Best-practice draft
Privacy notice
This notice explains the personal information Talent Drop currently receives through performer applications and booking enquiries, what the service does with it, and the choices available to the people concerned.
1. Who is responsible
The organisation or individual operating Talent Drop is the controller of the personal information described in this notice. “Talent Drop”, “we”, “us” and “our” refer to that operator.
Legal operator: [CLIENT CONFIRMATION REQUIRED]
Address: [CLIENT CONFIRMATION REQUIRED]
Privacy contact: privacy@talentdrop.scot [public mailbox activation required]
2. Information we collect
Performer applications
Name, email address, primary discipline, Scotland connection, a short description of the performer’s work, consent status, submission time, status and a reference.
Booking enquiries
Name, email address, selected performer, venue or project and the message supplied by the enquirer, together with consent status, submission time, status and a reference.
Abuse prevention and technical records
The submission service creates a keyed hash from the requesting IP address for coarse rate limiting. Talent Drop’s submissions table does not store the raw IP address. Hosting and infrastructure providers may temporarily process ordinary request metadata, such as IP address, browser information, timestamps and requested pages, to deliver and protect the service.
Please do not submit special-category, criminal-offence, financial, identity-document or other unnecessarily sensitive information through these forms.
3. Why we use information
- Receive, review and respond to performer applications.
- Receive and route booking enquiries concerning an approved performer.
- Keep a private record of the conversation and its reference.
- Detect repeated automated submissions and protect the service.
- Investigate errors, misuse, disputes or security incidents.
Application or enquiry information is not published automatically, used to create a public profile automatically, sold, used for behavioural advertising or used to buy performer search rank.
4. Lawful basis
Recommended default for performer applications: legitimate interests in receiving, assessing, corresponding about and administering a voluntary application, supported by a documented balancing assessment. Contract or steps requested before entering a contract should be used only where a genuine potential contract exists and the particular processing is necessary for that step.
Separate optional uses: publishing a profile, retaining someone for unrelated future opportunities or sending marketing should not be bundled into the application acknowledgement. Use a separate, specific permission or another documented lawful basis appropriate to that distinct purpose.
Recommended default for booking enquiries: legitimate interests in receiving and responding to genuine business enquiries, and steps requested before entering a contract where applicable. The operator should document the legitimate-interests assessment before launch.
Security and abuse prevention: legitimate interests in operating a reliable and secure website. If a legal obligation later requires information to be used or retained, that purpose and basis should be recorded and this notice updated.
These are recommended defaults, not a declaration of legal compliance. The confirmed operator should review and approve the basis for each implemented purpose before publication.
5. Publication is separate
Submitting a performer application does not make a person a member and does not publish their information. A public performer profile requires a separate human review, a private preview and clear permission for the specific biography, images, credits, links or media to be published. A booking enquiry remains private between authorised operators and the relevant people unless disclosure is agreed or otherwise lawfully required.
6. Service providers and recipients
Access should be limited to people who need it to review or answer a submission. The current technical design uses:
- Vercel to host and deliver the website and server-side submission endpoint.
- Supabase as the private submissions database. Browser users have no direct read or write policy for this table.
- Resend to send a submission notification only when the notification service is configured.
- The selected performer or an authorised representative, when needed to answer a relevant booking enquiry.
No general “trusted partners” permission is claimed. Any new processor, advertiser, analytics service, payment service or mailing platform must be assessed and added to this notice before receiving personal information.
7. International transfers
Some infrastructure providers may process information outside the United Kingdom. Before launch, the operator should record each provider’s processing locations, contract and transfer safeguard, retain the relevant data-processing terms, and update this section with the verified position. Personal information should not be sent to a new country or provider merely for convenience.
CLIENT CONFIRMATION REQUIRED: completed processor register, processing locations and transfer safeguards.
8. How long we keep information
Recommended default: keep unsuccessful or inactive performer applications and booking enquiries for no longer than 12 months from submission, then delete or irreversibly anonymise them unless a documented dispute, contract, legal obligation or active conversation requires a different period.
The database already records a 12-month retention date for each submission. The operator should run a monthly deletion review, close completed records promptly and record any exception with an owner, reason and revised deletion date. Clearing a browser form does not delete the private server record; data-rights requests use the contact route.
9. Security
The current design validates and size-limits submissions, uses a honeypot and rate limit, keeps service credentials on the server, stores submissions in a private row-level-security-enabled table and does not expose database access to browser clients. Notification failure does not discard the database record.
Best-practice operation also requires least-privilege access, multi-factor authentication where offered, prompt removal of old access, secure backups, tested restore and deletion procedures, software updates and an incident log. No internet service can promise guaranteed security.
10. Cookies and technical logs
The current release candidate uses no analytics and no advertising cookies, and does not include behavioural tracking. A cookie consent banner is therefore not proposed for the present functionality. Hosting providers may still create short-lived technical and security logs needed to serve requests and investigate faults.
If analytics, embedded media, advertising, accounts, payments or non-essential cookies are introduced, they must be assessed before launch and the notice and consent controls updated first.
11. Your data protection rights
Depending on the circumstances and lawful basis, a person may be able to ask for access to their information, correction, deletion, restriction, objection, portability or withdrawal of consent. A request should describe the relevant application or enquiry and include its reference if available. The operator may ask for proportionate information to confirm identity before disclosing or changing a private record.
Recommended operational targets are to acknowledge a request within two working days and complete it within one calendar month unless an applicable exception or permitted extension is documented. There is normally no charge, but the operator should obtain qualified advice before refusing, extending or charging for a request.
12. Children and young people
Recommended launch rule: the online forms are for people aged 18 or over. Someone under 18 should not submit personal information through the forms; a parent or guardian should use the confirmed public contact route instead. A child-specific process, consent model and age-appropriate notice must be designed before actively recruiting or profiling under-18s.
13. Data incidents
Suspected loss, unauthorised access, mistaken disclosure or misuse of personal information should be reported immediately to the confirmed operator. The operator should contain the issue, preserve facts, assess likely risk, document the decision and seek qualified guidance on notifying affected people or the Information Commissioner’s Office within any applicable deadline.
14. Contact and complaints
Use the contact and data-rights page. The proposed dedicated address is privacy@talentdrop.scot, but that public mailbox is not active yet and must not be presented as working until delivery and monitoring are verified.
If a concern is not resolved, a person can find independent information or raise a complaint with the Information Commissioner’s Office.
15. Changes to this notice
This notice should be reviewed whenever the forms, purposes, providers, membership service, advertising model or retention process changes. The published version should show an effective date and retain a record of material changes.
Draft updated: 25 August 2026. Effective date: [CLIENT CONFIRMATION REQUIRED].