Back to homepage

COMBAT THEATER PRIVACY POLICY

PRIVACY POLICY FOR COMBAT THEATER

This Privacy Policy explains how Combat Theater Ltd (“Combat Theater”, “we”, “us”, or “our”) collects, uses, and shares personal data in connection with this website (combat.theater) and the Combat Theater software (the “Software”).

Combat Theater Ltd is the controller of the personal data described in this policy.

We are a company incorporated in England and Wales. Our registered office is 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

For privacy questions or data-protection complaints, contact us at contact@combat.theater.

1. WHO THIS POLICY COVERS


We supply the Software only to businesses, for use by technically skilled professionals. We do not sell to consumers or to individuals acting in a personal capacity.

This policy still applies to personal data we hold about people who represent those businesses — for example a named contact’s name, work email, or phone number.

We do not knowingly collect personal data about children, and the Software is not intended for anyone under 18.

2. PERSONAL DATA WE COLLECT


2.1 Information you give us

Depending on how you deal with us, this may include:

  • Name and work email address
  • Organisation name
  • Message content, intended use, and optional team size (from our contact and demo forms)
  • Optional contact phone number
  • Number of licences purchased
  • Payment and invoicing details for bank transfers (for example the paying organisation’s name and payment references)

2.2 Information collected when you use the Software

The Software does not send product usage or technique execution telemetry to Combat Theater. Network communications initiated by the Software for Combat Theater-operated functionality are limited to licence activation and validation through LimeLM (operated by wyDay).

The Software contacts LimeLM when you register a licence, and approximately every 30 days afterwards to confirm the licence is still valid and has not expired or been revoked.

That licence check typically involves:

  • Product key / licence information
  • Installation date and data needed to verify the key has not been altered
  • A hardware fingerprint generated from the machine, used to bind the licence to that computer. LimeLM / wyDay states that this fingerprint cannot be used to determine the make or model of the computer or other personal information about you

We do not collect crash reports, usage analytics, technique execution data, behavioural telemetry, or general application telemetry from the Software.

2.3 Information collected when you use this website

  • Technical data such as IP address, browser type, and similar request metadata, which may be processed by our hosting provider for security, availability, and abuse prevention
  • Information you submit through our forms, which is transmitted via our form processor to our email

We do not use Google Analytics or equivalent website analytics. We do not intentionally use advertising or conversion tracking pixels on this website.

2.4 Information from public or business sources

We may obtain professional contact information from publicly available or business sources, such as company websites, professional networking platforms (including LinkedIn), public professional profiles, referrals, or business directories.

This is typically limited to:

  • Name
  • Job title
  • Organisation
  • Work email or other professional contact information

We may use this to identify and communicate with organisations or professionals who may have a legitimate business interest in Combat Theater.

3. HOW WE USE PERSONAL DATA AND OUR LAWFUL BASES


We process personal data where UK data protection law allows us to. The lawful bases we rely on are:

  • Contract (UK GDPR Article 6(1)(b)): to take steps at your request before entering a contract, and to perform a licence agreement — including issuing licences, keeping customer records, and validating licences through LimeLM
  • Legitimate interests (UK GDPR Article 6(1)(f)): our interests in operating and protecting the business and website; responding to prospective and existing customers; maintaining appropriate business and customer records; promoting Combat Theater to organisations or professionals likely to have a relevant business interest in the product; and protecting our legal and commercial interests. We do not rely on legitimate interests where they would be overridden by the individual’s rights and interests
  • Legal obligation (UK GDPR Article 6(1)(c)): to keep accounting, tax, and company records as required by UK law, including HMRC and Companies Act requirements

We use personal data to:

  • Respond to contact and demo requests
  • Discuss licensing and provide the Software
  • Issue invoices, receive bank transfers, and keep customer and licence records
  • Activate and periodically re-validate licences
  • Operate and secure this website
  • Advertise Combat Theater on platforms such as LinkedIn and X (see section 7)
  • Contact relevant business representatives about Combat Theater where there is a relevant business context

We may contact business representatives about our products or services where there is a relevant business context and where permitted by law, including the Privacy and Electronic Communications Regulations (PECR). We may rely on legitimate interests for this where appropriate. This is limited B2B outreach, not consumer marketing or a newsletter. You can object to direct marketing at any time by emailing contact@combat.theater.

We do not sell personal data. We sell the Software to businesses. We do not sell, rent, or trade contact details or other personal data.

We do not use automated decision-making, including profiling, that produces legal or similarly significant effects.

4. WHO WE SHARE PERSONAL DATA WITH


We share personal data with service providers who process it on our instructions, where needed to run the business. Providers we currently use include, for example:

  • Cloudflare — website hosting, content delivery, and related security
  • Static Forms — transmission of contact and demo form submissions to our email
  • Proton Mail — business email
  • LimeLM / wyDay — licence registration, activation, and periodic licence validation
  • Banking providers — receiving and reconciling bank transfers
  • Professional advisers (for example accountants or lawyers) where required to obtain advice or meet legal obligations

We may also use other providers in these categories from time to time. We may disclose personal data if required by law, to protect our legal rights, or in connection with a business transfer (such as a sale of the company), in which case we would take reasonable steps to keep the data protected.

The website may load resources from third-party infrastructure providers. Where this occurs, those providers may receive technical request information such as your IP address.

5. INTERNATIONAL TRANSFERS


We are established in the United Kingdom. Some of our providers may process data outside the UK, including in the United States.

For example, Cloudflare, Static Forms, and LimeLM / wyDay may process data in the United States or other countries. Proton Mail is provided from Switzerland, which the UK currently recognises as providing an adequate level of protection.

Where UK law requires safeguards for restricted international transfers, we use providers and arrangements intended to provide the safeguards required by applicable UK data-protection law. Depending on the provider and destination, that may involve UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where a provider participates, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. Not every mechanism applies to every provider.

We supply the Software worldwide except where that would breach applicable UK sanctions, export controls, or other legal restrictions.

6. HOW LONG WE KEEP PERSONAL DATA


We keep personal data for as long as we need it for the purposes above:

  • Enquiries that do not become a customer: 12 months after our last correspondence, unless we need to keep it longer to deal with a complaint or legal claim
  • Customer, licence, invoice, and payment records: for the life of the relationship and then for 6 years after the end of the relevant financial year, in line with UK tax and company record-keeping requirements
  • Licence activation data held by LimeLM: for the duration of the licence, and for a reasonable period afterwards for support, dispute, fraud-prevention, or licence-record purposes
  • Website security logs: according to our hosting provider’s security and abuse-prevention retention periods, which we do not directly control
  • Professional contact information obtained from public or business sources: for as long as there is a relevant business purpose, or until you object

We will delete or anonymise personal data when we no longer need it, unless the law requires us to keep it.

7. ADVERTISING


We may advertise Combat Theater to businesses on platforms such as LinkedIn and X. Those platforms process information about their own users under their privacy policies.

We do not intentionally use advertising cookies, conversion pixels, or similar tracking technologies on this website, and we do not sell personal data for advertising.

8. COOKIES AND SIMILAR TECHNOLOGIES


We do not intentionally use analytics or advertising cookies on this website.

Cloudflare or other infrastructure may use cookies or similar storage for website delivery, security, abuse prevention, or similar essential functions. The website or your browser may also store data locally for site functionality or presentation.

You can control cookies through your browser settings. Blocking some cookies may affect site availability or security checks.

9. HOW WE LOOK AFTER PERSONAL DATA


We take reasonable technical and organisational measures to protect personal data, including using providers appropriate to a business of our size, limiting access to people who need it for their role, and using encrypted transport (HTTPS) for this website and form submissions.

No method of transmission or storage is completely secure. If we become aware of a personal data breach that must be reported, we will do so in line with UK GDPR.

10. YOUR RIGHTS


Under UK GDPR you have the right, in certain circumstances, to:

  • Access the personal data we hold about you
  • Have inaccurate personal data corrected
  • Have personal data erased
  • Restrict our processing
  • Object to our processing, including processing based on legitimate interests
  • Object at any time to processing of your personal data for direct marketing
  • Receive personal data you provided to us in a portable format, where applicable
  • Withdraw consent, where we rely on consent

To exercise these rights, email contact@combat.theater. We may need to verify your identity before fulfilling a request. Some rights are limited where we must keep data to perform a contract or to meet a legal obligation.

If you have a concern about how we handle your personal data, email contact@combat.theater. We will acknowledge a data-protection complaint within 30 days, investigate it appropriately, keep you informed where necessary, and provide an outcome without undue delay.

You also have the right to complain to the UK Information Commissioner’s Office (ICO), the supervisory authority for data protection in the UK: ico.org.uk.

If you are in the European Economic Area, you may also be able to complain to your local supervisory authority.

11. CHANGES TO THIS POLICY


We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. If we make a material change, we will take reasonable steps to bring it to your attention.

12. CONTACT


Combat Theater Ltd
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
contact@combat.theater