Last updated 23 July 2026
Lima Delta maintains appropriate technical and organisational measures to protect the personal data it processes on behalf of clients. The measures below summarise our current practice.
Access to personal data is limited to authorised personnel on a need-to-know basis, using role-based access controls.
When we build custom applications, e-learning or other on-the-job tools, our design principle is that user and learner data remains within your organisation's already-approved ecosystem of tools. E-learning is typically handed over so that any learner data flows to your existing LMS, and integrations with SharePoint or other systems are built to keep data inside your environment. Data does not leave your organisation unless explicitly agreed. See our sub-processors and where they process data.
All data, including personal data, is encrypted in transit and at rest.
Company devices are centrally managed and encrypted through a mobile device management (MDM) system, with enforced screen locks and the ability to remotely revoke access to, or wipe, a lost or stolen device.
Multi-factor authentication is enforced on all accounts with access to personal data, alongside password policies consistent with current good practice.
Code, source content, footage and project files are stored with reputable cloud providers operating enterprise-grade security.
Files are transferred to and from clients securely using platforms and services. The precise method varies by client and is usually defined in client specific terms or MSAs.
All staff and subcontractors are bound by written confidentiality obligations. Our contracts with production subcontractors ask them to handle securely and, where applicable, erase any personal data or footage held on their own equipment.
Project files are retained and recoverable through the versioning and retention features of our cloud providers.
We align our breach response with the Information Commissioner's Office (ICO) guidance on personal data breaches. As a processor acting on our clients' behalf, we will notify affected clients without undue delay of any personal data breach, and assist them in meeting their own obligations, including the UK GDPR requirement to report notifiable breaches to the ICO within 72 hours of becoming aware.
Personal data and footage are retained, deleted or returned in line with each client's contract terms.
Staff receive periodic data protection and security awareness training.
These measures describe our current organisational and technical practice and may be updated as our tools and processes evolve. For the specific detail required for a security assessment or questionnaire, please contact security@limadelta.co.uk, or write to Lima Delta Ltd, GF.OF.19, FOUNDRY Hove, 3 Ellen Street, Hove, BN3 3LN.