Revised%2520RWF%2520plain%2520logo%2520black%2520mk%25203_edited_edited.png

Privacy Notice

Effective from 30 December 2019

INTRODUCTION
Rear Window Films (collectively the “Company” or “we”), which can be contacted at the email address mail@rearwindowfilms.com, want to inform you about how we collect, use and disclose personal data from and about you, through this website and its associated mobile sites, applications and widgets (collectively, the “Company Services”). Notwithstanding anything to the contrary in any other policy or contained otherwise on this website, in the event of a conflict, the terms of this Privacy Policy shall prevail. 

What and who this Privacy Policy covers
The Company is the data controller of the personal data we collect from and about you through the Company Services. 
This Privacy Policy applies to all users, including both those who use the Company Services without being registered or having subscribed and those who have registered with or subscribed to a Company Service. 
For further information please see below. 

What kind of personal data do we collect about you?
The Company might collect data from and about you. 
More specifically, the Company collects (1) registration data, (2) public data and Posts, and (3) data that you have permitted social media to share with the Company. 
However, we do not collect either financial information from a payment service provider or sensitive data relating to you. 
For further information, please see below. 

Why do we collect your personal data?
The main reason why we collect data about you is to provide you with Company Services and to allow you to interact with such services. 
In addition, with your prior consent, we can send you offers, promotions, and marketing communications, including based on your personal preferences and habits. 
For further information, please see below . 

On what legal bases do we use your personal data?
Your personal data is mainly collected in order to provide you with Company Services. 
Your personal data is also necessarily collected to comply with legal obligation or to protect the legitimate interest of the Company. 
Failure to provide such data will make it impossible to offer you the Company Services. 
When your personal data is collected for marketing purposes, you have the option not to provide the Company with your personal data. 
For further information, see below 

How do we process your personal data? 


The security of your data is a priority for us. For this purpose, the Company has implemented adequate administrative, technical and physical measures designed to safeguard your personal data against loss, theft and unauthorized use, disclosure or modification. 
For further information, see below. 

Who can access to your personal data?


The Company might share your personal data with (i) service providers, (ii) our affiliated companies and (iii) national authorities, when allowed by the applicable laws. 


For further information, see below. 

Is your personal data transferred abroad?


Your personal data might be transferred to other countries within or outside the European Economic Area. In any case, we always make sure that appropriate and suitable safeguards compliant with applicable laws are in place to protect your personal data. 
For further information, see below. 

What are your rights with regard to your personal data? You have, among others, the right to access, complete, update, amend and delete your personal data. 
For further information, see below. 

Updates to this Privacy Policy The Company may modify or update this Privacy Policy, including in order to comply with applicable law. 
Please look at the Effective Date at the top of this Privacy Policy to see when this Privacy Policy was last revised. 

How can I contact you with regard to the processing of my personal data?
You can contact us at the following email mail@rearwindowfilms.com

1. WHAT AND WHO THIS PRIVACY POLICY COVERS 


Rear Window Films are the data controllers of the personal data (e.g. information that identifies a specific person, such as full name or email address) we collect from and about you through the Company Services that is processed in compliance with the terms of this Privacy Policy. 
This Privacy Policy applies to all users, including both those who use the Company Services without being registered with or subscribing to a Company Service and those who have registered with or subscribed to a Company Service. 

2. WHAT TYPE OF PERSONAL DATA DO WE COLLECT ABOUT YOU? 


The Company collects (1) registration data, when you sign up or for a Company Service, (2) public data and posts that you share through the Company Services, (3) data that you have permitted social media to share with this Company, and (4) activity data when you access and interact with a Company Service. More specifically, the Company collects the following types of data from and about you: 
Registration data is the information you submit to register for a Company Service. Registration Information may include, for example, name, surname, email address, gender, country, postcode and birthday date. 


Public data and Posts which consist of comments or content that you post on the Company Services and the personal data about you that accompanies those posts or content, which may include a name, user name, comments, likes, status, profile information and picture. Public information and Posts are always public, which means they are available to everyone and may be displayed in search results on external search engines. 


Data from Social Media. If you access or log-in to a Company Service through a social media service or connect a Company Service to a social media service, the data we collect may also include your user ID and/or user name associated with that social media service, any information or content you have permitted the social media service to share with us, such as your profile picture, email address or friends lists, and any information you have made public in connection with that social media service. When you access the Company Services through social media services or when you connect a Company Service to social media services, you are authorizing the Company to collect, store, and use such data and content in accordance with this Privacy Policy. 


Activity Data. When you access and interact with the Company Services, we may collect certain information about those visits. For example, in order to permit your connection to the Company Services, our servers receive and record information about your computer, device, and browser, including potentially your IP address, browser type, and other software or hardware information. If you access the Company Services from a mobile or other device, we may collect a unique device identifier assigned to that device, geolocation data, or other transactional information for that device.
Information from Other Sources. We may supplement the information we collect with information from other sources, such as publicly available information from social media services and commercially available sources. 

 

We do not collect:


• Financial information from a payment service provider: in some cases, we may use an unaffiliated payment service to allow you to purchase a product or make payments (“Payment Service”). If you wish to purchase a product or make a payment using a Payment Service, you will be directed to a Payment Service webpage. Any information that you provide to a Payment Service will be subject to the applicable Payment Service's privacy policy, rather than this Privacy Policy. We have no access to any payment data regarding the Payment Service. 
• Sensitive information: we ask that you do not send us, and you do not disclose, any sensitive personal data (such as social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, criminal background or trade union membership) on or through the Company Services or otherwise. 
Linked Services. The Company Services may also be linked to sites, including social media sites, operated by unaffiliated companies, and may carry advertisements or offer content, functionality, games, newsletters, contests or sweepstakes, or applications developed and maintained by unaffiliated companies. The Company is not responsible for the privacy practices of unaffiliated companies, and once you leave the Company Services or click an advertisement you should check the applicable privacy policy of the other service. 



3. WHY DO WE COLLECT YOUR PERSONAL DATA?


We use the personal data we collect from and about you to: 


a) Provide the Company Services and features to you;
b) Measure and improve those Company Services and features;
c) Improve your experience with both online and off-line Company Services by delivering content you will find relevant and interesting; 
d) Allow you to comment on content, and participate in online games, contests, or rewards programs;
e) Provide you with customer support and to respond to enquiries;
f) Protect the rights of the Company and others: more specifically, there may be instances when the Company may use your personal data, including situations where the Company has a good faith belief that such processing is necessary in order to: (i) protect, enforce, or defend the legal rights, privacy, safety, or property of the Company, our Company Affiliates or their employees, agents, contractors, licensors and suppliers (including enforcement of our agreements and our terms of use); (ii) protect the safety, privacy, and security of users of the Company Services or members of the public; or (iii) protect the Company, as well as other third parties involved, such as Company suppliers, against fraud or for risk management purposes; 
g) Comply with the law or legal obligation and/or to respond to requests from public and government authorities; 
h) Complete a corporate transaction, such as a proposed or actual reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of Company business, assets or stock (including in connection with any bankruptcy or similar proceedings). For example if the Company is involved in a merger or transfer of all or a material part of its business, the Company may transfer your information to the party or parties involved in the transaction as part of that transaction; 
i) Allow social sharing functionality; if you log in with or connect a social media service account with the Company Services, we may share your user name, picture, and likes, as well as your activities and comments with other users of that Company Service and with your friends associated with your social media service. We may also share the same information with the social media service provider; 
j) With your prior consent, send you - via email, SMS, telephone, chat and social media - offers, promotions and other marketing communications regarding the Company Services and/or regarding the products and services of third parties operating in the entertainment sector, including group companies, as well as regarding co-branded services or features, such as contests or other promotions offered with a third party or Company Affiliate that may be hosted on the Company Services or on the Company Affiliate or third party's services; 
k) With your prior consent – send to you marketing communications customized to your interests and needs by means of the channels of communication set out under letter j) above. 
We may use anonymized personal data or information that no longer identifies you personally, even indirectly (e.g. statistics), for additional purposes or share it with third parties. 

 


4. ON WHAT LEGAL BASES DO WE PROCESS YOUR PERSONAL DATA? 


The processing of your personal data for the purposes of: 
 

  • Section 3, letters from a) to f) of this Privacy Policy is necessary for the provision of the Company Services and, therefore, it is mandatory since otherwise the services could not be provided; 
     

  • Section 3, letter g) of this Privacy Policy is mandatory, as it is required under applicable laws; and 
     

  • Section 3, letter h) of this Privacy Policy is performed on the basis of the legitimate interest of the Company and of its counterparties to perform such economic activities, which is adequately balanced with your interest since the data processing is performed within the limits strictly necessary to perform such economic activities. This data processing activity is not mandatory and you can object at any time by contacting us at the email address in Section 11 of this Privacy Policy. 

On the contrary, the processing of: 

  • Section 3, letter i) is discretionary, but without your consent, it is impossible to connect to social media services account with the Company Service so that you will have to log to the Company Service using a different mechanism; 
     

  • Section 3, letters j) and k) is discretionary, but without your consent, it is impossible for the Company and/or third parties to provide you with (i) generic marketing communications of the Company and third parties’ services/products; (ii) communications based on your interests and needs; and (iii) co-branded services. 

Below you can find an explanatory chart on the matter above:


Purpose of processing Legal Basis Voluntary or necessary provision of personal data 
Section 3. a): Provision of Company Services Performance of contract Provision is necessary
Failure to provide data would make it impossible for us to provide the Company Services 
Section 3. b): Analysis and improvement of Company Services Performance of contract Provision is necessary
Failure to provide data would lead to impaired Services 
Section 3. c): Improvement of user experience Performance of contract Provision is necessary
Failure to provide data would lead to impaired Services 
Section 3. d): User interactions (comments, contests participation, etc.). Performance of contract Provision is necessary
Failure to provide data would make it impossible for us to provide the Company Services 
Section 3. e): Customer support Performance of contract Provision is necessary
Failure to provide data would make it impossible for us to provide the Company Services 
Section 3. f): Protection of Company and third parties’ interests Performance of contract Provision is necessary
Failure to provide data would make it impossible for us to provide the Company Services 
Section 3. g): Compliance with legal obligation Legal obligation
Provision is mandatory
Failure to provide data would make it impossible to provide the Company Services 
Section 3. h): Corporate transaction Legitimate interest Provision is not mandatory
You can exercise your right to object to processing, but the Company may continue to process your data in the case of compelling legitimate grounds, which override your interests, or for legal defense in which case you may request that the Company limits the processing of personal data in accordance with 8(d)(iv).
Section 3. i): Social media sharing Consent Provision is voluntary
You can exercise your right to withdraw your consent at any time, without consequences, other than the need to log in with a different account 
Section 3. j): Generic marketing Consent Provision is voluntary
You can exercise your right to withdraw your consent at any time, without consequences, in order to stop receiving marketing communications 
Section 3. k): Targeted marketing Consent Provision is voluntary
You can exercise your right to withdraw your consent at any time, without consequences, in order to stop receiving marketing communications 
Should you wish to withdraw your consent, please contact us at the email address in Section 11 or, in the case of j) and k), select the unsubscribe link contained within any marketing communication. 



5. HOW DO WE PROCESS YOUR PERSONAL DATA?


With regard to the above mentioned purposes, the data is processed through both electronic and manual means, and is protected through adequate security measures, taking into account the state of art, the costs of implementation and the nature, scope, context and purpose of processing as well as the risk of varying likelihood and severity for the rights and freedoms of individuals. In this regard, the Company uses appropriate administrative, technical, personnel and physical measures to safeguard personal data in its possession against loss, theft and unauthorized use, disclosure or modification. 

6. WHO HAS ACCESS TO YOUR PERSONAL DATA?


For purposes consistent with the purposes as per Section 3 of this Privacy Policy, the Company may share your personal data to the following categories of recipients located within the European Union or outside of the European Union in compliance and within the limits of the provisions of Section 7 below: 
Third party service providers entrusted with processing activities and duly appointed as processors when required by applicable laws, e.g. cloud service providers, other entities of the group, providers of services instrumental to or supporting the Company Services - and thus, by way of example and without limitation, companies that provide IT services, experts, consultants and lawyers. 
Companies resulting from corporate transactions, such as from possible mergers, demergers, or other transformations. 
Company Affiliates, in their capacity of data controllers or data processors; 
Business partners. With your prior consent, the Company may share your personal data with usiness partners operating in the entertainment sector in order to send you marketing communications. 
Competent national authorities in order to comply with applicable laws. 

7. IS YOUR PERSONAL DATA TRANSFERRED ABROAD? 


Your personal data may be transferred to countries within and outside the European Economic Area, in particular to the United States. Some non EEA countries are recognized by the European Commission as providing an adequate level of data protection according to EEA standards. The full list of these countries is available at https://ec.europa.eu/info/law/law-topic/data-protection_en. For transfers from the EEA to countries not considered adequate by the European Commission, we have put in place appropriate and suitable safeguards designed to protect your personal data and the transfer of your personal data in compliance with applicable data protection laws, such as standard contractual clauses adopted by the European Commission as per Articles 45 and 46 of the EU General Data Protection Regulation 2016/679 (the “Privacy Regulation”). 
You have the right to request a copy of the above measure or further information on your personal data by contacting the Company at the address indicated in Section 11 of this Privacy Policy. 

8. WHAT ARE YOUR RIGHTS WITH REGARD TO YOUR PERSONAL DATA? 


You have the right, at any given time, to:


a. a) Obtain confirmation as to whether or not your personal data exist and to be informed of its content and source, verify its accuracy or request rectification, update or amendments; 
b. b) Request the deletion, conversion to an anonymous form or restriction of any personal data processed in breach of applicable law; 
c. c) Oppose its processing, in all cases, for legitimate reasons
d. Request that the Company limit the processing of your personal data on the grounds that:
(i) You content the accuracy of the personal data until we have taken sufficient steps to correct or verify its accuracy;
(ii) The processing is unlawful but you do not want us to erase the data;
(iii) We no longer need the personal data for the purposes of the processing, but you require the personal data for the establishment, exercise or defense of legal claims;
(iv) Where you have objected to processing justified on legitimate interests grounds pending verification as to whether the Company has compelling legitimate grounds to continue processing.
e. Object to the processing of your personal data; 
f. Request the erasure of your personal data without undue delay;
g. Receive an electronic copy of your personal data, that you have provided to us, if you would like to port your personal data to yourself or a different provider (“data portability”), when the personal data is processed by automatic means and the processing is either (i) based upon your consent or (ii) the fact that the processing is necessary for the provision of the Company Service; and 
h. Lodge a complaint with the relevant supervisory authority. The UK supervisory authority for data protection issues is the Information Commissioner's Office (www.ico.org.uk).
In this regard, you may send your request to the address in Section 11 of this Privacy Policy. In your request, please include your email address, name, address, and telephone number and specify clearly what information you would like to access, change, update, suppress or delete. 
Remember that even after you cancel your account, or if you ask us to delete your personal data, copies of some information from your account may remain viewable in some circumstances where, for example, you have shared information with social media or other services or, for example, when retention of such copies is necessary to comply with legal obligation or legal defence. Because of the nature of caching technology, your account may not be instantly inaccessible to others. We may also retain backup information related to your account on our servers for some time after cancellation or your request for deletion, to comply with applicable law. 
We also give you many choices regarding our use and disclosure of your personal data for marketing purposes. You may revoke your consent, in any given time, for: 

 

  • Receiving electronic communications from us. If you no longer want to receive marketing-related emails from us on a going-forward basis, you may opt-out of receiving these marketing-related emails by either simply changing your preferences on your user profile settings, if you registered, or by following the unsubscribe instructions in our communications. You may also send a request to the address of Section 11 of the Privacy Policy. In any case, the Company may continue to send you administrative communications related to the provision of the Company Services. 
     

  • Our sharing of your personal information with Company Affiliates or business partners for their marketing purposes. If you would prefer that we do not share your personal information on a going-forward basis with Company Affiliates and/or business partners for their direct marketing purposes, you may opt-out of this sharing by either simply changing your preferences on your user profile settings, if you registered, or by following the unsubscribe instructions in our communications or sending a request to the address of Section 11 of the Privacy Policy. 
    In all the above cases, we may contact you and ask you for more information, that is necessary to properly handle your request. Also, the additional rights outlined in Section 9 below will be effective from May 25, 2018. 

 


9. RETENTION PERIOD APPLYING TO YOUR PERSONAL DATA 


We will retain your data only for the period necessary to fulfil the purposes for which the data was collected as outlined in this Privacy Policy. In any case, the following retention periods will apply to the processing of your personal data for the purposes indicated below: 
 

  • Data collected for the purposes as per Section 3, letters from a) to h) of this Privacy Policy is retained for the time of provision of the Company Services plus the length of any applicable statutory limitation period following the termination of the Company Services; 
     

  • Data collected for the purpose as per Section 3, letter i) of this Privacy Policy is retained for the time necessary to log on to the Company Services through a social network; and 
     

  • Data collected for the purpose as per Section 3, letters j) and letter k) is retained for as long as necessary to fulfil the purposes we collected it for (e.g., to provide you with marketing communications). Should you decide to opt-out from receiving marketing communications, please note that we will be required to retain limited data in order for us to respect your opt-out and ensure that you do not receive marketing communications). 

  • At the end of the retention period, your personal data will be either cancelled, anonymized or aggregated. 


10. UPDATE TO THIS PRIVACY POLICY 


The Company may modify or update this Privacy Policy for any reason (including, but not limited to, changes in applicable law and interpretations, decisions, opinions and orders relating to such applicable law). Please look at the Effective Date at the top of this Privacy Policy to see when it was last revised. Any changes to this Privacy Policy will be provided in advance by posting the revised Privacy Policy on the Company Services. If we make material changes to this Privacy Policy that change the nature of processing or expand our rights to use the personal data we have already collected from you, we will notify you in advance and provide you with a choice about our future use of the personal data, as may be required by applicable law. 

11. CONTACT US 


If you have questions about this Privacy Policy, please contact the Company at the following email address mail@rearwindowfilms.com with the subject line Rear Window Films Privacy Policy Enquiry. 

Revised%2520RWF%2520plain%2520logo%2520black%2520mk%25203_edited_edited.png

Rear Window Films is a production company based in London, producing original cinematic thrillers.

FOLLOW US @
  • Facebook
  • Twitter
  • Instagram
  • YouTube

* We do not accept unsolicited material

2017 © REAR WINDOW FILMS, All rights reserved.