Privacy Policy

Data Protection & User Rights

Last Updated: December 2025 | Effective Date: December 3, 2025

CINPIX is committed to protecting your privacy and ensuring you have a positive experience on our platform. This policy outlines our practices regarding data collection, usage, and protection.

We believe that everyone has a right to privacy. And we respect and protect your privacy when delivering services to you on this Platform. This privacy policy explains how we collect, use, share, protect, and process your personal data ("Personal Data") that we may collect from you or about you, in compliance with the requirements of the Personal Data (Privacy) Ordinance (Chapter 486 of the Laws of Hong Kong) (the "PDPO" or "Ordinance"). Where applicable (e.g., if you are in the EU/UK or California), additional GDPR/CCPA rights apply as detailed below.

A reference to "Platform", "CINPIX," "we," "us" or the "Company" is a reference to cinpix.com, and its affiliate involved in Personal Data processing. This policy forms part of our Personal Information Collection Statement (PICS) – see collection points (e.g., registration) for specifics on voluntary supply, purposes, and rights.

1. What Information We Collect from You

We collect Personal Data only for lawful purposes directly related to our services, ensuring it is necessary, adequate, and not excessive. You supply your Personal Data in a voluntary way unless legally required (e.g., age verification). You may give your consent by clicking on the "Consent" box on PICS. Categories include:

  • Account & Registration Data: Username, email, hashed password, region, language, account status, timestamps, preferences.
  • Transaction & Payment Data: ticket purchase records, order ID, transaction status, refund details, invoice title (Note: Full payment card data is processed solely by third-parties like Stripe, PayPal, Alipay HK); we do not store it).
  • System & Device Data: IP address, device identifiers, OS/browser version, app version, time zone, session duration, playback events (start, pause, buffering, completion), crash logs
  • Push & Identifiers: push tokens (APNs/FCM), advertising identifiers, notification preference toggles
  • B2B Partner Data: organization name, representative's name, title, work email, address, operation logs if you are the business partner
  • Community / IM Data: chat or roundtable posts, replies, mentions, emojis, images/GIFs, private messages (if activated), report/appeal records, group membership, moderation logs. (Note: All uploaded media is automatically stripped of EXIF/GPS metadata)
  • Security & Anti-Abuse Data: login history, 2FA token IDs, watermark ID, suspicious device or behavior risk scores
  • Consent & Preference Logs: cookie/SDK consent choices, marketing opt-ins, privacy settings, timestamps
  • Optional Sensitive Data: real-name or age verification only when legally required; payment info handled exclusively by third-party processors

2. How We Collect Your Privacy

The Personal Data we collect from you and about you depends on the context of your interaction with our services. It also depends on what services, functionalities or experience you use, your location and applicable laws.

  • Directly from You: We collect your Personal Data directly from you when you register and configure your account, purchase movies' tickets, makes comments on movies, join IM/roundtables, participate in our events, reach out to us for customer support, or establish partnership relationships with us. We seek your prior explicit consent where voluntary.
  • Automatically: We may use commonly used tools such as cookies, SDKs, trackers for performance and security (e.g. crash analytics, playback metrics, anti-abuse logs) (collectively "Cookies") to collect your Personal Data ("Cookie Information") so as to provide the experiences you request, recognize your visit, track your interactions, and improve your and other customers' experience.

On first access, our Consent Manager requires affirmative choice for categories: Strictly Necessary (always on), Functional, Analytics, Marketing. On your first visit to our platform, websites and applications, non-marketing cookies/ SDKs require your affirmative consent. And marketing cookies/SDKs require your separate express opt-in consent. You may manage these cookies/SDKs via browser or Settings > Privacy. We honor Do Not Track/GPC signals.

  • From Third Parties: We also collect information about you from third parties when payment service providers return transactions' results, and when content security service providers or anti-fraud vendors provide risks' scores. We also collect contact information about you if you are the authorized representative of a film festival partner, and after the film festival partner provides us with your contact information with your consent.

3. How We Use Your Personal Information

We use and process your information, to the extent that doing so is necessary, by automated decision-making and profiling only for original or directly related purposes for which you are informed, and then conduct human review when necessary. We do not use your data for automatic decision-making that significantly affects you without human review. If you fail to provide your information as required by law or under such contract, we are unable to perform such contract under which to provide services to you. Purposes:

  • Service Provision: We use and process your information when you register and log in an account with our platform, websites and applications, when you book and schedule screenings, when you participate in chatrooms and roundtable discussions(live-streaming), when you purchase and pay for tickets, and when you seek our customer support. And we also use process your information when our platform provides a real-time multilingual translation for the subtitles of the movies screened on our platforms, websites and applications.
  • Community Governance and Content Security: We use and process your information to prevent spams and harassments, identify and delete prohibited contents, accept relevant reporting and appeals, and record the procedures for account suspension and reinstatement.
  • Security and Compliance: We also use and process your information to implement DRM, prevent piracy, screen recording and unauthorized to distribution by forensic watermarking, have access to and audit logs, comply with tax and accounting rules, and resolve complaints by right holders, to the extent that doing so is necessary.
  • Services Improvement and Analytics: We use and process your information to monitor the quality of our services, improve the experience that you use our services, and do A/B testing by anonymized/aggregated analysis for the purposes of scheduling optimization and features iteration.
  • Notifications and Marketings (ONLY with your separate express consent): We use and process your information to market our services to you, such as issuing festival tickets, updating scheduling and providing event information. We seek your prior separate express approval before such marketing, and you may unsubscribe our marketing services at any time.
  • Legal Obligation: We use and process your information to implement orders by regulatory authorities / courts, and comply with anti- money laundering and sanctions rules.

4. Whom We Share Your Data With?

We may share your information with:

  • Processors/Service Providers: In order to create, deliver, maintain, and market our Services to you and with your consent, we share your information with service providers who perform services, to the extent that it is necessary for them to do so, such as cloud and database, CDN, firewall and DDoS protection, anti-cheating and content security, crash/performance analytics, email and SMS, push notifications (APNs/FCM), customer support ticketing and authentication (if necessary). We also sign data processing agreement or similar agreements with the service providers, under which their services shall be in compliance with ISO 27001/27701 or equivalent security standards and the PDPO.
  • Partners and Film Festival Organizers (B2B): With your consent, we also share anonymous or de-identified usage data (such as booking volume, completion rate, heat maps, rating distribution), to the extent that doing so is necessary, with our partners and film festival organizers on an aggregate basis. Such anonymous or de-identified usage data contain no identifiable personal information, except as expressly approved by you separately or as required by law.
  • Legal and Regulatory Authorities: Without your consent, we also disclose your information to any regulatory authority or competent law enforcement body, court or other third party to (i) comply with any subpoena, notice, notification, order, judgement, award, or other legal obligation, other applicable law, regulation or legal process; (ii) protect the rights, property or safety of CINPIX, the Platform, or our customers or others; (iii) protect or defend against attacks or fraud; and (iv) enforce, remedy or apply our Users' Agreement or other agreements.
  • Corporate Transactions: If we are involved in a merger, acquisition, reorganization, liquidation, dissolution or fundamental corporate change, or the acquisition of all or part of our assets, business unit, stock, shares or equity by another company, we may share your information with that company (including its professional advisors) subject to confidentiality obligations.
  • Cross-Border Transfers: When personal data is transferred from regions like the EU/UK/CA to Hong Kong, we notify you of such transfer in PICS, and employ lawful mechanisms such as Standard Contractual Clauses (SCCs) with supplementary technical/organizational measures (encryption, data minimization, access controls) to provide comparable protection via contracts. We honor GPC (Global Privacy Control) signals and provide an "Do Not Sell or Share My Personal Information" opt-out portal. We do not sell personal information nor engage in "sharing" for cross-context behavioral advertising as defined under California law.

5. How We Protect Your Data

We take all practicable steps and measures to secure your information as much as possible. However, no method of transmission or storage is 100% secure. This means that an accidental or unlawful destruction, loss, alteration, change, modification, or un authorized access to, or disclosure of, your information may occur despite our best efforts.

  • Transport & Storage Encryption: In order to increase security of data transfer, we use the encrypted HTTP/TLS to send all and any of your data between you and our websites, platforms and applications, which is particularly useful for your information such as passwords, credit card numbers or bank account. We also encrypt your data in the backups of our database by AES-256 so as to secure your information from cyber threats.
  • Access & Permissions: We use two-step verification (2SV) to protect your information. With 2SV, you sign in to your account with our platforms, websites or applications in two steps with a strong password and something you have (such as your phone or security key). We also follow the principle of least privilege to improve our security posture by limiting your information to only that for which any authorized users require to execute its specific task. We also require two-party approval for sensitive actions to protect against malicious actions, and conduct regular access audit to maintain the security of our platforms, websites and applications.
  • Content Protection: We encrypt or lock the digital content of your information using DRM to prevent unauthorized copying, sharing, redistribution or screen recording thereof. We also overlay dynamic watermark on documents containing your information to deter and make it easier to trace any unauthorized dissemination of your information. Our platforms, websites and applications incorporate anti-screen recording protection to disrupt or prevent unauthorized screen captures. We concurrently identify and handle, on a tiered basis, abnormalities that could indicate a security threat.
  • Engineering Security: We audit source code of the software for our platforms, websites, applications at runtime with the goal of uncovering and identifying security vulnerabilities, bugs and other programming issues before it is released. We also scan open source dependencies included in the software for our platforms, websites and applications to detect and identify publicly disclosed vulnerabilities contain therein. We also conduct annual penetration testing to find and exploit any vulnerabilities and weak spots in the system for our platforms, websites and applications. We manage and deploy changes to the software for our platforms, websites and applications in a controlled and consistently repeatable manner, and also use an emergency drill procedure to test the response of the system for our platform, websites and applications.
  • Vendor Management: We sign data processing agreement with service providers, under which their services shall be in compliance with the requirements of ISO 27001/27701 or equivalent certification and the PDPO. We also reserve the right to conduct security assessment or audit of the software for our platforms, websites and applications.
  • Data Breach Notification: If any data breach occurs, which possibly poses high risks to you, we will, pursuant to applicable laws, notify relevant regulatory authorities within no more than 72 hours and inform affected users as soon as feasibly possible to provide mitigation measures and contact points therefor.

6. How You Opt Out of Our Services

You may opt out of our Services as follows:

  • Stop Marketing Emails/Push Notifications: You may disable marketing emails/in-app push notifications in "Account Settings - Notifications," or click Unsubscribe at the bottom of any marketing email. We'll stop marketing promotions within 10 business days of receiving your request, but you may still receive non-marketing service messages. You may also send an email to us at [email protected].
  • Disable Non-Essential Cookies/SDKs: You may withdraw your consent at any time on the Cookie/SDK Consent Manager (available on first settings- privacy), or adjust your browser settings to disable non-essential Cookies/SDK. You also use SDK-specific opt-out tools (e.g. Google Analytics Opt-out) to opt out of SDKs. Please note that some features (like personalized recommendations) may not work properly. Strictly necessary cookies cannot be disabled.
  • Turn Off Personalized Recommendations/Profiling: You may turn off personalization and profiling, and toggle off "Personalized Content" in your Privacy Settings at any time, but this does not disable essential services. After you turn off personalized recommendations /profiling, you'll see generic, non-tailored content, basic functions and non-personalized recommendations only.
  • Cross-Context Behavioral Advertising/Sale or Sharing: We do not sell or share your personal information for cross-context behavioral advertising. Should our policy change in the future, we will provide a "Do Not Sell or Share My Personal Information" opt-out portal and will honor opt-out preferences by default.
  • Account & Data: You download/delete your data or request account deactivation via the "My Data" section. We'll delete your account within 40 days under Hong Kong laws. You may also send an email to us at [email protected].

We process opt-out and withdrawal requests for free within 40 days and may need to verify your identity where necessary.

7. How Long We Retain Your Data

We might retain your data for no longer than is necessary for the original or directly related purposes for which it was collected, subject to applicable laws, regulations and rules and contractual obligations. We also determine appropriate retention periods depending on the amount, nature and sensitivity of your personal data, the potential risk of harm from its unauthorized use or disclosure and the purpose for which it was collected, subject to applicable laws, regulations and rules and contractual obligations. For example, your transaction data will be retained for 7 years for tax purpose, and your log data will be retained for 12 months upon deactivation of your account.

After expiry of the appropriate retention periods, we will purge your personal data from our electronic, manual and other filing systems or anonymize or pseudonymize it subject to applicable laws, regulations and rules and our internal policies. For more information on retention period, you could contact us using contact information as detailed in Article 11 below.

8. How We Settle Your Disputes with Us

You may submit complaints or requests to exercise your rights by sending emails to [email protected] or using the in-app/web form on the Platforms, Websites and Applications.

We will respond to your request within forty (40) days (in complex cases. This period may be extended by up to an additional two (2) months, and we will inform you of the reasons for the delay).

If you are dissatisfied with our response, you may lodge a complaint with the Office of the Privacy Commissioner for Personal Data (PCPD) in Hong Kong or the relevant data protection authority in your jurisdiction.

We retain records of complaints and their handling for at least 12 months and continually improve our processes accordingly.

9. Children's Data

Our Platform is not directed for minors under the age of 13 (or under the age of 16 in the EU/UK) and does not offer registration or personalized services to them.

We do not knowingly collect personal data from minors without parental consent. If we discover that we have inadvertently collected personal information from such children or minors, we will promptly delete the relevant accounts and all associated data, and, where feasible, notify their parents or legal guardians. If any purchases or activities are involved, we will process refunds or cancellations in accordance with applicable laws and regulations.

Only in cases where it is genuinely necessary to process minors' personal information for educational or public-interest collaborations will we obtain verifiable parental consent through schools or directly from legal guardians. In such cases, we will also provide children with a clear, easy-to-read privacy notice specifically designed for them, along with simple and accessible mechanisms for parents and children to withdraw consent at any time.

10. What Are Your Rights with Respect to Your Personal Data

Under the PDPO, You have the following rights with respect to your personal data:

  • Access and Rectification: You may view, export, or update your personal data in our systems. You also request a copy of your personal data and correct inaccuracies, and we will respond within 40 days of receiving such request.
  • Deletion / Account Deregistration: You may request the deletion of your personal data that is no longer necessary or deregister your account (subject to legally mandated retention exceptions).
  • Restriction of / Objection to Processing: You may request restriction of or object to certain specific processing activities (e.g., profiling or personalization).
  • Data Portability: You may obtain a copy of your personal data in a structured, commonly used, and machine-readable format.
  • Withdrawal of Consent: You may withdraw your consent at any time for processing that is based on consent (e.g., marketing or non-essential cookies/SDKs).
  • Human Review of Automated Decisions: You may challenge significant decisions made solely through automated processing and request human review and explanation.

We will use reasonable methods to verify your identity and will respond to your requests within the timeframes required by applicable laws, regulations and rules and contractual obligations.

11. How to Reach Us

For any questions, you may reach us by the following contact information:

12. Our Cookies Policy

We use Cookies to collect your information so that we recognize you and your devices, track your interactions with our Services, infer your browsing preferences, and customize and improve your experience. The data we and third parties collect using these Cookies include, without limitation, log-in details, authentication details, IP-address, access times, pages visited, the links and features used, and the preference configurations on your device and across our platforms, websites and applications. You also can manage preferences, at any time via the initial consent banner or through "Settings → Privacy", on whether to accept these Cookies. You also can opt out of these Cookies via the consent banner or through "Settings → Privacy", but certain features on our platforms, websites and applications do not work properly after you do so.

How we use different categories of these Cookies and how you manage these Cookies are described as follows:

TypeDescriptionManaging Settings for UsersRetention Periods
Strictly NecessaryThese Cookies are essential for our basic website/app functionality. Enables core operations like page navigation, secure login, payment processing, and maintaining session state. They cannot function properly without these.These Cookies cannot be disabled (otherwise service will not work)
You may block them in our browser/app settings, but will break functionality of our websites/apps
Your data collected by session cookies will be deleted when your session ends.
FunctionalFunctional cookies enhance your experience by remembering preferences and settings (language, region, font size, UI customization). They are not essential but improves usability, functions, performance, and services on our websites and applications.You may opt out of these Cookies by deleting/blocking via our browser controls, clicking on the toggle in our applications' preferences/privacy menuYour data collected by functional cookies will be retained for a period of between 6 and 12 months
Analytics/PerformanceThey collect aggregated usage data to measure and improve our website/app performance. They track page views, session duration, click paths, error reports, and user flows. They involve third-party analytics SDKs (e.g., Google Analytics, Firebase).You may opt out of these analytical/ performance cookies. For example, you may opt out from data collection using Analytics SDK opt-out tools (e.g., Google Analytics Opt-out Browser Add-on). You may also configure your browser settings to block third-party cookies. You may also opt out by clicking on "Disable Analytics Tracking" in your application settings. We honor your browser DNT signals.Your data collected by analytics/marketing cookies will be retained for a period of less than 13 months.
Marketing/Push NotificationThey track your behavior across our websites/apps to build profiles and deliver personalized advertising, promotions, cross-app tracking, and push notifications. They include advertising SDKs, retargeting pixels, and social media plugins. Our marketing SDK partners includeA clear, separate, unticked consent checkbox will be available for you to opt in to our marketing communications when you sign up in our websites. We also request your consent for our marketing communications in our applications.

If you opt-in to marketing communications, you withdraw consent free of charge at any time by clicking on "unsubscribe" banner or through "Settings → Privacy" in your individual browser or our applications. We will cease using your data for marketing within 10 working days of receiving your request.
Your data will be deleted upon opt-out.

13. Automated Decision-Making and Appeal Process

We use algorithms for preliminary screening and ranking in anti-abuse systems and content recommendation. If such automated processing results in restrictions on your account or playback rights, you may request human review by going to "My Data → Appeal" in the app or by emailing [email protected]. We will provide an initial response within 72 hours and complete the review within 14 days (in complex cases, this period may be reasonably extended, and we will inform you of the reasons).

14. AI and Machine Learning Processing

We have formulate internal AI use policies to ensure that our employees comply with the least-necessary-input principle. Specific measures are stated as follows:

  • Real-time Translation & Subtitles: We may use built-in or third-party models to process text in a controlled environment. Original video sources and users' personal data are never used for model training.
  • Content Moderation: Automated tools may be used to detect and flag violating or abusive content solely for governance and enforcement purposes.
  • Data Minimization: All AI processing follows de-identification and least-necessary-input principles, with strict limits on the use and retention of results to comply with PCPD AI framework.

15. Additional Rights for Non-Hong Kong Residents

15.1 GDPR (EU/UK Residents):

You have additional rights: data portability, restriction of processing, objection to automated decisions, and right to be forgotten. We will respond to requests within one month (extendable by two months for complex cases).

15.2 CCPA (California Residents):

You have the right to know, access, delete, correct and restrict the use and no discrimination of, your personal information, and to opt-out of "sale" or "sharing" of personal information. We currently do not sell or share personal information, nor engage in "sharing" for cross-context behavioral advertising as defined under applicable California law. We honor Global Privacy Control (GPC) signals, and provide an "Do Not Sell or Share My Personal Information" opt-out portal.

15.3 International Data Transfers (GDPR Context):

For EU/UK data transfers to Hong Kong, we rely on Standard Contractual Clauses (SCCs) supplemented by technical/organizational measures (encryption, data minimization, access controls). A copy of the SCCs can be provided upon request.

16. Changes and Version Control

The current version number and effective date are displayed on this page. For material changes, we will notify you in a prior 30 days via pop-up, in-app message, or email, and where required, obtain renewed consent.

17. Community & UGC Rules (cross-reference with Community Guidelines)

Round-table groups and instant messaging features are intended solely for civil discussions related to films and festivals. We strictly prohibit harassment, hate speech, pornography, copyright infringement, illegal content, and any behavior that disrupts order. We may remove content, mute, or ban accounts for violations, and we retain necessary audit logs and evidence as required to meet legal obligations.

Questions About Our Privacy Policy?

If you have any concerns or questions about our privacy practices, please don't hesitate to reach out.