Privacy Policy
Version 3
Film Distribution Group
Privacy Policy
Last updated: 18.07.2026
This Privacy Policy describes how Film Distribution Group (hereinafter also referred to as “we,” “us,” “our,” or “Group”) processes personal data in accordance with applicable data protection laws in Estonia, Latvia, Lithuania, and the European Union (including the EU General Data Protection Regulation, “GDPR”). It applies to all companies within the Group, including their websites, business operations, and communications.
This Privacy Policy explains what personal data we process, why, and what rights you have. If you have any questions, please contact us using the details in Section 13.
1. WHO WE ARE
Parent Company
Theatrical Film Distribution OÜ
Tööstuse 47D-15, 10416 Tallinn, ESTONIA
Reg. No: 12394464 | VAT Code: EE102801495
Website: https://www.filmdistribution.eu
Group Companies
1. Estonia
Estonian Theatrical Distribution OÜ
Tööstuse 47D-15, 10416 Tallinn, ESTONIA
Reg. No: 12396084 | VAT Code: EE101603623
Website: https://heafilm.ee
2. Latvia
Latvian Theatrical Distribution SIA
Dzelzavas street 120 G, Riga, Latvia, LV-1021
Reg. No: 40103625421 | VAT Code: LV40103625421
Website: https://labskino.lv
3. Lithuania
Theatrical Film Distribution UAB
Jogailos g. 4, LT-01116 Vilnius, Lithuania
Reg. No: 302950470 | VAT Code: LT100007448011
Website: https://dukine.lt
Dukine Film Distribution UAB
Jogailos g. 4, LT-01116 Vilnius, Lithuania
Reg. No: 305461381 | VAT Code: LT100013224519
Website: https://dukine.lt
Each of the above entities is a separate legal entity and acts as a “data controller” where it determines the purposes and means of processing personal data related to its own activities. When we refer to “Film Distribution Group” or “Group,” we mean any or all of the above entities collectively, where applicable.
2. SCOPE AND APPLICABILITY
This Privacy Policy:
-
Applies to all personal data that we collect, use, or otherwise process about individuals (including but not limited to customers, website visitors, event participants, collaboration partners, contractors, business contacts, and persons who contact us or otherwise engage with us).
-
Covers multiple jurisdictions, including Estonia, Latvia, Lithuania, and broader EU requirements under the GDPR. Where local laws in any of these countries impose stricter requirements, those requirements will take precedence.
-
Supplements any specific notices that might be provided to you at the point of data collection (for example, additional terms on a particular website or service).
Our websites and services are directed at general audiences. Where processing of a child’s personal data would be based on consent in the context of information society services, the age thresholds of national law apply (13 in Estonia and Latvia, 14 in Lithuania).
3. TYPES OF PERSONAL DATA WE COLLECT
Depending on how you interact with us, we may process the following categories of personal data:
-
Identification Data: such as name, surname, date of birth (where necessary), national ID or other identifiers (if legally required or relevant for the service).
-
Contact Details: including email address, postal address, phone number, country of residence, and preferred language of communication. This includes business contact details obtained from public business registers (see Section 6).
-
Transaction and Payment Information: where necessary for our services, such as billing details, purchase histories (for tickets, products, services), payment methods, partial credit card details (if applicable), or bank account information.
-
Communication Data: including email correspondence, messages sent through contact forms on our websites, or interactions via social media platforms.
-
Website and Technical Data: IP addresses, device identifiers, browser type, cookie information, operating system details, and log information about how you use our websites. When you arrive at our websites from an advertising platform, this also includes advertising click identifiers (e.g., fbclid, ttclid, gclid) used to measure advertising effectiveness. (See also Section 11 on Cookies and advertising measurement.)
-
Profile or Preference Data: such as your interests, event attendance history, or preferences for certain films or newsletters—where you have given us explicit consent or we have a legitimate interest to process these for marketing purposes.
-
Video Surveillance (CCTV): if you visit our premises (cinema halls, offices, or event locations where CCTV is in use) for security and fraud prevention purposes (see Section 10).
-
Any Other Information: that you voluntarily provide to us, such as feedback, survey responses, or details related to marketing consents.
We strive to collect only the minimum necessary data to fulfill the relevant purpose.
4. LEGAL GROUNDS FOR PROCESSING
We will only process your personal data if there is a valid legal basis under applicable data protection laws. Such legal bases include:
-
Consent: Where you have clearly consented to a certain type of data processing (e.g., receiving our newsletters or participating in loyalty programs). You may withdraw this consent at any time by contacting us or using the opt-out mechanisms provided (e.g., unsubscribe links in emails).
-
Performance of a Contract: Where the data processing is necessary for us to provide services you have requested or to take steps at your request before entering into a contract (e.g., ticket purchases, distribution agreements).
-
Legal Obligations: Where we are required to process your personal data to comply with statutory or regulatory obligations (e.g., tax, accounting, record-keeping, consumer protection laws).
-
Legitimate Interests: Where necessary to pursue our legitimate business interests, provided such interests are not overridden by your fundamental rights and freedoms. This may include direct marketing (including business-to-business marketing described in Section 6), security measures, or fraud prevention.
5. PURPOSES FOR PROCESSING
We process personal data for the following main purposes:
- Provision of Services
To sell and deliver tickets, distribute films, and provide related entertainment services, including after-sales and customer support.
- Customer Relationship Management
To manage customer accounts, respond to inquiries, provide technical and operational support, and process refunds or complaints where necessary.
- Marketing and Communications
To send newsletters, promotions, and information about our upcoming events, offers, or services (see Section 6 for details on marketing emails, including emails to business contacts). You have the right to opt out of such communications at any time.
- Business Analytics and Improvements
To evaluate and improve the quality of our services, including usage analytics for websites, analysing trends, and refining our marketing approaches.
- Legal and Compliance
To comply with applicable laws, such as maintaining accounting records, fulfilling tax obligations, and cooperating with law enforcement when required.
- Security and Fraud Prevention
To protect our premises, customers, employees, and business data through measures such as CCTV surveillance, IT security, and access controls.
6. DIRECT MARKETING AND EMAILS TO BUSINESS CONTACTS
6.1. Film notifications and newsletters for consumers
There are two ways to sign up for our consumer emails:
-
Subscribe box. You enter your email address in a subscription box on one of our websites — for our newsletter or for notifications about a specific film.
-
Your actions in your account. If you are a registered user, you can also subscribe to notifications about a specific film by marking it on the website — for example as a film you want to see or want to be reminded about. We treat such an action as your request to be notified about that film (for example, when it arrives in cinemas).
We send these emails because you asked for them (consent, expressed by your subscription or by such an action). Every email contains an unsubscribe link, and you can opt out at any time — no reason needed; registered users can also manage their notification preferences in their account. Unsubscribing stops the emails; it does not affect any other service we provide to you.
6.2. Film newsletters to business contacts
We also send film newsletters — about a single upcoming release or several — to the business contacts of companies in Estonia, Latvia, and Lithuania (for example, to invite companies to organise a cinema visit or cooperate on a release). For these campaigns:
Where the addresses come from. We use companies’ own official contact details published in public business registers — in Estonia the open data of the e-Business Register (e-äriregistri avaandmed), in Latvia the Register of Enterprises (Uzņēmumu reģistrs), and in Lithuania the Register of Legal Entities (Registrų centras / Juridinių asmenų registras). From the register we obtain the company name, registry code, and the email address the company itself has registered as its official contact. We may also use business contact details you have given us directly (for example, at a trade event or in previous cooperation).
Legal basis. In all three countries, direct marketing to a company’s electronic contact details is permitted without prior consent. Every such email contains an unsubscribe link. Opt-outs take effect immediately.
-
Estonia: § 103¹(2) of the Electronic Communications Act (elektroonilise side seadus). Per the Data Protection Inspectorate’s guidance, contact details entered in the Business Register as the company’s contact details are treated as the legal person’s contact details, including where the address contains a person’s name.
-
Latvia: Articles 8 and 9 of the Information Society Services Law (Informācijas sabiedrības pakalpojumu likums). The Data State Inspectorate has confirmed that commercial communications may be sent to a company’s electronic address without prior consent, subject to sender-identification and opt-out duties.
-
Lithuania: Article 81 of the Law on Electronic Communications (Elektroninių ryšių įstatymas), as amended with effect from 22 April 2026. Direct marketing to legal persons, including work contact addresses, does not require prior consent; every message must contain a clear, free opt-out.
Where such an address identifies a natural person (for example, firstname.surname@company), we additionally process that person’s data on the basis of our legitimate interest (GDPR Article 6(1)(f)) in offering our films and services to companies through their published business contacts. We have carried out and documented a balancing assessment; you may request a summary of it via the contact details in Section 13. The campaign sender is the Group company running the campaign in the respective country (see Section 1) — for example, Estonian Theatrical Distribution OÜ for campaigns relating to heafilm.ee.
What we process. The business contact email address, company name and registry code, the content and delivery status of the emails we send, engagement events (delivered, opened, clicked, bounced, unsubscribed, complained — see Section 6.3), and opt-out (suppression) status.
Your right to object — at any time. You may object to receiving direct marketing at any time, free of charge, and without giving reasons. Use the unsubscribe link in any email (one click is enough), or contact us via Section 13. Once you object, we stop immediately: your address is added to our suppression list and no further marketing emails are sent to it. Hard bounces and spam complaints are treated the same way and suppressed automatically.
Every marketing email we send identifies the sender, is recognisable as a marketing message, and contains a working unsubscribe mechanism (including a one-click unsubscribe header supported by most email programs).
6.3. Email measurement (opens and clicks)
Our marketing emails use standard measurement techniques — a small tracking image (pixel) and wrapped links — that tell us whether an email was delivered, opened, or clicked. We use this information to measure campaign performance, keep our lists accurate, and stop emailing addresses that do not work. We do not use it to make automated decisions that would have legal or similarly significant effects on you. If you do not want this measurement, simply unsubscribe — suppressed addresses are not emailed at all; you can also disable image loading in your email program, which prevents open tracking.
7. RETENTION OF PERSONAL DATA
We will retain personal data only for as long as is necessary to fulfil the purposes for which it was collected unless a longer retention period is required or permitted by law. The criteria used to determine our retention periods include:
-
Legal and Regulatory Requirements: Certain data (e.g., invoices) must be retained for minimum periods under accounting and tax laws — for example, 7 years in Estonia, and depending on the document type, 5 to 10 years in Latvia and generally 10 years in Lithuania.
-
Contractual Obligations: Data linked to an ongoing service contract will be stored until the contract’s obligations are fulfilled and relevant claim limitation periods expire.
-
Legitimate Business Purposes: Data needed for security (e.g., CCTV) or fraud-prevention may be stored for a reasonable period to protect our rights and interests.
-
Consent-Based Processing: If the legal basis for processing is your consent, we will continue to process the data until you withdraw your consent or the purpose of the processing is achieved.
-
Marketing Contact and Opt-Out Data: Business contact data used for marketing (Section 6) is kept only while it remains current and relevant for the campaign purpose. Records of opt-outs (the suppression list) are kept for as long as necessary to honour your objection — if you ask us to erase your data, we keep the minimum needed (the address and its opt-out status) solely to make sure we never email you again.
Typical retention periods by data category:
| Data category | Typical retention period |
|---|---|
| Accounting and tax records | 7 years (Estonia); 5–10 years depending on document type (Latvia); 10 years (Lithuania) |
| Contract and customer data | Until obligations are fulfilled and claim limitation periods expire |
| Marketing contact data (business contacts) | While current and relevant for the campaign purpose |
| Opt-out (suppression) records | As long as necessary to honour the objection |
| CCTV footage | Up to 30 days (see Section 10) |
Once data is no longer needed, we will securely delete or anonymise it.
8. DATA SHARING AND INTERNATIONAL TRANSFERS
We do not sell personal data to third parties.
- Within the Group
Personal data may be shared among our Group companies in Estonia, Latvia, and Lithuania for business continuity, centralized administrative and financial functions, or unified marketing campaigns, where permitted by law and aligned with this Privacy Policy.
- Third-Party Service Providers
We engage external providers to process data on our behalf. Such providers only have access to data necessary for their tasks and are contractually obligated to maintain confidentiality and adhere to data protection standards. Our main service providers are:
| Provider | Role | Location |
|---|---|---|
| FilmHQ OÜ (reg. no 17108523, Tööstuse 47D-15, 10416 Tallinn, Estonia) | The platform we use to service our customers: our websites and consumer portals, customer and campaign management, and related data hosting. Processes data on our behalf under a data processing agreement. Main sub-processors: Supabase (database hosting, EU — Frankfurt), Vercel (web hosting and content delivery), Cloudflare (security and content delivery); FilmHQ’s current provider list is published in its privacy policy at filmhq.pro/privacy. | EU |
| APL Digital Solutions OÜ (reg. no 14994211, Tartu mnt 80d, 10112 Tallinn, Estonia) | Operates the Markus cinema-industry data system and certain of our websites, including the databases behind them: those sites’ website data and usage data are stored and processed on systems APL operates on our behalf, hosted on Microsoft Azure cloud infrastructure in the EU. | EU |
| Google Ireland Limited | Website analytics and tag management (Google Analytics via Google Tag Manager) on our websites, including this one: usage statistics, subject to your cookie choices — see the Cookie Policy. Our newer film landing pages measure ad conversions server-side instead, as described in Section 6.3. | EU (US parent — see item 5 below) |
| Mailgun Technologies, Inc. (part of the Sinch group) | Email delivery and email measurement for our marketing and service emails (Section 6): recipient email addresses, message content, and delivery/engagement events. We use Mailgun’s EU region (EU data residency). | EU (US parent — see item 5 below) |
| Other supporting providers (IT support and maintenance, advertising and media agencies working within our advertising accounts, accounting and professional advisers) | Engaged under equivalent contractual data protection terms. | — |
Some third parties are not our service providers but receive data as described elsewhere in this Policy and process it under their own privacy policies: the advertising platforms (Meta, TikTok, Google) that receive advertising-measurement events as described in Section 6.3 — for the collection and transmission of those events we are jointly responsible with the platform concerned, while their further processing is their own responsibility — and providers of embedded content (e.g., YouTube) when you play a video on our sites.
- Business Transfers
If we undergo any reorganization, merger, or acquisition, personal data may be transferred as part of the business transaction, subject to confidentiality arrangements.
- Legal Requirements
Where required by law or to protect our rights, property, or safety (or that of our customers or others), we may disclose personal data to law enforcement or relevant authorities.
- Transfers Outside the EEA
Generally, we aim to store and process personal data within the European Economic Area (EEA). If data is transferred outside the EEA, we ensure an adequate level of protection for each recipient: for United States providers certified under the EU–U.S. Data Privacy Framework (such as Mailgun Technologies, Inc. and Google LLC), the European Commission’s adequacy decision applies; otherwise we use EU Standard Contractual Clauses or other recognized transfer mechanisms in accordance with GDPR. You can request a copy of the relevant safeguards via the contact details in Section 13.
9. YOUR RIGHTS
You have certain rights regarding your personal data under the GDPR and other applicable laws:
- Right of Access
You can request information about whether and how we process your personal data, and obtain a copy of it.
- Right to Rectification
You can request that inaccurate or incomplete personal data be corrected or updated.
- Right to Erasure (“Right to be Forgotten”)
In certain cases, you can request that we erase your personal data, for example if the data is no longer required for the purpose it was collected or if you withdraw your consent (where applicable). Note that if you have opted out of marketing, we keep the minimum needed to honour that opt-out (see Section 7).
- Right to Restrict Processing
You can request that the processing of your personal data be restricted if you contest its accuracy or if the processing is unlawful but you oppose erasure.
- Right to Data Portability
Where processing is based on your consent or the performance of a contract and is carried out by automated means, you can receive your personal data in a structured, commonly used, and machine-readable format, and request its transfer to another controller, where technically feasible.
- Right to Object
You can object to the processing of your personal data for direct marketing at any time, free of charge and without giving reasons — including any related profiling. We will stop immediately. The easiest way is the unsubscribe link in any of our emails. You can also object to other processing based on our legitimate interests, in which case we will re-assess the processing.
- Right to Withdraw Consent
If our processing relies on your consent, you can withdraw it at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
To exercise any of the above rights, please contact us using the details in Section 13 (“Contact Us”). We may need to verify your identity before implementing your request. We will respond without undue delay and at the latest within one month.
10. VIDEO SURVEILLANCE (CCTV)
We may operate CCTV systems in certain premises for security, fraud prevention, and safety reasons. When you enter those areas, you may be captured on CCTV footage.
-
Storage Duration: CCTV footage is typically stored for up to 30 days unless required for a longer period (e.g., ongoing investigations).
-
Restricted Access: Only authorized personnel (or authorities, when legally permitted or required) have access to CCTV footage.
11. COOKIES AND SIMILAR TECHNOLOGIES
Our websites use cookies and similar technologies to enhance user experience, analyze traffic, and facilitate certain website functions. A cookie is a small text file that a website stores on your device. You can control and manage your cookie preferences through your browser settings. Please see our separate Cookie Policy (available on each website) for additional details about how we use cookies and how you can opt out.
Advertising measurement. When you arrive at our consumer websites from an advertising platform, a click identifier (e.g., fbclid, ttclid, gclid) is stored in a first-party cookie for up to 90 days. Key events (such as viewing a film page) may be reported to the advertising platform concerned (Meta, TikTok, Google) directly from our servers, together with the click identifier and technical data such as a hashed identifier, IP address, and event time. The legal basis is our legitimate interest in measuring and optimising our advertising. The Cookie Policy on each website describes the applicable controls.
12. SECURITY MEASURES
To protect your personal data, we implement appropriate technical and organizational measures, such as:
-
Firewalls, secure servers, and encryption of data in transit where appropriate.
-
Limitation of access to personal data solely to authorized persons on a need-to-know basis.
-
Incident management procedures in the event of data breaches, including notifications to supervisory authorities and, where appropriate, affected individuals.
13. CONTACT US
For any questions about this Privacy Policy or our data processing practices, or to exercise your rights, please reach out to us at:
Email: info@filmdistribution.eu
Postal Address: Theatrical Film Distribution OÜ, Tööstuse 47D-15, 10416 Tallinn, ESTONIA
If you have concerns regarding our handling of your personal data, you also have the right to lodge a complaint with your local supervisory authority or another supervisory authority in the EU:
-
Estonia: Andmekaitse Inspektsioon (Data Protection Inspectorate), Tatari 39, 10134 Tallinn; info@aki.ee; www.aki.ee
-
Latvia: Datu valsts inspekcija (Data State Inspectorate); www.dvi.gov.lv
-
Lithuania: Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate); vdai.lrv.lt
14. CHANGES TO THIS PRIVACY POLICY
We may update or modify this Privacy Policy from time to time to reflect changes in our data processing practices or to comply with new regulatory obligations. Any changes will be effective immediately upon posting the revised Policy on our websites, and the updated date will be indicated at the top of this document. We encourage you to periodically review this page for the latest information on our privacy practices.