Privacy Policy
Last updated: September 2026
DanceMate is a software platform that helps dance schools manage their technique content, events, attendance, exams and admin. This policy explains what personal data is collected, why, where it goes, and your rights over it.
DanceMate is provided by Nelochem Ltd, a company registered in England and Wales under company number 17387331, trading as DanceMate, whose registered office is 20 Patten Close, Marks Tey, Colchester, Essex, CO6 1ND, United Kingdom. For privacy enquiries, contact info@dancemate.co.uk. We are subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The DanceMate business was previously carried on by Chris Burrell as a sole trader, and transferred to Nelochem Ltd on 18 August 2026. Nelochem Ltd took over as operator on exactly the same terms, and now stands in place of the sole trader everywhere this policy says "we".
1. The two roles we play
DanceMate acts in two different capacities, and your rights run to different people depending on which applies:
- Data controller — for the data of the dance school owners who subscribe to DanceMate (your name, email address and account information). For this data, come to us directly.
- Data processor — for the data that dance schools store in DanceMate about their own students, parents, event attendees, staff and exam candidates. For this data, the school is the controller and we act only on its behalf.
One exception: the security logs and anti-abuse rate limits described in sections 2 and 10 are run for our own purpose of protecting the platform, so we act as controller for that limited processing, whoever the user is.
Our full data processing agreement — the written contract UK GDPR requires between each school and us — is published openly, including the sub-processor list and security measures.
2. Data we collect about school owners
When you sign up for and use DanceMate, we hold:
- Signup details — your school's name, your name, your email address, and your chosen plan and technique-book options
- Account credentials — your school's access code (staff logins sit under section 3, since your school controls who it adds)
- Billing information — a Stripe customer reference, your plan and subscription status. Card details are entered on Stripe's own pages and never touch our systems
- Correspondence — support requests, feedback you send through the in-app tools, and emails you exchange with us
Legal basis: performance of a contract — this data is necessary to provide the service. Providing the signup details is a contractual requirement: without a school name and a working email address we can't create the account or deliver your access code. Nothing else in this policy is data you are obliged to give us.
We send service emails connected to your account (such as your welcome email and trial reminders); these are part of the service, not marketing, and we do not send marketing email.
To protect the platform we also apply rate limits to signups and sign-in attempts, which briefly process the requesting IP address. Legal basis: our legitimate interest in keeping the service secure and abuse-free.
3. Data schools store within DanceMate
Schools use DanceMate to run their teaching and events, which may involve storing:
- Names, email addresses and phone numbers of students, parents, contacts, ticket buyers and event attendees
- Exam candidate details — name, age or date of birth, grades, results and fees
- Attendance registers and class records
- Staff details — names, email addresses and login credentials for staff the school adds
- Notepads — what each user writes in their own Home notepad, seen only by them
- Notification subscriptions — if a user turns on push notifications, the browser's push endpoint and delivery keys for that device, together with the name it was registered under
We process this data solely on the school's instruction, use it for nothing else, and never sell it or use it to train machine-learning models.
4. Where data is stored
Personal data entered into DanceMate is stored in a PostgreSQL database provided by Neon, hosted in a United Kingdom data centre (AWS London, eu-west-2). Neon acts as a data-storage sub-processor. Neon is a US-headquartered company: your data itself is stored in London, and any access from outside the UK (for example for support or platform operations) is safeguarded by standard contractual clauses with the UK addendum under Neon's data processing agreement. You can read Neon's privacy policy at neon.tech/privacy-policy.
DanceMate's application runs on Vercel, which processes requests (including form submissions) as they pass through the platform; some of this processing takes place on servers in the USA, safeguarded by standard contractual clauses with the UK addendum. We use Resend to send emails — staff invitations, trial reminders, notifications and the emails schools send to their own contacts — and Resend processes recipient addresses and message content for that purpose. Resend is a US-based provider; that processing is safeguarded by standard contractual clauses with the UK addendum under Resend's data processing agreement (Resend's privacy policy).
Subscription payments are handled by Stripe (for UK merchants, Stripe Payments UK, Ltd). Card details are entered on Stripe's own hosted pages and are never seen by, or stored on, DanceMate — we hold only a customer reference, the plan, and the subscription status. Stripe may transfer payment data to Stripe, Inc. in the USA under Stripe's own safeguards — its data transfer agreements incorporating standard contractual clauses with the UK addendum (Stripe's privacy policy).
Copies of the relevant transfer safeguards are available on request from info@dancemate.co.uk.
5. Cookies, local storage and tracking
DanceMate sets no cookies of its own, uses no tracking pixels, and runs no analytics. The app keeps a small amount of information on your own device: your sign-in session, offline work waiting to sync and the app's offline copy (all strictly necessary to provide the service), plus a few device-only conveniences — like which school to open — stored in response to your own choices. Nothing on your device is used to track you, which is why there is no consent banner. The full list, including what happens on YouTube video playback and Stripe's checkout pages, is in our Cookie & Storage Policy.
6. How long we keep data
- School owner data — kept while you subscribe. After your subscription or trial ends we keep your account for up to 12 months so you can come back with everything intact, then delete it — no later than 12 months after the end. Ask sooner and we delete it within 30 days.
- School data (students, attendees, staff, etc.) — kept while the school subscribes; schools manage their own records and set their own retention policies. When the subscription ends, this data is deleted or returned as the school chooses, and in any case deleted on the same 12-month timetable above.
- Security and audit logs — purged automatically: failed sign-in logs after 90 days; the email-sending log and the account activity log after 12 months.
Deletion removes data from our live systems. Residual copies can persist in database backups (encrypted at rest by our database provider) for a short further period before being overwritten in the normal backup cycle; backups are used only for disaster recovery, and if one ever had to be restored, we would re-delete the data.
7. Who we share data with
We do not sell, rent or share personal data with anyone for marketing. Five providers are our sub-processors — they process schools' data on our behalf, under the written contracts our data processing agreement requires (its Annex B is the authoritative list):
- Neon — database storage, UK data centre (section 4)
- Vercel — application hosting and request processing (section 4)
- Resend — email delivery (section 4)
- Anthropic — AI assistance with support messages and our own operational records; it never receives the records schools store about their students (see the DPA's Annex B)
- OpenAI — text-to-speech for our own internal back-office assistant, so we can listen to its written summaries; those summaries can name a school or quote part of a support message, and it receives nothing else (see the DPA's Annex B)
Two further services receive data but are not our sub-processors: Stripe handles your school's subscription payments directly, as its own controller, and never receives the data your school stores about students (section 4); and YouTube (Google) is contacted by your own browser only if you click to play a video linked to a technique group — we send it nothing (see the Cookie & Storage Policy).
We would also disclose data if the law genuinely required it — and only what it required.
8. Children
Dance schools teach children, so the data schools store in DanceMate often includes children's names, ages and progress. For all of it, the school is the data controller and decides what is recorded; DanceMate is the processor and applies the same security to it as to everything else. We never collect information from children directly, the app has no public signup for students, and children's data is never used for anything beyond the school's own administration.
9. Your rights under UK GDPR
If we are the data controller for your data (you are a school owner), you have the right to:
- Access — request a copy of the data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data
- Restriction — ask us to limit how we use it while a concern is resolved
- Portability — receive your data in a portable format
- Object — object to processing based on legitimate interests
To exercise any of these, email info@dancemate.co.uk. We will respond within one month. If you are a student, parent or attendee, contact your dance school — they are the controller, and we will assist them.
You also have the right to complain to the Information Commissioner's Office (ICO) if you believe your data has been handled unlawfully — though we'd appreciate the chance to put it right first.
10. Security
Access to each school's DanceMate is protected by an access code chosen by the school and by individual staff logins. Data in transit is encrypted with HTTPS. The database is accessible only to the DanceMate application, using credentials never exposed to the browser, and each school's data is isolated by the application from every other school's.
To protect accounts against break-in attempts, we keep a short security log of failed sign-in attempts: the time, the type of credential tried, the outcome, where relevant which account was targeted (for example, an attempt against a removed staff login), and the requesting IP address and browser user-agent — never the value that was entered. Legal basis: our legitimate interest in keeping schools' accounts secure. These logs are deleted automatically after 90 days (section 6).
If a personal data breach ever affects your data, we will inform you without undue delay, and the ICO where the law requires it.
11. Changes to this policy
We may update this policy from time to time. The date at the top always reflects the latest version, and if a change is significant we will tell school owners by email.
12. Contact
For any privacy question or request, contact info@dancemate.co.uk, or write to Nelochem Ltd, trading as DanceMate, 20 Patten Close, Marks Tey, Colchester, Essex, CO6 1ND.
← Back to DanceMate