Effective: January 1, 2023

This Sony Pictures Entertainment Business to Business Privacy and Cookies Policy (“Privacy Policy”) describes the privacy practices of Sony Pictures Entertainment Inc. (a subsidiary of Sony Group Corporation (“Sony”)) and/or certain of its affiliates and business divisions (collectively, “SPE,” “we,” “our,” or “us”), as the controller of Personal Information collected in connection with our Business Relationship (defined below). This Privacy Policy applies to our websites, applications or events that specifically reference it and is expressly not applicable to our consumers, job applicants, employees, or other categories of workers. Where required by applicable law, we may provide additional notices about our data handling practices and your choices. Please read those additional privacy disclosures to understand how they apply to you.

As used in this Privacy Policy:

Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly; and

Business Relationship” means our connection with you in the context of your role as our past, current, or prospective vendor, client, service provider or other external business partner, or if you attend our events (e.g., as a member of the media industry).

The SPE affiliate or business division responsible for the processing of your Personal Information is generally the company with the Business Relationship with you and, where applicable, is the ‘data controller’ of your Personal Information. If you are unsure about which SPE entity is the data controller of your Personal Information or if you have any further questions about this Privacy Policy, please contact us using the options set out here. SPE’s corporate offices are located at 10202 West Washington Boulevard, Culver City, California 90232 USA. Our sites may contain links to third party websites. We are not responsible for the privacy, information security or other practices of third-party sites, and we encourage you to read the legal notices posted on other sites when you leave our site.

TABLE OF CONTENTS:

For more information on each of these key points, see the full wording of the Policy below. For our California Notice at Collection, please click here.

  • INFORMATION WE COLLECT
  • SOURCES FROM WHICH WE COLLECT PERSONAL INFORMATION
  • PURPOSE AND LEGAL BASIS FOR PROCESSING YOUR INFORMATION
  • DISCLSOURE OF YOUR PERSONAL INFORMATION
  • DATA RETENTION
  • CALIFORNIA PRIVACY RIGHTS
  • PRIVACY RIGHTS IN THE EUROPEAN ECONOMIC AREA AND THE UNITED KINGDOM
  • DATA TRANSFERS AND APPLICABLE LAW
  • COOKIES AND SIMILAR TRACKING TECHNOLOGY
  • HOW TO MANAGE COOKIES
  • DO NOT TRACK
  • CHANGES TO THIS PRIVACY POLICY
  • CONTACT US
INFORMATION WE COLLECT

We may collect the following categories of Personal Information relevant to our Business Relationship with you. The specific Personal Information we collect about you may vary depending on the nature of your interactions with us and may not include all of the categories or examples listed below.

  • Identifiers, including real name, alias, postal address, unique personal identifier, online identifier, IP address, email address, account name, or other similar identifiers. The Identifiers we collect also include social security number, driver’s license, state identification card or passport number; as well as account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account.
  • Personal records, including your name, signature, social security number, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or other financial information, medical information, or health insurance information. This category includes the information described in Cal. Civ. Code § 1798.80(e), some of which is duplicative of the other Personal Information listed here.
  • Characteristics of protected classifications, including date of birth, age, race, ancestry, ethnic origin, sex, gender, sexual orientation, gender identity, military or veteran status, disability. This category includes Personal Information that reveals racial or ethnic origin and union membership; as well as Personal Information collected and analyzed concerning sexual orientation.
  • Commercial information, including records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
  • Biometric information, including fingerprints and facial scans that are used for the purpose of uniquely identifying an individual.
  • Internet or other electronic network activity information, including browsing history, search history, and information regarding your interactions with our websites, applications, or advertisements.
  • Geolocation data, including information inferred from your IP address or unique device identifier. In some cases, this may include precise geolocation (location within a radius of 1,850 ft.).
  • Audiovisual information, including closed-circuit images, photographs and video of you, and audio recordings when you interact with us on a recorded phone line or via videoconferencing.
  • Professional or employment-related information, including your company name, your company URL, your job title, your work contact details, such as email and phone number, work area, primary language, and reason for access.
  • Inferences used to create a profile reflecting your preferences, characteristics, behavior.
  • Others, including dietary requirements, including allergies and food preferences.
SOURCES FROM WHICH WE COLLECT PERSONAL INFORMATION

Generally, we collect the categories of Personal Information described above from the following categories of sources:

  • Directly from you.
  • Automatically when you use our electronic systems (including our websites, applications, access-control systems, and location-tracking tools).
  • Created by us (e.g., if we create records pertaining to you, provide you with a login or user ID, or otherwise generate information linked to you).
  • From service providers that help us to run our business, which may include your employer as well as other entities with which we have an established service provider relationship under law.
  • From third parties, which may include entities with which we do not have established service provider relationships and individuals outside of SPE who may provide us your Personal Information.
  • Government or public records.
PURPOSE AND LEGAL BASIS FOR PROCESSING YOUR INFORMATION

We use your Personal Information for purposes that relate to our Business Relationship, which may include:

  • To provide you with the information and/or services you request.
  • To facilitate your provision of information and/or services to us.
  • To communicate with you.
  • To enter into contracts, make or request payments, or conduct pre-contract due diligence
  • To process your registration and enroll you in our systems.
  • To facilitate contract administration or account management for our purchases of services.
  • To allow you access to content related to our movies, TV shows, DVD releases, games, and other offerings.
  • To organize, invite and host you at our events or screenings
  • To promote our content, products, or services
  • To respond to your requests and facilitate your responses to our requests.
  • To manage our corporate diversity and inclusion initiatives.
  • To complete a corporate transaction such as a reorganization, merger, sale or joint venture.
  • To help ensure security and support IT resources and infrastructure.
  • To comply with laws.
  • To detect and prevent fraud or other illegal or unauthorized conduct.

If you are a person in the European Economic Area or the United Kingdom, our legal basis for collecting and using your Personal Information described above falls into the following categories and will depend on the Personal Information concerned as well as the specific context in which we process it.

  • TO FULFIL A CONTRACT, OR TAKE STEPS LINKED TO A CONTRACT
    • To process your registration on a site or app, or entry into an event.
    • To send you information about changes to our terms or policies and other transactional messages.
    • To process payment.
    • To create or administer your online account or subscriptions.
  • WHERE NECESSARY FOR PURPOSES WHICH ARE IN OUR, OR THIRD PARTIES’, LEGITIMATE INTERESTS. THESE INTERESTS ARE:
    • To provide you with access to content, events or sites.
    • To send you information you have requested.
    • To ensure the security of our sites and apps, by trying to prevent unauthorized or malicious activities.
    • To enforce compliance with the Terms of Use posted in association with this Privacy Policy and other policies.
    • To help other organizations (such as copyright owners) to enforce their rights.
    • To determine your approximate location and adapt our content (e.g., language, currency, territory restrictions).
    • To analyze how our site or content is used (including frequency and length of viewings).
    • To improve our services, including analyzing your feedback and comments provided via a survey or event feedback.
    • To tailor advertisements and offers for you, if permitted by applicable law.
    • To provide you with customer support.
  • WHERE YOU GIVE US CONSENT
    • Where you ask us to send marketing information to you via a medium where we need your consent under applicable law.
    • To tailor advertisements and offers for you, where consent is required under applicable law.
    • Where required by applicable law, consent to place cookies and to use similar technologies. For more information please also see the section on Cookies.
    • On other occasions where we ask you for consent, for a purpose which we explain at that time
  • WHERE NECESSARY FOR US TO COMPLY WITH OUR LEGAL OBLIGATIONS
    • In response to requests by government, regulators, judicial or law enforcement authorities.
    • To comply with tax or accounting rules or other legal obligations under applicable law.
DISCLOSURES OF YOUR PERSONAL INFORMATION

We share Personal Information with our service providers and contractors for the following purposes:

Category of Personal Information Purposes for Disclosure
Identifiers
Personal records
Commercial information
Professional or employment-related information

  • To communicate with you
  • To facilitate services we perform for you or that you perform for us
  • To enter into contracts or conduct pre-contract due diligence
  • To carry out our obligations under contract
  • To process payments
  • For analytic services
  • Auditing and compliance
  • In relation to content creation or distribution
  • Marketing and advertising our content, products, and services (except for cross-context behavioral advertising)
  • To manage corporate information technology
  • To manage the security of SPE premises and systems
  • Research for technological development and demonstration
  • Verifying or maintaining the quality or safety of our services
  • Additional services performed on our behalf (e.g., providing access to content, products and services, event hosting, data storage, and other functions that help us to run our business)
Characteristics of protected classifications
  • To manage our corporate diversity and inclusion initiatives
  • To facilitate services we perform for you or that you perform for us
  • Research for technological development and demonstration
Biometric Information & Geolocation Data (including precise geolocation and the processing of biometric information for the purpose of uniquely identifying you)
  • Auditing and compliance
  • To manage corporate information technology
  • To manage the security of SPE premises and systems
  • Research for technological development and demonstration
  • Verifying or maintaining the quality or safety of our services
  • Data storage and related functions
Internet or other electronic network activity information
  • To facilitate services we perform for you or that you perform for us
  • For analytic services
  • Auditing and compliance
  • In relation to content creation or distribution
  • Marketing and advertising our content, products, and services (except for cross-context behavioral advertising)
  • To manage corporate information technology
  • To manage the security of SPE premises and systems
  • Research for technological development and demonstration
  • Verifying or maintaining the quality or safety of our services
  • Additional services performed on our behalf (e.g., providing access to content, products and services, data storage, and other functions that help us to run our business)
Audiovisual information
  • To facilitate services we perform for you or that you perform for us
  • To enter into contracts or conduct pre-contract due diligence
  • To carry out our obligations under contract
  • For analytic services
  • Auditing and compliance
  • In relation to content creation or distribution
  • To manage the security of SPE premises and systems
  • Research for technological development and demonstration
  • Verifying or maintaining the quality or safety of our services
  • Additional services performed on our behalf (e.g., providing access to content, products and services, event hosting, data storage, and other functions that help us to run our business)
Inferences
  • To facilitate services we perform for you or that you perform for us
  • To enter into contracts or conduct pre-contract due diligence
  • For analytic services
  • In relation to content creation or distribution
  • Marketing and advertising our content, products and services (except for cross-context behavioral advertising)
  • To manage corporate information technology
  • To manage the security of SPE premises and systems
  • Research for technological development and demonstration
  • Verifying or maintaining the quality or safety of our services
Social security number, driver’s license, state identification card, or passport number
  • To enter into contracts or conduct pre-contract due diligence
  • To process payments
  • Auditing and compliance
  • To manage the security of SPE premises and systems
  • Data storage and related functions
Account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account
  • To process payments
  • Auditing and compliance
  • To manage the security of SPE premises and systems
  • Data storage and related functions
Personal Information that reveals racial or ethnic origin, or union membership
  • To facilitate services we perform for you or that you perform for us
  • To enter into contracts or conduct pre-contract due diligence
  • To carry out our obligations under contract
  • For analytic services
  • Auditing and compliance
  • In relation to content creation or distribution
  • Data storage and related functions
  • To manage our corporate diversity and inclusion initiatives
Personal Information collected and analyzed concerning sexual orientation
  • To manage our corporate diversity and inclusion initiatives

Affiliate Sharing. In accordance with applicable law, we share your Personal Information with other Sony entities which are involved when we process data for the purposes listed above and when it may be necessary or appropriate for the establishment or management of our relationship with you.

Business Reorganization. SPE or any of its assets, may be sold, or other transactions may occur in which your Personal Information may be considered one of the business assets of the transaction. In this case, your Personal Information may be transferred to the purchaser or prospective purchaser to the extent permitted by law, either as part of the transaction or during any due diligence process.

Mandatory Disclosures and Legal Protections. We may share any category of Personal Information with government and law enforcement authorities and with other parties involved in, or contemplating, legal proceedings to comply with a legal obligation, when we believe in good faith that the law requires it, to verify or enforce our Terms of Use posted in association with this Privacy Policy or where this is necessary for us or for third parties to protect our or their rights, property, safety, or security.

With your consent. If required by law, we may ask for your consent to share your information with third parties or for additional purposes.

DATA RETENTION

We will retain your Personal Information for the period necessary to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required or permitted by law. This generally means holding the information for as long as one of the following apply:

  • Your Personal Information is reasonably necessary to manage our operations, to manage your Business Relationship with us, or to satisfy another purpose for which we collected the information;
  • Your Personal Information is reasonably necessary to carry out a disclosed purpose that is reasonably compatible with the context in which the Personal Information was collected;
  • Your Personal Information is reasonably necessary to protect or defend our rights or property (which will generally relate to applicable laws that limit actions in a particular case); or
  • We are otherwise required or permitted to keep your Personal Information by applicable laws or regulations.

Where Personal Information is used for more than one purpose, we will retain it until the purpose with the latest period expires. For more information about our retention policies, please contact us.

CALIFORNIA PRIVACY RIGHTS

If you are a California resident, please read this section for more information about your privacy rights under the California Consumer Privacy Act (“CCPA”).

To submit a request relating to your Personal Information, please use our webform here or email us at CCPA@spe.sony.com. Please note that if you submit a request, you will be asked to log into your account or to provide 2-3 pieces of Personal Information that we will match against our records to verify your identity. You may designate an authorized agent to make a request on your behalf; however, you will still need to verify your identity directly with us before your request can be processed. An authorized agent may submit a request on your behalf using the webform or the email address listed above.

Right to Correct Inaccurate Information. If you believe that Personal Information we maintain about you is inaccurate, you have the right to request that we correct that information.

Right to Delete Your Personal Information. You have the right to request that we delete Personal Information we collected from you, subject to certain exceptions. Where we use deidentification to satisfy a deletion request, we commit to maintaining and using the information in deidentified form and will not attempt to reidentify the information.

Right to Know. You have the right to know what Personal Information we have collected about you, which includes:

  1. The categories of Personal Information we have collected about you, including
    1. The categories of sources from which the Personal Information was collected
    2. Our business or commercial purposes for collecting or disclosing Personal Information
    3. The categories of recipients to which we disclose Personal Information
    4. The categories of Personal Information that we disclosed for a business purpose, and for each category identified, the categories of recipients to which we disclosed that particular category of Personal Information
  2. The specific pieces of Personal Information we have collected about you

Right to Opt Out of Sales and Sharing of Personal Information. We do not sell or share for cross-context behavioral advertising the Personal Information we collect pursuant to your Business Relationship with us. If you interact with SPE as a consumer, please review our California Consumer Privacy Notice for more information about our practices in that context.

Right to Limit the Use and Disclosure of Sensitive Personal Information. We do not use or disclose Sensitive Personal Information we collect pursuant to your Business Relationship with us for purposes to which the right to limit use and disclosure applies under the CCPA.

Right to Non-Discrimination for the Exercise of Your Privacy Rights. If you choose to exercise any of your privacy rights under the CCPA, you also have the right not to receive discriminatory treatment by us.

PRIVACY RIGHTS IN THE EUROPEAN ECONOMIC AREA AND THE UNITED KINGDOM

Where required by applicable law, you may have the right to obtain confirmation that we maintain certain Personal Information relating to you, to verify its content, origin, and accuracy, as well as the right to access, review, port, delete, or to block or to object to, or withdraw consent to the processing of certain Personal Information (without affecting the lawfulness of processing based on consent before its withdrawal). In particular, you may ask us not to use your Personal Information when we carry out profiling for direct marketing purposes or any other processing based on your consent.

Please contact us at SPE_EU_Privacy_Contact@spe.sony.com with general privacy related questions or to exercise your rights as provided by applicable law. We may request certain information for the purpose of verifying your identity prior to fulfilling your request.

We will make reasonable efforts to make such requested changes in our then-active and relevant databases as soon as practicable, but it is not always possible to change, remove or delete your information if our retention of this data falls within an exemption from the fulfilment of your data subject rights under applicable law. Further, we reserve the right to retain your Personal Information (a) as permitted by applicable law; (b) as required by applicable law; and (c) for so long as reasonably necessary to fulfil the purposes for which the data is retained except to the extent prohibited by applicable law.

You can opt out of receiving email newsletters by following the opt-out instructions provided to you in those emails.

DATA TRANSFERS AND APPLICABLE LAW

We operate internationally. As such, your Personal Information will be transferred to and processed in the United States and other countries that may not provide the same level of data protection as your home country. For a list of countries where your Personal Information may be transferred, please see here. We provide appropriate protections for international transfers as required by law for international data transfers. With respect to transfers originating from a country or a region such as the United Kingdom or the European Economic Area ("EEA"), and if the transfer is not to a country which is the subject of an adequacy decision or adequacy regulation (or equivalent), we implement appropriate solutions to address cross-border transfers as required by applicable law such as, with relation to the EEA, standard contractual clauses approved by the European Commission; and with the UK, standard contractual clauses approved by the UK government. Under such laws, you may request a copy of the suitable mechanisms we have in place by contacting us as detailed here. Where your consent is required by applicable law for the international transfer of Personal Information, by using our websites or apps or otherwise by engaging with us, and providing us with your Personal Information, you consent to the international transfer of your Personal Information.

COOKIES AND SIMILAR TRACKING TECHNOLOGY

We, as well as our service providers and third parties, collect information about you using cookies and similar technologies (such as tracking pixels or web beacons) in order to:

  • Perform functions necessary to provide our services, such as keeping you logged in and keeping our content secure.
  • Provide features or content based on your preferences, usage patterns and location.
  • Enhance your user experience by remembering your preferences, such as preferred language.
  • Monitor, evaluate and optimize the use and operation of our websites, such as checking for bugs and glitches.
  • Use analytics services, such as those provided by Google. If you don’t want us to use information about your visits in this way, and here for Google, to opt-out of their services.
HOW TO MANAGE COOKIES

Cookies and tracking pixels, among other tracking technologies, may generally be disabled or removed by tools available as part of most commercial browsers, and in some instances blocked in the future by selecting certain settings. Browsers offer different functionalities and options so you may need to set them separately.

DO NOT TRACK

Your web browser may provide you with a Do Not Track option that signals a user does not wish to have activity tracked. However, currently there is no universal standard for how to interpret that signal. We currently do not alter our practices when we receive a Do Not Track signal from a user’s browser.

CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time as our services and privacy practices change, or as required by law. The effective date of our Privacy Policy is posted above. We will post any updated version of the Privacy Policy on the applicable websites or applications.

CONTACT US

If you have any questions or comments regarding this Privacy Policy or our privacy practices, please contact us at the email address appropriate for where you reside:

European Union and the United Kingdom: SPE_EU_Privacy_Contact@spe.sony.com

Brazil: Privacy_Brasil@spe.sony.com

Canada: spe_can_privacy@spe.sony.com

United States, California: CCPA@spe.sony.com

Rest of the world, including the US: spe_privacy@spe.sony.com

SPE Privacy Officer: spe_privacy@spe.sony.com

You may also write to us at the relevant address of the entity listed here.

You may also have a right to submit a complaint to a supervisory authority for data protection in the country where you live, where you work, or where you consider that a breach of data protection has occurred.