Privacy Policy

Version 1.0 · Published on 18 March 2026

Privacy Policy / Politique de confidentialité

Version : 1.0 Effective date : March 17, 2026 Platform : TIMELESS — timeless.film Data Controller : TIMELESS CINEMA — SAS, SIREN 992 965 392


1. Introduction

TIMELESS CINEMA ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, how long we retain it, and what rights you have under applicable data protection law — in particular the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and the French Data Protection Act (Loi Informatique et Libertés).

This Policy applies to all Users of the TIMELESS platform (timeless.film, app.timeless.film), whether acting on behalf of an Exhibitor or a Rights Holder Account.

By accepting these terms at registration, you acknowledge having read and understood this Privacy Policy.


2. Data Controller

TIMELESS CINEMA Société par Actions Simplifiée (SAS) SIREN : 992 965 392 | SIRET : 992 965 392 00010 46 Rue Rouget de Lisle, 92800 Puteaux, France Publication Director : Leslie Vuchot

Contact for privacy matters: hello@timeless.film


3. Personal Data We Collect

3.1 Data You Provide Directly

CategoryDataCollected when
IdentityFirst name, last nameUser registration
ContactEmail addressUser registration
AuthenticationPassword (hashed — bcrypt), MFA/TOTP secret (encrypted)Registration / MFA activation
Language preferencePreferred locale (en or fr)Profile settings (used for email communications)
OrganisationCompany name, country, address, city, postal code, VAT numberAccount onboarding
Professional contextCinema type, contact email, contact phoneAccount settings
Cinema detailsCinema name, address, room capacity, projection typeExhibitor onboarding and account management
Financial (Rights Holders)Bank account details, identity documents via Stripe Connect KYCStripe Connect onboarding
CommunicationsNotes on screening requests, support messagesPlatform use

3.2 Data Collected Automatically

CategoryDataCollected when
TechnicalIP address, browser User-Agent, device typeEach authenticated request
Consent recordsTerms of Service / Terms of Sale acceptance: timestamp (UTC), IP, User-Agent, document versionEach acceptance event
SessionSession tokens, active account cookie, authentication stateLogin and navigation
UsagePages visited, actions taken (cart additions, request submissions, validations), search queriesPlatform use
API usageAPI token last-used timestamp, endpoint accessedAPI calls

3.3 Data from Third Parties

SourceDataPurpose
StripePayment status, charge ID, transfer ID, KYC verification status (Rights Holders), payout historyPayment processing and financial operations
Stripe TaxTax calculation, applicable VAT rate per transactionTax compliance
TMDB (The Movie Database)Film metadata, posters, cast and crew informationCatalogue enrichment — no personal data is sent to TMDB

4. Purposes and Legal Bases

PurposeData usedLegal basis (GDPR)
User account creation and authenticationIdentity, contact, authentication dataPerformance of contract (Art. 6.1.b)
Account organisation management (members, roles, invitations)Identity, contact, rolePerformance of contract (Art. 6.1.b)
Exhibitor onboarding (cinema and room data)Organisation, cinema detailsPerformance of contract (Art. 6.1.b)
Rights Holder onboarding (Stripe Connect KYC)Identity, financial dataLegal obligation + performance of contract (Art. 6.1.b, 6.1.c)
Processing Transactions (Screening Requests, payments, payouts)Identity, organisation, financial, request dataPerformance of contract (Art. 6.1.b)
DCP/KDM delivery coordinationIdentity, cinema details, order dataPerformance of contract (Art. 6.1.b)
Sending transactional emailsEmail, identity, transaction data, preferred localePerformance of contract (Art. 6.1.b)
Sending tokenised validation emails to Rights HoldersEmail, preferred locale, JWT token containing request ID and user IDPerformance of contract (Art. 6.1.b)
Recording Terms acceptance (proof of consent)Consent records (IP, User-Agent, timestamp, version)Legal obligation (Art. 6.1.c)
VAT calculation and invoicingIdentity, organisation, VAT number, transaction dataLegal obligation (Art. 6.1.c)
Platform security and fraud preventionIP, User-Agent, session data, API token usageLegitimate interests (Art. 6.1.f)
Platform analytics and improvementUsage data (anonymised where possible)Legitimate interests (Art. 6.1.f) — or consent for non-essential cookies
Legal dispute resolution and audit trailsAll relevant dataLegitimate interests (Art. 6.1.f)

5. Cookies and Tracking Technologies

5.1 Essential Cookies

These cookies are strictly necessary for the Platform to function. They cannot be disabled.

CookiePurposeDuration
Session tokenMaintains your authenticated session (Better Auth)30 days (refreshed every 24h)
active_account_idRemembers your currently selected AccountSession
CSRF tokenProtects against cross-site request forgerySession

5.2 Analytics Cookies (opt-in)

With your explicit consent, we may use analytics cookies to understand how Users interact with the Platform. These are only loaded after you opt in via the cookie consent banner.

5.3 Marketing Cookies (opt-in)

With your explicit consent, we may use marketing cookies to measure campaign effectiveness. These are only loaded after you opt in.

5.4 Cookie Consent

A cookie consent banner is displayed on your first visit to the Platform. Your consent choices are stored for 13 months (in line with CNIL recommendations). You can modify your preferences at any time via the "Manage cookies" link in the footer.

Refusing analytics and marketing cookies has no impact on your ability to use the Platform's core features.


6. Data Sharing and Sub-processors

We do not sell your personal data to third parties.

We share personal data with the following sub-processors as strictly necessary to provide the Services:

Sub-processorPurposeCountrySafeguard
Stripe, Inc.Payment processing, KYC verification (Rights Holders), payoutsUSAStandard Contractual Clauses (SCCs)
Resend, Inc.Transactional email deliveryUSAStandard Contractual Clauses (SCCs)
Scaleway SASCloud hosting, managed PostgreSQL database, file storage (DCP delivery)France / EUGDPR applies directly
TMDBFilm metadata API — no personal data is transmittedUSANo personal data transferred
Legal / judicial authoritiesIf required by applicable law or court orderAs applicableLegal obligation

All sub-processors outside the EEA are subject to appropriate safeguards in accordance with GDPR Chapter V (Standard Contractual Clauses or adequacy decisions).


7. Data Retention

Data categoryRetention periodJustification
Active User account dataDuration of active accountNecessary for the service
Data after account closure3 years post-closurePotential legal disputes
Transaction and order records10 yearsFrench commercial law (Code de commerce, Art. L123-22)
Invoicing and financial data10 yearsFrench tax law
Terms of Service acceptance records5 years from last acceptanceProof of consent obligations
Terms of Sale acceptance records5 years from last acceptanceProof of consent obligations
IP address and security logs12 monthsSecurity and fraud prevention
Cookie consent records13 monthsCNIL recommendation
Support communications3 years from resolutionDispute handling
API token metadata (hash, last used)Duration of token existence + 12 months after revocationSecurity audit

After the applicable retention period, data is securely deleted or anonymised.


8. Data Security

We implement appropriate technical and organisational measures to protect your personal data:

  • Passwords are hashed using bcrypt — plaintext passwords are never stored;
  • MFA/TOTP secret keys are encrypted at rest;
  • All data in transit is protected by TLS 1.2+;
  • Database access is restricted to authorised infrastructure components on a private network (Scaleway);
  • Multi-factor authentication (MFA/TOTP) is available to all Users and strongly recommended;
  • API tokens are stored exclusively as SHA-256 hashes — the plaintext token is shown only once;
  • Access to personal data within TIMELESS CINEMA is restricted to personnel with a legitimate operational need;
  • Session tokens can be individually revoked by the User at any time.

In the event of a personal data breach likely to risk your rights and freedoms, we will notify the CNIL (French supervisory authority) within 72 hours and affected individuals as required by GDPR Articles 33–34.


9. Your Rights

Under GDPR, you have the following rights with respect to your personal data:

RightDescriptionHow to exercise
Access (Art. 15)Obtain a copy of the personal data we hold about youEmail hello@timeless.film
Rectification (Art. 16)Request correction of inaccurate or incomplete dataEmail hello@timeless.film or update in Profile settings
Erasure (Art. 17)Request deletion of your data ("right to be forgotten"), subject to legal retention obligationsEmail hello@timeless.film
Restriction (Art. 18)Request that we limit processing of your data in certain circumstancesEmail hello@timeless.film
Portability (Art. 20)Receive your data in a structured, machine-readable formatEmail hello@timeless.film
Objection (Art. 21)Object to processing based on legitimate interestsEmail hello@timeless.film
Withdraw consent (Art. 7.3)Withdraw consent for consent-based processing (e.g. analytics cookies) at any timeManage cookies link in the footer

We will respond to all rights requests within 30 days. Response may be extended to 60 days for complex requests, with notice.

You also have the right to lodge a complaint with the competent supervisory authority:

CNIL — Commission Nationale de l'Informatique et des Libertés 3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07 www.cnil.fr


10. International Data Transfers

Some of our sub-processors (Stripe, Resend) are located in the United States. Data transfers to these processors are conducted under the European Commission's Standard Contractual Clauses (SCCs), ensuring an equivalent level of data protection to that provided within the EEA.

TIMELESS CINEMA's primary hosting infrastructure (Scaleway) is located in France and falls within the scope of GDPR directly.


11. Automated Decision-Making

We do not use fully automated decision-making processes that produce legal or similarly significant effects for our Users.


12. Children

The Platform is exclusively B2B and is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors.


13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via the Platform and/or by email. Your continued use of the Platform following notification of changes constitutes acceptance of the updated Policy.

The current version is always accessible at timeless.film/privacy.


14. Contact

For any privacy-related enquiry or to exercise your rights:

TIMELESS CINEMA 46 Rue Rouget de Lisle, 92800 Puteaux, France hello@timeless.film


Last updated: March 17, 2026 Version: 1.0