Privacy Policy

Last updated: July 2026

Who we are

Cinema Proof is a film business-plan service operated by Installz Ltd, a company registered in England and Wales (company number 15568673), registered office Baltic Wharf, Clifton Marine Parade, Gravesend, London DA11 0DR (“Cinema Proof”, “we”, “us”, “our”).

For the purposes of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the Data Protection Act 2018, Installz Ltd is the data controller for the personal data described in this policy.

If you have any questions about this policy or how we handle your data, contact us at hello@cinemaproof.net.

What this policy covers

This policy explains what personal data we collect when you use cinemaproof.net and our business-plan service, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

We designed this service around data minimisation: we collect only what we need to deliver your plan and run the business, and we do not keep your project materials any longer than necessary.

Information we collect

Account and contact details. Your name, email address, and company or project name when you create an account or place an order.

Project information. The film project details you submit through the order form so that we can produce your business plan — for example, budget, genre, target audience, comparable titles, financing goals, and any supporting notes you choose to share.

Payment information. When you pay, our payment provider (Stripe) processes your card details and returns payment metadata to us (such as the amount, currency, date, last four digits, and a transaction reference). We never see or store your full card number.

Communications. Emails and messages you send us, and our replies.

Technical and usage data. Basic information collected automatically when you visit the site, such as IP address, browser type, device information, and pages viewed, primarily through our hosting provider and any security tooling we use.

We do not intentionally collect special category data (such as health, biometric, or political data). Please do not include such information in your project brief.

How we use your information, and our lawful basis

Under UK/EU GDPR we must have a lawful basis for each use of your data:

What we doWhyLawful basis
Create and manage your accountTo give you access to the serviceContract
Produce and deliver your business planCore service you paid forContract
Process your paymentTo take payment and prevent fraudContract; Legal obligation
Communicate about your orderTo answer questions and deliver your planContract; Legitimate interests
Keep accounting and tax recordsWe are legally required toLegal obligation
Send our newsletterOnly if you opt inConsent
Secure the site and prevent abuseTo keep the service safeLegitimate interests

Where we rely on consent (for example, marketing emails), you can withdraw it at any time — see “Your rights” below. Withdrawing consent does not affect processing carried out before you withdrew it.

Your project information is treated as confidential business information and is private to your account. We do not use it to train any product, and we do not sell it.

Who we share your information with

We do not sell your personal data. We share it only with the service providers (“processors”) we rely on to run the service, and only to the extent each needs it. Each is bound by a data processing agreement requiring appropriate security and confidentiality.

ProviderPurposeLocation
StripePayment processing and billingUK / EU / US
ResendTransactional and (if opted in) marketing emailUS
SupabaseApplication database and account managementEU (Ireland)
VercelWebsite and application hostingUS / global edge
Anthropic PBCAssists in preparing your business-plan document from the details you submitUS

We may also disclose data where required by law, to enforce our terms, or in connection with a business sale or reorganisation — in each case subject to appropriate safeguards.

International transfers

Some of our processors are located outside the UK and the European Economic Area, including in the United States. Where we transfer your personal data internationally, we rely on appropriate safeguards recognised under UK/EU GDPR — such as the UK International Data Transfer Agreement (IDTA) or Addendum, the European Commission’s Standard Contractual Clauses, and/or applicable adequacy decisions (including the UK Extension to the EU–US Data Privacy Framework where the recipient is certified). You can request more detail about these safeguards at hello@cinemaproof.net.

How long we keep your information

We keep personal data only as long as we need it for the purpose we collected it, or as the law requires:

  • Project materials (your brief and supporting notes) — deleted from our active systems within 30 days of final delivery of your plan, unless you ask us to keep them for revisions.
  • Delivered plan — retained in your account until you delete it or close your account, so you can re-download it.
  • Account details — kept while your account is active.
  • Payment and accounting records — retained for six years after the relevant transaction, as required by UK tax and company law (HMRC).
  • Marketing preferences — kept until you unsubscribe or withdraw consent.

Your rights

Under UK/EU GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data, subject to records we must keep by law.
  • Restriction — ask us to limit how we use your data.
  • Portability — receive certain data in a portable format.
  • Object — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where we rely on consent.

To exercise any of these, contact hello@cinemaproof.net. We will respond within one month, as required by law. We may need to verify your identity first.

If you are unhappy with how we have handled your data, you can complain to a supervisory authority. In the UK this is the Information Commissioner’s Office (ICO) — ico.org.uk. In the EU, you may complain to the data protection authority in your country of residence. We would appreciate the chance to address your concern first.

Cookies and analytics

We use only strictly necessary cookies — the cookies required for the site to work. They keep you signed in to your account (via Supabase) and process payments and help detect fraud (via Stripe). These are always active and, because they are strictly necessary, do not require your consent.

We do not currently use analytics, advertising, or other non-essential cookies, so no cookie-consent banner is required. If we introduce analytics or other non-essential cookies in future, we will update this policy and, where the law requires, ask for your consent through a cookie banner before setting them.

Blocking strictly necessary cookies may stop parts of the site from working.

Children

Our service is intended for business users and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.

Security

We use appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, and vetted processors. No system is perfectly secure, but we work to protect your information and will notify you and the relevant authority of any personal data breach where the law requires.

Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new “Last updated” date and, for material changes, notify you by email or in-product.

Contact

Questions about this policy, or to exercise your rights: hello@cinemaproof.net. Installz Ltd, Baltic Wharf, Clifton Marine Parade, Gravesend, London DA11 0DR.