Privacy Policy
This Privacy Policy explains how we collect, use, share and protect personal data when you visit www.cinemabide.com or use the Cinemabide application at app.cinemabide.com (together, the “Service”).
1. Who we are
Aske Soluzio Informatikoa S.L. (“Aske”, “we”, “us”)
VAT / Tax ID: ESB95459152
C/ Mayor 17, 4º derecha, 48930 Areeta-Getxo, Bizkaia, Basque Country, Spain
Email: privacy@cinemabide.com · hello@cinemabide.com
Phone: +34 688 602 331
We are established in Spain and process personal data under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and Spanish Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD).
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy questions go to the address above and are handled by our management team.
2. Two different roles: controller and processor
Which role we play depends on the data, and it changes your point of contact:
- We are the controller for data about our own relationship with you — your account, your organisation’s billing details, website visits, support enquiries and marketing communications. This Policy governs that processing.
- We are a processor for the content our customers put into their workspace — production records, cast and crew details, contacts, contracts, call sheets, uploaded documents and similar material. The customer (normally the production company that owns the workspace) is the controller and decides why and how that data is processed. We act on their documented instructions. If your details are in a production company’s Cinemabide workspace and you want them corrected or removed, contact that company; we will support them in answering you, and we will pass your request on if you contact us instead.
3. Personal data we collect
3.1 Data you give us
- Account data — name, email address, password (stored only as a salted hash, never in readable form), preferred language, and multi-factor authentication settings.
- Sign-in via Google or Microsoft — if you create an account with one of these providers, we receive your name, email address and account identifier from them. We never receive your password.
- Organisation and billing data — company name, account type, VAT or tax number, postal address, postal code and billing email address. If and when you subscribe to a paid plan, payment card details are collected and processed directly by our payment provider; we never see or store your full card number. No payment details are collected during the free launch period.
- Workspace content — everything you or your colleagues enter into the application, including productions, cast, crew, locations, equipment, contracts, funding deals, festival submissions, distribution and marketing records, and any files you upload. We process this as a processor (see section 2).
- Communications — the name, email address, subject and message you send through our contact form, plus any correspondence by email or phone.
- Newsletter — your email address, if you subscribe.
3.2 Data collected automatically
- Technical and security logs — IP address, date and time, browser and device type, pages or API endpoints requested, and outcome. These are generated by our web and application servers.
- Session data — session and authentication tokens that keep you signed in.
- Usage analytics — aggregate statistics about how the marketing website is used, where consent has been given (see section 6).
- Push notification subscriptions — if you enable browser notifications, an endpoint identifier issued by your browser vendor.
We do not knowingly collect special categories of data (Article 9 GDPR) about website visitors or account holders, and we ask that you do not enter such data into free-text fields unless it is genuinely necessary for the production.
4. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Creating and running your account and workspace; providing the Service | Account, organisation, workspace content | Performance of a contract (Art. 6(1)(b)) |
| Authentication, multi-factor codes, password resets | Account, session, technical | Performance of a contract (Art. 6(1)(b)) |
| Service emails — verification, password reset, notices about changes | Account | Performance of a contract (Art. 6(1)(b)) |
| Billing, invoicing and tax records | Organisation, billing | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Answering enquiries sent through the contact form or by email | Communications | Legitimate interests — responding to those who contact us (Art. 6(1)(f)) |
| Security, abuse prevention, rate limiting, diagnostics and backups | Technical logs | Legitimate interests — keeping the Service secure and available (Art. 6(1)(f)) |
| Improving the Service and understanding aggregate usage | Analytics | Consent (Art. 6(1)(a)) |
| Newsletter and product announcements | Email address | Consent (Art. 6(1)(a)), withdrawable at any time |
| Optional AI assistance and search features | The content you submit to the feature | Performance of a contract (Art. 6(1)(b)); see section 7 |
| Establishing, exercising or defending legal claims | As relevant | Legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You may object to that processing at any time (see section 11).
5. Who we share personal data with
We do not sell personal data, and we do not share it for third-party advertising. We disclose it only to:
- Members of your own workspace — your colleagues see the content in the workspace according to the roles and permissions your organisation sets.
- Service providers acting as our processors, listed below, each bound by a written data processing agreement under Article 28 GDPR.
- Professional advisers — accountants, auditors and lawyers, where necessary and under a duty of confidentiality.
- Public authorities, where we are legally required to disclose.
- An acquirer, if the business or the relevant part of it is merged, acquired or reorganised; we will notify you before your data becomes subject to a different privacy policy.
5.1 Our processors
| Provider | Purpose | Location |
|---|---|---|
| IONOS SE | Server hosting, database and backups for the website and application | European Union |
| Google Ireland Ltd. | Google Analytics on the marketing website (consent-based); “Sign in with Google”, if you use it | EU, with transfers to the USA |
| Microsoft Ireland Operations Ltd. | “Sign in with Microsoft”, if you use it | EU, with transfers to the USA |
| OpenAI Ireland Ltd. | Language-model processing behind optional AI features (section 7) | EU, with transfers to the USA |
| Stripe Payments Europe Ltd. | Payment and subscription processing for paid plans — inactive during the free launch period | Ireland, with transfers to the USA |
Outgoing email is sent from our own mail server on our own infrastructure; message content is not handed to a third-party email marketing platform. Our vector search index is self-hosted alongside the application.
We keep this list current. If we add a processor that materially changes how your data is handled, we will update this Policy and, where required, tell you in advance.
6. Cookies and similar technologies
We use the smallest set of cookies and local storage that lets the Service work:
- Strictly necessary — session and authentication cookies and tokens that sign you in, keep you signed in and protect against request forgery. These cannot be switched off, and are set on the basis of Article 22.2 of Spanish Law 34/2002 (LSSI-CE) without consent.
- Preferences — local storage entries that remember your chosen language and whether you have dismissed a site notice, so we do not show it again.
- Analytics — Google Analytics, set only where analytics is enabled for the site and you have consented. You can withdraw consent at any time through the cookie controls or by clearing cookies in your browser.
Most browsers let you block or delete cookies. Blocking strictly necessary cookies will prevent you from signing in.
7. Artificial intelligence features
Some parts of the Service offer optional AI assistance — for example summarising or searching your own production records. When you use such a feature:
- The relevant content is sent to a language-model provider (currently OpenAI) to generate a response, and is transmitted encrypted in transit.
- We use these providers on business terms under which submitted content is not used to train their models, and is retained only briefly for abuse monitoring before deletion.
- Search indexes derived from your content are stored on our own infrastructure, inside your workspace’s boundary.
- No decision producing legal or similarly significant effects about you is made solely by automated means (Article 22 GDPR). AI output is a suggestion for a human to review, never a final decision.
If you would rather not send content to a language-model provider, do not use the AI features; the rest of the Service works without them.
8. International transfers
Our servers and your workspace data are in the European Union. Some of the providers listed in section 5.1 may process limited data outside the European Economic Area, principally in the United States. Where that happens, the transfer is covered by appropriate safeguards under Chapter V GDPR — the European Commission’s Standard Contractual Clauses, together with supplementary technical measures such as encryption, and, where applicable, the provider’s certification under the EU–US Data Privacy Framework. You can request a copy of the relevant safeguards from us.
9. How long we keep it
| Data | Retention |
|---|---|
| Account and workspace content | For as long as the account is active, then deleted within 90 days of the account being closed, unless the workspace owner asks for earlier deletion |
| Backups | Rolling backups overwritten within 90 days |
| Invoices and accounting records | Retained as required by Spanish commercial and tax law, generally 6 years (Commercial Code) and up to 10 years for anti-money-laundering purposes where applicable |
| Contact form and support correspondence | Up to 2 years after the matter is closed |
| Security and access logs | Up to 12 months |
| Newsletter subscription | Until you unsubscribe |
Where we are a processor, retention is set by the customer that controls the workspace, within the periods above.
10. How we protect it
We apply technical and organisational measures appropriate to the risk, including: encryption in transit (HTTPS/TLS), passwords stored only as salted hashes, optional multi-factor authentication, role-based access control within each workspace, strict separation between customer workspaces, least-privilege access for our staff, security review of dependencies in our build pipeline, regular backups, and logging of administrative access. No system is perfectly secure, but we will notify you and the Spanish Data Protection Agency of a personal data breach where the GDPR requires it.
11. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectify data that is inaccurate or incomplete.
- Erase your data (“right to be forgotten”) where the conditions in Article 17 are met.
- Restrict processing in the circumstances set out in Article 18.
- Portability — receive the data you provided in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible.
- Object to processing based on legitimate interests, and to direct marketing at any time and without justification.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise any of these, email privacy@cinemabide.com or write to the postal address in section 1. We may ask for proof of identity where we have reasonable doubt about who is making the request. We answer within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. Exercising these rights is free of charge unless a request is manifestly unfounded or excessive.
If you believe we have handled your data incorrectly, we would like the chance to put it right — but you always have the right to complain to the Spanish Data Protection Agency, Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid, www.aepd.es, or to the supervisory authority where you live or work.
12. Children
The Service is intended for professional use and is not directed at children. We do not knowingly create accounts for anyone under 14, the age of digital consent in Spain. Where a production involves minors, the production company is responsible for obtaining the parental or guardian consent required by law before entering their data.
13. Changes to this Policy
We may update this Policy as the Service develops or the law changes. The “last updated” date at the top always reflects the current version. If a change materially affects your rights, we will notify account holders by email or in the application at least 30 days before it takes effect.
14. Contact
Questions, requests and complaints about privacy: privacy@cinemabide.com, or Aske Soluzio Informatikoa S.L., C/ Mayor 17, 4º derecha, 48930 Areeta-Getxo, Bizkaia, Spain.