Opening Final Frame
Verifying your credentialsEstablishing an encrypted sessionPreparing your workspace
Secured by WorkOS
This is taking longer than usual. Your connection may be slow.

Privacy policy.

Last updated 19 August 2026

01

Who we are

Final Frame provides a media supply chain platform for studios, distributors and platform operators. This policy explains what personal data we process when you use final-frame.com and the Final Frame application, and why.

For personal data inside a customer organisation’s account - the names and addresses of the people they invite, the contacts they record - that organisation is the controller and we process on its instructions. For data about visitors to this site and our own records, we are the controller.

02

What we collect

Account data: name, work email address, and the organisation and role attached to your membership. Provided by you or by the colleague who invites you.

Usage and security data: sign-ins, the actions your account takes in the service, technical logs including IP address and browser type. Collected automatically to run and secure the service.

Content your organisation brings: catalogues, metadata, documents and media. We process this to provide the service and for no other purpose; it may incidentally include personal data such as the names of credited cast and crew.

03

Why we process it

To provide the service under our contract with your organisation; to secure it, which is our legitimate interest and your organisation’s; to meet legal obligations; and to communicate service matters such as invitations, approvals and status changes.

We do not sell personal data, and we do not use your organisation’s content to train machine-learning models for anyone else’s benefit.

04

Where it lives

The service runs on Google Cloud in London (europe-west2). Media assets are stored in per-organisation buckets under per-organisation encryption keys. Access within the product is enforced by row-level isolation in the database itself.

We use a small number of subprocessors to run the service, including Google Cloud for infrastructure and an established provider for transactional email. A current list is available on request from privacy@final-frame.com.

05

International transfers

Where a subprocessor processes personal data outside the UK, transfers rest on adequacy regulations or the appropriate standard contractual clauses with the UK addendum.

06

How long we keep it

Account and usage data is kept while your organisation’s subscription is active and for a limited period afterwards for security and legal purposes. Content is exportable for thirty days after termination and then deleted from production systems in the ordinary course of our backup cycles.

The service’s append-only audit trail records actions taken in a customer’s account; it belongs to that customer and follows their retention.

07

Cookies

The application uses one essential cookie, the session that keeps you signed in. This marketing site sets no advertising or analytics cookies and does not track you across other sites.

08

Your rights

Under the UK GDPR you can ask for access to your personal data, correction, erasure, restriction, portability, and to object to processing based on legitimate interests. Write to privacy@final-frame.com; where your data sits inside a customer’s account we may direct the request to them as controller.

You can complain to the Information Commissioner’s Office at ico.org.uk, though we would welcome the chance to resolve any concern first.

09

Changes to this policy

We will post changes here, and notify organisation administrators of material ones with reasonable notice. The date at the top is the date of the current version.

10

Contact

privacy@final-frame.com for anything in this policy.