StudioLot — Privacy Policy
Last Updated: 24 July 2026 · Effective Date: 24 July 2026 · Version 1.0
Introduction
StudioLot AI Private Limited ("StudioLot," "we," "our," or "us") provides a cloud-based film and content production management platform with embedded artificial intelligence capabilities (the "Platform" or "Services").
This Privacy Policy explains how we collect, use, disclose, transfer, retain, and protect personal data when you visit our websites, create an account, use the Platform, contact us, or otherwise interact with us. It also explains the rights available to you and how to exercise them.
Please read this Policy alongside our Terms and Conditions, and any Data Processing Addendum executed between you and StudioLot.
A note on AI model training
We do not use your content to train our AI models. We do not use your scripts, screenplays, uploaded files, prompts, generated outputs, or other Customer Content to train, fine-tune, retrain, or otherwise improve any general-purpose or foundation AI model, whether our own or a third party's. We contractually require our AI model providers not to do so either.
The only exception is where you affirmatively opt in to a feature that is clearly described as training a model for you — for example, a custom style model or character-consistency model trained exclusively for your own workspace. Such models are used only within your workspace and are not used to serve other customers.
We describe this in more detail in Section 6.
1. Scope and Roles
1.1 What this Policy covers
This Policy applies to personal data we process:
- when you visit https://studiolot.ai and our related web properties, documentation sites, and marketing pages;
- when you register for, administer, or use the Platform, including our web application, mobile applications, APIs, and SDKs;
- when you communicate with our sales, support, or customer success teams;
- when you attend our events, webinars, or demonstrations;
- when you apply for a role with us; and
- when we receive your personal data from a customer, partner, or public source.
1.2 Our role: controller and processor
We act in two distinct capacities.
As a controller. We determine the purposes and means of processing when we handle: account registration and administration data; billing and payment data; usage, telemetry, device, and log data; support and communication records; marketing and website analytics data; and security, fraud prevention, and abuse detection data. For this processing, this Privacy Policy is our controller-level notice.
As a processor. When a business customer uses the Platform, personal data contained within the content they upload — for example, cast and crew details in a call sheet, names appearing in a screenplay, faces in a reference photograph, or contact details in a production document — is processed by us on that customer's instructions. In that context: the customer is the controller; StudioLot is the processor (or sub-processor); the customer's own privacy notice, not this one, governs how that data is handled at controller level; and our obligations are set out in the Data Processing Addendum executed between StudioLot and that customer.
If you are an employee, crew member, cast member, contractor, or other individual whose data has been uploaded to the Platform by a production company or other StudioLot customer, please direct your privacy requests to that organisation in the first instance. We will assist them in responding, and we will forward requests we receive directly.
1.3 Controller identity
For processing where we act as controller, the data controller is:
StudioLot AI Private Limited
C-514, Fifth Floor, Sumadhura Anandam, Borewell Road, Whitefield, Bangalore - 560066, Karnataka, India
Email: [email protected]
Privacy contact. We have not appointed a statutory Data Protection Officer, as we are not currently required to do so. All privacy enquiries, data subject requests, and related correspondence should be directed to our privacy contact at [email protected].
2. Personal Data We Collect
2.1 Data you provide directly
| Category | Examples |
|---|---|
| Account data | Name, email address, password (hashed), username, profile photo, job title, company or production house name, department, phone number, country, preferred language |
| Billing data | Billing name, billing address, GST/VAT/tax identification number, purchase order references, invoice history, plan and subscription details, partial payment card details (last four digits, card brand, expiry) |
| Content data | Everything you upload to or create in the Platform: scripts and screenplays, treatments, breakdown sheets, schedules, storyboards, reference images, photographs, video, audio, location notes, cast and crew lists, budgets, project files, documents, and any personal data contained within them |
| Prompt data | The text prompts, parameters, style selections, and instructions you submit to the AI Services |
| Output data | Images, animatics, storyboard frames, schedules, breakdowns, and other content generated by the AI Services for you |
| Communications data | Support tickets, emails, chat messages, call notes, demo requests, survey responses, feedback, bug reports |
| Event and marketing data | Registration details for webinars, demos, and events; newsletter subscription details; marketing preferences |
| Verification data | Where required for enterprise onboarding or fraud prevention: business registration details, authorised signatory information and, where legally required, identity verification documents |
2.2 Data collected automatically
| Category | Examples |
|---|---|
| Device and technical data | IP address, browser type and version, operating system, device type and identifiers, screen resolution, language and locale, time zone |
| Usage data | Pages and screens viewed, features used, buttons clicked, session duration, navigation paths, referring and exit URLs, search queries within the Platform |
| AI usage metering | Number of generations, credits consumed, model routed to, render duration, queue times, error and failure rates, request and response sizes (metadata only) |
| Log data | Timestamps, request identifiers, API endpoints called, HTTP status codes, latency, error messages, stack traces |
| Security data | Login attempts and outcomes, authentication events, IP reputation signals, anomalous activity indicators, rate-limit events |
| Cookie and similar data | See Section 10 (Cookie Policy) |
| Approximate location | Derived from IP address at city/country level, used for security, fraud prevention, tax determination, data residency routing, and localisation. We do not collect precise GPS location. |
2.3 Data from third parties
| Source | Data received |
|---|---|
| Your organisation's administrator | Account provisioning details, role assignments, seat allocations, directory data via SSO/SCIM |
| Identity providers (e.g., Google, Microsoft Entra ID, Okta) | Name, email, unique identifier, group memberships, where you sign in via SSO |
| Payment processors (such as Stripe) | Transaction confirmations, payment status, fraud signals, partial card details |
| Integration partners (e.g., cloud storage, project tools, communication tools you connect) | Data you authorise the integration to share |
| Marketing and enrichment providers | Business contact details, firmographic data, event attendance |
| Publicly available sources | Company websites, public professional profiles, public registries |
| Referral sources | Details provided when someone invites you to a workspace |
2.4 Sensitive personal data
We do not seek and ask you not to submit special-category or sensitive personal data to the Platform. This includes government identifiers (Aadhaar, PAN, passport, national ID), payment card numbers, banking credentials, biometric or genetic data, health or medical information, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation, and criminal records.
If such data is submitted in breach of our Terms, it is processed only incidentally as part of your content, and you are responsible for having a lawful basis to do so. Enterprise arrangements permitting specific categories of sensitive data require a separate written agreement and additional safeguards.
2.5 Children's data
The Platform is not directed to individuals under eighteen (18) years of age and we do not knowingly collect their personal data as a controller. If we learn that we have collected such data without appropriate consent, we will delete it. Contact [email protected] if you believe a child's data has been provided to us.
Note that production content uploaded by customers may reference child performers. Such data is processed on the customer's instructions as processor, and the customer is responsible for the lawful basis, parental consents, and any applicable child labour and safeguarding requirements.
3. How We Use Personal Data
3.1 To provide the Services
- create, authenticate, and administer your account and workspace;
- process, store, render, and deliver your content;
- route your requests to the appropriate AI model and return outputs to you;
- enable collaboration, sharing, comments, and permissions within your workspace;
- synchronise with integrations you have connected;
- maintain version history and backups;
- provide search and retrieval across your workspace.
3.2 To operate and maintain the Platform
- monitor availability, performance, latency, and errors;
- diagnose and fix defects;
- perform capacity planning and infrastructure scaling;
- conduct maintenance, testing, and deployment;
- meter usage and enforce plan limits.
3.3 To secure the Platform
- detect, investigate, and prevent unauthorised access, account takeover, credential stuffing, fraud, abuse, and other malicious activity;
- enforce rate limits and detect anomalous consumption;
- apply safety filters and content moderation to prevent generation of prohibited content;
- investigate suspected violations of our Terms and Acceptable Use Policy;
- maintain audit logs;
- respond to security incidents.
3.4 To improve the Services (without training models on your content)
- analyse aggregated and de-identified usage patterns to understand which features are used and where users encounter friction;
- measure quality signals such as generation success rates, error rates, retry rates, and latency;
- run A/B tests and feature experiments;
- prioritise the product roadmap;
- improve prompts, guardrails, routing logic, and system configuration at an aggregate level.
This does not involve training AI models on your content. See Section 6.
3.5 To communicate with you
- send service and transactional messages (account confirmations, security alerts, billing notices, incident notifications, changes to terms);
- respond to support requests and enquiries;
- send product updates, release notes, and, where permitted, marketing communications about StudioLot products and events;
- conduct surveys and request feedback.
You can opt out of marketing at any time. Service and transactional messages cannot be opted out of while you hold an account.
3.6 To bill and manage the commercial relationship
- process payments, invoices, refunds, and collections;
- apply taxes and issue tax documentation;
- manage renewals, upgrades, downgrades, and cancellations;
- maintain financial and accounting records.
3.7 To comply with law and protect rights
- comply with legal, regulatory, tax, and accounting obligations;
- respond to lawful requests from public authorities, courts, and law enforcement;
- establish, exercise, or defend legal claims;
- enforce our Terms;
- protect the rights, property, and safety of StudioLot, our customers, and the public;
- report child sexual abuse material and other content we are legally required to report.
3.8 Corporate transactions
- to evaluate, negotiate, and complete a merger, acquisition, financing, reorganisation, or sale of assets, subject to confidentiality protections.
4. Legal Bases for Processing (GDPR / UK GDPR)
Where the EU or UK GDPR applies, we rely on the following legal bases.
| Purpose | Legal basis |
|---|---|
| Providing the Services to you under our Terms | Contract (Art. 6(1)(b)) |
| Account administration, authentication, support | Contract (Art. 6(1)(b)) |
| Billing, invoicing, collections | Contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) for tax and accounting records |
| Platform security, fraud and abuse prevention | Legitimate interests (Art. 6(1)(f)) — securing our service and protecting users; Legal obligation where mandated |
| Aggregated analytics and product improvement | Legitimate interests (Art. 6(1)(f)) — improving a service our users rely on, using data that is aggregated or de-identified |
| Content moderation and safety filtering | Legitimate interests (Art. 6(1)(f)); Legal obligation (Art. 6(1)(c)) for reportable content |
| Direct marketing to business contacts | Legitimate interests (Art. 6(1)(f)), or Consent (Art. 6(1)(a)) where required by local law |
| Non-essential cookies and similar technologies | Consent (Art. 6(1)(a)) |
| Training a custom model at your request | Consent (Art. 6(1)(a)) and/or Contract |
| Responding to legal requests, defending claims | Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f)) |
| Corporate transactions | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have conducted a balancing assessment to confirm that our interests are not overridden by your rights and freedoms. You may request a summary of that assessment at [email protected], and you have the right to object (see Section 11).
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Special category data. We do not intentionally process special category data as controller. Where such data appears incidentally in customer content, we process it as processor on the customer's instructions, and the customer is responsible for identifying an Article 9 condition.
Other jurisdictions. Where the India Digital Personal Data Protection Act, 2023 applies, we process personal data on the basis of consent or a legitimate use as recognised under that Act. Where other laws apply, we process on the bases those laws provide.
5. Automated Decision-Making and AI Processing
5.1 Automated decision-making
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing.
Automated processing is used for:
- Content safety filtering — automated classifiers may block a generation request or flag content for human review. A blocked request can be appealed to [email protected] and reviewed by a person.
- Fraud and abuse detection — automated signals may trigger rate limiting, additional verification, or temporary suspension. Suspensions are reviewed by a person before becoming permanent.
- Usage metering and plan enforcement — automated but purely administrative.
You may contact [email protected] to obtain human review of any automated decision that affects your access to the Services, express your point of view, and contest the decision.
5.2 How AI processing works
When you submit a prompt or content to the AI Services:
- your request is transmitted over an encrypted connection to our Platform;
- our orchestration layer applies safety filtering and selects an appropriate model;
- the request is processed either by a model hosted in our infrastructure or by a third-party model provider operating under contract with us;
- the output is returned to your workspace and stored there;
- metadata about the request (timing, credits, model used, success/failure) is logged for metering, security, and reliability.
Third-party model providers we use are listed in Section 7.2 below. Each is contractually prohibited from using your content for their own model training and from retaining it beyond the period necessary to return the output, and, where the provider supports it, we use zero-data-retention endpoints.
5.3 Limitations you should know about
AI outputs are probabilistic and may be inaccurate, incomplete, fabricated ("hallucinated"), or biased. Outputs may contain personal data that is incorrect or that resembles a real person without that person's involvement. You are responsible for reviewing outputs before relying on or publishing them. See Section 13.3 of our Terms and Conditions.
6. AI Model Training — Our Commitment
6.1 What we do not do
We do not use your content to train AI models. Specifically, we do not use the following to train, fine-tune, retrain, or improve any general-purpose, foundation, or shared AI model:
- scripts, screenplays, treatments, or other documents you upload;
- images, video, audio, or reference material you upload;
- prompts, instructions, parameters, or style inputs you submit;
- outputs generated for you;
- project data, schedules, breakdowns, cast and crew information; or
- any other Customer Content.
We contractually require every third-party AI model provider integrated into the Platform to apply the same restriction to data we route to them.
6.2 The only exception: models you ask us to build for you
If you affirmatively opt in to a feature that is expressly described as training a model on your material — for example, a custom visual style model, a character-consistency adapter, or a workspace-specific fine-tune — then we will use the specific content you designate for that purpose only. Where this applies:
- the resulting model is used exclusively within your workspace;
- it is not used to serve any other customer;
- it is not merged into any shared or general-purpose model;
- you may request its deletion at any time; and
- it is deleted when your account is terminated, subject to the retention periods in Section 9.
6.3 What we do use for improvement
We use aggregated and de-identified operational data — such as counts of generations, error rates, latency measurements, feature adoption metrics, and failure categories — to operate, secure, and improve the Services. This data does not identify you or any individual and cannot reasonably be used to reconstruct your content.
Where a support ticket or abuse investigation requires a person at StudioLot to view specific content, access is limited to authorised personnel, is logged, and is granted only for the duration of the investigation.
7. How We Disclose Personal Data
We do not sell personal data. We do not share personal data for cross-context behavioural advertising.
We disclose personal data in the following circumstances.
7.1 Within your organisation
Content and activity in a shared workspace is visible to other members of that workspace and to workspace administrators, according to the permissions configured by your organisation. Administrators may access, export, modify, restrict, or delete content and accounts within their workspace, and may view usage and audit information.
7.2 Service providers and subprocessors
We engage third parties to help us operate the Services. Each is bound by written contract to process personal data only on our instructions, to maintain appropriate security, and not to use the data for their own purposes.
| Category | Purpose | Examples |
|---|---|---|
| Cloud infrastructure and hosting | Compute, storage, networking | Hostinger — Mumbai, India |
| AI model routing (text and language models) | Routing inference requests to language models | OpenRouter |
| AI model routing (image models) | Routing inference requests to image generation models | ImageRouter |
| AI inference and GPU compute | Image, video, storyboard, and animatic generation | Segmind |
| 3D scene and location generation | Location visualisation and spatial generation | World Labs |
| Payment processing | Billing, subscriptions, tax | Stripe |
| Professional advisors | Legal, accounting, audit, insurance | As engaged from time to time |
We do not currently engage separate third-party providers for product analytics, error monitoring, CRM, marketing automation, customer support ticketing, or identity federation. Where we introduce such providers, this Policy and the table above will be updated in accordance with Section 14.
Note that OpenRouter, ImageRouter, and Segmind are routing and inference intermediaries that may in turn direct requests to downstream model providers. We require each to apply the model-training restriction described in Section 6 throughout the chain. A current list of downstream model providers reached through these services is available on request at [email protected].
7.3 Legal and safety disclosures
We may disclose personal data where we believe in good faith it is necessary to:
- comply with applicable law, regulation, legal process, or an enforceable governmental request;
- respond to a valid subpoena, court order, warrant, or similar legal demand;
- enforce our Terms and investigate potential violations;
- detect, prevent, or address fraud, security, or technical issues;
- protect the rights, property, or safety of StudioLot, our users, or the public;
- report content we are legally obliged to report, including child sexual abuse material.
Where lawfully permitted, we will notify affected customers of legal demands for their data before disclosure so they may seek protective relief. We do not currently publish a transparency report; we will update this Policy if that changes.
7.4 Corporate transactions
In connection with a merger, acquisition, financing, restructuring, bankruptcy, or sale of assets, personal data may be transferred to the counterparty or successor, subject to confidentiality undertakings. We will notify you of any such transfer that materially changes how your personal data is handled.
7.5 With your direction
We disclose data to third parties when you instruct us to — for example, by connecting an integration, sharing a project link, inviting a collaborator, or exporting data.
8. International Data Transfers
8.1 Where we process data
We are headquartered in India and our primary hosting infrastructure is located in Mumbai, India. Our AI model routing and inference subprocessors may process data in additional countries, as indicated in the table at Section 7.2.
8.2 Transfer safeguards
Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country not benefiting from an adequacy decision, we rely on one or more of the following:
- the European Commission Standard Contractual Clauses (Decision 2021/914), incorporated into our Data Processing Addendum;
- the UK International Data Transfer Addendum to the SCCs, or the UK IDTA;
- the Swiss addendum to the SCCs, where Swiss law applies;
- an adequacy decision, where one covers the destination;
- your explicit consent or another derogation under Article 49, where applicable.
We conduct transfer impact assessments where required and apply supplementary measures such as encryption in transit and at rest, access controls, and a policy of challenging overbroad government requests. Copies of the relevant transfer mechanisms are available on request at [email protected].
8.3 India
Where the Digital Personal Data Protection Act, 2023 applies, cross-border transfers are made in accordance with that Act and any restrictions notified by the Central Government from time to time.
9. Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law.
| Data category | Retention period |
|---|---|
| Account data | Duration of the account, plus 90 days after closure |
| Customer Content and Outputs | Duration of the subscription; available for export for 30 days after termination; deleted from active systems within 30 days thereafter and from backups within 90 days |
| Prompts and generation metadata | 12 months, or shorter where you delete the associated project |
| Billing and tax records | 8 years, or as required by applicable tax and companies law |
| Security and audit logs | 12 months, longer where required for an active investigation |
| Support communications | 24 months after case closure |
| Marketing data | Until you opt out, plus a suppression record retained indefinitely to honour your opt-out |
| Cookie data | As set out in Section 10 |
| Abuse and Terms-violation records | 5 years, to prevent repeat violations and support enforcement |
| Aggregated and anonymised data | Indefinitely (no longer personal data) |
Where we are required to retain data for legal, regulatory, tax, or dispute-related reasons, we retain it for the period required and then delete or anonymise it. Data in encrypted backups is deleted according to our backup rotation cycle.
10. Cookie Policy
This Cookie Policy forms part of our Privacy Policy and explains how we use cookies and similar technologies on our websites and in the Platform.
10.1 What cookies are
Cookies are small text files placed on your device when you visit a website. We also use related technologies including local storage, session storage, IndexedDB, software development kits, pixels, web beacons, and device fingerprinting signals. In this Policy, "cookies" refers to all of these.
10.2 Categories of cookies we use
(a) Strictly necessary cookies — required for the Platform to function. These cannot be switched off. They enable authentication, session management, security, load balancing, CSRF protection, and remembering your consent choices.
| Cookie / technology | Purpose | Duration |
|---|---|---|
| sessionid | Session authentication (Django session) | Session |
| studiolot_auth | Authentication token | Session |
| csrftoken | Cross-site request forgery protection | 12 months |
| studiolot_lb | Load balancing / request routing | Session |
| studiolot_consent | Stores your cookie consent choices | 12 months |
(b) Functional cookies — remember your preferences and enhance usability, such as language, theme, sidebar state, and recently opened projects.
| Cookie | Purpose | Duration |
|---|---|---|
| studiolot_locale | Language and locale preference | 12 months |
| studiolot_prefs | Interface preferences (theme, sidebar state, recent projects) | 12 months |
(c) Analytics and performance cookies — help us understand how the Platform is used, which features are adopted, and where errors occur.
We do not currently use any third-party analytics or performance cookies. We rely on server-side logs, which are described in Section 2.2. If we introduce third-party analytics, we will update this Policy and, where required, obtain your consent before doing so.
(d) Marketing and advertising cookies — used on public marketing pages to measure campaign effectiveness and, where applicable, to show relevant advertising.
We do not currently use any marketing or advertising cookies, and we do not use cookies for cross-site tracking or targeted advertising. If we introduce them, we will update this Policy and obtain your consent before setting them.
10.3 Consent
Where required by the ePrivacy Directive, the GDPR, or other applicable law, we place non-essential cookies only after you give consent through our cookie banner. The banner allows you to accept all, reject all non-essential cookies, or configure your choices by category. Rejecting is as easy as accepting.
Because we do not currently set analytics or advertising cookies, the only non-essential cookies we use are the functional cookies listed at 10.2(b).
You may change or withdraw your consent at any time via the "Cookie Settings" link in our website footer. Withdrawal does not affect the lawfulness of processing before withdrawal. We re-request consent at least every 12 months and whenever we materially change our cookie use.
10.4 Managing cookies through your browser
Most browsers allow you to block or delete cookies through their settings. Blocking strictly necessary cookies will prevent the Platform from working. Instructions are available in the help documentation for Google Chrome, Apple Safari, Mozilla Firefox, and Microsoft Edge.
10.5 Do Not Track and Global Privacy Control
We do not respond to browser Do Not Track signals, as there is no common standard. We do honour the Global Privacy Control (GPC) signal where legally required, treating it as a valid opt-out of sale/sharing and of targeted advertising.
10.6 Third-party cookies
Some cookies are set by third parties whose services appear on our pages, such as embedded videos, documentation widgets, or support chat. These parties may collect data about your browsing. We do not control their cookies; consult their own privacy policies.
11. Your Privacy Rights
11.1 Rights under the GDPR and UK GDPR
If you are in the EEA, UK, or Switzerland, you have the right to:
- Access — obtain confirmation of whether we process your personal data and receive a copy, together with information about the processing;
- Rectification — have inaccurate personal data corrected and incomplete data completed;
- Erasure ("right to be forgotten") — have personal data deleted where one of the grounds in Article 17 applies;
- Restriction — require that we limit processing in the circumstances set out in Article 18;
- Data portability — receive personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- Object — object at any time to processing based on legitimate interests, and to object absolutely to direct marketing;
- Not be subject to solely automated decision-making producing legal or similarly significant effects (see Section 5.1);
- Withdraw consent at any time where processing is based on consent;
- Lodge a complaint with a supervisory authority (see Section 11.6).
11.2 Rights under Indian law (DPDP Act, 2023)
If you are a Data Principal under the Digital Personal Data Protection Act, 2023, you have the right to:
- obtain a summary of the personal data being processed and the processing activities undertaken;
- obtain the identities of other Data Fiduciaries and Data Processors with whom your data has been shared;
- correction, completion, updating, and erasure of your personal data;
- nominate another individual to exercise your rights in the event of death or incapacity; and
- an accessible grievance redressal mechanism (see Section 11.6).
11.3 Rights under US state privacy laws
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another US state with a comprehensive privacy law, you may have the right to:
- know what personal information is collected, used, disclosed, and the categories of sources and recipients;
- access and obtain a portable copy;
- correct inaccurate personal information;
- delete personal information;
- opt out of the sale or sharing of personal information and of targeted advertising;
- opt out of profiling in furtherance of decisions producing legal or similarly significant effects;
- limit the use and disclosure of sensitive personal information; and
- not be discriminated against for exercising these rights.
We do not sell personal information and do not share it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We have not done so in the preceding twelve months.
You may exercise these rights, including through an authorised agent, by contacting [email protected]. We will verify your identity before responding. California residents may also have rights regarding "Shine the Light" disclosures under Cal. Civ. Code § 1798.83.
11.4 Rights under other laws
Residents of other jurisdictions — including Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), Japan (APPI), Singapore (PDPA), South Africa (POPIA), Saudi Arabia (PDPL), and the UAE (PDPL) — may have comparable rights. Contact us and we will respond in accordance with applicable law.
11.5 How to exercise your rights
Send your request to [email protected] or use the in-product privacy controls where available. Please include enough information for us to identify you and describe the right you wish to exercise.
- We will acknowledge within 72 hours, or sooner where required by law.
- We will respond substantively within one month (GDPR) or the period required by applicable law, extendable by two further months for complex requests, with notice to you.
- There is no fee unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline.
- We may need to verify your identity, and may request additional information for that purpose.
If your personal data was uploaded to the Platform by a StudioLot customer (for example, your production company), we act as processor and will refer your request to that customer, who is the controller. Please contact them directly for the fastest resolution.
11.6 Complaints and grievance redressal
If you are dissatisfied with our response, you may complain to a supervisory authority.
- EEA: the data protection authority of your habitual residence, place of work, or place of the alleged infringement. A list is available at https://edpb.europa.eu.
- UK: the Information Commissioner's Office — https://ico.org.uk.
- Switzerland: the Federal Data Protection and Information Commissioner.
- India: the Data Protection Board of India, after first raising the matter with our Grievance Officer.
Email: [email protected]; Address: C-514, Fifth Floor, Sumadhura Anandam, Borewell Road, Whitefield, Bangalore - 560066, Karnataka, India. Acknowledgement within twenty-four (24) hours; resolution within fifteen (15) days.
We would appreciate the opportunity to address your concerns before you approach a regulator.
12. Security
We maintain administrative, technical, physical, and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, and destruction. These include:
- encryption of data in transit using TLS 1.2 or above;
- encryption of data at rest using AES-256;
- role-based access control and least-privilege access provisioning;
- multi-factor authentication for administrative access;
- network segmentation, firewalls, and web application firewall protection;
- centralised logging, monitoring, and alerting;
- secure software development lifecycle practices and code review;
- dependency and vulnerability scanning and timely patching;
- periodic penetration testing by independent third parties;
- background screening of personnel where lawful, and confidentiality obligations;
- security awareness training;
- vendor due diligence and contractual security requirements;
- documented incident response and business continuity procedures.
No system is completely secure. We cannot guarantee absolute security. You are responsible for safeguarding your credentials and configuring workspace permissions appropriately.
Breach notification. Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the competent supervisory authority within 72 hours of becoming aware, and will notify affected individuals or our customers without undue delay where required. Where we act as processor, we will notify the controller without undue delay in accordance with our Data Processing Addendum.
13. Third-Party Links and Services
Our websites and the Platform may contain links to, or integrations with, third-party websites and services. This Policy does not apply to them. We are not responsible for their content, security, or privacy practices. Review their privacy policies before providing personal data.
14. Changes to This Policy
We may update this Policy to reflect changes in our practices, technology, legal requirements, or business.
- We will update the "Last Updated" date at the top.
- For material changes, we will provide prominent notice — by email to your registered address, by in-product notification, or by banner on our website — at least 30 days before the change takes effect.
- Where a change requires consent under applicable law, we will obtain it.
- Prior versions are available on request at [email protected].
Continued use of the Services after the effective date constitutes acceptance of the updated Policy, except where consent is required.
15. Contact Us
StudioLot AI Private Limited
Registered office: C-514, Fifth Floor, Sumadhura Anandam, Borewell Road, Whitefield, Bangalore - 560066, Karnataka, India
| Purpose | Contact |
|---|---|
| Privacy enquiries and data subject requests | [email protected] |
| Privacy contact | [email protected] |
| Security reports and vulnerability disclosure | [email protected] |
| Abuse and content reports | [email protected] |
| General support | [email protected] |
| Legal notices | [email protected] |