Skip to main content

Privacy Policy

Last Updated: 1st December 2025

1. Riolith Media’s commitment to protecting privacy

Riolith Media recognises that lasting relationships with audiences, clients, contributors, and partners depend upon rigorous protection of personal data and transparent, lawful processing. This Privacy Policy formalises those commitments and explains how personal data is collected, used, shared, stored, transferred, secured, and otherwise processed in connection with Riolith Media’s digital products and services, creative and production activities, events, research, advertising and analytics operations, and all other activities that reference this Policy.

2. Scope of application

This Policy applies to:

• Riolith Media and the entities, brands, and operations it controls;
• websites, mobile applications, newsletters, social pages, advertising technology, analytics and measurement tools, production and event operations, and research programmes; and
• offline interactions (e.g., production sets, events, screenings, studios, offices) and online interactions (e.g., account creation, newsletter subscriptions, submissions, e-commerce where offered).

Unless a service-specific notice says otherwise, Riolith Media is a data controller for the processing described here. Certain services are delivered with trusted providers acting as processors under written contracts. Where Riolith Media and a partner jointly determine purposes and means (e.g., co-branded events, co-published features, joint marketing), they may act as joint controllers under a documented allocation of responsibilities that protects data subject rights.

Good to know: Many experiences you have with Riolith Media involve additional parties (for example, event venues, ticketing platforms, advertising networks, analytics providers, social media platforms, payment processors, production partners). In those cases, your data may be processed by Riolith Media and by those parties as separate controllers for their own purposes under their respective privacy notices.

3. Riolith Media’s ten principles for protecting personal data

Lawfulness. Personal data is processed only where a valid legal basis applies.
Fairness. Uses are appropriate and can be explained.
Transparency. Processing is described in clear, accessible terms.
Purpose limitation & minimisation. Only the data needed for specified purposes is collected and used.
Accuracy. Reasonable steps keep data accurate and up to date.
Storage limitation. Data is retained only as long as necessary or required by law.
Security. Technical and organisational measures protect confidentiality, integrity, and availability.
Third parties. Vendors are vetted and bound by contract to protect data.
Transfers. International transfers rely on recognised legal mechanisms.
Breach response. Incidents are assessed promptly and notified to authorities and affected individuals where required.

4. What personal data is collected?

Depending on how you interact with Riolith Media, the following categories may be collected about you and, where relevant, about attendees or representatives you register or authorise:

Identity and contact data: name, alias/display name, email, telephone, postal address (where provided), company, job title, country, preferred language.

Demographic and profile data (if provided): age or age range, professional/industry role, interests and content preferences, subscription choices, communication preferences.

Government identifiers (only where lawful and necessary): passport/ID for access control to secured productions or events, age/identity verification for regulated venues or licensing.

Financial and transaction data: payment instrument details handled by PCI-compliant processors, billing address, VAT/tax ID (B2B), purchase history, refunds and chargebacks.

Account and authentication data: usernames, hashed passwords, security settings, login metadata.

Content and submissions: pitches, manuscripts, photographs, audio/video, artwork, comments, survey responses, competition entries, testimonials, correspondence, rights and release forms, and associated metadata.

Event/production data: RSVPs, attendance logs, accreditation, call sheets, crew/talent lists, dietary or accessibility needs that you choose to disclose, consent forms, waivers.

Device/usage/technical data: IP address, device identifiers, operating system, browser type and settings, network information, referring URLs, app telemetry, error logs, time-stamped interactions with content, emails, ads, and features.

Location data: general location from IP; precise geolocation only if you opt in via device settings for a specific feature.

Marketing/adtech data: cookie IDs, mobile advertising IDs, pixels, beacons, SDK signals, campaign source/medium, inferred interests and segments, engagement and conversion metrics.

Special category data (only when strictly necessary and lawful): e.g., health or disability information you disclose for accessibility, allergy or dietary requirements for events, union membership for regulated productions. Such data is processed only with explicit consent or another legal basis recognised by law.

5. When personal data is collected

Directly from you: account creation, newsletter sign-up, content submission, release/rights forms, purchases and paid registrations, production or event onboarding, surveys, customer support, B2B negotiations and fulfilment.

Automatically: through cookies, SDKs, pixels, tags, local storage, server logs, and similar technologies described in the Cookie Policy.

From trusted sources: ticketing and event platforms, payment processors, identity or age-verification providers, talent agencies, social sign-in, data clean rooms/measurement partners, ad networks, data management platforms, research vendors, anti-fraud providers, publicly available professional profiles, and client referrals—always in accordance with law and your settings with those services.

Providing personal data is voluntary; however, some services cannot be delivered without certain information (e.g., an email address to send a newsletter, payment details to complete a purchase, identity information to access a secured set).

6. Purposes of processing, legal bases, and retention

Riolith Media processes personal data for the purposes in Annex A with the corresponding legal bases (e.g., contract performance, legitimate interests, consent, legal obligation) and indicative retention periods consistent with the principles in Section 3. Major purposes include operating sites/apps; providing content and services; administering subscriptions and newsletters; managing events and productions; handling submissions and contributor relationships; conducting marketing and advertising (including interest-based advertising with consent where required); analytics and product improvement; platform and network security; compliance with law; and the exercise or defence of legal claims.

7. Access to and disclosure of personal data

Access within Riolith Media is limited to personnel who require it for their role (e.g., editorial, product, engineering, security, marketing, audience, commercial, finance, legal, compliance, production/events), under confidentiality obligations and role-based access controls.

Data may be disclosed to the following categories of recipients:

Service providers (processors): hosting, cloud/CDN, security/DDoS, identity and access management, email/newsletter platforms, collaboration tools, event/ticketing, payment processing and anti-fraud, adtech operating under instruction (consent management, measurement, frequency capping), research vendors, translators, archives.

Professional advisers: auditors, accountants, insurers, and legal counsel.

Commercial partners (separate controllers): co-sponsors of events, co-publishers of content, advertisers and clients commissioning campaigns, where a lawful basis applies; their privacy notices also apply.

Social/platform integrations: if you use social sign-in or interact with embedded features, relevant data may be shared with the platform in line with your settings there.

Corporate transactions: as part of a merger, acquisition, restructuring, or asset transfer, subject to appropriate safeguards and, where required, consent.

Authorities and regulators: where required by law, court order, or to exercise or defend legal rights; and to competent bodies for crime or fraud prevention, detection, or investigation.

Riolith Media does not sell personal data for monetary consideration. Where certain adtech practices could be deemed a “sale” or “share” under some U.S. state laws, opt-out mechanisms are provided (see Section 14).

8. International data transfers

Personal data may be transferred to countries outside your jurisdiction (including outside the EEA/UK). Transfers are made under recognised safeguards: European Commission/UK adequacy decisions; EU/UK Standard Contractual Clauses (with the UK Addendum where applicable) supplemented as necessary; or other lawful tools. A description or copy of relevant safeguards can be requested as set out in Section 13.

9. Data security

Appropriate technical and organisational measures protect personal data, including secure software development practices; network segmentation; encryption in transit and at rest where appropriate; least-privilege access and multifactor authentication for privileged accounts; endpoint protection; logging and monitoring; vulnerability and patch management; employee training; vendor due diligence and contractual security terms; incident response planning and testing. Payment processing is performed by PCI-DSS compliant providers through secure channels.

10. Cookies and similar technologies

Websites and apps use cookies, SDKs, pixels, local storage, and similar technologies for essential functionality, preferences, analytics, and (where permitted) advertising and measurement. Details on categories, purposes, retention, and controls (including consent and withdrawal) are provided in the Cookie Policy. Refusing non-essential technologies will not prevent access to core services but may affect certain features.

11. Your rights

Subject to law, you may request: access to personal data and processing information; rectification of inaccuracies; erasure in specified circumstances; restriction; objection to processing based on legitimate interests (including profiling and direct marketing); withdrawal of consent at any time (without affecting prior lawful processing); and data portability. Identity verification may be required. You may lodge a complaint with a supervisory authority (e.g., CNIL in France, or the authority where you live or work). See Section 13 for how to contact Riolith Media.

12. Children’s privacy

Services are not directed to children under 16. Personal data from children is not knowingly collected without appropriate parental/guardian consent and only where lawful and necessary (e.g., regulated productions or events). If collected contrary to this Policy, it will be deleted.

13. Notices related to local laws and regulations

13.1 EEA/UK
Processing complies with GDPR/UK GDPR and national laws. Legal bases are described in Annex A. International transfers rely on adequacy, Standard Contractual Clauses (and UK Addendum), or other lawful mechanisms. Individuals may contact their supervisory authority at any time.

13.2 United States — state privacy rights
Depending on your state (e.g., California, Colorado, Connecticut, Utah, Virginia), you may have rights to confirm processing and access, correction, deletion, portability, and to opt out of targeted advertising, certain profiling, and “sale” or “sharing” of personal data as defined by state law. Riolith Media provides state-specific controls where required (including a “Do Not Sell or Share My Personal Information”/“Your Privacy Choices” mechanism for California and recognition of Global Privacy Control signals where applicable). Requests may be sent to privacy@riolith.com; appeals of refused requests are available where required by law.

Riolith Media SAS
37, Avenue Maréchal-Foch
06000 Nice, France
info@riolith.com
Subscribe to our emails
Sign up to our newsletter for offers, new openings, and event updates across the network.
© 2026 Riolith Media. All Rights Reserved.