Privacy Policy
Effective date: [May 26, 2019]
Last updated: [September 19, 2025]
This Privacy Policy explains how Samko Bernat (“we”, “us”, “our”) collects, uses, discloses, and protects personal information when you visit www.samkobernat.com and related pages (the “Site”), interact with our content (including trailers and stills), contact us, or participate in brand-integration/collaboration forms (together, the “Services”).
By using the Site, you acknowledge this Policy. Where required by law (e.g., EU/EEA, UK), we only set non-essential cookies or process certain data with your consent.
1) Who we are (Controller / Owner)
Controller/Owner:
Samko Bernat
22880 Wedel, Germany
Email: management@samkobernat.com
2) What we collect
We collect personal information in three ways: you provide it, it’s collected automatically, or we receive it from third parties.
A. Information you provide
-
Contact details (name, email, company, role) when you email us or use forms.
-
Collaboration/brand-integration details (brand category, territories, interests, notes, links).
-
Press/festival inquiries (organization, request type, deadlines).
-
Newsletter (email address, optional profile preferences).
-
Uploads/submissions you choose to share (e.g., links to reels, decks).
B. Information collected automatically
-
Device/usage data: IP address, device type, browser, OS, language, referring pages, page views, time on page, click paths.
-
Approximate location (derived from IP, city/country level) for analytics and security.
-
Cookies and similar technologies (see Section 10).
C. Information from third parties
-
Analytics providers (aggregated engagement statistics).
-
Social platforms (if you interact with embedded Instagram/YouTube/Vimeo/TikTok content; they may set their own cookies).
-
Email & form providers (delivery status, bounce/complaint handling).
We do not intentionally collect sensitive categories of data. Please do not send sensitive information.
3) Why we process your data (Purposes & legal bases)
Purposes
-
Operate and secure the Site; prevent fraud/abuse; debug and monitor performance.
-
Respond to inquiries (media, festivals, brand integration, licensing, general).
-
Manage collaboration interest (e.g., product placement / presented-by / exclusivity).
-
Send updates (newsletter or release announcements, if you subscribe).
-
Measure reach & improve content (analytics, anonymized/aggregated).
-
Comply with laws and enforce our terms.
Legal bases (GDPR/UK GDPR)
-
Performance of a contract or pre-contractual steps (Art. 6(1)(b)): responding to your requests, sharing materials on request.
-
Legitimate interests (Art. 6(1)(f)): Site security, basic analytics, preventing misuse, essential communications.
-
Consent (Art. 6(1)(a)): non-essential cookies/marketing emails (opt-in where required).
-
Legal obligation (Art. 6(1)(c)): record-keeping, regulatory requests.
Your choices
-
You may opt out of non-essential cookies; unsubscribe from emails at any time via link or by contacting us.
4) Cookies & similar technologies
We use cookies, pixel tags, and local storage:
-
Strictly necessary: core functions, security, fraud prevention (non-optional).
-
Functional: remember preferences (language, layout).
-
Analytics: understand traffic patterns and improve the Site (subject to consent where required).
-
Embedded media: players from YouTube/Vimeo/Instagram/TikTok may place cookies. These platforms process data under their own policies.
Your control:
-
Use our cookie banner (where shown) to manage preferences.
-
Adjust browser settings to block/clear cookies; note some features may not work without them.
5) Disclosures (who receives your data)
We share data only as needed:
-
Hosting & web platform (e.g., Wix or similar) for Site operation.
-
Email/form providers (contact forms, newsletters).
-
Analytics & performance (IP-shortening or aggregated reports where available).
-
Content delivery & embeds (YouTube, Vimeo, Instagram, TikTok).
-
Professional advisors (legal/accounting) under confidentiality.
-
Authorities when required by law or to protect rights/security.
-
Business transfers: if we reorganize, merge, or transfer assets, data may be part of the transaction—your rights remain.
We do not sell personal information for money. Where laws define “sale” or “sharing” to include certain advertising or analytics uses, you may have additional opt-out rights (see Section 9).
6) International transfers
We operate internationally. Your data may be processed outside your country (including outside the EU/EEA/UK). Where required, we use appropriate safeguards (e.g., Standard Contractual Clauses, UK Addendum, or an adequacy decision). Copies of relevant safeguards can be requested via email.
7) How long we keep data (Retention)
We keep personal data only as long as necessary for the purposes above, then delete or anonymize it. Typical examples:
-
Inquiry emails/forms: up to 24 months after last contact (or longer where legally required).
-
Newsletter data: until you unsubscribe or after inactivity per provider’s rules.
-
Analytics logs: short technical retention for security/diagnostics; aggregated statistics may be kept longer without identifiers.
-
Contract or legal records: per statutory retention periods.
8) Security
We use technical and organizational measures appropriate to risk (TLS encryption in transit, access controls, least-privilege, provider due diligence). No system is 100% secure; please use caution when sending information online.
9) Your privacy rights
Your rights depend on your location’s laws. Subject to exemptions, you may request:
-
Access to your personal data and portability (copy in a structured format).
-
Correction of inaccurate data.
-
Deletion (“right to be forgotten”), restriction or objection to certain processing.
-
Consent withdrawal at any time (does not affect prior processing).
-
Opt-out of targeted advertising / certain analytics and of the “sale” or “sharing” of personal information as defined by some laws (e.g., CCPA/CPRA).
-
Non-discrimination for exercising your rights (CCPA/CPRA).
How to exercise rights
Email management@samkobernat.com with your request, your country/region, and sufficient details to identify you. We may ask for verification (e.g., confirming control of the email address). Authorized agents (where applicable) must include proof of authority.
EU/EEA/UK: You may lodge a complaint with your data protection authority (e.g., in Germany: the relevant Landesdatenschutzbehörde; in the UK: the ICO).
10) Children’s privacy
The Site is not directed to children under the age required by local law (e.g., 13 or 16). We do not knowingly collect personal data from children. If you believe a child provided data, contact us to remove it.
11) Third-party links & embeds
Our Site may link to third-party sites or embed third-party players (YouTube, Vimeo, Instagram, TikTok). These services operate under their own privacy policies and may collect data when you view or interact with their content. Review their policies for details and controls.
12) Email communications
-
Transactional: replies to your inquiries or requests (cannot generally be unsubscribed).
-
Updates/Newsletter: sent only with your consent or as otherwise permitted; you can unsubscribe any time via link or email.
13) Brand integration & collaboration forms
If you register interest for product placement, credit lines, or exclusivity:
-
We process business contact details, brand/category, territories, and preferences to evaluate fit and share materials.
-
We may track document access (e.g., deck opens) for security and interest measurement.
-
You can opt out or request deletion at any time unless retained for legal reasons.
14) Do Not Track / Global Privacy Control
Some browsers send Do Not Track or GPC signals. Where legally required and technically feasible, we will honor recognized signals for applicable opt-outs.
15) Changes to this Policy
We may update this Policy from time to time. Changes are effective when posted with a revised “Last updated” date. For material changes, we may provide additional notice.
16) Contact
For any questions, requests, or complaints regarding this Policy or our handling of personal data, contact:
Samko Bernat
22880 Wedel, Germany
Email: management@samkobernat.com
Region-specific notices (supplemental)
A) EU/EEA & UK (GDPR/UK GDPR)
-
Data controller: Samko Bernat (see Section 1).
-
Legal bases: as listed in Section 3.
-
Transfers: safeguarded by SCCs/UK Addendum where applicable (Section 6).
-
Your rights: access, rectification, erasure, restriction, portability, objection, and consent withdrawal (Section 9).
-
Supervisory authority: You have the right to lodge a complaint with your local authority.
B) California (CCPA/CPRA)
-
Notice at collection: We collect identifiers (name, email), commercial information (collaboration interests), internet activity (device/usage data), and geolocation (approximate).
-
Purposes: as in Section 3; No sale for money. We may engage in “sharing” or “targeted advertising” as defined by law when using certain analytics/embedded platforms—opt-out available via cookie controls or by contacting us.
-
Rights: know/access, correct, delete, opt-out of sale/sharing/targeted ads, limit use of sensitive data (we do not use sensitive data for inferring characteristics), non-discrimination. Submit requests via management@samkobernat.com.
C) Brazil (LGPD)
-
Legal bases: consent, legitimate interests, performance of contract, compliance with legal obligations.
-
Rights: confirm processing, access, correction, anonymization/blocking/deletion, portability, information about sharing, consent withdrawal, review of automated decisions.
