entering into a contract;
- to enter into or perform a contract;
- to verify authority or identity;
- to process payment;
- to comply with a legal obligation; or
- to administer a service or opportunity.
Where required information is not provided, we may be unable to respond fully, enter into a contract, provide a service, process a transaction or continue an engagement.
We will indicate where information is mandatory where reasonably practicable.
DISCLOSURE OF PERSONAL DATA
We may disclose personal data where lawful and reasonably necessary to:
- website hosting, infrastructure, database and technical-support providers;
- email, communications and customer-enquiry providers;
- cloud-storage and document-management providers;
- analytics, security, anti-abuse and performance providers;
- payment, invoicing, bookkeeping and accounting providers;
- professional advisers, including solicitors, accountants, auditors, insurers and consultants;
- clients, prospective clients, collaborators or opportunity providers where relevant to a requested service, introduction, booking or engagement;
- photographers, studios, creative professionals and service suppliers involved in delivering an agreed service;
- recruitment, talent or portfolio-related counterparties where appropriate;
- regulators, law-enforcement bodies, tax authorities, courts and public authorities where required or permitted by law;
- parties involved in a legal claim, complaint, investigation or dispute;
- a prospective buyer, investor, funder, partner or successor in connection with a proposed restructuring, investment, sale, acquisition or transfer of the whole or part of our business; and
- other parties where you have authorised the disclosure or where another lawful basis applies.
Service providers acting as processors are required to process personal data only for authorised purposes, apply appropriate security and confidentiality protections, and comply with applicable data protection obligations.
Some recipients may act as independent controllers. Where they do, their own privacy information will govern their subsequent processing.
We do not sell personal data.
INTERNATIONAL TRANSFERS
Some service providers or recipients may store or process personal data outside the United Kingdom.
Where personal data is transferred to a country that is not covered by applicable UK adequacy regulations, we will use an appropriate transfer mechanism where required. This may include:
- the UK International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses;
- another legally approved transfer mechanism;
- binding corporate rules where applicable; or
- a specific statutory derogation in limited circumstances.
We may also apply supplementary contractual, organisational or technical measures where appropriate.
You may contact us for further information about the safeguards relevant to a particular transfer, subject to legitimate confidentiality and security restrictions.
DATA SECURITY
We use appropriate technical and organisational measures designed to protect personal data against:
- unauthorised or unlawful access;
- accidental loss;
- destruction;
- alteration;
- misuse;
- unauthorised disclosure; and
- other forms of unlawful processing.
Measures may include, where appropriate:
- access controls;
- authentication measures;
- secure transmission;
- restricted administrative access;
- role-based permissions;
- system monitoring;
- logging;
- backup and recovery arrangements;
- supplier due diligence;
- contractual confidentiality and data-protection requirements;
- data minimisation; and
- incident-response procedures.
No internet transmission, website or storage system can be guaranteed to be completely secure. You are responsible for using appropriate care when sending information electronically and for protecting any credentials issued to you.
Where we become aware of a personal data breach, we will assess, document and address it in accordance with applicable legal requirements. Where required, we will notify the Information Commissioner and affected individuals.
DATA RETENTION
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to meet legal, accounting, regulatory, contractual and reporting requirements.
When determining an appropriate retention period, we consider:
- the amount, nature and sensitivity of the data;
- the purpose of processing;
- whether the purpose can be achieved by other means;
- contractual requirements;
- applicable limitation periods;
- legal and regulatory obligations;
- the likelihood of a dispute or legal claim;
- security considerations; and
- the potential risk arising from unauthorised use or disclosure.
Indicative retention periods include:
12.1Enquiries that do not become active engagements
Ordinarily retained for up to 24 months after the most recent substantive communication, unless a longer period is reasonably necessary because of an ongoing relationship, dispute, legal obligation or anticipated engagement.
12.2Client, contractual and project records
Ordinarily retained for the duration of the relationship and generally for up to six years afterwards, subject to any longer period required for legal claims, tax, insurance, professional obligations or contractual rights.
12.3Accounting and transaction records
Generally retained for at least the period required by applicable tax, accounting and corporate record-keeping law.
12.4Talent, recruitment and professional profiles
Retained while the relationship or profile remains active and for a reasonable period afterwards. We may contact you periodically where appropriate to confirm whether information remains current or should be removed.
12.5Photography, portfolio and licensing records
Creative files may be retained for the period reasonably necessary to deliver the service, maintain backups, evidence permissions, administer licences and protect legal rights. Contractual, release and licensing records may be retained for longer where necessary to establish permitted use.
12.6Complaints, disputes and legal records
Retained for as long as reasonably necessary to investigate and resolve the matter and for any relevant legal limitation or enforcement period.
12.7Website and security records
Retained according to operational, security and technical requirements. Cookie-specific durations are addressed in our Cookies Policy or cookie-preference interface.
12.8Marketing information
Retained until you withdraw consent or object, subject to keeping limited suppression information so that we do not send marketing contrary to your preference.
At the end of the applicable period, personal data will be securely deleted, anonymised or retained in a restricted form where continued retention is legally justified.
COOKIES AND SIMILAR TECHNOLOGIES
Our website may use cookies, local storage, pixels, tags and similar storage or access technologies.
Strictly necessary technologies may be used where required to provide a service requested by you, operate security controls or maintain essential website functionality.
Non-essential technologies will be used only in accordance with applicable law and the choices made through our cookie controls.
Please read our Cookies Policy for further information about:
- the categories of technologies used;
- their purposes;
- whether consent is required;
- how long they operate; and
- how you can change or withdraw your choices.
YOUR DATA PROTECTION RIGHTS
Subject to applicable legal conditions, restrictions and exemptions, you may have the following rights.
14.1Right of access
You may request confirmation that we process your personal data and obtain a copy of that data together with related information.
14.2Right to rectification
You may request correction of inaccurate personal data and completion of incomplete data.
14.3Right to erasure
You may request deletion of personal data in circumstances provided by law. This right is not absolute, and we may retain information where a lawful reason applies.
14.4Right to restriction
You may request restriction of processing in circumstances provided by law.
14.5Right to data portability
Where processing is based on consent or contract and is carried out by automated means, you may have the right to receive personal data you provided in a structured, commonly used and machine-readable format and, where technically feasible, transmit it to another controller.
14.6Right to object
You may object to processing based on legitimate interests or public-task grounds.
Where you object, we will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for legal claims.
You have an unconditional right to object to processing for direct-marketing purposes.
14.7Right to withdraw consent
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
14.8Rights relating to automated decision-making
You may have rights relating to significant decisions based solely on automated processing.
Unless we tell you otherwise in a specific context, we do not use solely automated decision-making that produces legal effects concerning you or similarly significantly affects you.
14.9Right to complain directly to us
You have the right to make a data protection complaint directly to Stratosphere Ventures Limited if you consider that our processing of your personal data infringes applicable data protection law.
Our complaints procedure is explained in section 16.
EXERCISING YOUR RIGHTS
To exercise a data protection right, contact:
Please provide sufficient information to identify:
- who you are;
- the right you wish to exercise;
- the personal data or processing concerned; and
- any relevant dates, communications, projects or reference information.
We may request reasonable proof of identity or authority where necessary to protect personal data from unauthorised disclosure. We will not request more information than is reasonably necessary.
You will not ordinarily be required to pay a fee. A fee may apply, or we may decline to act, only where permitted by law, including where a request is manifestly unfounded or excessive.
We will respond within the period required by applicable law. Where a lawful extension applies because of complexity or the number of requests, we will inform you.
Some rights are subject to legal restrictions and exemptions. Where we cannot comply fully, we will explain our decision unless the law prevents us from doing so.
DATA PROTECTION COMPLAINTS PROCEDURE
You may complain directly to us about any concern relating to our collection, use, disclosure, retention, security or other processing of your personal data.
Please send the complaint to:
Your complaint should, where possible, include:
- your name and contact details;
- a clear description of the concern;
- the personal data or processing involved;
- relevant dates;
- copies of relevant communications or documents; and
- the outcome you are seeking.
We will:
- provide an accessible means of making a complaint;
- acknowledge receipt within 30 days;
- take appropriate steps to investigate the complaint;
- keep you appropriately informed where the investigation is ongoing;
- respond without undue delay;
- communicate the outcome of our investigation; and
- explain any action taken or proposed where appropriate.
We may contact you for additional information where reasonably necessary to investigate the complaint.
You are not required to complete our internal complaints process before contacting the Information Commissioner, although the Information Commissioner may expect you to raise the matter with us first where appropriate.
COMPLAINTS TO THE INFORMATION COMMISSIONER
You may make a complaint to the Information Commissioner’s Office, the UK supervisory authority for data protection.
Information is available through the ICO’s official website.
The ICO can also be contacted at:
Telephone: 0303 123 1113
We would appreciate the opportunity to address your concern directly, but this does not affect your right to contact the ICO.
DIRECT MARKETING
We may send marketing or business-development communications where permitted by law.
The lawful basis and consent requirements may depend on:
- whether the recipient is an individual or a corporate subscriber;
- whether there is an existing customer relationship;
- the communication channel;
- how the contact details were obtained; and
- applicable electronic-marketing rules.
Every electronic marketing communication will provide an appropriate means of opting out where required.
You may stop direct marketing at any time by:
- using the unsubscribe or opt-out method provided;
- contacting stratosphereventure@gmail.com; or
- objecting to direct marketing under section 14.
Opting out of marketing will not prevent us from sending necessary administrative, contractual, transactional, security or service communications.
CHILDREN’S PERSONAL DATA
Our general website is intended for business and professional audiences and is not designed specifically for children.
We may process personal data relating to a person under 18 only where relevant to a legitimate service, opportunity, creative project or safeguarding matter and where appropriate legal, contractual and parental or guardian arrangements are in place.
Where a service involves a child, we may require:
- involvement or authorisation from a person with parental responsibility;
- age verification;
- appropriate consent, contract or another lawful basis;
- safeguarding controls;
- limits on publication or disclosure; and
- service-specific terms or privacy information.
A child or parent or guardian may contact us using the details in section 2 regarding relevant personal data.
THIRD-PARTY WEBSITES AND SERVICES
Our website may contain links to third-party websites, platforms or services.
Those third parties may act as independent controllers and apply their own privacy policies. We do not control their processing and are not responsible for the privacy, security or content of an independent third-party service.
You should review the relevant third party’s privacy information before supplying personal data.
ACTING AS A PROCESSOR
In some engagements, we may process personal data solely on a client’s documented instructions.
Where we act as a processor:
- the client will ordinarily be the controller;
- the client’s privacy information will govern its processing purposes;
- we will process the data in accordance with the applicable contract and data-processing terms; and
- requests relating to that data may need to be referred to the relevant controller.
Nothing in this section changes our status as controller for personal data that we process for our own administration, legal compliance, security, billing, business management or independent purposes.
CHANGES TO PURPOSE
We will use personal data for the purpose for which it was collected unless we reasonably determine that another purpose is compatible with the original purpose and lawful.
Where we need to use personal data for a materially different or incompatible purpose, we will identify an appropriate lawful basis and provide additional privacy information where required.
CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy where necessary to reflect:
- legal or regulatory changes;
- changes to our services;
- changes to website functionality;
- changes to suppliers or processing activities;
- improvements to our privacy practices; or
- changes required for clarity or accuracy.
The current version will be published on our website with its effective date.
Where a change materially affects how we process existing personal data, we will take reasonable steps to bring the change to the attention of affected individuals where required.
CONTACT US
Questions, requests or complaints concerning this Privacy Policy or our use of personal data should be sent to: