CINEMAFON PERSONAL DATA PROTECTION AND PRIVACY POLICY
(Compliant with GDPR & UK DPA 2018)
Data Controller : Cinemafon Limited (Registered in the UK, address: IP28 7DE Suffolk).
Data Processors : Sub-processors under GDPR Article 28 (list available upon request).
Collected Data :
Identity (name, surname), contact (email, phone), financial (IBAN, payment history), technical (IP, cookies).
Collection Channels :
Purpose | Legal Basis | Retention Period |
---|---|---|
Contract execution (membership) | Contract performance (6/1/b) | 10 years |
Legal obligation (tax, FCA) | Legal compliance (6/1/c) | As required by law |
Marketing (newsletter) | Explicit consent (6/1/a) | Until consent withdrawal |
Analytics (Google Analytics) | Legitimate interest (6/1/f) | 26 months |
Within UK/EU:
Transfers Outside EU:
Only under GDPR Articles 45-46 via:
Essential Cookies : Session management (non-optional).
Requests to: info@cinemafon.com (responded within 30 days).
Appendix 1: Sub-Processor List (GDPR Article 28)
Cinemafon Limited engages the following sub-processors. This list is available electronically upon request:
Sub-Processor | Service | Purpose | Location | Compliance |
---|---|---|---|---|
Stripe Payments UK Ltd | Payment processing | Secure payment gateway | UK | PCI-DSS, GDPR |
Google Cloud Europe Ltd | Data hosting | Server storage | Netherlands | SCC, ISO 27001 |
Mailchimp (Intuit) | Email marketing | Newsletters | USA | SCCs + BCRs |
(GDPR Article 46 & UK IDTA)
Transfer Mechanism: European Commission’s 2021/914 SCCs.
Key Safeguards:
Declaration
"Cinemafon Limited is registered with the UK ICO and has appointed a DPO under GDPR Article 37."
"I consent to the processing of my personal data under the above terms."
[✔️] I Agree
[ ] I Disagree