How we handle your data
Effective date: 18 September 2026
First published: 23 February 2023
Contact (Privacy & Legal): productions@lowlightking.com
This Privacy Policy explains how LowLightKing Productions Pvt Ltd (“LowLightKing”, “we”, “us”) collects, uses, discloses, stores, transfers and protects personal data when you interact with our websites, client services, productions, locations, communications and related platforms (collectively, the “Services”). It is written to the Digital Personal Data Protection Act 2023 and the Digital Personal Data Protection Rules 2025 in India, and, where they apply to us, to the GDPR, the UK GDPR, the twenty US state privacy laws now in force, and the transparency duties of the EU Artificial Intelligence Act.
DPDPA Section 9 — verifiable parental consent: we do not process the personal data of anyone under 18 without verifiable consent from a parent or lawful guardian. On-set involvement of a minor requires a signed parental or guardian release before filming, and we do not track, behaviourally monitor or target advertising at children.
1) Who we are
LowLightKing is a video production company providing creative development, pre-production, production, post-production, distribution support and related services. Depending on the engagement we act as a data fiduciary / controller (we decide why and how data is processed) or as a data processor / service provider (we process data on a client's instruction). Where we act as a processor, the data processing agreement governs, together with the client's own instructions, and it prevails over this Policy on anything to do with that client's data.
LowLightKing Productions Pvt Ltd, CIN U92490KL2022PTC074053, GSTIN 32AAECL9221H1ZP. Registered office: 43/2153, E1, Jewel Homes, WhiteField, A-Block, SRM Road, Kaloor, Kochi, Kerala – 682018, India.
Where the DPDP Act has reached. The Digital Personal Data Protection Rules 2025 were notified on 13 November 2025 and commence in stages: the Data Protection Board on notification, Consent Manager registration at twelve months, and the substantive Data Fiduciary duties at eighteen months. Several of those duties are therefore not yet in force. We do not wait for them — the itemised notice in Section 4, the retention schedule in Section 13, the breach route in Section 15 and the grievance mechanism in Section 21 are all in operation now. Where we describe something as a legal requirement we mean one that binds us today, and where we have gone ahead of the schedule this Policy says so rather than implying the Act already compels it.
We are not a Significant Data Fiduciary. The Central Government has not notified us as one, and we do not meet the volume or sensitivity profile the classification is aimed at. If that changes, the additional duties — a Data Protection Officer based in India, an annual data protection impact assessment, an independent audit and an algorithmic due-diligence obligation — attach to us and this Policy will say so before they do.
2) Scope
This Policy applies to personal data collected from:
- Website visitors, leads, prospects and social media visitors
- Clients, client representatives and brand partners
- Talent (actors, models, voice artists), crew, contractors, suppliers
- Location owners and representatives, and on-site visitors
- Job applicants and interns
- Anyone appearing in production footage (see Section 9)
Not covered: your purely personal or household use, and third-party sites and platforms you use independently of us.
3) Definitions
- “Personal data” means information that identifies or can reasonably identify an individual, directly or indirectly.
- “Sensitive personal data” includes government identifiers, biometrics, financial and bank details, health information and precise location, where regulated as such — including under Rule 3 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, which remain in force until they are repealed on the DPDP Act's own schedule.
- “Processing” includes collection, recording, storage, use, disclosure, transfer and deletion.
4) What we collect
On this website. This site operates no form of its own. The Video Strategy Audit is requested through a HubSpot form embedded on the page, which collects a name, a work email address and a company name into HubSpot's records, under the consent wording that form presents, and as described in the cookie notice and in Section 7 below. Everything else reaches us as an email or a phone call, and we hold what you send.
The consent wording we use when we ask to store your details and contact you about an enquiry is:
I agree that LowLightKing Productions Pvt Ltd may store these details and contact me about this enquiry. They are not sold or passed to anyone else.
That sentence is the consent notice, and where it is given it is the record we keep of what was agreed to, together with the moment it was agreed. It is never pre-checked. You can withdraw it at any time by writing to productions@lowlightking.com; withdrawing is as easy as giving it was, and it does not affect anything done before you withdrew.
Across the business more broadly, depending on the engagement, we also collect the categories below. Each is listed against the specific purpose it is collected for, because a list of data beside a separate list of purposes does not tell you which is held for which — and an itemised notice is what Section 5 of the DPDP Act and Rule 3 of the DPDP Rules 2025 ask for.
| What we collect | The specific purpose it is collected for |
|---|---|
| Identity and contact — name, email, phone, company, role, addresses | Answering your enquiry, quoting for a project, administering the account, and reaching you about a shoot |
| Commercial and project — briefs, scripts, decks, references, budgets, invoices, purchase orders | Scoping, quoting, producing and invoicing the project, and keeping the accounting record the law requires |
| Talent and crew administration — CVs, portfolios, headshots, measurements, scheduling availability | Casting a role, booking a crew position, and building a schedule that works |
| Compliance and KYC, when required — passport or visa, national identifier, tax details, bank details, invoicing details | Paying a contractor, deducting tax at source, and meeting the identity and record-keeping duties that come with doing so |
| On-set safety and logistics — emergency contact, dietary needs, and medical considerations relevant to safety | Keeping people safe on a set, and only where necessary and proportionate to that |
| Communications — messages, and recordings of calls or meetings where lawful and with notice | Running the engagement, recording what was agreed, and evidencing an approval |
| Device and usage — IP address, device type, browser, pages viewed, referrals, timestamps, approximate location | Serving and securing this website. What reaches us is described in the cookie notice; we set no identifier of our own |
| Footage and audio — raw and edited recordings, which may include faces and voices | Producing, editing and delivering the project, and a re-cut inside the window in Section 13 |
| Still images — production stills and behind-the-scenes captures | Delivering the project, and portfolio use only on the terms in Section 10 |
| Location and access logs — access logs, visitor registers, call sheets, equipment checkout logs | Controlling access to a set, accounting for equipment, and answering a claim arising from a shoot |
| Security — CCTV at controlled premises where notice is posted and it is legally permitted | Safety and incident investigation at that location, and nothing else |
We do not collect any of this speculatively. A category appears on a project because that project needs it, and the ones that do not apply are not collected at all.
5) Why we process personal data
The table in Section 4 states the specific purpose for each category. Grouped, those purposes are:
- Delivering the Services: planning, shooting, editing, grading, delivery, project management
- Client management: quotations, proposals, invoicing, payments, account administration
- Production operations: casting, crew hiring, schedules, permits, logistics, safety
- Quality, security and fraud prevention: access control, incident detection, abuse prevention
- Legal and compliance: tax, accounting, audits, lawful requests, dispute handling
- Marketing and growth: portfolio, case studies, announcements, enquiries
- Maintaining this website: performance monitoring, cookieless traffic measurement, and product analytics that records which pages are read, what is clicked on them, a masked screen recording of the visit, and script errors
6) Lawful bases for processing
Under the DPDP Act we rely on your consent, or on a legitimate use the Act recognises — principally that you gave us the data voluntarily for a purpose you have not objected to, and compliance with a legal obligation. Where the GDPR or the UK GDPR applies to a piece of processing, the basis is one of:
- Consent — marketing, certain recordings, certain talent usage
- Contract — performing a production agreement or taking pre-contract steps
- Legal obligation — tax, labour, accounting, lawful government requests
- Legitimate interests — security, preventing misuse, running the business, balanced against your rights
- Vital interests — rare, and confined to a safety emergency on set
7) How we disclose personal data, and to whom
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose it to:
- Clients, as required to deliver the project
- Processors — the named list below
- Production partners — crew, studios, equipment rental houses, casting agencies, location managers, couriers
- Professional advisers — lawyers, accountants, auditors, insurers
- Authorities, where required by law or court order, or to protect rights or safety
These are the processors that hold personal data on our behalf:
| Processor | What it does | Where |
|---|---|---|
| Cloudflare, Inc. | Website hosting and delivery, storage of production masters and deliverables, and cookieless traffic measurement. | United States, with a global edge network |
| Microsoft Corporation | Business email and document storage. | United States and its regional data centres |
| Vidyard | Hosting for the audit video we make for you, and the viewer-level view data shown back to you on the audit call. It is not embedded on this website. | Canada and the United States |
| HubSpot, Inc. | The form used across the site to request the Video Strategy Audit, and the record of what is submitted through it. | European Union (the eu1 data centre), and the United States |
| PostHog, Inc. | Product analytics for this website: which pages are read, in what order, and what is clicked on them. It is not cookieless — it sets a browser identifier of its own, which is the first storage this site places of its own accord. It also records the screen during a visit and replays it back to us, collects script errors, and can show a chat window, a survey or a guided tooltip. | European Union (PostHog's EU cloud), and the United States where PostHog operates from |
| Vimeo, Inc. — named, not yet carrying data | The video player on this site, which loads only when a visitor presses play and is asked not to track. No video identifier is configured yet, so nothing has ever loaded. | United States |
| Freshworks (Freshsales) — named, not yet carrying data | The record of enquiries made through this website, and the sales correspondence that follows one. | United States and India |
Individual crew and production partners engaged for a specific project also handle personal data, and are bound by written confidentiality obligations before they get access.
8) Cross-border transfers
The processors above are outside India, so your data is processed outside India. Section 16 of the DPDP Act permits transfer to any country the Central Government has not restricted by notification. No such restriction has been notified as at the date of this Policy; if one is, we will comply with it and change what we do rather than change this page after the fact.
The DPDP Rules 2025 add a second control on top of that negative list: the Central Government may require that personal data of a specified class, made available to a Data Fiduciary by a foreign state or its instrumentality, is processed subject to conditions it prescribes. None applies to us today. If one is prescribed for anything we hold, we meet it or we stop holding the data.
Transfers into India — from the EU, the UK, the United States and elsewhere — are a separate question with separate answers, and they are in Sections 23, 24 and 25 and in the data processing agreement.
9) Film and video-specific privacy rules
Releases and approvals. We use talent releases, location releases and client approvals to govern how footage, images and audio may be used. A release names the media, the territory and the term, and states whether a likeness or voice may be used to generate or train synthetic output — a person's name, image, likeness and voice are protected in their own right in India, and a signed release is how that protection is respected rather than argued about later.
Public filming and incidental capture. Filming in public or semi-public places can capture people incidentally. Where it is required and feasible we use notice and signage, controlled sets, consent workflows, and blurring, redaction or audio masking.
Minors. A verified parental or guardian consent is required before any minor is filmed. Where a child takes part in an audio-visual production, the permissions, supervision ratios, working-hour limits and earnings-deposit requirements set by the law governing children's participation in that work are conditions of the shoot, not options, and we will not proceed without them.
Faces, voices and biometric-like elements. Footage inherently contains faces and voices. We treat production media as sensitive operational content and protect it with the access controls described in the security policy.
10) Marketing, portfolio and case studies
We show work only when:
- the client contract permits it, or
- consent has been obtained, or
- the client has already released the content publicly and our use matches the agreed terms.
A client is named in a case study only with written consent. If you need no-publicity, it must be agreed in writing in advance.
11) Cookies
See the cookie notice, which states exactly what this website stores in your browser today, and what the two third-party embeds store.
12) Your rights and choices
Under the DPDP Act you may ask for a summary of the personal data we hold and how it is being processed, ask for correction, completion or updating, ask for erasure, withdraw consent, nominate someone to exercise your rights if you die or become incapacitated, and complain. Email productions@lowlightking.com with “Privacy Request” and enough detail for us to identify you. We may refuse or limit a request where the law allows — legal privilege, fraud prevention, another person's rights, or a contractual restriction — and we will tell you which applies rather than simply declining.
If we act as a processor for a client, we pass your request to that client rather than answering it ourselves, and we will tell you we have.
We answer a request within 30 days. Where the DPDP Rules set a shorter or longer period for a particular request once the Data Fiduciary duties commence, the shorter of the two is what we do.
Nomination. You may nominate someone to exercise these rights on your behalf if you die or lose capacity. Tell us the nominee's name and how to reach them, and we will record it against your data.
Data Protection Board of India. If our Grievance Officer (Section 21) has not resolved your complaint, you may take it to the Data Protection Board of India, which is the adjudicating authority under the DPDP Act. Complaining to us first is not a precondition imposed by us — it is simply faster.
13) Data retention
We keep personal data only as long as the purpose requires, or as long as a law requires. The schedule, category by category, is published at data storage and retention — including the 90 days we hold delivered masters and the 6 months we hold raw footage and working files. It is the single source for retention; where an older document of ours says something different, that schedule is what happens.
14) Security controls
The controls in force — two-factor authentication, full-disk encryption on the machines holding footage, per-project access, revocable delivery links, access logging, and written confidentiality obligations on everyone with access — are published in full at security and disclosure, together with what we do not claim. No security programme guarantees zero risk.
15) Breach and incident notification
If a personal data breach occurs we investigate and contain it, and tell the people affected without delay, in plain terms, describing what happened, what it is likely to mean for them, and what we are doing about it.
Three clocks can run at once, and they are not the same clock:
- The Data Protection Board of India. Rule 7 of the DPDP Rules 2025 sets a two-stage route: an initial intimation without delay, then a detailed report within 72 hours of becoming aware — the facts and circumstances, the remedial measures taken, our findings on who caused it, and a summary of what we told the people affected. The 72 hours run continuously, including weekends. An extension has to be asked for; it is not assumed.
- CERT-In. Where the directions of 28 April 2022 apply to the incident, the first report goes in within 6 hours of noticing it. Where we do not yet have the full picture at six hours we file what we have and supplement it, which those directions expressly permit. Six hours is not extendable.
- Our client. If we are processing on a client's instruction, we notify that client without undue delay and in time for them to meet their own deadlines — which for a controller under the GDPR means inside their 72 hours, not at the end of ours. The DPA governs, and it is the document that controls where the two disagree.
We do not wait for one clock to finish before starting another, and we do not delay an intimation to reach a tidier account of what happened.
16) Audits, compliance and documentation
We keep internal records and logs for governance, security, legal defence and operational continuity. Client audit rights are governed by the DPA, which sets out what we will answer, how often, and what we will not open up because it belongs to another client.
17) Third-party links and platforms
Our Services reference and integrate third-party services. Their privacy practices are theirs, not ours, and you should read their policies. The ones we actually use are named in Section 7 rather than left as a category.
18) Disputes and priority of documents
Where this Policy conflicts with a signed production agreement, the signed agreement controls. Unless mandatory local law requires otherwise, the governing law is that of India and the State of Kerala, and the courts at Kochi have jurisdiction.
19) Updates to this Policy
We may update this Policy. The effective date at the top changes when we do, and a change that materially affects how we process your personal data will be notified to you rather than left for you to notice.
Four things are in motion as at the date of this Policy and none of them is law we can write to yet: the remaining commencement stages of the DPDP Rules 2025; the European Commission's Digital Omnibus, which would move the cookie rules into the GDPR and is still in negotiation; the new Standard Contractual Clauses for importers already subject to the GDPR, consulted on but not adopted; and the appeal against the EU–US Data Privacy Framework pending before the Court of Justice. This Policy states the law as it stands, not as it is proposed. When one of those lands, this page changes.
20) Contact
All privacy, legal and production data requests: productions@lowlightking.com.
21) Grievance Officer
LowLightKing Productions Pvt Ltd has appointed a Grievance Officer to address complaints and data-related requests from users, clients and data principals, as the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 and the DPDP Act both require.
Grievance Officer: Paul Joseph, Founder
Company:
LowLightKing Productions Pvt Ltd
Address: 43/2153, E1, Jewel Homes, WhiteField, A-Block, SRM Road, Kaloor, Kochi, Kerala
– 682018
Email: productions@lowlightking.com
Phone: +91 99953 70707
Complaints are acknowledged within 24 hours and resolved within 30 days of receipt. Email us with the subject line “Grievance – [Your Name]” and a description of the concern. This mechanism covers privacy, data processing, content, accessibility and any other matter arising from your dealings with LowLightKing or this website.
22) On-set production privacy notice
Every active filming location carries a printed Production Privacy Notice at its entry points, naming the project, the shoot dates and the location. By entering an active set you acknowledge that video, photographs and audio may be recorded and that you may be captured incidentally or intentionally. On set we may collect your image, likeness and voice; behind-the-scenes recordings and stills; access and visitor records; CCTV footage where posted and required for safety; and limited contact details for scheduling, safety or access control.
Recordings are used to produce, edit and deliver the project; for quality control, continuity and operational documentation; for security and incident investigation; and for client approvals, compliance and legal defence. Where legally or contractually required we ask you to sign a release. If you do not wish to be recorded, tell the production manager immediately and avoid marked filming zones — we may not be able to accommodate every non-recording request inside an active set area.
Minors must be accompanied by a parent or lawful guardian at all times, and a verified parental or guardian release is required before any minor is filmed. Scripts, sets, props, call sheets, shot lists and captured media are confidential unless expressly authorised, and unauthorised recording may lead to removal from the set. Captured media and logs are retained on the schedule in the retention policy, and may be shared with clients, post-production partners, insurers, advisers and authorities where required by law or contract.
For privacy questions relating to on-set data, contact productions@lowlightking.com or +91 99953 70707.
23) If you are in the European Union or the United Kingdom
When this applies. We are established in India and we do not target the EU or the UK market. The GDPR and the UK GDPR nonetheless reach our processing in two situations: where we film or otherwise process the personal data of people in the EU or the UK on the instruction of a client established there, and where a client's own obligations flow down to us by contract. In the first case the client is the controller and we are the processor, and the data processing agreement governs.
Your rights. Where the GDPR or UK GDPR applies you have the rights of access, rectification, erasure, restriction, portability and objection, the right not to be subject to solely automated decisions with legal effect — we make none — and the right to complain to a supervisory authority, which for the UK is the Information Commissioner's Office. Where we hold your data as a processor, we will pass your request to the controller.
Complaints. The UK's Data (Use and Access) Act 2025 requires an organisation to facilitate complaints, acknowledge one within 30 days and respond without undue delay; that duty has been in force since 19 June 2026. The grievance mechanism in Section 21 already acknowledges within 24 hours and resolves within 30 days, for anyone, anywhere, and it is the route to use. If you are in the UK and we have not resolved your complaint, you may take it to the ICO.
Transfers into India. India has no adequacy decision. Where we process personal data subject to the GDPR, the European Commission's 2021 Standard Contractual Clauses (Decision (EU) 2021/914) apply, and where it is subject to the UK GDPR, the Information Commissioner's International Data Transfer Addendum applies. Both are incorporated into the DPA, and we will supply what a client needs for its transfer impact assessment. The Commission consulted on a further set of clauses for importers already subject to the GDPR; they have not been adopted, so we do not cite them as if they existed, and the DPA carries our commitment to execute them once they are.
Representative. We have not appointed a representative under Article 27, because our processing does not fall within Article 3(2): we neither offer goods or services to people in the EU or the UK nor monitor their behaviour. That position is testable rather than asserted — it would change if we offered the Video Strategy Audit to buyers established in the EU or the UK, or if we measured the behaviour of visitors there. If either happens, we appoint one.
Artificial intelligence. The EU AI Act's transparency duties under Article 50 have applied since 2 August 2026, and they can reach us directly rather than only through a client, because the Act follows the output: a producer outside the Union is in scope where what it makes is used inside it. What that means for a specific deliverable is in the AI and synthetic media policy and in clause 18 of the Terms.
Accessibility. The conformance target for this website, and the European Accessibility Act position, are in the accessibility statement.
24) If you are in the United States
We are not the kind of company these laws are aimed at. We do not sell to consumers in the United States, we do not advertise to them, and we do not believe we meet the revenue or volume thresholds that make an organisation a “business” or “controller” under any of the twenty state privacy laws now in force. Whether or not we do, the commitments below are the same.
Our role. Where we process personal information on behalf of an organisation that is covered, we act as a service provider under the California Consumer Privacy Act, and in the equivalent role each of the other state laws names — “processor” in Colorado, Connecticut, Virginia and the states that followed Virginia's template, “contractor” where a state uses that term. We certify that we understand and will comply with the restrictions that role carries: we do not sell personal information, do not share it for cross-context behavioural advertising, do not retain, use or disclose it outside the business purpose stated in the contract, and do not combine it with personal information obtained from anyone else. Those commitments are set out in the data processing agreement and they are not limited to California.
Universal opt-out and Global Privacy Control. Twelve states have required businesses to honour an opt-out preference signal since 1 January 2026. This site sets no identifier of its own and runs no advertising, cross-context or otherwise, so there is nothing here for such a signal to switch off. The third-party form embedded on our pages is described in the cookie notice, including what it writes and how to stop it.
Biometric information. Footage contains faces and voices. We do not extract faceprints or voiceprints, do not run facial recognition or voice identification, and do not use recordings to build a biometric template — which is what the Illinois Biometric Information Privacy Act, the Texas CUBI Act and the Washington My Health My Data Act are concerned with. Where a client's brief would require any of that, it has to be agreed in writing first, and the release signed by the person concerned has to say so.
Name, image, likeness and voice. Several states protect these in their own right, separately from privacy law, and specifically against synthetic reproduction — Tennessee's ELVIS Act and California's AB 1836 and AB 2602 among them. Our releases state the media, the territory and the term, and state expressly whether a likeness or voice may be used to generate, alter or train synthetic output. Where they do not say so, no synthetic use is permitted. Clause 11.5 of the Terms is the contractual version of this and the AI policy is the operational one.
Your rights. If a state law gives you a right against us directly, exercise it by writing to productions@lowlightking.com with “Privacy Request” in the subject line. We do not discriminate against anyone for making one. Where we hold your information for a client as a service provider, we pass your request to that client and tell you we have.
25) If you are somewhere else
The four regimes above are the ones our work actually touches. Others reach us the same way the GDPR does — through a client whose obligations flow down by contract — rather than because we operate there. Where that happens:
- The Gulf. The UAE's Federal Decree-Law 45 of 2021 and the DIFC and ADGM regimes, and Saudi Arabia's Personal Data Protection Law, each impose controller-to-processor terms and transfer conditions of their own. We will sign an addendum that meets them.
- Singapore, Canada, Australia and elsewhere. The same answer: the obligations are taken on by contract, in the DPA or in an addendum on the client's paper, and we say plainly if something in one is beyond what a company of our size can honestly commit to rather than signing it and hoping.
What we will not do is claim registration, certification or established presence in a jurisdiction we have none in. The security policy states what we do not claim, and this section works the same way.
26) AI and synthetic media
Where AI is used in our work, what is never generated, who carries the labelling duty under which law, and our rule that client material and personal data are never used to train or fine-tune a model, are all in the AI and synthetic media policy. It is part of this notice by reference and it is written to be read on its own.
The other documents
This is one of nine. The index lists them all and says what each one decides.