Privacy policy
Last updated 7 September 2026.
This policy explains how guest photos, operator accounts and event data are handled, the lawful bases we rely on, how long anything is kept, and the rights you and your guests have under UK data protection law.
1. Who is responsible for your data
Cine Booth AI is operated by KUJI DIGITAL LTD, a company registered in England and Wales. Contact us at cineboothai@gmail.com for anything in this policy, including data rights requests.
There are two different relationships, and which one applies depends on whose data it is.
For photos and information captured from guests at an event, the event operator decides why the booth is being used and is the data controller. We act as their processor and handle guest photos only on their documented instructions and as described here.
For operator accounts, billing, support, website enquiries and platform security, we are the controller ourselves.
This policy also serves as the data-processing terms between us and each operator. Operators must have their own privacy notice covering their events.
2. Guest photos and what happens to them
Guests are told on screen what will happen before the camera starts, and must actively agree. Nothing is captured without that agreement.
Guest photos are used for one purpose only: creating the movie or cover the guest asked for, and delivering it to that guest and to the operator running the event.
A guest can stop at any point during capture and choose to delete their photos immediately. That deletion is carried out straight away, not queued.
Guest photos are never sold, never shared with advertisers, never used to promote our business, and never used to train AI models.
The lawful basis for handling guest photos is the guest's consent, obtained by the operator at the booth. Consent can be withdrawn at any time, and withdrawal stops any further processing.
3. Face data and special category data
Guest photos show faces. Our processing produces a stylised likeness; it is not used to uniquely identify a person, we do not run facial recognition, we do not match faces across events, and we do not build face templates or a face database.
Even so, we treat face imagery as sensitive. It is stored in access-controlled systems, isolated per operator, kept behind private links that expire, and deleted on the schedule below.
Where an operator's use of the service would amount to biometric identification, that operator is responsible for the additional legal requirements that brings, and must tell us in advance.
4. AI providers and who else sees the data
Producing a movie requires sending the guest's photos to specialist AI providers we contract with. They may only use the material to produce that result, must not use it for their own purposes or model training, and must delete it after processing.
We also use service providers for hosting and databases, email delivery, payment processing, and error monitoring. Each is bound by a written contract and may only act on our instructions.
We do not sell personal data. We may disclose data where we are legally required to, to protect people from harm, or in connection with a sale or reorganisation of our business.
5. Operator account data
If you hold an account with us we process:
- identity and contact details: name, email address, company details, team member records
- account activity: events, bookings, devices, generations, settings and support messages
- billing: credit balance, purchases, invoices and payment references — card details are handled by our payment provider and never reach our systems
- technical data: IP address, device and browser information, and security logs
6. Why we process operator data, and on what basis
To perform our contract with you: running your account, processing purchases, delivering the service and providing support.
For our legitimate interests: keeping the platform secure, preventing fraud and abuse, understanding how features are used so we can improve them, and defending legal claims. We balance these against your interests and use the least intrusive option available.
To meet legal obligations: tax, accounting and records we must keep by law.
With your consent: marketing emails, where you have opted in. You can withdraw consent at any time using the unsubscribe link.
7. Enquiries and website use
If you contact us through the website we keep your message and contact details so we can reply and keep a record of the conversation. We also record basic anti-abuse information such as the time and source of the submission.
We use only the cookies and local storage needed to make the site and the operator app work — signing you in, keeping your session, and letting a booth keep working when the venue connection drops. We do not use advertising or cross-site tracking cookies.
8. How long we keep things
We keep personal data no longer than we need it. Finished guest media is retained for 30 days after the event and is then purged. Limited operational, consent, security, financial and aggregated or analytics records may be kept for longer where this is necessary for legal, accounting, security or service-improvement purposes.
- guest capture photos: deleted once the movie is produced, or immediately if the guest stops and deletes
- finished guest movies and covers, and their delivery links: retained for 30 days after the event and then purged
- guest consent records: kept as a minimal record that consent was given, so both we and the operator can evidence it
- operator account records: kept while the account is open and for up to 12 months after closure
- billing and tax records: kept for 6 years as required by UK law
- security and error logs: typically 90 days
- aggregated or anonymised usage statistics, which do not identify individuals: kept indefinitely
9. Where data is stored and transferred
Our primary application database and storage run on European-region cloud infrastructure.
Certain data may be processed internationally by third-party providers, including AI, email, payment and infrastructure providers. Some of these providers operate outside the UK and EEA, including in the United States.
Where data is processed outside the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on the UK International Data Transfer Addendum or Standard Contractual Clauses, together with appropriate additional safeguards. You can ask us for details of the safeguards used.
10. Security
We use access controls, encryption in transit, per-operator data isolation, private expiring links for guest media, role-based permissions and audit logging. Access to production data is limited to staff who need it.
No system is perfectly secure. If a personal data breach occurs that is likely to affect people's rights, we will notify the Information Commissioner's Office within 72 hours where required, and will tell affected operators without undue delay so they can inform their guests.
11. Your rights
You have the right to access your data, correct it, have it deleted, restrict or object to its processing, receive a portable copy, and withdraw consent where processing relies on consent.
Guests should make requests to the operator who ran their event, because that operator is the controller. If a guest contacts us directly, we will pass the request to the relevant operator and support them in answering it.
We respond to requests within one month. We do not charge for this, and we may ask for information to confirm identity before acting.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
12. Children
The platform is not intended for children. Operators must not capture anyone under 16 without the clear agreement of a parent or guardian present at the event, and must not run the experience in a setting aimed at younger children.
If we learn that a child's data has been captured without proper agreement, we will delete it.
13. Automated decisions
We do not make decisions producing legal or similarly significant effects about anyone by automated means alone. Automated checks are used for image quality and safety, and a person can review any outcome on request.
14. Changes to this policy
We will update this policy as the service and the law change, and we will tell account owners by email about material changes. The date at the top shows when it was last revised.
Also read our terms of service and refund policy. Data questions: cineboothai@gmail.com.
