Privacy Policy
We process personal data only as needed to provide you with a functional website. This policy describes what data is collected, who processes it, and what rights you have.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
bce films & more GmbH
Bettina Ehrhardt
Occamstraße 6
80802 Munich
Germany
Phone: +49 173 200 33 66
Email: bce@bcefilms.com
Further details can be found in the Legal Notice.
2. Your rights
At any time, you have the right to:
- Access to your stored data (Art. 15 GDPR)
- Rectification of incorrect data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw consent at any time, with effect for the future (Art. 7 (3) GDPR)
To exercise these rights, an informal email to bce@bcefilms.com is sufficient.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority for us is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de
3. Hosting and server log files
This website is hosted by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. The servers are located in the European Union. We have concluded a data processing agreement with Hetzner pursuant to Art. 28 GDPR.
Each time the website is accessed, the server automatically records the following technical data in so-called server log files:
- IP address (stored in truncated form and automatically deleted after no more than 14 days)
- Date and time of access
- Page or file requested
- Volume of data transferred
- HTTP status code
- Browser type and version, operating system
- Referrer URL (previously visited page)
This data is used solely for technical operation, security and error analysis. The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in the secure and stable operation of the website). The data is not merged with other data sources and is not analysed on a personal level.
4. Cookies
This website does not set cookies of its own. No tracking or advertising cookies are used. Possible exceptions: embedded third-party content (e.g. YouTube and Vimeo videos) may set its own cookies when played – details below in the relevant sections. When purchasing streaming access to a film or making a voluntary contribution, the embedded Stripe checkout interface may set cookies necessary for secure payment processing (see section 5).
5. Streaming access to films
On bcefilms.eu you can purchase paid access to stream individual films – either time-limited or as long-term access. To process the transaction and deliver the content, we process the following data:
- Email address (obtained from the payment process)
- Title of the film purchased
- The film's language version chosen at purchase
- Access type (time-limited access, long-term access, or long-term access with a support contribution)
- Personal access token (a unique one-time link granting access to the film)
- Stripe session ID (to prevent duplicate records)
- Date of purchase
- For time-limited access: the date on which the 30-day period for starting playback expires
- Timestamp of first playback (for time-limited access: start of the 72-hour viewing window)
- Access status (active or revoked)
- Your consent to performance of the contract beginning immediately and to the resulting expiry of your right of withdrawal (§ 356(6) BGB) – with its timestamp, the version of the text consented to, and the language of the order
- Your acceptance of our Terms and Conditions given during payment (we store only the fact that it was given; we do not receive a timestamp for it)
The legal basis is Art. 6 (1) lit. b GDPR (performance of a contract).
Payment processing – Stripe
Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland, and Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA. The checkout is presented as an embedded form on our website; your payment details (e.g. card information, billing address) are processed directly by Stripe – we do not receive or store this data.
Stripe is more than a purely technical payment processor: it settles the transaction as the merchant of record and additionally processes your data for its own purposes of fraud prevention and risk assessment (including Stripe Radar) and to meet its own legal and regulatory obligations (e.g. anti-money-laundering, financial-supervisory and tax record-keeping duties). For this purpose Stripe may also collect technical information about your device and the transaction within the embedded checkout.
Stripe therefore has a dual role: where Stripe executes the payment on our behalf it acts as our processor, and we have concluded a data processing agreement with Stripe pursuant to Art. 28 GDPR. Where Stripe processes data for fraud prevention, for settlement as merchant of record and to meet its own legal obligations, Stripe acts as an independent controller within the meaning of the GDPR and processes your data in accordance with its own privacy policy. The legal basis is Art. 6 (1) lit. b GDPR (performance of a contract) and Art. 6 (1) lit. f GDPR (legitimate interest in fraud prevention and secure payment processing).
Because Stripe transfers data to the USA, data is transferred to a third country. This transfer is safeguarded by the EU-US Data Privacy Framework (DPF) and, where applicable, supplementary Standard Contractual Clauses pursuant to Art. 46 GDPR.
Stripe's privacy policy: https://stripe.com/privacy
Transactional email – Resend
After your purchase we send you your personal film access link by email. For technical delivery we use the service Resend, operated by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. In this process we transmit in particular your email address, the content of the transactional email including the personal access link, and technical send and delivery metadata. The transfer to the USA is safeguarded by the EU-US Data Privacy Framework (DPF) and, where applicable, supplementary Standard Contractual Clauses pursuant to Art. 46 GDPR. We have concluded a data processing agreement with Resend pursuant to Art. 28 GDPR.
Resend's privacy policy: https://resend.com/legal/privacy-policy
Voluntary contributions
For films we make available for streaming free of charge, you may make a voluntary contribution to us (see Section 5 of our Terms & Conditions). Such a contribution grants no access to a film. We create no record of it in our access database: no access token is generated, no film licence is associated with it, and your email address is not stored on our server.
The payment data – in particular your email address, the amount, the time, and which film page the contribution was made from – is processed and stored solely by our payment provider Stripe, where we access it through the Stripe dashboard. The statements in the "Payment processing – Stripe" section above apply accordingly, save that contributions are not processed via Stripe Managed Payments and Link does not act as merchant of record for them. The legal basis is Art. 6 (1) lit. b GDPR (carrying out the payment you initiated) and Art. 6 (1) lit. f GDPR (legitimate interest in attributing and accounting for contributions received).
Retention
This purchase and access data is stored on our server in the European Union (see section 3). For long-term access, the data is retained for as long as access to the film exists. For time-limited access, the data is automatically deleted 14 days after the 30-day period for starting playback has expired. Records relevant for tax and accounting purposes are subject to statutory retention obligations (e.g. up to 10 years under German commercial and tax law); these records are held by our payment provider Stripe, not in our own access database.
6. Contact form
If you contact us via the contact form or by email, we process the data you provide (name, email address, message) solely to handle your enquiry. The legal basis is Art. 6 (1) lit. b GDPR (pre-contractual measures) or Art. 6 (1) lit. f GDPR (legitimate interest in responding to enquiries).
For the technical delivery of the form message to our email address we use the service Resend, operated by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. The data you provide (name, email address, subject, message), together with technical send and delivery metadata, is transmitted to Resend and the message is forwarded to our inbox. Resend does not store your message permanently.
Because Resend is operated in the USA, data is transferred to a third country. The transfer is safeguarded by the EU-US Data Privacy Framework (DPF) and, where applicable, supplementary Standard Contractual Clauses pursuant to Art. 46 GDPR. We have concluded a data processing agreement with Resend pursuant to Art. 28 GDPR.
Resend's privacy policy: https://resend.com/legal/privacy-policy
Your enquiry will be deleted once it has been fully processed, provided no statutory retention obligations apply.
7. Audience analytics with Umami
We use Umami, a privacy-friendly open-source analytics tool (umami.is), to evaluate the use of our website. Umami is self-hosted on our own Hetzner server (see section 3). No data is transmitted to third parties.
Umami works entirely without cookies. No data is stored on or read from your device. To measure unique visitors without cookies, the full IP address and user-agent string are processed transiently in the server's volatile memory to generate an anonymised daily hash. The raw IP address is never written to disk or stored permanently. Analysis is carried out in aggregate; no profiling or tracking of individuals across different days takes place.
The data recorded includes page views, country of origin (country level), browser type and screen resolution. The statistics are stored without the IP address; we are unable to attribute them to a specific person, and visitors are not recognised beyond the day in question. This data is used solely to improve the content and structure of the website.
The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in privacy-friendly statistical audience measurement and in the stable technical operation of the website). Because Umami sets no cookies and does not store or read any information on your device, consent under § 25 TDDDG (formerly TTDSG) is not required.
You can object to this audience measurement at any time by enabling the "Do Not Track" (DNT) setting in your browser. When this signal is set, Umami records no data about your visit.
8. Embedded videos (Vimeo)
On individual pages of this website, we embed videos from the Vimeo platform. This applies both to freely accessible trailers and films and to films you have purchased streaming access to (see section 5). The provider is Vimeo, LLC, 555 West 18th Street, New York, New York 10011, USA.
We use Vimeo in its "Do Not Track" mode. According to Vimeo, in this mode it does not use tracking cookies and does not analyse your user behaviour for advertising purposes. However, a connection to Vimeo's servers is still established as soon as you visit a page with an embedded video – this is technically necessary in order to display the video.
The following data is transmitted to Vimeo at a minimum:
- Your IP address
- Date and time of access
- The page on our site that was accessed
- Technical information about your browser and operating system
If you are logged in to Vimeo at the same time, Vimeo may assign this information to your user account. You can prevent this by logging out of Vimeo before visiting our website.
Because Vimeo is operated in the USA, data is transferred to a third country. The transfer takes place on the basis of the EU-US Data Privacy Framework (DPF) and, where applicable, supplementary Standard Contractual Clauses pursuant to Art. 46 GDPR.
The legal basis for embedding is Art. 6 (1) lit. f GDPR (legitimate interest in presenting our film work in an appealing way) and, for purchased streaming access, Art. 6 (1) lit. b GDPR (performance of a contract).
Vimeo's privacy policy: https://vimeo.com/privacy
9. Embedded videos (YouTube)
On individual pages of this website, we embed videos from the YouTube platform. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
We embed YouTube exclusively via the youtube-nocookie.com domain in the so-called "privacy-enhanced mode". According to YouTube, no cookies are set in this mode as long as you do not start the video. However, a connection to Google's servers is still established as soon as you visit a page with an embedded video – this is technically necessary to load the preview image and the player.
The following data is transmitted to Google at a minimum:
- Your IP address
- Date and time of access
- The page on our site that was accessed
- Technical information about your browser and operating system
As soon as you start a video, YouTube sets additional cookies and transmits further usage data to Google. If you are logged in to Google at the same time, Google may assign this information to your user account. You can prevent this by logging out of Google before visiting our website.
Because Google also transfers data to the USA, data is transferred to a third country. The transfer takes place on the basis of the EU-US Data Privacy Framework (DPF) and, where applicable, supplementary Standard Contractual Clauses pursuant to Art. 46 GDPR.
The legal basis for embedding is Art. 6 (1) lit. f GDPR (legitimate interest in presenting our film work in an appealing way).
Google's privacy policy: https://policies.google.com/privacy
10. Links to social networks
Our website contains links to our profiles on Instagram, Facebook and YouTube. These links are implemented as plain hyperlinks or icons – there is no direct embedding of these services. Only when you click on one of these links are you redirected to the provider's site and data is transmitted to the provider.
For the data processing that takes place on the platforms themselves, the respective providers alone are responsible:
- Instagram & Facebook: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland – Privacy Policy
- YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland – Privacy Policy
11. Data security
Your data is transmitted encrypted via HTTPS (TLS). We take technical and organisational measures to protect your data against loss, manipulation and unauthorised access. Our security measures are continuously updated in line with technical developments.
12. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy should legal requirements or the services used on the website change. The current version is always available on this page.