Privacy notice / Draft 7 August 2026
Privacy should be operational, not decorative.
Draft identity and contact details
Ensomos is a brand operated by [REGISTERED LEGAL ENTITY], with its business address at [BUSINESS ADDRESS]. Privacy questions and rights requests may be sent to [PRIVACY CONTACT EMAIL].
1. What this notice covers
This draft explains how the Ensomos website and showroom handle information submitted by website visitors, including collection briefs, work-email requests for longer samples, and ordinary technical records used to operate and secure the site.
It does not describe every processing activity involved in a contracted data-collection project. Each commercial project should have its own agreement, capture protocol, rights schedule, and privacy assessment.
2. Information we collect
- Contact and company details, such as your name if provided, company, and email.
- Requirement details, including task, environment, viewpoint, geography, volume, timing, and free-text notes.
- Longer-sample acknowledgements, including the sample requested, terms version accepted, and submission time.
- Limited device, security, and server-log information needed to deliver and protect the service.
3. Why we use it
We use submitted information to respond to your request, evaluate operational feasibility, arrange a scoping conversation, manage sample access, prevent misuse, maintain security, and comply with applicable law. We do not use a collection brief to authorize unrelated marketing or model training.
4. Public sample footage
The public gallery is intended to contain short, watermarked, evaluation-only derivatives selected from authorized source footage. A release review must check faces, voices, badges, documents, screens, addresses, site identity, confidential processes, and brand marks before a clip is made public.
Visual controls and watermarks discourage misuse but do not make video impossible to copy. Rights, contractual controls, access limits, and the release-review process are the primary safeguards.
5. Sharing, storage, and transfers
We may use vetted service providers for hosting, security, communications, and business operations. They should process data only under documented instructions and appropriate contracts. Data may be handled outside your country when necessary, subject to applicable transfer restrictions and contractual safeguards.
6. Retention and security
Proposed retention schedule: collection briefs and sample-access requests that do not become projects may be retained for up to 24 months after the last meaningful contact. Project and contracting records may be retained for the contract term and for any longer tax, accounting, security, dispute, or legal period that applies. Security logs may be retained for up to 12 months unless a longer period is needed to investigate an incident. Counsel must approve these periods before launch. We use proportionate technical and organizational safeguards, but no system is perfectly secure.
7. Your choices and rights
Depending on applicable law, you may ask for access, correction, deletion or erasure, withdrawal of consent, restriction, objection, portability, or grievance review. Send a verified request to [PRIVACY CONTACT EMAIL]. A response and identity- verification procedure must be approved before public launch.
8. Children
This business service is not directed to children. Do not submit personal information about a child through the site. Field collection involving minors requires a separate legal and safeguarding process and is outside this showroom flow.
Reference framework
Counsel should validate this draft against the Digital Personal Data Protection Act, 2023, the EU data-protection framework, and the California Attorney General’s CCPA guidance, as applicable to the business, buyers, workers, and deployment.