Privacy Notice

Version

1.1

Effective date

October 2026

Classification

PUBLIC

Document owner

Company Management

Review

September 2027

ICO registration

ZB441034

Company number

13521468

Contact

team@ki-sl.co.uk

 

KI Sound & Light Ltd respects your privacy and is committed to protecting personal information. This notice explains how we collect, use, store, share and protect personal information and how individuals can exercise their rights under UK data protection law.

1. Who we are

KI Sound & Light Ltd is the data controller responsible for deciding how and why personal information is processed.

Controller

KI Sound & Light Ltd

Company number

13521468

Address

46 East St, Braintree, CM7 3JJ, United Kingdom

Email

team@ki-sl.co.uk

Website

www.ki-sl.co.uk

ICO registration

ZB441034

Data protection responsibility

Company Management

2. Who this notice applies to

This notice applies to personal information relating to:

  • customers and prospective customers;
  • employees and representatives of business customers;
  • suppliers and their representatives;
  • freelancers and independent contractors;
  • job applicants, successful and unsuccessful candidates, and referees;
  • venue, site and production contacts;
  • event organisers and people making enquiries;
  • visitors to our premises;
  • people recorded by CCTV or vehicle dashcams;
  • people appearing in photographs or video connected with our work; and
  • website visitors.

KI Sound & Light also processes personal information about employees, workers, former employees and workers, and job applicants. Applicants should read our Recruitment Privacy Notice for detailed information about recruitment processing. Employees and workers should read the Workforce Privacy Notice, which is made available through the Staff Handbook and, once introduced, through Breathe. These more specific notices explain the relevant processing, lawful bases, recipients, retention periods and safeguards and should be read alongside this general Privacy Notice.

3. Personal information we collect

3.1 Identity and contact information

  • name
  • company or organisation
  • job title or role
  • postal, billing or delivery address
  • email address
  • telephone or mobile number

3.2 Enquiries, quotations and bookings

  • enquiries, quotations and proposals
  • bookings, hire agreements and contracts
  • equipment and services provided
  • event dates and locations
  • delivery and collection arrangements
  • venue and site contacts
  • purchase orders and customer notes
  • equipment returns, damage or loss
  • complaints, previous transactions and booking correspondence

3.3 Identity verification

  • photographic identification such as a driving licence or passport where reasonably necessary
  • utility bill or similar proof of address
  • a record that an appropriate identity check was completed

3.4 Financial and accounting information

  • billing and invoice information
  • payment records, account balances and purchase orders
  • transaction and payment-status information
  • bank details where necessary to make a refund

3.5 Suppliers, freelancers and contractors

  • identity and contact details
  • bank/payment and tax/UTR information where applicable
  • qualifications, competency information, certificates and insurance
  • emergency contacts where collected
  • information necessary to engage or manage the person for a project

3.6 Recruitment information

When recruiting, we process information needed to assess applications and meet recruitment-related legal obligations. Applicants should read our Recruitment Privacy Notice for details of the information collected, sources, lawful bases, recipients, retention and safeguards.

3.7 Health information

In limited circumstances we may process health information relating to employees, workers, freelancers or contractors where it is genuinely relevant to health and safety, sickness administration or appropriate work arrangements. This may include an allergy or other information needed to make safe arrangements. Health information is special category personal data and receives additional protection.

For employees and workers, where the information is necessary to meet employment, social protection or health and safety obligations, we normally rely on Article 6(1)(c) UK GDPR together with Article 9(2)(b) and Schedule 1 Part 1 paragraph 1 of the Data Protection Act 2018. KI maintains an Appropriate Policy Document for this processing. For genuinely independent freelancers or contractors where that employment condition does not apply, we will only collect health information where an appropriate Article 6 basis and Article 9 condition have been identified; this may include explicit consent where it is appropriate and freely given.

3.8 Communications

Business communications may take place through Microsoft 365 email, Microsoft Teams, telephone, OnRent Events (formerly Current RMS) and other approved company systems. Substantive business records should be retained in approved systems. WhatsApp is not an approved permanent business-record system; if material business information is received through WhatsApp, staff must transfer it into an approved company system where appropriate.

3.9 Website, cookies and analytics

Our website is built using WordPress and hosted by IONOS. Technical information may include IP address, browser/device information, pages visited, dates and times, referring source, approximate network-derived location, cookie identifiers and server/security logs. We use Google Analytics only in accordance with our cookie-consent configuration. Further detail is in our Cookie & Similar Technologies Policy.

3.10 Marketing information

Where we conduct email marketing, we may process name, company, email address, customer status, marketing preference, source/date of consent or other preference, unsubscribe information and campaign-delivery information. Brevo is configured to provide anonymous campaign-level open/click statistics. Individual-level open/click tracking is not part of KI’s standard marketing process and is only permitted where separate per-contact tracking consent has been recorded. We use Brevo for email marketing and may record preferences in OnRent Events.

3.11 Photography and video

We may take photographs or video to evidence completed work and maintain project records. A project image retained as operational evidence is assessed separately before it is selected for portfolio, website or social-media marketing. Identifiable people are generally incidental to images of equipment, installations or events. Where photography forms part of a customer-organised event, responsibility for attendee notices or consents may rest with the event organiser where the organiser determines the purposes and means of that photography. Where KI independently decides to capture or publish identifiable images for its own purposes, KI remains responsible for the lawfulness of that use.

3.12 CCTV

We operate CCTV inside and outside our warehouse for security, crime prevention/detection, incident investigation and protection of people and property. CCTV does not record audio. Recordings are stored locally and access is restricted to Company Management.

3.13 Vehicle dashcams

Company vehicles may have outward-facing dashcams. They do not record audio or routine GPS location. Footage is stored on local SD cards and is used for road safety, collision/incident investigation, insurance and legal claims.

3.14 Security, access and audit information

To protect our systems and information we may process security and audit data such as Microsoft 365/Entra sign-in and audit logs, device-management information, authentication/MFA records, access logs, security alerts, investigation notes and information relating to suspected security incidents or personal data breaches. We use this information to secure systems, investigate incidents, demonstrate accountability and meet legal obligations.

4. How we obtain personal information

We normally obtain information directly from the person concerned, for example through an enquiry, quotation, booking, hire, payment, supplier relationship or other communication. We may also obtain relevant information from customers, venues, event organisers, employers, production companies, suppliers and other people involved in a project.

Where information is obtained from venues, event organisers, employers, customers or publicly available business directories/search results, we only process information relevant to the service being provided or the legitimate purpose for which it was obtained. We do not routinely collect public contact details for unsolicited marketing.

5. How and why we use personal information

We identify a lawful basis for each purpose. Where we rely on legitimate interests, we assess the purpose and necessity of the processing and balance our interests against the rights, freedoms and reasonable expectations of the individuals concerned. We document material assessments and keep them under review.

Activity

Purpose

Lawful basis

Enquiries and quotations

Responding to enquiries; preparing quotations; proposed bookings

Article 6(1)(b) steps before contract where applicable; Article 6(1)(f) legitimate interests for business contacts

Bookings and service delivery

Managing hires, events, deliveries, returns and customer service

Article 6(1)(b) contract; Article 6(1)(f) legitimate interests

Identity verification

Fraud/theft prevention; protection of valuable equipment

Article 6(1)(f) legitimate interests

Accounting and debt recovery

Invoices, payments, refunds, tax/accounting and recovery of sums owed

Article 6(1)(b), 6(1)(c) and/or 6(1)(f)

Suppliers/freelancers

Engagement, project administration, competency and payments

Article 6(1)(b), 6(1)(c) and/or 6(1)(f)

Employee/worker health data

Sickness, health and safety, statutory employment obligations

Article 6(1)(c); Article 9(2)(b); DPA 2018 Schedule 1 Part 1 paragraph 1

Independent contractor health data

Safe project arrangements where genuinely necessary

Appropriate Article 6 basis plus Article 9 condition identified before processing; explicit consent may be used where appropriate

Direct marketing

Relevant newsletters/services/offers

Article 6(1)(a) consent and/or 6(1)(f) where lawful; PECR applies

Website analytics

Understanding and improving website use

Article 6(1)(a) consent where Google Analytics is used

Security/audit logging

Cybersecurity, access control, investigations and breach management

Article 6(1)(f) legitimate interests and/or 6(1)(c) legal obligation

CCTV/dashcams

Security, safety, incident investigation and legal/insurance claims

Article 6(1)(f) legitimate interests

Photography/video

Evidence of work, portfolio and marketing

Article 6(1)(f) legitimate interests where proportionate; consent where more appropriate

6. Direct marketing

We may send marketing about equipment hire, production services, company news and relevant offers. Email marketing is managed using Brevo.

For individuals, sole traders and other individual subscribers, unsolicited email marketing is sent only where valid consent exists or the PECR soft opt-in requirements are met. For corporate subscribers, different PECR rules apply; where an identifiable business contact is involved, UK GDPR still applies and KI relies on a documented legitimate-interests assessment where appropriate.

Public availability of an email address does not itself amount to marketing consent. Every marketing email provides a straightforward way to unsubscribe. We retain the minimum information necessary to honour opt-outs on a suppression list.

7. Cookies and similar technologies

Our website uses cookies and similar storage/access technologies. We use Complianz as our consent-management plugin. Where consent is required, non-essential technologies including Google Analytics are blocked until the visitor makes an appropriate choice. Visitors can reject optional technologies and can later change or withdraw their preferences.

See our separate Cookie & Similar Technologies Policy for the current categories, purposes, durations and consent controls.

8. Systems and storage

System/provider

Use

OnRent Events

Rental/customer management. KI is controller for information KI enters; OnRent Events / inspHire Limited acts as processor. OnRent Events uses AWS and published information states hosting in the United States; support personnel may access data when authorised.

Microsoft 365

Email, Teams, SharePoint/OneDrive and associated productivity/security services. Relevant tenant data locations are configured for the UK, with international support/subprocessing possible under Microsoft contractual arrangements.

Local company storage

Project and operational files. Personal data is limited where practicable; temporary local downloads must be deleted when no longer needed.

Sage Business Cloud Accounting

Accounting and financial administration; OnRent Events may transfer invoice/contact data to Sage.

Square / Sage payment services

Card payment processing. KI does not normally retain complete payment-card details.

Brevo

Email newsletter/marketing management.

WordPress / IONOS

Website platform and hosting.

Google Analytics

Website analytics, subject to cookie consent.

9. Who we share information with

We do not sell personal information. Where necessary and proportionate, information may be shared with:

  • technology and cloud service providers acting for us;
  • payment and accounting providers;
  • transport providers such as One Step Beyond, Atlas Couriers and SVL Trucking where contact/location data is needed for a delivery or collection;
  • freelancers/subcontractors, venues, event organisers and other production companies where operationally necessary;
  • our accountants, HR consultants, insurers, solicitors and other professional advisers; and
  • courts, regulators, HMRC, law-enforcement or other authorities where required or lawful.

10. International transfers

Some providers operate internationally. Where personal information is transferred outside the UK in a way that is restricted by UK data protection law, we use or require an appropriate transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to Standard Contractual Clauses, or another recognised safeguard. OnRent Events publishes that its hosting takes place in the United States. Google Analytics, Square and other providers may also involve international processing.

11. How long we keep personal information

Record

Normal retention

Customer/bookings/hire records

6 years after last transaction or end of customer relationship, longer where a specific dispute/legal/insurance reason applies.

Unsuccessful enquiries/quotes

Up to 2 years after last meaningful contact.

Business email

Retained according to content and business purpose. Contractual/customer/project, financial, workforce, incident, rights-request and other formal records follow the applicable category period; transitory email is deleted when no longer needed. Microsoft 365 retention controls are to support these content-based rules.

Accounting records

Normally 6 years from the end of the relevant accounting period/financial year, or longer where an applicable statutory, HMRC enquiry or other documented requirement applies.

Project personal data

Normally 6 years after last relevant job/customer relationship.

ID/proof of address

Underlying documents only while genuinely needed; normally delete after successful hire, return and settlement. Keep a check record where appropriate.

Supplier/freelancer contractual records

Normally 6 years after last transaction/engagement.

Health data

Only as long as necessary for the engagement, health/safety/employment purpose or legal requirement.

Recruitment

See the Recruitment Privacy Notice. Unsuccessful selection records are normally retained for 12 months; records may be preserved longer while a complaint, claim or investigation remains active.

Marketing

While subscribed; suppression data retained as necessary to honour opt-out.

CCTV

Normally 30 days with automatic overwrite; incident footage may be retained longer for an active investigation, insurance matter or legal claim.

Dashcams

Ordinary footage overwritten automatically; incident footage retained as necessary.

Security/audit logs

According to the verified configuration and security need for each system, recorded in KI’s internal System Security Log Register; incident/breach records may be retained longer for accountability or legal purposes.

Photography/video

Project-evidence imagery is retained while reasonably necessary for the project/evidence purpose. Images selected for public portfolio/marketing use are separately assessed and their continued identifiable use is periodically reviewed.

12. Data security

We use proportionate technical and organisational measures including individual user accounts, MFA, password-protected systems, encryption where appropriate, role-based and need-to-know access, restricted management SharePoint areas, Microsoft 365 security controls, audit logging, secure local storage, leaver access-removal controls, incident response, secure deletion/shredding and controlled access to special category data. Privileged access is restricted to authorised Company Management. Our approved access-control procedure requires access permissions to be reviewed at least quarterly and when responsibilities change. We review third-party providers proportionately and maintain internal processor/third-party assurance records.

13. Your rights

  • to be informed about processing;
  • to request access to personal information;
  • to request correction of inaccurate/incomplete information;
  • to request erasure in certain circumstances;
  • to request restriction in certain circumstances;
  • to data portability where applicable;
  • to object to processing based on legitimate interests;
  • to object to direct marketing at any time;
  • to withdraw consent where consent is relied upon; and
  • rights relating to certain solely automated decisions; and
  • to make a data protection complaint directly to KI.

To exercise a right, contact team@ki-sl.co.uk. We may verify identity and will respond within the period required by law. KI does not currently make solely automated decisions that produce legal or similarly significant effects.

14. Data protection complaints

Complaints should be sent to Company Management at team@ki-sl.co.uk or 46 East St, Braintree, CM7 3JJ, United Kingdom. In accordance with the Data (Use and Access) Act 2025, we will acknowledge receipt of a data protection complaint within 30 days of receiving it. Without undue delay, we will log the complaint, make appropriate enquiries, take appropriate steps to respond, preserve relevant records while the complaint is active, and keep the complainant informed about progress. We will inform the complainant of the outcome without undue delay, including any corrective action or lessons learned where appropriate.

You also have the right to complain to the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; telephone 0303 123 1113; www.ico.org.uk.

15. Children

Our products and services are not directed towards children and we do not knowingly contract directly with people under 18. Children may incidentally appear in event photography; where this occurs we consider the event context and any additional protections or permissions that may be appropriate.

16. Changes to this notice

We review this notice at least annually and when there is a material change to our processing, systems, service providers, retention practices or legal requirements. The current version will be published on our website.