1. About This Policy
CinemaAI ("we", "us", or "our") is a Canadian AI creative and technology studio specialising in cinematic AI commercials, AI-generated films, website design and development, AI automation, voice AI solutions, digital marketing, and creative technology for SaaS, AI, fintech, startup, and technology companies. We provide creative, production, and digital services to clients across Canada, the United States, the United Kingdom, the European Union, and worldwide.
This policy explains how we collect, use, store, share, and protect personal data when you visit cinemaai.ca, engage our services, or communicate with us. We comply with PIPEDA and applicable Canadian provincial privacy law. Where we process the personal data of individuals located in the United Kingdom or European Union, we also comply with the UK GDPR and EU GDPR to the extent they apply.
Using our website or services means you accept the practices described here. If you disagree with any part of this policy, please do not use our website or services.
CinemaAI • Canada • hello@cinemaai.ca
2. Information We Collect
2.1 Information You Provide
When you contact us, complete a form, book a consultation, or engage our services, you may provide the following:
| Data Type | Purpose |
|---|---|
| Full name | Identifying you as a contact or client |
| Email address | Communication, proposals, and deliverables |
| Phone number | Direct communication and project coordination |
| Company name | Tailoring services to your business context |
| Website URL | Reviewing your existing digital presence |
| Job title | Understanding your role and decision-making authority |
| Project requirements | Scoping and delivering services |
| Budget information | Preparing appropriate proposals |
| Uploaded files and assets | Producing creative, development, or marketing deliverables on your behalf |
| Message content | Responding to enquiries and managing projects |
| Voice or audio recordings | Building, training, or testing voice AI solutions where a project requires it |
| System access credentials (e.g., website admin, hosting, ad accounts, CRM) | Delivering website development, automation, or digital marketing services |
2.2 Information Collected Automatically
Visiting our website automatically generates technical and behavioural data: IP address, browser type and version, device and operating system, country of access, session duration, pages viewed, referring URL, and cookie identifiers. This is collected through cookies and similar technologies, covered in Sections 5 and 6.
2.3 Client-Uploaded Assets and Business Information
Delivering a project often means clients share brand assets, images, video, audio, source code, documents, scripts, website content, or other proprietary materials ("Client Assets"). You retain all intellectual property in your Client Assets. We process them solely to deliver the agreed services — never to train our own models, and never shared beyond the providers listed in Section 9 without your consent.
Confidential business information disclosed during an engagement — strategy, financials, product roadmaps, client lists — is handled under the same confidentiality standard set out in Section 10.
2.4 System and Platform Access
Website development, automation, and digital marketing engagements sometimes require access to a client's own systems — a website admin panel, hosting account, advertising platform, analytics dashboard, or CRM. Where this is necessary, we request only the level of access the project requires, and that access is removed at the end of the engagement unless you ask us to retain it.
2.5 Information From Third Parties
We sometimes learn about you through public sources, referrals, or platforms such as LinkedIn when identifying potential clients. Where this happens, we'll tell you the source within a reasonable timeframe.
3. How We Use Your Information
3.1 Service Delivery
- Responding to enquiries and preparing quotations
- Delivering film, content, and creative production services
- Designing, developing, and maintaining client websites and software
- Building and operating automation workflows and voice AI solutions
- Planning and running digital marketing campaigns
- Managing project communication and coordination
- Processing payments and managing billing
- Scheduling consultations via Calendly
3.2 Business Operations
- Maintaining records of client engagements
- Issuing invoices and managing accounts
- Resolving disputes and enforcing agreements
- Complying with legal and regulatory obligations
3.3 Website Improvement
- Understanding how visitors use our website
- Diagnosing technical issues and monitoring performance
3.4 Marketing Communications
- Sending newsletters and service updates, where you've consented or we hold a legitimate interest
- Running targeted advertising on Meta, LinkedIn, and Google
- Measuring campaign effectiveness
3.5 AI-Powered Service Delivery
Generating content, video, copy, code, and automations using AI platforms — including OpenAI and Anthropic — by processing prompts, briefs, and uploaded materials. This includes voice AI solutions and automation workflows built for clients. Full detail is in Section 8.
3.6 Data Minimisation and Privacy by Design
We collect and retain only what's adequate, relevant, and necessary for the purposes above, anonymising or pseudonymising where we can. We aim to consider privacy throughout the design and delivery of our services and collect only the information reasonably necessary to provide those services.
4. Legal Basis for Processing
PIPEDA requires a lawful reason to process personal data, and where UK GDPR or EU GDPR apply to individuals in those jurisdictions, so do those frameworks. Here is ours, activity by activity.
| Processing Activity | UK/EU GDPR Basis | PIPEDA Equivalent |
|---|---|---|
| Responding to enquiries and delivering services | Performance of a contract | Contractual necessity |
| Processing payments | Performance of a contract | Contractual necessity |
| Marketing to existing clients | Legitimate interests | Implied consent |
| Marketing to new contacts | Consent | Express consent |
| Website analytics | Legitimate interests | Legitimate business interest |
| Advertising and retargeting | Consent | Express consent |
| Legal and regulatory compliance | Legal obligation | Legal obligation |
| Fraud prevention and security | Legitimate interests | Legitimate business interest |
| AI-powered content generation | Performance of a contract | Contractual necessity |
Where we rely on legitimate interests, we've weighed those interests against your rights and are satisfied ours don't override them. You can object to this basis at any time — see Section 14.
5. Cookies
Cookies are small files placed on your device that help us run, measure, and improve our website.
5.1 Types of Cookies We Use
| Category | Description | Examples |
|---|---|---|
| Strictly necessary | Required for the site to function; cannot be disabled | Session management, security tokens, Cloudflare |
| Functional | Remember preferences and improve usability | Theme (light/dark mode), form state |
| Analytics | Measure traffic, behaviour, and performance | Google Analytics, Microsoft Clarity |
| Marketing | Track conversions and enable targeted advertising | Meta Pixel, LinkedIn Insight Tag, Google Ads |
5.2 Managing Cookies
You can manage or remove cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website.
Where applicable, we comply with the requirements of UK PECR, the EU ePrivacy Directive, and other applicable privacy laws regarding the use of cookies and similar technologies.
6. Analytics & Tracking Technologies
We use the following services to understand website usage and marketing performance:
| Service | Provider | Purpose | Data Processed |
|---|---|---|---|
| Google Analytics 4 | Google LLC | Traffic analysis, behaviour, conversions | Anonymised IP, device data, page views, events |
| Google Search Console | Google LLC | Search performance and indexing | Aggregated search query data |
| Microsoft Clarity | Microsoft Corporation | Session recording, heatmaps, UX analysis | Anonymised session data, clicks, movement |
| Meta Pixel | Meta Platforms, Inc. | Ad conversion tracking, retargeting | IP address, browser, on-site actions |
| LinkedIn Insight Tag | LinkedIn Corporation | Ad conversion tracking, B2B analytics | LinkedIn member data where applicable, page URL |
Where these services transfer data outside the UK or EEA, we rely on the safeguards described in Section 11.
7. Marketing Communications
Where you've consented, or where we hold a legitimate interest as an existing client, we may send newsletters, case studies, service announcements, industry insights, or occasional offers.
We use Resend to deliver these emails. Every marketing message includes an unsubscribe link; you can also opt out by emailing hello@cinemaai.ca. Unsubscribing doesn't affect transactional messages tied to an active service agreement.
We do not sell, rent, or trade your contact information to third parties for their own marketing purposes.
8. AI Services & Automated Processing
AI is core to how we work, so this section sets out — specifically — what gets processed, by whom, who owns what comes out the other end, and where a human is always in the loop.
8.1 AI Platforms We Use
| Provider | Purpose | Data Processed |
|---|---|---|
| OpenAI | AI content generation, software development assistance, reasoning, automation, and workflow support | Prompts, briefs, content inputs we or clients supply |
| Anthropic | AI content generation, software development assistance, reasoning, automation, and workflow support | Prompts, briefs, content inputs we or clients supply |
Our core AI providers are currently OpenAI and Anthropic. We may use additional AI service providers where appropriate to deliver the services you request. Where we do so, we take reasonable steps to select providers that offer appropriate privacy, security, and contractual protections for the services they provide.
8.2 Prompts, Uploaded Files, and Client Assets
When we generate content on your behalf, prompts and briefs go to the provider's API to produce outputs. Where a service genuinely requires it, Client Assets — images, video, audio, source code, documents — may be submitted as inputs too. We apply data minimisation throughout: only what the task actually needs gets submitted, and we do not knowingly send sensitive personal data (health, financial, or similar) unless a specific service requires it and you've consented.
8.3 API Processing and No Model Training
OpenAI's and Anthropic's commercial API agreements provide that data submitted through their APIs is not used to train their underlying models by default. This is a materially different arrangement from consumer-facing chat products, and it's why we use commercial APIs rather than consumer tools for client work. For full detail, see the OpenAI Privacy Policy and Anthropic Privacy Policy.
8.4 Human Review and Automated Decision-Making
We do not make decisions about you solely by automated means where those decisions would have a legal or similarly significant effect. AI-generated outputs intended for clients are reviewed by CinemaAI before they are delivered. AI assists our work, but important deliverables are subject to human review.
8.5 Ownership of Outputs
Content generated with AI tools in the course of your project is created by CinemaAI on your behalf. All intellectual property in delivered outputs transfers to you on full payment, per your service agreement. We may keep anonymised or non-identifiable examples of the work for our own portfolio unless you ask us in writing not to. You retain full IP in every Client Asset you give us — see Section 2.3.
8.6 Voice AI Solutions
Where a project involves building a voice AI solution, we may process voice or audio recordings to develop, configure, or test that solution — for example, a client's own reference audio, or call recordings used to refine a voice agent's responses. This audio is processed only for the purposes of the engagement and is not used to train our own general-purpose models. Where end users interact with a voice agent we've built for a client, the client is the data controller for that interaction, and CinemaAI acts as data processor — see Section 8.7.
8.7 AI Chatbots, Voice Agents, and Automation Workflows
Where we build a chatbot, voice agent, or automation workflow as part of a client engagement, personal data collected or processed by that tool's end users is governed by the relevant client's own privacy policy — the client is the data controller for that processing, and CinemaAI acts as data processor. Automation workflows may connect to a client's own systems (for example, a CRM, email platform, or website) to move data between them; we configure these connections to process only the data necessary for the workflow the client has requested.
9. Data Sharing & Third-Party Providers
We do not sell your personal data. We share personal data only with trusted third-party providers where necessary to deliver our services or operate our website. Where applicable, these providers process data under contractual terms or data processing agreements appropriate to the services they provide. Personal data may also be shared where Sections 9.2 and 9.3 apply.
9.1 Service Providers
The table below covers tools and platforms CinemaAI itself uses to run its business and deliver services. It does not include a client's own website, hosting, advertising accounts, or CRM — where a project requires us to access those, Section 2.4 explains how that access works.
| Provider | Role | Data Processed |
|---|---|---|
| Cloudflare | CDN, DDoS protection, DNS, security | IP address, request metadata |
| Vercel | Website hosting and deployment | Request logs, IP address |
| GitHub | Code repository and development infrastructure | No personal data from site visitors |
| Google Workspace | Email, documents, project communication | Client contact data, emails, documents |
| Microsoft 365 | Business productivity and collaboration | Client contact data, documents |
| Stripe | Payment processing | Name, email, billing address, payment details |
| Calendly | Meeting scheduling | Name, email, calendar availability |
| Resend | Transactional and marketing email delivery | Name, email address, email content |
| Google Analytics | Website analytics | Anonymised visitor data |
| Microsoft Clarity | UX analytics and session recording | Anonymised session data |
| Meta Platforms | Advertising and conversion tracking | Hashed identifiers, behavioural data |
| Advertising and B2B analytics | Hashed identifiers, page interaction data | |
| OpenAI | AI content generation | Prompts and content inputs |
| Anthropic | AI reasoning and generation | Prompts and content inputs |
| YouTube (Google LLC) | Video hosting and portfolio embedding | Viewer IP, device data if embedded |
| Vimeo | Video hosting and portfolio embedding | Viewer IP, device data if embedded |
This list changes as our stack evolves. If you need the current version for procurement or due diligence, email hello@cinemaai.ca.
9.2 Legal Disclosure
We may disclose personal data where the law, a court order, or a regulator requires it, or to protect the rights, property, or safety of CinemaAI, our clients, or the public.
9.3 Business Transfers
If CinemaAI is acquired, merged, or sells assets, personal data may transfer to the successor entity, which will continue to honour the commitments in this policy. We'll notify affected individuals.
10. Client Confidentiality
Beyond data protection law, we treat everything a client shares with us as confidential by default. This includes:
- Unreleased campaigns, films, and creative concepts
- Investor materials, decks, and fundraising narratives
- Prompts, briefs, and internal direction given to our team
- Uploaded assets — brand materials, footage, audio, source code, documents, and data
- Access credentials and any systems we're granted access to during a project
- Internal business information: strategy, financials, product roadmaps, marketing performance data, and client lists
We use this information only to deliver the agreed services. We do not reference unreleased client work in our own marketing, portfolio, or case studies without written permission, and we do not disclose it to any party outside the providers listed in Section 9. This obligation survives the end of an engagement.
11. International Transfers
CinemaAI is based in Canada. Many of our service providers operate in the United States, the United Kingdom, and other countries, so your personal data may be processed or stored outside Canada.
United States — Google, Meta, Microsoft, OpenAI, Anthropic, Stripe, Calendly, Vercel, GitHub, Resend, and Vimeo all operate infrastructure in the United States. United Kingdom and European Union — where a provider or a client engagement involves individuals in the UK or EU, we take reasonable steps to apply appropriate safeguards, such as Standard Contractual Clauses or UK International Data Transfer Agreements, where those frameworks apply to the transfer.
Under PIPEDA, we remain accountable for personal data we transfer to third parties for processing, regardless of where that processing takes place, and we select providers on that basis.
Email hello@cinemaai.ca for detail on any specific transfer.
12. Data Security
We apply technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure:
- HTTPS encryption across our website, enforced via Cloudflare
- Access controls and role-based permissions on internal systems
- Payment processing through Stripe — we never store full card data
- Encryption of data in transit and at rest where applicable
- Confidentiality obligations on everyone with access to personal data
- Multi-factor authentication on supported business systems, including GitHub and Cloudflare
Access to client information is restricted to authorised personnel involved in delivering the requested services.
No transmission over the internet is completely secure, and we can't guarantee absolute protection. Our breach response procedure is set out in Section 17.
13. Data Retention
We keep personal data only as long as the purpose it was collected for requires — including legal, accounting, and reporting obligations.
| Data Category | Retention Period | Reason |
|---|---|---|
| Client contact and project data | 7 years after project completion | Tax and legal record-keeping requirements |
| Financial and billing records | 7 years | Legal obligation |
| Marketing contact data (non-client) | 3 years, or until opt-out | Legitimate interests |
| Website analytics data | 26 months | Google Analytics default retention |
| Enquiry data (not converted) | 12 months | Legitimate interests |
| Client-uploaded assets | Duration of engagement plus 90 days, unless otherwise agreed | Service delivery and handover |
| System access credentials | Removed at end of engagement, unless retention is requested | Limiting access to the active project period |
| Voice and audio recordings | Duration of engagement, unless otherwise agreed | Voice AI development and testing |
| Cookie data | Up to 13 months | Analytics and functionality |
Once data is no longer needed, we delete or anonymise it. Fully anonymised data that cannot be re-identified may be kept indefinitely for aggregated reporting.
14. Your Privacy Rights
14.1 Rights Under PIPEDA (Canada)
As a Canadian business, CinemaAI is primarily accountable under PIPEDA. Canadian residents can access their personal information, challenge its accuracy and have it corrected, withdraw consent subject to legal or contractual limits, and complain to the Office of the Privacy Commissioner of Canada.
14.2 Rights Under UK GDPR and EU GDPR
Where UK GDPR or EU GDPR apply to your personal data, you also have the following rights:
| Right | What It Means |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Correct inaccurate or incomplete data |
| Erasure | Request deletion in certain circumstances |
| Restriction | Limit how we process your data while a dispute is resolved |
| Portability | Receive your data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interests or direct marketing |
| Automated decisions | Not be subject to solely automated decisions with significant effect |
| Withdraw consent | Withdraw at any time where processing is consent-based |
14.3 Exercising Your Rights
Email hello@cinemaai.ca to exercise any of the above. We respond within 30 days (PIPEDA) or within one calendar month where UK/EU GDPR applies, and may ask you to verify your identity first.
Canadian residents unsatisfied with our response can complain to the Office of the Privacy Commissioner of Canada: priv.gc.ca. UK residents can complain to the Information Commissioner's Office: ico.org.uk. EU residents can complain to their local supervisory authority.
15. Children's Privacy
Our website and services are directed at businesses and professionals. We don't knowingly collect personal data from children under 16 (13 in Canada). If we learn we've inadvertently done so, we'll delete it promptly — contact hello@cinemaai.ca if you believe this has happened.
16. Third-Party Websites
Our website may link to or embed third-party content, including YouTube and Vimeo videos. We're not responsible for their privacy practices — review their policies directly: Google / YouTube, Vimeo. Embedded videos may set their own cookies and collect viewing data.
17. Data Breach Procedures
If a personal data breach occurs, we will:
- Contain and assess the breach as soon as we identify it
- Notify the Office of the Privacy Commissioner of Canada and affected individuals where the breach creates a real risk of significant harm, as required under PIPEDA
- Where UK GDPR or EU GDPR apply, notify the ICO or the relevant EU supervisory authority within 72 hours where the breach risks individuals' rights and freedoms
- Notify affected individuals without undue delay where the risk is high
- Document the breach and the remedial steps taken
Suspect your data's been compromised? Contact us immediately at hello@cinemaai.ca.
18. Changes to This Policy
We review this policy regularly and update it as our practices or the law changes. Material changes update the "Last updated" date above and, where appropriate, come with an email notice or a notice on our website. Continued use of our website or services after a change means you accept the revised policy. Earlier versions are available on request.
19. Contact
Questions, concerns, or requests about this policy or how we handle your data:
CinemaAIWebsite: cinemaai.ca
Email: hello@cinemaai.ca
We aim to respond to privacy enquiries within 5 business days, and to fulfil formal requests within the legally required timeframe.
Canadian residents: Office of the Privacy Commissioner of Canada — priv.gc.ca. UK residents: Information Commissioner's Office — ico.org.uk.