Privacy Policy

Last updated: September 2026

This notice explains how LEX Liverpool ("we", "us", "our") collects, uses and protects personal data through the Production Management System ("PMS", "the system") — an internal tool used by our staff to manage production budgets, scheduling and CurrentRMS reporting. It is written to meet our obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

LEX Liverpool is the data controller for personal data processed through PMS. For any question about this notice or how your data is handled, contact our data protection point of contact:

dpo@lexliverpool.com

2. What data we process

PMS handles two broad categories of personal data:

  • Staff account data — name, work email address, role/permissions, login activity, and any profile details you add (e.g. an avatar). This is used to operate and secure the system itself.
  • Business data sourced from CurrentRMS — names, contact details, and transaction/financial information relating to customers, venues and suppliers, pulled into PMS for budgeting, scheduling and reporting purposes. This data originates in CurrentRMS, where LEX Liverpool is also the controller.

3. Why we process it, and our lawful basis

  • Legitimate interests — running internal business systems, producing management reports and budgets, and keeping records secure. We consider this necessary for day-to-day operations and not overridden by staff or customer interests.
  • Contractual necessity — staff accounts are provisioned as part of your employment, to give you the access your role requires.
  • Legal obligation — some records (e.g. financial data) are retained to meet accounting and tax obligations.

4. Who has access

Access is restricted to authorised LEX Liverpool staff, scoped by role (Admin, Manager, Viewer). Data also passes through the following processors on our behalf:

  • CurrentRMS — the source system for customer, opportunity and invoice data.
  • Our hosting provider — runs the application and database infrastructure that PMS relies on.

We do not sell personal data, and we do not share it with third parties beyond the processors above except where required by law.

5. International transfers

Where any of the processors above store or process data outside the UK, we rely on appropriate safeguards (such as Standard Contractual Clauses or an adequacy decision) to ensure your data receives an equivalent level of protection.

6. How long we keep data

We keep personal data only for as long as necessary for the purposes described above, including to meet legal, accounting or reporting requirements. Staff account access is removed when employment ends; underlying records may be retained for a limited period afterwards where we have a legal or operational reason to do so.

7. Your rights

Under UK GDPR, you have the right to:

  • Request access to the personal data we hold about you
  • Ask us to correct inaccurate data
  • Ask us to erase your data, where applicable
  • Restrict or object to certain processing
  • Request a portable copy of data you provided to us

To exercise any of these rights, contact dpo@lexliverpool.com. If you're not satisfied with our response, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

8. How we protect your data

Passwords are stored using industry-standard hashing (bcrypt), sessions are hardened against common web attacks, all forms are protected against cross-site request forgery, and access is controlled by role-based permissions. Access is also logged for security review.

9. Changes to this notice

We may update this notice from time to time. The "last updated" date at the top reflects the most recent revision.

10. Contact

Questions about this notice or your data can be sent to dpo@lexliverpool.com.

← Back to login