Showcase legal
Last updated 10 September 2026
Showcase™ turns a company’s filmed content into posts its people can schedule and publish from their own accounts. Every person has their own login. Every connection to LinkedIn, Instagram or a file store is made by its owner and can be removed by them. Nothing publishes unless a person schedules it. This page says where the data lives, how it is protected, and what we do not yet offer, so an IT team can assess it without a call.
Account data, workspace data, transcripts and post text are held in a managed PostgreSQL database in the European Union (Frankfurt), on a paid tier with automated daily backups retained for seven days. Films and clips are hosted on a global video delivery network, with playback restricted to Showcase domains. The application layer runs on a global hosting network; server code may execute in the United States. AI drafting sends the content involved in each request to providers in the United States and receives the draft back. Transfers outside the UK rely on the UK International Data Transfer Agreement or Addendum and, where applicable, adequacy decisions. The full list of providers is in section 12.
All traffic is encrypted in transit with TLS, and the service sends HTTP Strict Transport Security with preload so a browser will not connect any other way. Data at rest is encrypted by the database and storage providers. Access tokens for connected accounts are additionally encrypted in the application with AES-256-GCM under a key held outside the database, so a copy of the database alone does not yield a usable token.
Each person has an individual account with an email address and a password of at least eight characters, set by the person on first use and changed through an emailed reset link. There are no shared logins. People who appeared in a film and are invited as guests sign in through an emailed link and see only the episode they were on. Sessions use short-lived tokens that are refreshed while the person is active. An account an administrator deactivates is refused at the next request.
Multi-factor authentication and single sign-on (Microsoft Entra, Google Workspace, SAML) are not offered today. Both are on the roadmap; a client that needs one should raise it before rollout so it can be scheduled.
Access is scoped by role and workspace and enforced in the database with row-level security, not only in the interface. A Director sees their company’s workspace. An Ensemble seat or Viewer sees the company’s Showcases and their own posts, never a colleague’s drafts. A guest sees one episode. A production partner reaches only the clients they deliver to. Showcase staff administer the platform and act within a client’s workspace only to support it. Personal posts belong to their author: a reviewer can approve or ask for changes, and cannot publish as another person.
Showcase never asks for a platform password. Each connection is made by the account holder through that platform’s own consent screen, with the narrowest permissions the feature needs: LinkedIn (profile, email address, and posting on the person’s behalf); Dropbox (reading the folders a producer maps); Vimeo and YouTube (uploading to the connected account); Instagram (reading the connected professional account and publishing to it). Disconnecting inside Showcase deletes the stored token, and the person can also revoke Showcase from the platform’s own settings. Showcase does not read a person’s feed, messages, contacts or analytics.
Posts are drafted from the transcript, the workspace’s brand context and, for personal posts, the person’s own voice notes. The content involved in a request is sent to the AI provider for that request and is not used by us or by the provider to train models. Usage is metered per client and per seat, and an administrator can pause AI for a client instantly while the rest of the service stays up.
Films are served through a video delivery network and play only on Showcase domains; the embed refuses to load elsewhere. A show’s pages are visible to the workspace’s team by default. A public link is a setting a Director or producer turns on deliberately; when on, the page is reachable by anyone with the address, is never indexed by search engines, and can be turned off again at any time.
Every response carries a Content Security Policy that names the only origins scripts, frames and media may load from; frames are limited to Showcase itself; content type sniffing is disabled; the referrer policy is strict-origin-when-cross-origin; and the camera, microphone and location APIs are switched off. Only essential cookies are set: session authentication and security.
Content and account data are kept for the life of the customer relationship, then deleted or returned as the agreement provides, with an export available on request within 30 days of termination. Deleting a post removes it from Showcase; it does not recall anything already published to a platform. Disconnecting an account deletes its token at once. A person can ask for their personal data to be deleted by writing to the address below, and a request from a customer’s administrator is honoured for their own people.
The service is deployed continuously from a reviewed code repository; dependencies are kept current; server logs and error reports are monitored and retained for a limited period. Scheduled publishing runs on a fixed timetable and only sends what a person has approved and dated. We have not yet commissioned an independent penetration test or held a certification such as ISO 27001 or SOC 2; we will say so on a questionnaire rather than imply otherwise, and we will complete a client’s security questionnaire on request.
Suspected vulnerabilities and incidents should be reported to david@frontandcentre.com. If a breach affects personal data we notify affected customers without undue delay and the Information Commissioner’s Office within 72 hours where the law requires it, with what happened, what data was involved and what we have done.
Vercel (application hosting). Supabase (database, authentication and file storage, EU region). Cloudflare (video hosting and delivery). Anthropic and OpenAI (AI drafting and search). Deepgram (speech-to-text for transcripts). Resend (transactional email such as sign-in links). Platforms a person connects themselves (Dropbox, Vimeo, YouTube, LinkedIn, Instagram, Google or Microsoft services) receive data on that person’s instruction under their own terms. The privacy policy carries the legal basis for each.
Showcase is operated by Front&Centre®, a trading name of Neuro Spicy Ltd (England and Wales, company number 15218263). Security and data questions, questionnaires and data requests: david@frontandcentre.com. We aim to answer within five working days and data-subject requests within a month.