# MyFinalVideo — Privacy Policy

**Effective Date:** May 26, 2026
**Draft revision:** 22 September 2026 — publication requires verified operator details, contracts, legal review and deployed-behavior checks.

> **Review scope:** GDPR, KVKK and applicable US/other local privacy requirements. This working revision is not a finding that every listed law applies or that compliance has been established.

---

## Table of Contents

1. [Identity of the Data Controller](#1-identity-of-the-data-controller)
2. [EU Representative](#2-eu-representative)
3. [Data We Collect](#3-data-we-collect)
4. [Special Categories of Personal Data](#4-special-categories-of-personal-data)
5. [How We Use Your Data](#5-how-we-use-your-data)
6. [Third-Party Data: Emergency Contacts & Recipients](#6-third-party-data-emergency-contacts--recipients)
7. [Data Sharing & Subprocessors](#7-data-sharing--subprocessors)
8. [International Data Transfers](#8-international-data-transfers)
9. [Data Retention Schedule](#9-data-retention-schedule)
10. [Your Rights under GDPR](#10-your-rights-under-gdpr)
11. [Your Rights under KVKK](#11-your-rights-under-kvkk)
12. [Your Rights under CCPA / CPRA](#12-your-rights-under-ccpa--cpra)
13. [Automated Decision-Making](#13-automated-decision-making)
14. [Security Measures](#14-security-measures)
15. [Children's Privacy](#15-childrens-privacy)
16. [Cookies & Tracking Technologies](#16-cookies--tracking-technologies)
17. [Changes to This Policy](#17-changes-to-this-policy)
18. [How to Exercise Your Rights](#18-how-to-exercise-your-rights)
19. [Right to Lodge a Complaint](#19-right-to-lodge-a-complaint)
20. [Contact](#20-contact)

---

## 1. Identity of the Data Controller

MyFinalVideo is the product name. The operator's verified legal name and service address must be completed before this draft is published. The operational contact shown by the service is **support@myfinalvideo.com**. A city or product name alone is not a verified controller identity.

The controller, relevant legal roles, applicable markets and any California business-status determination require an assessment using the actual operator and processing. This draft does not invent a company registration, address or status.

---

## 2. EU Representative

No verified appointment or representative contact details are recorded for this revision. **support@myfinalvideo.com** is an operational contact, not evidence of an Article 27 representative or DPO appointment. Determine whether an appointment is required and provide the verified details before the relevant launch.

---

## 3. Data We Collect

MyFinalVideo collects the following categories of personal data, depending on your use of the Service:

### 3.1 Account & Identity Data

| Data Item | Description | Source |
|---|---|---|
| Full name | The name you provide at registration | Provided by user |
| Email address | Your registered email address used for login, check-ins, and notifications | Provided by user |
| Password hash | Your password is never stored in plaintext; the system hashes it using bcrypt before database storage | Generated at registration |
| Phone number | Optional; stored for future compatibility (SMS notifications are currently disabled/unsupported) | Provided by user |
| Account creation timestamp | Date and time your account was created | Generated automatically |
| Account plan status | Free Trial / Essential / Family — your current subscription tier | Generated automatically |
| Check-in interval setting | Your chosen Proof of Life interval (e.g., 6 months, 1 year) | Provided by user |

### 3.2 Video & Audio Content Data

| Data Item | Description | Source |
|---|---|---|
| Video file (encrypted blob) | Your uploaded personal video message, stored in AES-256-GCM encrypted form on Google Cloud Storage | Uploaded by user |
| Encrypted Data Encryption Key (DEK) | The AES-256-GCM key used to encrypt your video, itself encrypted by the Google Cloud KMS root Key Encrypting Key (KEK); stored in Cloud Firestore | Generated automatically at upload |
| Nonce / Initialization Vector (IV) | Cryptographic nonce used in AES-256-GCM encryption; stored in Cloud Firestore alongside the encrypted DEK | Generated automatically at upload |
| Video metadata | File name, file size, upload timestamp, dispatch status ("pending" / "dispatched"), associated recipient IDs | Generated automatically at upload |

### 3.3 Emergency Contact Data

| Data Item | Description | Source |
|---|---|---|
| Emergency contact full name | Name of each emergency contact you designate | Provided by user |
| Emergency contact email address | Email address of each emergency contact | Provided by user |
| Emergency contact phone number | Phone number of each emergency contact (optional) | Provided by user |

### 3.4 Recipient Data

| Data Item | Description | Source |
|---|---|---|
| Recipient full name | Name of each video recipient you designate | Provided by user |
| Recipient email address | Email address to which the video delivery link will be sent | Provided by user |
| Recipient phone number | Phone number of recipient; stored for future compatibility (SMS notifications are currently disabled/unsupported) | Provided by user |

### 3.5 Check-In & Escalation History

| Data Item | Description | Source |
|---|---|---|
| Check-in timestamps | Date and time of each successful Proof of Life check-in response | Generated automatically |
| Escalation event log | Log of each escalation email sent, emergency contact notification, and dispatch trigger event | Generated automatically |
| Dispatch timestamp | Date and time the Video Dispatch Engine was triggered | Generated automatically |

### 3.6 Payment & Transaction Data

The application processes checkout/session, payment and provider event references, plan/entitlement state, gift/redemption relationships, and amount/currency or payer metadata where supplied by the selected provider. These references may relate to identifiable people; they are not inherently non-sensitive merely because they are not card numbers.

Dodo and Creem integrations exist; cryptocurrency is not accepted. Card details should be entered only on the selected provider's checkout. Actual active merchant accounts, contractual roles, checkout behavior and historical records require verification; this draft does not claim that every payment uses Dodo or that a certification has been verified. See the provider and retention sections below.

### 3.7 Technical & Usage Data

| Data Item | Description | Source |
|---|---|---|
| IP address | Your IP address at the time of login, registration, and certain in-app actions | Collected automatically |
| Device information | Browser type, operating system, screen resolution (collected via session) | Collected automatically |
| Session tokens | JSON Web Tokens (JWT) used to maintain your logged-in state | Generated automatically |
| Log data | Server-side logs of platform requests, errors, and security events | Collected automatically |

---

## 4. Special Categories of Personal Data

Videos may contain images, voices and information about health, beliefs or other sensitive aspects of the people represented. Their classification depends on the content, purpose and processing. A facial image or voice recording is not automatically special-category biometric identification merely because it is recorded. The prior blanket classification is withdrawn; review under GDPR Article 4(14), Article 9 and Recital 51, and separately under applicable local law.

The revised registration and upload screens ask you to acknowledge that videos may contain personal information, including images, voices and sensitive details, and that you have read this policy. This is a content-notice acknowledgement, not consent to biometric identification or consent from every person appearing in a recording. Only upload content you have authority to provide. The controller must document the applicable purpose/basis and any required consent or withdrawal handling before publication.

---

## 5. How We Use Your Data

We process account and authentication records to provide access; encrypted videos and key metadata for storage/playback and eligible delivery; recipient and contact details for the chosen delivery/confirmation process; payment records for plan entitlements and refunds; and operational records for support, security and cleanup.

The controller must approve a purpose-by-purpose legal-basis map for users, recipients, contacts and people appearing in videos. Contract, consent, legal obligation and legitimate interest are different possible bases, each with its own conditions. This draft does not claim that registration consent covers all processing, that a legitimate-interest balancing assessment has passed, or that an unverified fixed billing-retention period is legally required.

---

## 6. Third-Party Data: Emergency Contacts & Recipients

**6.1 Applicability of GDPR Article 14.** Your emergency contacts and your video recipients are **not registered users of MyFinalVideo**. Their personal data is provided to us by you. This Section constitutes the required Article 14 GDPR disclosure for data subjects whose data is collected from a third party (the registered user).

**6.2 Categories of Data Stored About Third Parties.**

*Emergency contacts:*
- Full name
- Email address
- Phone number (if provided)

*Video recipients:*
- Full name
- Email address
- Phone number (if provided)

**6.3 Processing Third-Party Data.** Contact and recipient details support the user-selected confirmation and delivery process. The purpose, necessary fields, lawful basis, notice timing and objection handling must be assessed for these individuals separately; the user’s registration checkbox is not their consent.

**6.4 Notification of Third Parties.** Emergency contacts and recipients are notified by MyFinalVideo in the following circumstances:

| Person | When Notified | Method | Content of Notification |
|---|---|---|---|
| Emergency contact | When the escalation sequence reaches Step 5 (Section 6.3 of Terms of Service) | Email through the configured provider when enabled | Informed that the user has designated them as an emergency contact; asked to confirm whether the user is alive or deceased; informed of the consequences of their response |
| Video recipient | When the Video Dispatch Engine dispatches the user's video | Email through the configured provider when enabled; SMS is unsupported | Informed that the user has sent them a personal video message; provided a secure, time-limited link to access the video; informed of the 90-day access window |

**6.5 Third Parties' Rights.** Emergency contacts and recipients whose data we hold have the following rights:
- **Right to access:** Request confirmation of whether we hold their data and obtain a copy.
- **Right to erasure:** Request deletion of their data. Note: deletion of an emergency contact's data may prevent us from fulfilling the user's escalation sequence.
- **Right to object:** Object to processing based on legitimate interest. We will comply unless we have a compelling legitimate ground.

Third parties may exercise these rights by contacting **support@myfinalvideo.com**.

**6.6 Data Minimisation and Notice.** Contact details are associated with account/video records and operational events such as confirmation or delivery. Only necessary fields should be collected. Notification during escalation or dispatch is not proof that initial-collection notice requirements were met; that notice process remains part of the publication review.

---

## 7. Data Sharing & Service Providers

| Service | Purpose and data involved | Current status |
|---|---|---|
| Google Cloud | Runtime, account/contact/recipient metadata, encrypted video storage and key-management operations | Observed runtime in europe-west1; inspected Firestore/video storage in us-central1 |
| SendGrid / Twilio | Transactional email addresses and message contents, including confirmation/access links | Default configured provider; operator has deferred activation |
| Amazon SES / AWS | Transactional email if explicitly selected | Alternative implementation, not automatic failover; active account/region not verified |
| Dodo Payments and Creem | Payment/checkout references and relevant account or billing data when the integration is used | Integrations exist; active merchant accounts, agreements and historical use require reconciliation |
| Google Fonts and cdnjs / Cloudflare | Network request information when external fonts/assets are fetched | Referenced by some public pages |

Google Ads has been removed from the revised public frontend. Historical advertising records and any older deployed page require separate checks. No supported current SMS delivery is established. Provider roles, contracting entities, accepted agreements, retention and access countries must be verified; public DPA links are not evidence of contract acceptance.

**7.1 Marketing.** This release does not enable optional advertising tracking. Separate business outreach records require their own purpose and notice assessment. No transfer of private video content for advertising is part of the described service.

**7.2 Business Transfers.** Any proposed transfer of the business or data must be reviewed for an applicable legal basis, purpose limits, security, transparency and individual rights. A sale must not be represented as granting unrestricted use of personal data or automatically removing existing obligations.

**7.3 Law Enforcement Requests.** Requests are assessed for validity, scope and applicable authority. Disclosure or preservation is limited to what is justified and required; notify affected people where appropriate and permitted. This is not a promise of an automated legal-hold capability.

---

## 8. International Data Transfers

The inspected API and scheduled runtimes are in **europe-west1 (Belgium)**. The inspected Firestore database and video bucket are in **us-central1 (United States)**, and the bucket's CMEK key path is also in us-central1. Other keys, provider support access and email/payment processing locations require a complete inventory.

The service is not confined to EEA storage. Region selection alone does not establish GDPR or KVKK compliance. The operator must confirm the relevant entities, agreements, destinations, access paths and applicable transfer mechanism/assessment before publishing a completed transfer notice. This revision does not assert that a transfer impact assessment was approved or that all transfers are covered by executed SCCs.

The [Google Cloud Data Processing Addendum](https://cloud.google.com/terms/data-processing-addendum) and [Twilio Data Protection Addendum](https://www.twilio.com/en-us/legal/data-protection-addendum) are provider reference terms; their applicability and acceptance must be verified against the actual accounts.

---

## 9. Data Retention Schedule

| Data or event | Revised behavior and remaining limits |
|---|---|
| Active account videos, wrapped keys and associated records | Kept to provide the service, subject to deletion and applicable lifecycle rules; no guaranteed service duration |
| Expired trial | Scheduled cleanup eligibility 180 days after trial expiry |
| Completed posthumous delivery | Cleanup eligibility 180 days after successful account-level completion, when all videos have been dispatched; pending annual messages remain protected |
| Recipient access | Default 90-day token lifetime, configurable before issue; earlier revocation/deletion may end access |
| Abandoned signed upload | Cleanup eligibility after 24 hours; still-valid upload authorization can delay completion |
| Account deletion / destructive password recovery | Storage erasure before related metadata; failures remain pending for retry |
| Object versions and provider copies | Live/noncurrent generations must be removed; inspected GCS soft-delete is 7 days. Backup and provider expiry are separate |
| Audit, billing, abuse-prevention and backup records | Collection-specific purposes, legal periods and verified expiry rules remain to be completed; no universal fixed period is asserted |
| Offline drafts and recipient downloads | Copies on the relevant device; server erasure cannot reliably remove them |

Deletion is not instantaneous physical erasure from every system. See the [Content Retention and Deletion Policy](/legal/retention) for scope, retries and limitations. The earlier claim of a temporary decrypted delivery copy is withdrawn; normal v2 delivery uses the original ciphertext.

---

## 10. Your Rights under GDPR

If you are located in the European Economic Area, you have the following rights under GDPR:

**10.1 Right of Access (Art. 15).** You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data and information about how it is processed.

**10.2 Right to Rectification (Art. 16).** You have the right to request correction of inaccurate or incomplete personal data we hold about you. You can correct most account data directly within your account settings.

**10.3 Right to Erasure ("Right to be Forgotten") (Art. 17).** You may request erasure subject to applicable conditions and exceptions. The revised workflow records pending cleanup and retries failed storage erasure before removing related metadata. Any separately retained record must have an explained purpose and retention basis. An email hash can be matched against known addresses; hashing does not make it anonymous or exempt from review.

**10.4 Right to Restriction of Processing (Art. 18).** You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data or have objected to processing.

**10.5 Right to Data Portability (Art. 20).** You have the right to receive the personal data you have provided to us in a structured, commonly used, machine-readable format, and to transmit that data to another controller. For video content, this right is satisfied through the self-service download function. For structured personal data (account metadata), submit a portability request to **support@myfinalvideo.com**.

**10.6 Right to Object (Art. 21).** You have the right to object to processing based on our legitimate interest (GDPR Art. 6(1)(f)). Upon receipt of an objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.

**10.7 Right Not to be Subject to Automated Decision-Making (Art. 22).** You have the right not to be subject to a decision based solely on automated processing that produces significant legal effects concerning you. The Proof of Life escalation and dispatch system constitutes automated decision-making. Please refer to Section 13 for a full explanation of this system and your right to request human review and to challenge dispatch decisions.

**10.8 Right to Withdraw Consent (Art. 7(3)).** Where processing is based on your consent (particularly for special category / biometric data under Art. 9(2)(a)), you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

**10.9 Right to Lodge a Complaint (Art. 77).** You have the right to lodge a complaint with the supervisory authority in your EU member state of habitual residence, place of work, or place of the alleged infringement. See Section 19.

---

## 11. Your Rights under KVKK

Pursuant to **KVKK Article 11**, all data subjects (regardless of location) whose data is processed by MyFinalVideo have the following rights:

**11.1 Right to Learn.** You have the right to learn whether your personal data is being processed by MyFinalVideo.

**11.2 Right to Access.** You have the right to request information about the processing of your personal data if it has been processed.

**11.3 Right to Know the Purpose.** You have the right to know the purpose of the processing of your personal data and whether it is being used in accordance with that purpose.

**11.4 Right to Know Third Parties.** You have the right to know the identities of third parties to whom your personal data has been transferred, domestically or internationally.

**11.5 Right to Rectification.** You have the right to request correction of incomplete or inaccurate personal data.

**11.6 Right to Erasure or Destruction.** You have the right to request the deletion or destruction of personal data where the reasons requiring its processing have ceased to exist, subject to applicable legal retention obligations.

**11.7 Right to Request Notification to Third Parties.** You have the right to request that correction or erasure of your personal data be notified to the third parties to whom it was transferred.

**11.8 Right to Object to Automated Processing.** You have the right to object to results arising from the automated analysis of your personal data that are to your detriment.

**11.9 Right to Claim Damages.** You have the right to claim compensation for any damage arising from unlawful processing of your personal data.

To exercise your KVKK rights, submit a written request to **support@myfinalvideo.com**. We will respond within **30 calendar days** of receipt of a valid request, in accordance with KVKK Article 13.

---

## 12. Your Rights under CCPA / CPRA

If you are a resident of the State of California, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following rights:

**12.1 Right to Know (Cal. Civ. Code § 1798.100).** You have the right to request disclosure of: (a) the categories of personal information we collect about you; (b) the categories of sources from which we collect it; (c) our business or commercial purpose for collecting it; (d) the categories of third parties with whom we share it; and (e) the specific pieces of personal information we have collected about you.

**12.2 Right to Delete (Cal. Civ. Code § 1798.105).** You have the right to request the deletion of personal information we have collected from you, subject to certain exceptions (e.g., legal obligation to retain, completion of a transaction you requested).

**12.3 Right to Correct (Cal. Civ. Code § 1798.106).** You have the right to request correction of inaccurate personal information we maintain about you.

**12.4 Sale/Sharing Requests.** The revised frontend has no enabled advertising tracker. This fact alone does not determine the applicability of California sale/sharing rules to every processing activity. Contact support to exercise an applicable right; the operator must assess the actual business and processing rather than assume an exemption.

**12.5 Sensitive Information Requests.** Contact support to request an applicable restriction on processing sensitive information. The operator must assess and respond to the request; do not assume that use of the service removes this right.

**12.6 Right to Non-Discrimination (Cal. Civ. Code § 1798.125).** We will not discriminate against you for exercising any of your CCPA rights. Exercising your rights will not result in denial of services, different pricing, or different quality of service.

**12.7 Authorized Agent.** California residents may designate an authorized agent to make a CCPA request on their behalf. We may require: (a) proof that the agent is authorized to act on your behalf; and (b) verification of your own identity directly.

**12.8 Shine the Light (Cal. Civ. Code § 1798.83).** California residents may request information about personal information shared with third parties for direct marketing purposes. **We do not share personal information for direct marketing purposes.**

**12.9 Categories of Personal Information Collected (Cal. Civ. Code § 1798.140).** For CCPA disclosure purposes, we collect:

| CCPA Category | Examples from MyFinalVideo |
|---|---|
| Identifiers | Name, email address, IP address |
| Personal information (Cal. Civ. Code § 1798.80(e)) | Name, email, phone number |
| Biometric information | Facial image and voiceprint in user-uploaded videos |
| Internet or other electronic network activity | Session tokens, log data, device info |
| Geolocation data | IP-derived approximate location only |
| Audio, electronic, visual, or similar information | Video and audio recordings uploaded by user |
| Commercial information | Payment transaction records (plan purchased, amount) |
| Inferences drawn from the above | Dispatch status (presumed deceased) — used solely for service delivery |

---

## 13. Automated Decision-Making

**13.1 Automation and Human Confirmation.** Scheduled checks, reminders and delivery processing use automation. Release requires explicit confirmation from a designated emergency contact; silence alone does not authorize delivery. That contact response is a product safeguard, not a claim that GDPR Article 22 cannot apply. The legal basis, applicable safeguards and consent wording require review for this revised processing model.

**13.2 Description of the Logic.** When email delivery is enabled, a check-in starts a cycle. Unanswered checks lead to reminders after 7 and 14 days, a warning after 21 days, and emergency-contact escalation after 22 days. After 29 unanswered days the case is held for review. If there is no emergency contact, the absence of one does not authorize release. Explicit death confirmation starts a 48-hour cooldown. Any annual date hold must also be satisfied, and uploads must be complete before recipient delivery.

**13.3 The "I'm OK" Confirmation.** Opening an email link displays a form and does not change your status. Submit the confirmation form, or use the dashboard check-in control, to record that you are alive. A successfully recorded confirmation cancels pending escalation and release and invalidates platform-controlled delivery access. If another vault operation is in progress or persistence fails, retry after the displayed error; do not assume the confirmation was saved. An email already delivered or a downloaded copy cannot be recalled.

**13.4 False Positive and Delay Risks.** Mistaken or malicious emergency-contact confirmation, account compromise and software or operational failures can cause harmful outcomes. Missed email or silence alone must not release messages. Missing contacts, provider outages and review holds can delay delivery indefinitely. This service does not independently establish death or replace official records.

**13.5 Requesting Review.** Contact **support@myfinalvideo.com** to request human review, explain your position or contest a release decision. Review requests are subject to actual support availability; receipt of a request is not proof that pending release was stopped. Platform access may be blocked where technically possible, but recipient-held copies cannot be retrieved.

**13.6 Applicable Rights.** This disclosure does not limit your applicable rights to information, objection, restriction, withdrawal of consent or human intervention. Article 22 safeguards and the basis for any processing of special-category data must be evaluated for the actual service; accepting general terms is not described here as proof that all such conditions are met. See the [European Commission's guidance on individual requests](https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/dealing-requests-individuals_en).

---

## 14. Security Measures

MyFinalVideo implements the following technical and organizational security measures to protect your personal data:

**14.1 Client-Side Envelope Encryption (v2).** All video content is encrypted **in your browser** before being uploaded to our servers. Encryption uses **AES-256-GCM** with a unique Data Encryption Key (DEK) generated locally. The DEK is wrapped (encrypted) using a key derived from a user-specific password via PBKDF2, creating a client-side "owner-wrapped DEK". A separate "dispatch-wrapped DEK" — re-wrapped using a dispatch secret stored encrypted in Google Cloud KMS — is also created at upload time. Normal v2 upload transfers ciphertext and wrapped key material. At delivery, the server unwraps the DEK in memory to re-wrap it for the recipient. This is server-assisted encryption, not an absolute zero-knowledge design.

**14.2 Normal Video Flow.** The current v2 browser encrypts video bytes before upload, and normal recipient playback decrypts in the browser. The server can unwrap key material during delivery, so this is not an absolute guarantee that a privileged actor could never access content.

**14.3 Dispatch Key Re-Wrapping.** During video dispatch, the Dispatch Engine uses Google Cloud KMS to decrypt the dispatch secret, then performs PBKDF2 + AES Key Wrap (RFC 3394) to unwrap the dispatch-wrapped DEK and re-wrap it for the recipient using the recipient's access token. The raw video ciphertext is served to the recipient's browser, which performs the final AES-256-GCM decryption locally. The server performs key re-wrapping only — it does not perform video decryption.

**14.4 Nonce (IV) Generation.** The browser generates a random IV and per-video key for each encryption. This reduces reuse risk; random generation is not a claim that collisions or implementation compromise are mathematically impossible.

**14.5 Account Authentication.** User authentication is handled by our backend application, which implements industry-standard bcrypt credential hashing, rate limiting, and JWT session management. Passwords are never stored in plaintext by MyFinalVideo.

**14.6 Transport Security.** Production access is intended to use HTTPS. Provider connections, edge configuration and TLS policy must be validated on the deployed service; local configuration is not a measurement of every connection.

**14.7 Access Control.** Access to production infrastructure is restricted to the platform owner via Google Cloud IAM with least-privilege principles. No third party has unauthorized access to production data stores.

**14.8 Security Logging.** Operational and security records support investigation and service monitoring. Actual log sinks, access and retention must be inventoried; a universal 90-day retention period has not been verified.

**14.9 Data Breach Response.** In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the relevant supervisory authority without undue delay and, where feasible, within **72 hours** of becoming aware of the breach (GDPR Art. 33). Where the breach is likely to result in a high risk, we will also notify affected data subjects without undue delay (GDPR Art. 34).

**14.10 No Security Guarantee.** Despite the measures described above, no security measure is unconditionally infallible. We cannot guarantee the absolute security of your data against all possible attacks, breaches, or vulnerabilities. We commit to responding promptly to identified vulnerabilities and incidents.

---

## 15. Children's Privacy

**15.1 Minimum Age Restriction.** MyFinalVideo is not designed for, marketed to, or intended to be used by individuals under the age of **18 years**. We do not knowingly collect, process, or store personal data from children under 18.

**15.2 Discovery of Under-Age User.** Reports of an under-age account are assessed promptly. Account restriction, erasure and any legally required further action follow the applicable process; physical deletion has the limitations described in Section 9.

**15.3 Parental Notification.** If you are a parent or guardian and believe that your child (under 18) has created a MyFinalVideo account, please contact us immediately at **support@myfinalvideo.com** and we will take prompt action.

---

## 16. Cookies & Tracking Technologies

**16.1 Browser Storage.** Authentication uses session cookies. Language/country preferences use localStorage, and optional local drafts use IndexedDB. The revised application has no enabled optional advertising or analytics tag. See the Cookie and Browser Storage Policy for actual lifetimes and controls.

**16.2 Cookie Policy.** A full description of the cookies we use, their purposes, duration, and your choices is available in the MyFinalVideo **Cookie Policy**, accessible at **myfinalvideo.com/legal/cookie-policy**.

**16.3 Essential Cookies.** Certain cookies are strictly necessary for the platform to function (e.g., session authentication cookies containing secure JWT refresh tokens set by our backend). These cannot be disabled without preventing you from using the Service.

**16.4 Analytics Cookies.** If we use analytics tools (e.g., Google Analytics), we will obtain your prior consent via a cookie consent banner before setting non-essential analytics cookies. You may withdraw this consent at any time via your cookie preferences.

---

## 17. Changes to This Policy

**17.1 Right to Update.** We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or platform functionality. The "Last Updated" date at the top of this document will always reflect the date of the most recent update.

**17.2 Material Changes.** For material changes — meaning changes that significantly affect how we process your personal data or reduce your rights — we will: (a) update this Policy with a new "Last Updated" date; and (b) send a notification email to your registered email address at least **30 days** before the change takes effect.

**17.3 Non-Material Changes.** Minor, non-material changes (such as typographical corrections, clarifications, or addition of new subprocessors with equivalent safeguards) may be made without individual notification, but will always be reflected in the "Last Updated" date.

**17.4 Continued Use as Acceptance.** Your continued use of MyFinalVideo after a material change to this Privacy Policy takes effect constitutes your acceptance of the updated Policy. If you do not agree with the updated Policy, you must stop using the Service and may delete your account.

---

## 18. How to Exercise Your Rights

**18.1 Submission of Rights Requests.** To exercise any of the rights described in Sections 10, 11, or 12, submit a written request by email to:

**support@myfinalvideo.com**

Your request should include: (a) your full name and registered email address; (b) the specific right or rights you wish to exercise (e.g., access, erasure, portability); and (c) any relevant details to help us identify and locate your data.

**18.2 Identity Verification.** To protect against unauthorized requests, we may ask you to verify your identity before processing your request. This may include confirming your email address via a one-time verification link, answering security questions, or providing other reasonable identifying information. We will not process a request where we cannot reasonably verify the identity of the requester.

**18.3 Response Timeframe.** We will respond to your request within:

| Regulation | Response Deadline |
|---|---|
| GDPR (EU/EEA users) | **1 month** (30 calendar days) from receipt of valid request; extendable by 2 additional months for complex requests with notification |
| KVKK (all users) | **30 calendar days** from receipt of valid request |
| CCPA (California users) | **45 calendar days** from receipt of verifiable request; extendable by 45 additional days with notification |

**18.4 No Fee for Rights Requests.** We will process your rights request free of charge. If requests are manifestly unfounded or excessive (in particular, repetitive), we reserve the right to charge a reasonable fee or refuse to act, in accordance with GDPR Article 12(5).

**18.5 Self-Service Options.** Many rights can be exercised directly within your account settings, including: downloading your videos (portability), correcting your account information (rectification), and deleting your account (erasure).

---

## 19. Right to Lodge a Complaint

You have the right to lodge a complaint with a competent supervisory authority if you believe our processing of your personal data violates applicable law.

**19.1 European Union / EEA Residents (GDPR).** You may lodge a complaint with the **data protection supervisory authority in your EU member state of habitual residence, place of work, or place of the alleged infringement**. A list of EU supervisory authorities is available at: [https://edpb.europa.eu/about-edpb/about-edpb/members_en](https://edpb.europa.eu/about-edpb/about-edpb/members_en)

No verified EU representative appointment is recorded for this draft. The support mailbox remains an operational contact and must not be presented as that appointment.

**19.2 Turkey / Turkish Residents (KVKK).** You may lodge a complaint with the:

**Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — KVKK)**
Nasuh Akar Mahallesi, Ziyabey Caddesi No:19, Balgat, 06520 Ankara, Turkey
Website: [https://www.kvkk.gov.tr](https://www.kvkk.gov.tr)
Email: kvkk@hs01.kep.tr

**19.3 California Residents (CCPA / CPRA).** You may submit a complaint to the:

**California Privacy Protection Agency (CPPA)**
2101 Arena Boulevard, Sacramento, California 95834, USA
Website: [https://cppa.ca.gov](https://cppa.ca.gov)

Alternatively, you may submit a complaint to the:

**California Office of the Attorney General**
Website: [https://oag.ca.gov/privacy/ccpa](https://oag.ca.gov/privacy/ccpa)

**19.4 We Encourage Direct Contact First.** Before lodging a formal regulatory complaint, we encourage you to contact us directly at **support@myfinalvideo.com** so that we may have the opportunity to resolve your concern quickly and informally. This does not limit your right to go directly to a supervisory authority.

---

## 20. Contact

For all privacy-related inquiries, data subject access requests, complaints, or questions about this Privacy Policy:

**Data Controller:** Legal operator and service address require verification before publication. MyFinalVideo is the product name.
Email: **support@myfinalvideo.com**
Website: **myfinalvideo.com**

**EU Representative:** Appointment/applicability and contact details require verification before publication.

Requests must be handled within the applicable statutory deadlines. The responsible operator, intake process and response coverage require confirmation before publication; this draft is not evidence of an active response team.

---

*MyFinalVideo — myfinalvideo.com*
*© MyFinalVideo. All rights reserved.*
*This Privacy Policy is governed by the laws of the Republic of Turkey, with EU and California statutory rights preserved as required by applicable law.*
