Where data sits, and how long it stays
Effective date: 18 September 2026
Contact: productions@lowlightking.com
This is the schedule. It covers everything we hold, from a form submission to a shoot's camera originals, and it is the document the privacy notice and the Terms both point at rather than restating retention in three places and disagreeing.
1) The principle
We keep personal data for as long as the purpose it was collected for requires, and no longer, unless a law requires us to keep it. Where a period is set below, that period is what happens. Where the row states a purpose instead of a period, the data is deleted when that purpose ends — we would rather publish that than publish a number nobody has actually set.
2) The schedule
| What | Where | How long | Why |
|---|---|---|---|
| Audit requests — name, work email and company, submitted through the HubSpot form, under the consent wording that form presents | HubSpot's records, and the mailbox the request is answered from | While the request is open and for as long as the engagement it leads to runs. Deleted on request, and when neither is live any longer. | Your consent, and our interest in answering the request you made |
| Enquiries made by email or telephone — whatever you choose to send us | The mailbox the enquiry is answered from | While the enquiry is open and for as long as the engagement it leads to runs. Deleted on request, and when neither is live any longer. | Our interest in answering the enquiry you made |
| Raw footage — camera and audio originals, logs and proxies | Cloudflare R2 and production drives | 6 months from final delivery, then deleted | Delivering the project, and re-cuts within those 6 months |
| Masters and delivered files | Cloudflare R2 | 90 days from final delivery, then deleted. Deleted sooner if the client asks. Keep your own copy: after 90 days we cannot re-supply one. | Re-supplying a client who has lost their copy |
| Working files — timelines, project files, grades, audio sessions | Production drives | 6 months from final delivery, with the raw footage | Delivering the project, and re-cuts within those 6 months |
| Talent, crew and location releases, and the consent records behind them | Document storage | For as long as the footage they permit is in use, and for three years after that so the permission can still be evidenced | Legal obligation, and defending a claim about how footage was used |
| Crew and contractor KYC — identity documents, tax and bank details | Document storage, and our accounting records | Eight financial years, with the books they belong to | Companies Act 2013, section 128(5), and tax law |
| Contracts, statements of work, invoices and payment records | Accounting records and document storage | Eight financial years from the end of the financial year | Companies Act 2013, section 128(5), and tax law |
| On-set safety records, call sheets and visitor registers | Production files | Twelve months from the shoot | Safety records, and defending a claim arising from a shoot |
| Correspondence — email and messages about a project | Microsoft 365 | For as long as the engagement runs and while a claim arising from it could still be brought | Performing the contract, and defending a claim |
| Website traffic measurement — the count of pages served | Cloudflare Web Analytics | Cloudflare holds it in aggregate. Nothing identifying a visitor is stored, and nothing is written to your browser. | Our interest in knowing which pages are read |
| Website product analytics — pages read, the order they were read in, what was clicked, a masked screen recording of the visit, script errors, and anything written into a chat window or survey, against a browser identifier PostHog sets | PostHog | For as long as we are using it to decide what this site should say, and for as long as PostHog's own retention holds it. No period is published here that nobody has confirmed. Sending Do Not Track stops it being collected at all. | Our interest in knowing which pages are read and which are not |
3) Raw footage and masters, specifically
These are two different windows and it matters which one you need.
Masters and delivered files: 90 days. The finished files are delivered to you, so the copy that matters is already yours. What we keep for 90 days is a safety net: if you lose your copy inside that window, ask and we will send it again. After 90 days we no longer hold it. A client who wants them deleted sooner only has to say so, and we will confirm the deletion in writing.
Raw footage and working files: 6 months. Camera and audio originals, logs, proxies, timelines, grades and audio sessions are held twice as long, because they are what a re-cut is made from and a delivered master cannot be re-cut. A new version, a different length or a new platform variant is possible inside those six months and impossible after them.
Keep your own copy. Ninety days after final delivery we may no longer hold your finished files, and six months after it we hold nothing from the project at all — at which point a new version means shooting again. Clause 9.1 of the Terms has always put the obligation to download and back up on the client; these windows are what that obligation costs if it is not met. Extended archival can be bought, and has to be agreed in the statement of work before the window in question runs out.
This replaces the 30–90 day archive window the Terms published before 11 September 2026. Where an older statement of work states a different period, that signed document governs for that project.
4) Where the data physically sits
Production media and deliverables are stored with Cloudflare. Correspondence and documents sit in Microsoft 365. An audit request made through the form on this site sits in HubSpot's records; an enquiry made by email or telephone sits in the mailbox it is answered from, and nowhere else. Each of these is outside India, and the transfer position is set out in the privacy notice and, for client data we process on instruction, in the data processing agreement.
We name a CRM in the list below as a processor because one is intended and is named before it carries anything, which is what the “not yet carrying data” marker means. Until then nothing is in it. An earlier version of this page said enquiries went to a CRM, and that was never true.
| Processor | What it holds | Where |
|---|---|---|
| Cloudflare, Inc. | Request metadata, IP address in transit, stored production media and client deliverables. | United States, with a global edge network |
| Microsoft Corporation | Correspondence and stored documents. | United States and its regional data centres |
| Vidyard | Viewer IP address, device and browser, and which parts of a video were watched. | Canada and the United States |
| HubSpot, Inc. | Name, work email address, company, anything written in the form, and the browser identifier HubSpot sets to recognise a returning visitor. | European Union (the eu1 data centre), and the United States |
| PostHog, Inc. | Pages viewed, referrer, the text and position of what is clicked, device and browser, IP address, the browser identifier PostHog sets to recognise a returning visitor, a screen recording of the visit with every form field masked, script errors, and anything written into a chat window or survey. | European Union (PostHog's EU cloud), and the United States where PostHog operates from |
| Vimeo, Inc. — not yet carrying data | Viewer IP address, device and browser, once a player is pressed. | United States |
| Freshworks (Freshsales) — not yet carrying data | Name, work email address, company, the message written in the form, and the consent record. | United States and India |
5) Backups
Deleting something removes it from the live systems above. Where a copy persists in a backup, it is deleted on that backup's own cycle rather than immediately, and it is not used for anything in the meantime — not for a re-supply, not for a re-cut, not to answer a question about what a file used to say. A backup exists to restore a system after a failure and for nothing else.
We have not set a fixed maximum for how long a backup copy can survive a deletion. Publishing a number nobody has confirmed would be inventing a fact, and this page's whole value is that it does not. Ask and we will tell you the current cycle for the system your data is in.
6) Asking us to delete something
Write to us and say what you want deleted. We will tell you what we hold, what we can delete, and what we are required to keep and for how long — accounting records and signed releases are the usual cases where the answer is that we cannot. We answer within 30 days, and we will confirm a deletion in writing if you ask for the confirmation. Your rights, and how to escalate if you are not satisfied, are in the privacy notice.
The other documents
This is one of nine. The index lists them all and says what each one decides.