1. Who we are
BandHQ is a management and community app for amateur brass bands, operated by Vivid Vision Designs Ltd, a company registered in England & Wales (company number 16091475), registered office 5 High Street, Husbands Bosworth, Lutterworth, England, LE17 6LJ. In this policy, “BandHQ”, “we”, “us” mean Vivid Vision Designs Ltd.
For anything in this policy, including any request about your data, contact us at privacy@usebandhq.com (general enquiries: hello@usebandhq.com).
We are registered with the UK Information Commissioner's Office (ICO), registration number ZC203564.
We have not appointed a statutory Data Protection Officer, as we are not required to. Data-protection questions go to privacy@usebandhq.com.
2. The two roles we play
Data-protection law distinguishes the controller (who decides why and how data is used) from the processor (who acts on the controller's instructions). BandHQ is one or the other depending on the data:
- We are a processor for the personal data a band puts into BandHQ about its own members — names, contact details, instruments, availability, messages, and so on, and about a small number of people who are not members — a guest player booked to cover a chair for one engagement. See “If a band recorded your details and you have no account” below. The band (through its committee or organising body) is the controller of that data and decides how it is used. If you are a member of a band that uses BandHQ, your band's own privacy arrangements govern that data.
- We are a controller for the data we collect for our own purposes: the people who administer a band account, visitors to our website, people who ask about the product, and people who contact support.
The sections below describe the data we handle as a controller. For member data we process on a band's behalf, see your band.
3. If you are a band member using BandHQ
Your band chose BandHQ and controls your data in it. You can:
- See your data — view and download what BandHQ holds about you from your in-app profile.
- Correct your data — edit your own profile details in-app.
- Ask for more — for access, correction, deletion or any other right, contact your band, who is the controller. We support them in fulfilling those requests.
If a band recorded your details and you have no account
A band that books a guest player — a dep covering a chair for one engagement — can record how to reach them: their name, and optionally the band they normally play for, a phone number, an email address, and a short note. You may be in BandHQ this way without ever having used it, and without having agreed to anything.
Being plain about what that does and does not mean:
- Why it is held. The band is organising a performance and needs to reach the player it booked. The lawful basis is the band’s legitimate interest (Art. 6(1)(f)); the band is the controller and we hold it on their instructions.
- Who can see it. The administrators of that one band, and nobody else in it — enforced in the database rather than by the app remembering to hide it. Our own staff can reach it through our internal operator console.
- How long it is kept. It is deleted with the event it was recorded for. Nothing is retained to re-book you next season.
- You get nothing from us. No account, no invitation, no notifications, no email. Your details are a note the committee made, not a relationship with BandHQ.
- Your rights. You can ask for access, correction or deletion — through the band, who is the controller, or by emailing privacy@usebandhq.com and we will pass it on and support them. There is no self-service route, because there is no account to sign in to.
4. The personal data we handle (as a controller)
| Who | What we collect | Where it comes from |
|---|---|---|
| Band administrators / users | Name, email, phone, instrument, role, sign-in credentials, and (if set) a profile photo | You, or your band when they set up your account |
| Prospects / enquirers | Name, email, band name, and what you told us | An enquiry form or an email to us |
| Newsletter subscribers | Name, email, and (optionally) band and role | You, when you sign up |
| Website visitors | Strictly necessary cookies, standard server logs, and aggregate page-view counts | Automatically, when you visit |
| People who contact support | Your name, contact details and the content of your message | You |
Website measurement. Our public marketing site counts page views so we can see which pages people find useful. It is cookieless — it stores nothing on your device — and it is served from our own domain rather than a third-party host. It produces aggregate figures only: which page was viewed, the page that referred you, your country, and the kind of device and browser. It does not identify you, follow you across other websites, or record your session.
We do not use advertising trackers, and we do not build advertising profiles. We do not collect location from your device. For the cookies and similar storage we use, see our Cookie Policy.
Do you have to provide it? Some data is needed to provide the service — for example, we can't create or run your account without a name and a way to sign you in. If you don't provide it, you won't be able to use those parts of BandHQ. Optional data (marked as optional in the app) is up to you.
5. Why we use it, and our legal bases
| Purpose | Legal basis (UK GDPR Art. 6) |
|---|---|
| Providing and securing the service to account holders | Performance of a contract (Art. 6(1)(b)) |
| Keeping the service safe, preventing abuse, and improving the product | Legitimate interests (Art. 6(1)(f)) |
| Responding to enquiries and support | Legitimate interests / steps prior to a contract (Art. 6(1)(f), (b)) |
| Counting page views on our marketing site, in aggregate | Legitimate interests (Art. 6(1)(f)) |
| Marketing emails to prospects and subscribers | Consent, or legitimate interests where permitted — every marketing email carries an unsubscribe link, honoured on receipt |
Where we rely on legitimate interests (Art. 6(1)(f)), those interests are: keeping the service and its users secure and preventing abuse; running and improving BandHQ; and responding to people who contact us. We only rely on this where it doesn't override your rights, and you can object — see section 11.
6. Children & young members
Brass bands often include children and young people, so protecting young members matters to us. This section explains how their data is handled.
Age of consent. Under UK GDPR, a child can consent to an online service from age 13. Younger children cannot give that consent themselves, so under-13s do not create their own BandHQ account — they take part only through their band, added by a band administrator, with the involvement of a parent or guardian.
The band is responsible. The band, as the controller, is responsible for having an appropriate lawful basis for recording a young member's data and for obtaining parental/guardian consent where it is needed. BandHQ processes that data only as a processor, on the band's behalf, under our Data Processing Agreement.
What we do to protect young members. In line with the ICO's Children's Code (Age Appropriate Design Code), BandHQ:
- applies high-privacy settings by default for under-18s and keeps their data to the minimum needed to run the band;
- is invite-only — there is no public discovery of bands or members;
- does not serve advertising, build behavioural profiles, or use members' content to train AI;
- does not collect device location.
If we turn you away for being under 13. Sign-up asks for a date of birth. If it puts you under 13 we refuse to create the account — and we keep a record that we did, so that the same address cannot simply come back the next day with a different date of birth. That record is deliberately small:
- a one-way scrambled version of the email address, never the address itself. It can be compared against a later sign-up, but it cannot be read, listed, or used to contact anyone;
- the youngest age given, how many times it was tried, and when;
- no name, no address, no message, nothing else.
If an account is later created from the same address claiming to be older, that contradiction is flagged for a person at BandHQ to look at. Nothing is automatic: the obvious innocent explanation is a parent who tried to sign their child up, was refused, and then signed up themselves — and an account is never suspended without a person deciding. We keep these records for one year from the last attempt, and our lawful basis is our legitimate interest in keeping under-13s off a service they are too young to consent to, and in meeting our child-safety duties.
Parents & guardians. A parent or guardian can access, correct or delete their child's data and withdraw consent, through the band administrator or by contacting us. How to keep young members safe on BandHQ, and how to report a concern, is set out in our Child Safety & Acceptable Use policy. As a service used by children, BandHQ also has duties under the UK Online Safety Act.
7. Who we share it with
We do not sell personal data. We share it with the service providers (“sub-processors”) that make BandHQ work, each under a contract that limits them to acting on our instructions. In summary: Supabase (database, authentication and file storage; EU, Ireland), Vercel (application hosting, and the cookieless page-view counting described in section 4; functions pinned to the EU, Dublin), Resend (email; USA), Google Cloud (automated safety scanning of uploaded images, on Google’s European Union endpoint), and Apple and Google (mobile app distribution and push notifications). The full list, with what each one receives and where it processes it, is in Annex 3 of our Data Processing Agreement, and the current set is shown on our Trust & security page. We may also disclose data where the law requires it, or to protect our rights, our users, or the public.
8. How we protect it
Security measures include:
- Row-Level Security, so each band's data is isolated at the database, not just in the interface.
- Hashing of secrets and encryption of sensitive tokens, on top of encryption at rest.
- Short-lived signed links for private files, with access re-checked on every request.
- Two-step sign-in on our own operator accounts. Every Vivid Vision Designs account that can reach band data requires a second factor. It is not currently offered to band administrators, and we would rather say so than imply a protection you do not have.
No system is perfectly secure, but we take these measures seriously and review them. If a personal-data breach occurs, we will notify the ICO and affected people where the law requires.
9. Sending data outside the UK/EEA
Your core data is stored in the EU (Ireland), and transfers between the UK and the EEA are covered by adequacy. Some providers that help us deliver email and hosting may process limited data outside the UK/EEA. Where they do, we rely on an approved safeguard — the UK Addendum to the EU Standard Contractual Clauses, or equivalent.
10. How long we keep it
- Account data — for as long as your band holds an active account with us, and for a limited period afterwards to handle queries and our own legal obligations.
- Billing records — we hold none. BandHQ takes no payments and has no billing of any kind. If that changes, tax and accounting law will require us to keep those records for the period it specifies (in the UK, generally six years), and we will say so here before we start.
- Safeguarding records — a report about a member, and the moderation decision taken on it, outlive the band’s account. If a band closes its account, or is deleted, the report stays with us and keeps a note of which band it concerned. We keep them because we may need to answer a later question from the band, a parent or an authority about a decision we took, and a record deleted on a schedule is one we cannot answer from. We do not delete them on a timer. Where material has to be preserved for a referral to law enforcement, it is kept until that authority confirms it may be released, whatever the rest of this section would otherwise say.
- Records of a refused sign-up — where we turned someone away for being under 13 (see section 6), the scrambled address and the age given are kept for one year from the last attempt, then deleted automatically.
- Guest dep contact details — deleted automatically the night after the event they were recorded for. Nothing is kept to re-book the same player later.
- Prospect and marketing data — until you unsubscribe or ask us to stop, after which we keep only a suppression record so we don't contact you again.
For member data we hold as a processor, retention is the band's decision; BandHQ provides tools to support it.
11. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, object to, and port your personal data, and to withdraw consent where we rely on it.
- If BandHQ is the controller (your account with us, an enquiry, or support), contact us at privacy@usebandhq.com and we will respond within one month.
- If you are a member of a band using BandHQ, exercise these rights with your band (the controller). You can view and correct your own profile in-app.
Your right to object
You can object to processing we carry out on the basis of our legitimate interests, on grounds relating to your situation, and we will stop unless we have compelling grounds to continue. You have an absolute right to object to direct marketing at any time — every marketing email has an unsubscribe link, honoured on receipt, or email privacy@usebandhq.com.
You also have the right to complain to the ICO (ico.org.uk), though we'd appreciate the chance to help first.
12. Automated decision-making
BandHQ does not make decisions with legal or similarly significant effects about you by purely automated means, and does not carry out that kind of profiling.
13. Changes to this policy
We'll update this policy as the product and the law change, and note the “last updated” date at the top. We'll tell administrators about material changes by an in-app notice and/or email.
14. Contact
Vivid Vision Designs Ltd — privacy@usebandhq.com, 5 High Street, Husbands Bosworth, Lutterworth, England, LE17 6LJ. To complain to a regulator: Information Commissioner's Office, ico.org.uk.