Draft. This policy has not yet been reviewed by a lawyer and must be before launch — read it as a statement of intent, not as final legal wording.

Legal

Privacy policy

Last updated 17 September 2026.

1. Who we are

PrePro Selects is a client gallery, review and delivery platform for production companies. This policy explains what we do with personal data, in the sense the General Data Protection Regulation (EU) 2016/679 gives that term.

Placeholder — founder to complete before launch

The controller for the purposes of this policy is the entity named here.

Legal entity name
[ legal entity name ]
Legal form and country of incorporation
[ e.g. Delaware corporation, United States — or a Spanish S.L. ]
Registered address
[ street, postcode, city, country ]
Company registration number
[ registration number and register ]
VAT number
[ VAT number ]
Data protection contact
[ confirm: privacy@preproselects.com ]
Data protection officer
[ not appointed — Art. 37 GDPR and Art. 34 LOPDGDD do not require one for this processing; confirm with counsel ]
Establishment in the EU
[ either: "the company's central administration is in Spain, at [address]" — in which case the AEPD is the lead authority and no representative is needed — or: "none" ]
Representative in the EU (Art. 27 GDPR)
[ name, address, email — mandatory if the company has no EU establishment; may not be the processor ]
Representative in the UK (Art. 27 UK GDPR)
[ name, address, email — needed once there are UK customers or viewers ]

For anything covered by this policy, write to privacy@preproselects.com.

2. Controller or processor

Two different relationships run through this platform, and the answer to "who is responsible for this data" is different in each.

We are the controller for the data of the people who buy and administer PrePro Selects: the producers and heads of production who hold an account, the people who contact us through the website, and the billing contacts on a subscription. We decide why and how that data is processed.

We are the processor for everything a customer puts into their workspace: the photographs, video, call sheets and casting material they upload, the names of their projects and clients, the gallery logins they create for their clients, and the record of what those clients looked at and liked. The customer is the controller for all of it. We process it on their documented instructions, which are the actions they take in the product plus the data processing agreement.

If you were given a login to look at a gallery and you want to know what is held about you, the production company that invited you is the controller and is the right first contact. Write to us anyway if you cannot reach them and we will pass the request on and tell you we have.

3. Data we hold as controller

Personal data held by PrePro Selects as controller
CategoryWhat it containsWhere it comes from
Account Name, work email address, role in the workspace, an Argon2id hash of the password, invitation and password-reset tokens You, or a colleague who invited you
Sessions A keyed hash of each session token, creation and last-seen time, device class, browser user agent and, for a staff sign-in, the IP address it came from — shown to you in the app's session list so you can recognise your own devices. A gallery session records only a salted hash of the address Generated when you sign in
Workspace Company name, plan, subscription status, logo and accent colour, contact email You
Billing Billing name and address, VAT number, invoices, payment status. Card details are held by our payment processor and never by us You, and our payment processor
Enquiries Email address, company, country and message from the contact form, plus a salted hash of the sending IP address, the browser user agent and the referring page You, when you use the contact form
Support correspondence Emails you send us and our replies You
Server logs Web server access logs, which include the connecting IP address, the requested path and a timestamp Generated automatically
Audit log Administrative actions inside a workspace — who invited whom, who deleted what Generated by the product

We do not buy contact lists, we do not enrich your record from third-party data brokers, and we do not profile you. There is no automated decision-making that produces legal or similarly significant effects.

4. Data we hold as processor

On behalf of our customers, and only on their instructions, the platform holds:

  • Uploaded material — stills, video, PDFs and the derivatives generated from them. Photographs of identifiable people are personal data, and on this platform they are frequently the whole point: casting portraits, crew stills, scouting images with passers-by in frame.
  • Project metadata — project, client, category and folder names, notes and file names.
  • Gallery logins — the username, display name, password hash, permissions and expiry of each client login the customer creates.
  • Viewing records — when a gallery session started, how long it lasted, which images were opened, liked, annotated or downloaded, a coarse device class, the browser user agent, and a salted hash of the viewer's IP address rather than the address itself.

The salted hash is deliberate. Counting sessions requires knowing whether two visits came from the same place; it does not require knowing where that place is. The hash supports the first and cannot answer the second, so no raw viewer IP address is written to the database at any point.

We do not use this material for our own purposes. We do not train machine learning models on it, we do not scan it for content beyond generating thumbnails and poster frames, and we do not disclose it to anyone except the sub-processors listed below and where the law compels us.

5. Lawful bases

Lawful bases for processing
PurposeBasis
Giving you an account and running the service you subscribed toPerformance of a contract — Art. 6(1)(b)
Answering an enquiry sent through the contact formSteps taken at your request before entering a contract — Art. 6(1)(b), and our legitimate interest in responding to business enquiries — Art. 6(1)(f)
Taking payment, issuing invoices, keeping accounting recordsContract — Art. 6(1)(b) — and legal obligation — Art. 6(1)(c)
Rate limiting, login throttling, abuse detection, fraud prevention, server logsLegitimate interests — Art. 6(1)(f): keeping the service available and other people's material private
Service email you cannot opt out of — security notices, breach notifications, changes to these terms, billing failuresContract — Art. 6(1)(b) — and legal obligation — Art. 6(1)(c)
Marketing email about the productConsent — Art. 6(1)(a) — withdrawable at any time, or Art. 6(1)(f) for existing customers about a directly comparable service, with an unsubscribe link in every message
Processing a customer's project material and their clients' viewing recordsWe act as processor on the customer's instructions — Art. 28. The customer determines the lawful basis

Where we rely on legitimate interests we have weighed those interests against your rights and freedoms, and you can object at any time — see section 9.

6. How long we keep it

Retention periods
DataKept for
Account and workspace recordsWhile the workspace exists, then 30 days after it is closed
Uploaded material and project metadataUntil the customer deletes it. On closure of a workspace, 30 days for export, then the storage subtree is purged
Gallery loginsUntil deleted or expired by the customer; removed with the project
Viewing records and analytics events24 months, then deleted
SessionsUntil they expire — one hour for a staff access token, 30 days for a refresh token, 14 days for a gallery session — or until revoked
Staff sign-in IP addressWith the session it belongs to: until it expires or you revoke it
Web server access logs14 days
Audit log12 months
Contact form enquiries24 months from the last exchange, unless the enquiry became a subscription
Invoices and accounting recordsAs long as tax and commercial law requires, typically up to ten years
BackupsRolling 14 days, after which the backup containing the data expires

Deleting something in the product removes it from every view immediately and queues the bytes for removal from disk. It remains in the nightly backups until those backups age out, which is the honest description of what "deleted" means for any system that keeps backups at all. If you need a deletion confirmed earlier than that, tell us and we will handle it individually.

7. Sub-processors

These are the only third parties that can touch personal data held on this platform. Customers on a signed data processing agreement are notified before a sub-processor is added or replaced, and may object.

Sub-processors
ProviderPurposeLocation
IONOS SE Servers, storage and backups — all data at rest Germany
Stripe Payments Europe, Ltd. Subscription billing, card processing, invoices Ireland, with onward transfer to the United States
[ transactional email provider ] Invitations, password resets, download notifications, service email [ EU region — to be confirmed ]

The email provider is a placeholder pending the founder's final choice of relay. No other analytics, advertising, support-chat or tracking provider is used.

8. International transfers

All customer data at rest — the database, the media volume, the backups — is held in Germany, on infrastructure operated by IONOS SE, and does not leave the European Union in the ordinary course of running the service. There is no US region, no replication abroad and no CDN. The people who administer the servers do so from Spain.

The operating company. The entity that runs PrePro Selects is identified on the legal notice page. If that entity is incorporated in the United States and has no establishment in the EU, then under the GDPR it is a third-country recipient of the personal data our EU customers entrust to it, even though the servers are in Germany — so we treat the relationship with every EU customer as a transfer and put the safeguards in place that Chapter V requires: the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914, module two) are built into the data processing agreement, backed by a transfer impact assessment whose conclusion is easy to state: the data never physically leaves the EU, no US infrastructure is used, and the only route by which a US authority could reach it is legal process served on the company, which we handle as the legal notice page describes. If the company is certified under the EU-US Data Privacy Framework we say so on that page and the certification becomes the primary safeguard, with the clauses kept as a fallback. If instead the company is established in the EU, none of this paragraph applies and there is no transfer at all.

Payment processing is the other routine transfer. Stripe Payments Europe, Ltd. is established in Ireland and transfers some data onward to its parent in the United States, under the EU-US Data Privacy Framework and the Standard Contractual Clauses together with Stripe's own transfer safeguards. No project media is ever sent to Stripe — only the billing contact, the amount and the subscription state.

We will not move hosting outside the EU without notifying customers in advance and giving anyone who objects the opportunity to terminate.

Founder to confirm before launch

Country of incorporation and whether the company has an EU establishment (see section 1). Keep the paragraph on the operating company only if the entity is outside the EU.

9. Your rights

Under the GDPR you have the right to:

  • Access — a copy of the personal data we hold about you, and an explanation of what we do with it.
  • Rectification — correction of anything inaccurate. Most account fields you can edit yourself in the app.
  • Erasure — deletion, where we have no overriding obligation to keep it. Invoices are the usual exception.
  • Restriction — a pause on processing while a dispute about accuracy or legitimate interests is resolved.
  • Portability — your data in a structured, machine-readable format. In practice: a full export of your workspace, which you can also trigger yourself at any time.
  • Objection — to any processing we base on legitimate interests, and at any time and without reason to direct marketing.
  • Withdrawal of consent — where consent was the basis, withdrawable at any time without affecting what was lawful beforehand.

Send requests to privacy@preproselects.com. We answer within one month and will tell you if we need the extension the regulation allows for a complicated request. We may ask you to confirm your identity first — not to obstruct you, but because handing an account's data to whoever asks would be the very failure this section exists to prevent. Exercising these rights is free.

If your request concerns material inside a customer's workspace — a gallery you were given access to, a photograph of you in a casting folder — we will forward it to that customer, who is the controller, and confirm to you that we have. We do not delete a customer's material on a third party's instruction.

If you are in the United States. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for profiling that produces legal or similarly significant effects — so there is nothing to opt out of, and the rights listed above are available to you in the same way, by writing to the same address. No page on this site tracks anyone across other websites, so a browser's Do Not Track or Global Privacy Control signal changes nothing: every visitor is treated as though it were set. No third party collects personal information about your activity over time and across different websites through this service. We do not collect biometric identifiers: photographs and video are stored and shown to people, never scanned for face geometry.

10. Cookies

PrePro Selects sets three cookies — sl_staff for the admin app, sl_guest for a client gallery and sl_preview for a staff member previewing a gallery as a client — and keeps a few entries in your browser's local storage for the same purpose: your session token and the name you typed. All of them are strictly necessary for a service you asked for, which is why there is no consent banner: there is nothing to consent to. The public pages of this website set nothing at all. Names, lifetimes and how to remove them are on the cookie policy page.

Where the gallery runs embedded inside a customer's own website, no cookie is set; the embedded session is a token held by the page and passed with each request.

There is no analytics cookie, no advertising cookie, no tag manager, no pixel, no session recording and no third-party JavaScript on any page of this site or the product.

11. Security

Passwords are hashed with Argon2id. Session tokens are stored only as a keyed hash. Every query is scoped to one workspace, storage is partitioned per workspace on disk, and media is served through short-lived signed links with Cache-Control: private so no shared cache can retain one client's material. Everything is served over TLS. The measures are described in full, in engineering terms, on the security page.

If a personal data breach occurs we notify the competent supervisory authority within 72 hours where the regulation requires it, and affected customers without undue delay. When we act as processor, we notify the customer without undue delay so that they can meet their own deadline.

12. Children

PrePro Selects is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 16, and we do not knowingly collect personal data from a child under 13 through this website; if we learn that we have, we delete it.

Material uploaded by a customer may depict minors — child casting is ordinary production work — and where it does, the customer is the controller and is responsible for holding the consents the law requires: for the processing of a child's data, a parent's or guardian's consent below the age of 14 in Spain (Article 7 LOPDGDD); for the use of a minor's image, the consent that Organic Law 1/1982 requires, with its formalities. We show such material only to the people the customer has authorised and never use it for anything of our own.

13. Changes

When this policy changes we update the date at the top of the page. If a change materially affects how we handle personal data, we email account holders at least 30 days before it takes effect. Previous versions are available on request.

14. Complaints

Tell us first — privacy@preproselects.com — and we will try to put it right. You also have the right to complain to a data protection supervisory authority, either in the EU member state where you live or work, or where the alleged infringement took place.

For most of the people who use this platform that is the Spanish authority, the Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid, aepd.es, which accepts complaints online. If you are in the United Kingdom, it is the Information Commissioner's Office, ico.org.uk.

Placeholder — founder to complete

The lead supervisory authority follows the registered seat of the entity named in section 1.

Lead supervisory authority
[ if the company has an EU establishment: the authority of that member state — for Spain, the AEPD above. If it has none, there is no lead authority: every EU authority is competent, and the representative named in section 1 is the point of contact ]

Last updated 17 September 2026. See also the terms of service and the data processing agreement.