Privacy Policy

Effective Date: 30 September 2025

Operated by: Atlas Distribution GmbH, Pestalozzistr. 5–8, 13187 Berlin, Germany

Website: http://www.miralot.com

Contact: legal@miralot.com

1. Introduction and Data Controller

Atlas Distribution GmbH operates the Miralot platform and is the data controller responsible for processing your personal data in accordance with the EU GDPR and German BDSG.

Data Controller:

Atlas Distribution GmbH

Pestalozzistr. 5–8, 13187 Berlin, Germany

Email: legal@miralot.com

2. Scope of This Privacy Policy

This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the Miralot platform. It applies to all users, including filmmakers, production companies, distributors, and festival organizers. By using our services, you acknowledge that you have read and understood this Privacy Policy.

3. Personal Data We Collect

3.1 Account and Registration Data

When you create an account, we collect: name and surname, email address, and encrypted password.

3.2 Film and Submission Data

When you use our services, we collect: film metadata (title, genre, length, language, country, year), director information (name, age, gender), film materials (synopsis, stills, trailers, press kits), submission history, and festival preferences.

3.3 Payment Data

For paid subscriptions: payment method (processed by Stripe/PayPal), billing address, transaction history, and VAT information. We do not store complete credit card numbers.

3.4 Communication Data

Email correspondence, newsletter subscriptions (if opted in), and support requests.

3.5 Usage and Technical Data

IP address (anonymized/deleted after 7 days), browser type, operating system, pages visited, features used, date/time of access, and referral source.

4. How We Use Your Personal Data

4.1 Service Provision

We use your data to create and manage your account, provide festival submission recommendations, submit films on your behalf, process payments, communicate about your account, and provide customer support.

4.2 Algorithm Improvement

We use anonymized film metadata to improve our festival matching algorithm. Personal identifying information is never used for training. All processing occurs on EU servers in Germany.

Current processing: Genre, length, language, country, year, director demographics, submission outcomes, AI-assisted genre extraction.

Future processing: Film screenshots and visual analysis.

4.3 Business Analytics

We analyze usage patterns, submission success rates, platform metrics, and subscription data. We may create pseudonymous user profiles (deleted within 2 years of account closure). Individual users are not identified in aggregate reports.

4.4 Marketing

With your consent, we may send newsletters and use film materials for promotional purposes. Withdraw anytime via email unsubscribe or contact legal@miralot.com.

5. Cookies and Tracking

Essential Cookies (always active): Session management, authentication, security, CSRF protection, load balancing.

Optional Cookies (require consent): Pirsch Analytics (EU-based), potentially Google Analytics, A/B testing, Facebook Pixel.

Manage preferences via our cookie banner, account settings, or browser settings. Disabling essential cookies may affect functionality.

6. Data Sharing

6.1 Festival Submissions

We transmit your film materials to: FilmFreeway (USA), Festhome (Spain), Shortfilmdepot (Germany), and other platforms/festivals worldwide as selected by you.

Important: This may involve transfers outside EU/EEA. By using our Submission Service, you explicitly consent to these transfers.

6.2 Service Providers

We use: Hetzner (hosting, Germany), Stripe (payments, USA, SCCs), PayPal (payments, USA, SCCs), Brevo (email, France), Pirsch Analytics (Germany), and potentially Google Analytics (USA, anonymized).

All providers are bound by data processing agreements.

6.3 No Sale of Data

We do not sell, rent, or trade your personal data to third parties.

7. International Data Transfers

Transfers outside EU/EEA occur for: festival submissions (with consent), payment processing (protected by SCCs), and potential Google Analytics (anonymized, with consent).

We ensure protection through Standard Contractual Clauses, explicit consent, and anonymization where possible.

8. Data Retention

Active accounts: Data retained while account is active.

After termination: Personal data deleted within 90 days; anonymized metadata may be retained (you can object); invoices retained 10 years for tax compliance.

IP addresses: Anonymized/deleted after 7 days. Server logs retained 31 days.

Backups: May retain deleted data up to 90 days.

9. Your Data Protection Rights

Under GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion (exceptions apply for legal requirements)
  • Restriction: Limit how we use your data
  • Portability: Receive data in machine-readable format
  • Object: Object to processing based on legitimate interests or direct marketing
  • Withdraw consent: For newsletter, promotional materials, optional cookies

Lodge a complaint: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstr. 219, 10969 Berlin, Germany

Exercise your rights: Contact legal@miralot.com. We respond within 30 days.

10. Security Measures

Technical: SSL/TLS encryption, encrypted password storage (bcrypt/Argon2), EU-based servers, role-based access controls, encrypted backups, log file monitoring.

Organizational: Data processing agreements, employee training, incident response procedures, security audits, privacy by design principles.

Your responsibility: Keep login credentials secure. Notify legal@miralot.com immediately if you suspect unauthorized access.

11. Children's Privacy

Miralot is not intended for children under 18. Users under 18 may only use our services under parental supervision with consent. If we learn we have collected data from a child under 18 without parental consent, we will delete it promptly.

12. Server Log Files

Our hosting provider collects: accessed files, date/time, data transferred, browser type, operating system, referrer URL, IP address (anonymized after 7 days), and access provider. Log files retained maximum 31 days for security purposes.

13. Changes to This Policy

We may update this Privacy Policy. Material changes will be notified by email at least 6 weeks in advance. Continued use after changes constitutes acceptance. Current version available at: http://www.miralot.com/privacy

14. Contact Information

Atlas Distribution GmbH

Pestalozzistr. 5–8

13187 Berlin, Germany

Email: legal@miralot.com

Website: http://www.miralot.com