Privacy Policy

Last updated: 30 July 2026

Privacy at a Glance

1. About This Policy

CinemaAI ("we", "us", or "our") is a Canadian AI creative and technology studio specialising in cinematic AI commercials, AI-generated films, website design and development, AI automation, voice AI solutions, digital marketing, and creative technology for SaaS, AI, fintech, startup, and technology companies. We provide creative, production, and digital services to clients across Canada, the United States, the United Kingdom, the European Union, and worldwide.

This policy explains how we collect, use, store, share, and protect personal data when you visit cinemaai.ca, engage our services, or communicate with us. We comply with PIPEDA and applicable Canadian provincial privacy law. Where we process the personal data of individuals located in the United Kingdom or European Union, we also comply with the UK GDPR and EU GDPR to the extent they apply.

Using our website or services means you accept the practices described here. If you disagree with any part of this policy, please do not use our website or services.

Privacy & Data Requests

CinemaAI Canada hello@cinemaai.ca

2. Information We Collect

2.1 Information You Provide

When you contact us, complete a form, book a consultation, or engage our services, you may provide the following:

Voluntarily Provided Personal Data
Data TypePurpose
Full nameIdentifying you as a contact or client
Email addressCommunication, proposals, and deliverables
Phone numberDirect communication and project coordination
Company nameTailoring services to your business context
Website URLReviewing your existing digital presence
Job titleUnderstanding your role and decision-making authority
Project requirementsScoping and delivering services
Budget informationPreparing appropriate proposals
Uploaded files and assetsProducing creative, development, or marketing deliverables on your behalf
Message contentResponding to enquiries and managing projects
Voice or audio recordingsBuilding, training, or testing voice AI solutions where a project requires it
System access credentials (e.g., website admin, hosting, ad accounts, CRM)Delivering website development, automation, or digital marketing services

2.2 Information Collected Automatically

Visiting our website automatically generates technical and behavioural data: IP address, browser type and version, device and operating system, country of access, session duration, pages viewed, referring URL, and cookie identifiers. This is collected through cookies and similar technologies, covered in Sections 5 and 6.

2.3 Client-Uploaded Assets and Business Information

Delivering a project often means clients share brand assets, images, video, audio, source code, documents, scripts, website content, or other proprietary materials ("Client Assets"). You retain all intellectual property in your Client Assets. We process them solely to deliver the agreed services — never to train our own models, and never shared beyond the providers listed in Section 9 without your consent.

Confidential business information disclosed during an engagement — strategy, financials, product roadmaps, client lists — is handled under the same confidentiality standard set out in Section 10.

2.4 System and Platform Access

Website development, automation, and digital marketing engagements sometimes require access to a client's own systems — a website admin panel, hosting account, advertising platform, analytics dashboard, or CRM. Where this is necessary, we request only the level of access the project requires, and that access is removed at the end of the engagement unless you ask us to retain it.

2.5 Information From Third Parties

We sometimes learn about you through public sources, referrals, or platforms such as LinkedIn when identifying potential clients. Where this happens, we'll tell you the source within a reasonable timeframe.

3. How We Use Your Information

3.1 Service Delivery

  • Responding to enquiries and preparing quotations
  • Delivering film, content, and creative production services
  • Designing, developing, and maintaining client websites and software
  • Building and operating automation workflows and voice AI solutions
  • Planning and running digital marketing campaigns
  • Managing project communication and coordination
  • Processing payments and managing billing
  • Scheduling consultations via Calendly

3.2 Business Operations

  • Maintaining records of client engagements
  • Issuing invoices and managing accounts
  • Resolving disputes and enforcing agreements
  • Complying with legal and regulatory obligations

3.3 Website Improvement

  • Understanding how visitors use our website
  • Diagnosing technical issues and monitoring performance

3.4 Marketing Communications

  • Sending newsletters and service updates, where you've consented or we hold a legitimate interest
  • Running targeted advertising on Meta, LinkedIn, and Google
  • Measuring campaign effectiveness

3.5 AI-Powered Service Delivery

Generating content, video, copy, code, and automations using AI platforms — including OpenAI and Anthropic — by processing prompts, briefs, and uploaded materials. This includes voice AI solutions and automation workflows built for clients. Full detail is in Section 8.

3.6 Data Minimisation and Privacy by Design

We collect and retain only what's adequate, relevant, and necessary for the purposes above, anonymising or pseudonymising where we can. We aim to consider privacy throughout the design and delivery of our services and collect only the information reasonably necessary to provide those services.

PIPEDA requires a lawful reason to process personal data, and where UK GDPR or EU GDPR apply to individuals in those jurisdictions, so do those frameworks. Here is ours, activity by activity.

Lawful Bases for Processing
Processing ActivityUK/EU GDPR BasisPIPEDA Equivalent
Responding to enquiries and delivering servicesPerformance of a contractContractual necessity
Processing paymentsPerformance of a contractContractual necessity
Marketing to existing clientsLegitimate interestsImplied consent
Marketing to new contactsConsentExpress consent
Website analyticsLegitimate interestsLegitimate business interest
Advertising and retargetingConsentExpress consent
Legal and regulatory complianceLegal obligationLegal obligation
Fraud prevention and securityLegitimate interestsLegitimate business interest
AI-powered content generationPerformance of a contractContractual necessity

Where we rely on legitimate interests, we've weighed those interests against your rights and are satisfied ours don't override them. You can object to this basis at any time — see Section 14.

5. Cookies

Cookies are small files placed on your device that help us run, measure, and improve our website.

5.1 Types of Cookies We Use

Cookie Categories
CategoryDescriptionExamples
Strictly necessaryRequired for the site to function; cannot be disabledSession management, security tokens, Cloudflare
FunctionalRemember preferences and improve usabilityTheme (light/dark mode), form state
AnalyticsMeasure traffic, behaviour, and performanceGoogle Analytics, Microsoft Clarity
MarketingTrack conversions and enable targeted advertisingMeta Pixel, LinkedIn Insight Tag, Google Ads

5.2 Managing Cookies

You can manage or remove cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website.

Where applicable, we comply with the requirements of UK PECR, the EU ePrivacy Directive, and other applicable privacy laws regarding the use of cookies and similar technologies.

6. Analytics & Tracking Technologies

We use the following services to understand website usage and marketing performance:

Analytics and Tracking Services
ServiceProviderPurposeData Processed
Google Analytics 4Google LLCTraffic analysis, behaviour, conversionsAnonymised IP, device data, page views, events
Google Search ConsoleGoogle LLCSearch performance and indexingAggregated search query data
Microsoft ClarityMicrosoft CorporationSession recording, heatmaps, UX analysisAnonymised session data, clicks, movement
Meta PixelMeta Platforms, Inc.Ad conversion tracking, retargetingIP address, browser, on-site actions
LinkedIn Insight TagLinkedIn CorporationAd conversion tracking, B2B analyticsLinkedIn member data where applicable, page URL

Where these services transfer data outside the UK or EEA, we rely on the safeguards described in Section 11.

7. Marketing Communications

Where you've consented, or where we hold a legitimate interest as an existing client, we may send newsletters, case studies, service announcements, industry insights, or occasional offers.

We use Resend to deliver these emails. Every marketing message includes an unsubscribe link; you can also opt out by emailing hello@cinemaai.ca. Unsubscribing doesn't affect transactional messages tied to an active service agreement.

We do not sell, rent, or trade your contact information to third parties for their own marketing purposes.

8. AI Services & Automated Processing

AI is core to how we work, so this section sets out — specifically — what gets processed, by whom, who owns what comes out the other end, and where a human is always in the loop.

8.1 AI Platforms We Use

AI Service Providers
ProviderPurposeData Processed
OpenAIAI content generation, software development assistance, reasoning, automation, and workflow supportPrompts, briefs, content inputs we or clients supply
AnthropicAI content generation, software development assistance, reasoning, automation, and workflow supportPrompts, briefs, content inputs we or clients supply

Our core AI providers are currently OpenAI and Anthropic. We may use additional AI service providers where appropriate to deliver the services you request. Where we do so, we take reasonable steps to select providers that offer appropriate privacy, security, and contractual protections for the services they provide.

8.2 Prompts, Uploaded Files, and Client Assets

When we generate content on your behalf, prompts and briefs go to the provider's API to produce outputs. Where a service genuinely requires it, Client Assets — images, video, audio, source code, documents — may be submitted as inputs too. We apply data minimisation throughout: only what the task actually needs gets submitted, and we do not knowingly send sensitive personal data (health, financial, or similar) unless a specific service requires it and you've consented.

8.3 API Processing and No Model Training

OpenAI's and Anthropic's commercial API agreements provide that data submitted through their APIs is not used to train their underlying models by default. This is a materially different arrangement from consumer-facing chat products, and it's why we use commercial APIs rather than consumer tools for client work. For full detail, see the OpenAI Privacy Policy and Anthropic Privacy Policy.

8.4 Human Review and Automated Decision-Making

We do not make decisions about you solely by automated means where those decisions would have a legal or similarly significant effect. AI-generated outputs intended for clients are reviewed by CinemaAI before they are delivered. AI assists our work, but important deliverables are subject to human review.

8.5 Ownership of Outputs

Content generated with AI tools in the course of your project is created by CinemaAI on your behalf. All intellectual property in delivered outputs transfers to you on full payment, per your service agreement. We may keep anonymised or non-identifiable examples of the work for our own portfolio unless you ask us in writing not to. You retain full IP in every Client Asset you give us — see Section 2.3.

8.6 Voice AI Solutions

Where a project involves building a voice AI solution, we may process voice or audio recordings to develop, configure, or test that solution — for example, a client's own reference audio, or call recordings used to refine a voice agent's responses. This audio is processed only for the purposes of the engagement and is not used to train our own general-purpose models. Where end users interact with a voice agent we've built for a client, the client is the data controller for that interaction, and CinemaAI acts as data processor — see Section 8.7.

8.7 AI Chatbots, Voice Agents, and Automation Workflows

Where we build a chatbot, voice agent, or automation workflow as part of a client engagement, personal data collected or processed by that tool's end users is governed by the relevant client's own privacy policy — the client is the data controller for that processing, and CinemaAI acts as data processor. Automation workflows may connect to a client's own systems (for example, a CRM, email platform, or website) to move data between them; we configure these connections to process only the data necessary for the workflow the client has requested.

9. Data Sharing & Third-Party Providers

We do not sell your personal data. We share personal data only with trusted third-party providers where necessary to deliver our services or operate our website. Where applicable, these providers process data under contractual terms or data processing agreements appropriate to the services they provide. Personal data may also be shared where Sections 9.2 and 9.3 apply.

9.1 Service Providers

The table below covers tools and platforms CinemaAI itself uses to run its business and deliver services. It does not include a client's own website, hosting, advertising accounts, or CRM — where a project requires us to access those, Section 2.4 explains how that access works.

Third-Party Service Providers
ProviderRoleData Processed
CloudflareCDN, DDoS protection, DNS, securityIP address, request metadata
VercelWebsite hosting and deploymentRequest logs, IP address
GitHubCode repository and development infrastructureNo personal data from site visitors
Google WorkspaceEmail, documents, project communicationClient contact data, emails, documents
Microsoft 365Business productivity and collaborationClient contact data, documents
StripePayment processingName, email, billing address, payment details
CalendlyMeeting schedulingName, email, calendar availability
ResendTransactional and marketing email deliveryName, email address, email content
Google AnalyticsWebsite analyticsAnonymised visitor data
Microsoft ClarityUX analytics and session recordingAnonymised session data
Meta PlatformsAdvertising and conversion trackingHashed identifiers, behavioural data
LinkedInAdvertising and B2B analyticsHashed identifiers, page interaction data
OpenAIAI content generationPrompts and content inputs
AnthropicAI reasoning and generationPrompts and content inputs
YouTube (Google LLC)Video hosting and portfolio embeddingViewer IP, device data if embedded
VimeoVideo hosting and portfolio embeddingViewer IP, device data if embedded

This list changes as our stack evolves. If you need the current version for procurement or due diligence, email hello@cinemaai.ca.

9.2 Legal Disclosure

We may disclose personal data where the law, a court order, or a regulator requires it, or to protect the rights, property, or safety of CinemaAI, our clients, or the public.

9.3 Business Transfers

If CinemaAI is acquired, merged, or sells assets, personal data may transfer to the successor entity, which will continue to honour the commitments in this policy. We'll notify affected individuals.

10. Client Confidentiality

Beyond data protection law, we treat everything a client shares with us as confidential by default. This includes:

  • Unreleased campaigns, films, and creative concepts
  • Investor materials, decks, and fundraising narratives
  • Prompts, briefs, and internal direction given to our team
  • Uploaded assets — brand materials, footage, audio, source code, documents, and data
  • Access credentials and any systems we're granted access to during a project
  • Internal business information: strategy, financials, product roadmaps, marketing performance data, and client lists

We use this information only to deliver the agreed services. We do not reference unreleased client work in our own marketing, portfolio, or case studies without written permission, and we do not disclose it to any party outside the providers listed in Section 9. This obligation survives the end of an engagement.

11. International Transfers

CinemaAI is based in Canada. Many of our service providers operate in the United States, the United Kingdom, and other countries, so your personal data may be processed or stored outside Canada.

United States — Google, Meta, Microsoft, OpenAI, Anthropic, Stripe, Calendly, Vercel, GitHub, Resend, and Vimeo all operate infrastructure in the United States. United Kingdom and European Union — where a provider or a client engagement involves individuals in the UK or EU, we take reasonable steps to apply appropriate safeguards, such as Standard Contractual Clauses or UK International Data Transfer Agreements, where those frameworks apply to the transfer.

Under PIPEDA, we remain accountable for personal data we transfer to third parties for processing, regardless of where that processing takes place, and we select providers on that basis.

Email hello@cinemaai.ca for detail on any specific transfer.

12. Data Security

We apply technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure:

  • HTTPS encryption across our website, enforced via Cloudflare
  • Access controls and role-based permissions on internal systems
  • Payment processing through Stripe — we never store full card data
  • Encryption of data in transit and at rest where applicable
  • Confidentiality obligations on everyone with access to personal data
  • Multi-factor authentication on supported business systems, including GitHub and Cloudflare

Access to client information is restricted to authorised personnel involved in delivering the requested services.

No transmission over the internet is completely secure, and we can't guarantee absolute protection. Our breach response procedure is set out in Section 17.

13. Data Retention

We keep personal data only as long as the purpose it was collected for requires — including legal, accounting, and reporting obligations.

Retention Periods
Data CategoryRetention PeriodReason
Client contact and project data7 years after project completionTax and legal record-keeping requirements
Financial and billing records7 yearsLegal obligation
Marketing contact data (non-client)3 years, or until opt-outLegitimate interests
Website analytics data26 monthsGoogle Analytics default retention
Enquiry data (not converted)12 monthsLegitimate interests
Client-uploaded assetsDuration of engagement plus 90 days, unless otherwise agreedService delivery and handover
System access credentialsRemoved at end of engagement, unless retention is requestedLimiting access to the active project period
Voice and audio recordingsDuration of engagement, unless otherwise agreedVoice AI development and testing
Cookie dataUp to 13 monthsAnalytics and functionality

Once data is no longer needed, we delete or anonymise it. Fully anonymised data that cannot be re-identified may be kept indefinitely for aggregated reporting.

14. Your Privacy Rights

14.1 Rights Under PIPEDA (Canada)

As a Canadian business, CinemaAI is primarily accountable under PIPEDA. Canadian residents can access their personal information, challenge its accuracy and have it corrected, withdraw consent subject to legal or contractual limits, and complain to the Office of the Privacy Commissioner of Canada.

14.2 Rights Under UK GDPR and EU GDPR

Where UK GDPR or EU GDPR apply to your personal data, you also have the following rights:

Data Subject Rights
RightWhat It Means
AccessRequest a copy of the personal data we hold about you
RectificationCorrect inaccurate or incomplete data
ErasureRequest deletion in certain circumstances
RestrictionLimit how we process your data while a dispute is resolved
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interests or direct marketing
Automated decisionsNot be subject to solely automated decisions with significant effect
Withdraw consentWithdraw at any time where processing is consent-based

14.3 Exercising Your Rights

Email hello@cinemaai.ca to exercise any of the above. We respond within 30 days (PIPEDA) or within one calendar month where UK/EU GDPR applies, and may ask you to verify your identity first.

Canadian residents unsatisfied with our response can complain to the Office of the Privacy Commissioner of Canada: priv.gc.ca. UK residents can complain to the Information Commissioner's Office: ico.org.uk. EU residents can complain to their local supervisory authority.

15. Children's Privacy

Our website and services are directed at businesses and professionals. We don't knowingly collect personal data from children under 16 (13 in Canada). If we learn we've inadvertently done so, we'll delete it promptly — contact hello@cinemaai.ca if you believe this has happened.

16. Third-Party Websites

Our website may link to or embed third-party content, including YouTube and Vimeo videos. We're not responsible for their privacy practices — review their policies directly: Google / YouTube, Vimeo. Embedded videos may set their own cookies and collect viewing data.

17. Data Breach Procedures

If a personal data breach occurs, we will:

  1. Contain and assess the breach as soon as we identify it
  2. Notify the Office of the Privacy Commissioner of Canada and affected individuals where the breach creates a real risk of significant harm, as required under PIPEDA
  3. Where UK GDPR or EU GDPR apply, notify the ICO or the relevant EU supervisory authority within 72 hours where the breach risks individuals' rights and freedoms
  4. Notify affected individuals without undue delay where the risk is high
  5. Document the breach and the remedial steps taken

Suspect your data's been compromised? Contact us immediately at hello@cinemaai.ca.

18. Changes to This Policy

We review this policy regularly and update it as our practices or the law changes. Material changes update the "Last updated" date above and, where appropriate, come with an email notice or a notice on our website. Continued use of our website or services after a change means you accept the revised policy. Earlier versions are available on request.

19. Contact

Questions, concerns, or requests about this policy or how we handle your data:

CinemaAI
Website: cinemaai.ca
Email: hello@cinemaai.ca

We aim to respond to privacy enquiries within 5 business days, and to fulfil formal requests within the legally required timeframe.

Canadian residents: Office of the Privacy Commissioner of Canadapriv.gc.ca. UK residents: Information Commissioner's Officeico.org.uk.