โปร่งใสด้วยการออกแบบ

มุมมอง AIF ที่ชัดเจน

ข้อมูลที่เผยแพร่ ความพร้อมใช้งานในปัจจุบัน และความคืบหน้าในที่เดียว เอกสารจะปรากฏที่นี่หลังจากการตรวจสอบและเผยแพร่แล้วเท่านั้น

เอกสารทั้งหมด

Privacy Notice

2026-09-18.1
1. Scope and data responsibility This notice explains personal information used by AI Film Market for browsing, watchlists, accounts, project participation, payments and support. The responsible data user is 香港人工智能電影製片人協會, registered in Hong Kong. Use the Privacy and Data Requests form linked on this page to request access, correction or assistance. This page separates current device and hosting behaviour from processing that begins only when a service is connected. Using a public catalogue does not require an account or consent to marketing. Do not send sensitive documents while a suitable collection channel is unavailable. 2. Information collected and why Hosting systems may receive IP address, request time, browser information, requested URLs and technical error or security events to deliver pages, investigate faults and protect the service. We do not ask for your name or email merely to browse films. Avoid placing private information in URLs, since URLs can appear in browser history and infrastructure logs. When enabled, account sign-in uses your email, authentication/session records and selected language. Participation forms collect the fields you enter, such as name, role, country or region, institution, project description, intended AIF amount and questions. They are used to administer your account, evaluate and respond to your request and maintain its history; an intended amount is not a payment. 3. Required fields and your choices Required fields are marked or validated in the relevant form. Without the information necessary for authentication or a specific request, that function cannot be completed; public browsing remains available. Optional notes can be omitted. A saved browser draft is not a submitted request. Submission requires the indicated user action and a successful server response. Do not include another person’s data without authority, passport or identity-card copies, full bank/card credentials, seed phrases, private keys or confidential contracts in ordinary forms. If identity checks become necessary, a separate notice will identify the provider, exact data, purpose, recipients and retention before collection. 4. Cookies, local storage and drafts The aif-locale preference cookie lasts up to one year; the corresponding local-storage preference remains until cleared. The aif:film-watchlist:v1 record stores selected film codes on your device until removed. Investment drafts (aif:investment-draft:…) and the roadshow draft (aif:roadshow-draft) use session storage for the browser tab, including the fields you choose to save. A browser can restore a tab session, so close-and-reopen is not a reliable secure deletion method. Use the controls below to clear this site’s watchlist or drafts on this device. They do not delete submitted server records, records on another device or another origin. A preview URL and the main domain have separate browser storage. On shared devices, clear drafts and sign out when finished; remove site data in browser settings for a broader reset. 5. Installed app and offline storage The PWA caches selected public static assets, such as fonts, icons and the offline page. It does not intentionally cache authenticated pages, API responses, form submissions, transaction balances or one-time codes. Offline mode is for recovery and navigation, not transaction execution. Installing the app does not enable payment or grant additional account permissions. The release does not request contacts, microphone, camera or location access and does not implement advertising tracking or analytics profiling. Any future optional tracking or push notification feature will require its own explanation and permission where applicable. Necessary session cookies may be set when authentication is enabled. 6. Service providers and disclosure The website is hosted on Vercel. When you use account and order services, Supabase processes the relevant authentication, database and private file records; Resend processes transactional email delivery. Access is limited to authorized staff, the requested project workflow and providers performing the stated function. General browsing does not authorize publication of your identity or requests. Information may also be disclosed where required by law or a valid legal process, or as reasonably necessary to investigate fraud, protect rights or respond to a security incident. Any project-team sharing beyond the explained workflow needs a clear purpose and suitable authorization. We do not sell personal information. 7. External sources and cross-border handling Some film posters are loaded from external INDEX/source hosting. Loading an image can disclose your IP address, browser information and permitted referrer data to that host even without clicking an external link. Following a link to HKAIIFF, a wallet, payment provider or another service makes that service’s own terms and privacy notice relevant; its controller is distinct from this platform. Hosting and connected providers may process data outside your location. The actual database region, relevant provider arrangements and lawful transfer safeguards must be confirmed before account collection opens. No exclusive Hong Kong storage location or universal data-localization guarantee is claimed. Material changes to recipients or international processing will be reflected in this notice. 8. Transaction and blockchain records Placing or settling an order creates records of the accepted agreement, quantity, quote, payment asset and network, payment reference and screenshot, saved wallet address, any wallet ownership verification, delivery and refund or dispute history. Payment evidence is private to you and authorized finance staff. Before requesting additional identity information, we explain the verification provider, purpose and applicable requirements. Our forms do not collect bank card numbers or private keys. Public blockchains can permanently expose wallet addresses, transaction amounts and timestamps, and other information may make an address identifiable. On-chain records generally cannot be erased by deleting an account. Do not put personal information into transaction memo fields. No transaction is written on-chain by simply saving a film or submitting an investment intent. 9. Retention and deletion Device-storage periods and local deletion controls are described above. Server records are retained while needed to provide the service, resolve disputes, reconcile transactions and meet applicable obligations. Access is restricted by role. On a deletion request, the operator reviews which records can be deleted or anonymized and explains any records that must be retained. On-chain records cannot be erased by this platform. Server data should be kept no longer than needed for the stated service and applicable legal obligations. A deletion request may be limited by an unresolved dispute, fraud investigation or a specific legal retention duty; the reason and affected categories should be explained. Backups may require controlled expiry rather than immediate removal. Deleting local data does not submit a server deletion request. 10. Security and incident response Designed controls include HTTPS, role-based access, record ownership restrictions, server-side validation and audit records for sensitive operations. These controls require correct production configuration and do not eliminate all risk. Credentials and service keys must not be placed in public pages or messages. Staff should use only the access necessary for their role. A suspected incident should be investigated, contained and documented, including the affected data and steps users should take. Affected people and authorities should be notified where required by applicable law. This notice does not claim a completed independent security audit or promise that every incident can be prevented. 11. Access, correction and complaints Depending on applicable law, you may request access, correction, deletion, restriction or an export, and withdraw an optional consent without changing the lawfulness of earlier processing. These requests may require proportionate identity verification; do not send identity documents unsolicited. Include the account email or request reference and a clear description, not passwords or private keys. Use the Privacy inquiry form on the Contact page and retain the submission reference. We respond using the contact email you provide, subject to appropriate identity verification. Applicable response deadlines, any lawful fee and reasons for a refusal will be explained. You may also use the account support channel. Your right to complain to the relevant regulator remains available, including the PCPD where Hong Kong privacy law applies. 12. Children, marketing and changes Account and financial participation are not directed to children under 18. If a child’s information is inadvertently submitted, the responsible operator should assess and remove it where appropriate. Transactional messages concern authentication, requests, orders or security. They are not permission to send promotions; any future marketing programme requires a separate lawful choice and an effective unsubscribe mechanism. The version and revision date appear above. Changes to purposes, providers, retention, controller details or new financial services are reflected before the changed collection begins, with notice and renewed consent where required. Each service page identifies its actual availability.