PRIVACY

Privacy Policy

Last updated: June 2026

1. Who We Are

Eaarth Ltd ("EAARTH", "we", "us", "our") is a company registered in England and Wales. We are registered with the Information Commissioner's Office (ICO) under registration number ZC173483.

We operate the EAARTH platform, an all-in-one production management system for the film and television industry, available at www.eaarth.app and associated subdomains (collectively, the "Service").

If you have a privacy question, you can contact us at any time through in-app chat. We do not publish an email address for privacy or support queries.

2. What Data We Collect

Depending on how you use the Service, we may collect:

  • Account data: name, email address, phone number, role, and company affiliation.
  • Identity verification data: a live selfie and a photo of a government-issued ID document, used once to confirm your identity through automated face-matching and document analysis. We do not retain the photos themselves, only the extracted result: your legal name, date of birth, document type and number, whether you are verified, and the date of verification, plus a reference code from our verification provider. This applies both to right-to-work checks for production crew and to the identity verification required to use EAARTH DM. Our aim is to repeat this check every 12 months to keep your account current; this annual process is being rolled out and is not yet fully in place for all accounts, and we will update this section once it is. Whether this specific data is encrypted at rest is still being confirmed against our hosting infrastructure's configuration, and we will confirm this here once that check is complete. We will never sell, lease, trade, or otherwise commercially exploit your biometric or identity verification data, and we will never share it for marketing, advertising, or with data brokers, it is used solely for the identity-verification purpose described here.
  • Payment data: bank account details, payment card information, transaction history, and wallet balances processed through EAARTH PAY.
  • Production data: scripts, schedules, callsheets, budgets, contracts, and other documents you upload or create within EAARTH OS.
  • Communications: messages sent via EAARTH DM and any correspondence with our support team.
  • Usage data: IP address, browser type, device identifiers, pages visited, and time spent on the platform.
  • Cookies: small files placed on your device for authentication and to remember a basic interface preference. We do not use analytics, advertising, or tracking cookies. See Section 9.

3. How We Use Your Data

We use your personal data to:

  • Create and manage your EAARTH account and portal access.
  • Verify your identity and prevent fraud (KYC/AML compliance).
  • Process payments and maintain financial records through EAARTH PAY.
  • Provide, improve, and personalise the Service.
  • Send transactional communications (confirmations, alerts, approvals).
  • Send service updates and, where you have opted in, marketing communications.
  • Meet our legal obligations under UK and applicable law.
  • Resolve disputes and enforce our Terms of Use.

4. Legal Basis for Processing

Under UK GDPR, we process your personal data on the following bases:

  • Contract: processing necessary to provide the Service you have signed up for.
  • Legal obligation: right-to-work identity checks for production crew, financial record-keeping, and tax compliance.
  • Special category data (biometric identity verification): EAARTH DM offers two ways to verify your identity: a fast, automated Face ID match (a live selfie checked against your government ID), or a manual, document-only check that involves no biometric processing at all, reviewed by a real member of our team. The document-only option is presented to you on the consent screen itself, before you are asked to agree to the biometric option, so choosing Face ID is a free, informed choice rather than the only route available. That is what makes relying on your explicit consent (UK GDPR Article 9(2)(a)) a valid legal basis for the biometric path. This directly addresses the ICO's own guidance that biometric consent is not freely given where there is no real alternative, the same principle the ICO applies to a gym that requires facial recognition for entry with no other way in. The document-only path does not involve special category data at all, so it is processed under ordinary personal data rules, specifically performance of a contract (Article 6(1)(b)), not consent. Withdrawing your biometric consent does not lock you out of EAARTH DM: your biometric data is deleted immediately (see Section 7), and you can switch to the document-only path instead to keep verifying and using the Service. If an automated verification decision goes against you, you already have the right to ask a real person to review it, see Section 8.
  • Legitimate interests: fraud prevention, platform security, and improving the Service.
  • Consent: marketing emails. You may withdraw consent at any time.

5. Sharing Your Data

We do not sell your personal data. We may share it with:

  • Service providers: cloud hosting and identity verification are both provided by Amazon Web Services (AWS), specifically AWS Rekognition for face-matching and AWS Textract for reading ID documents. EAARTH PAY payments run on the regulatory permissions of our banking and payments partner, TBC. Our RAM AI assistant is powered by Groq and, where separately configured, Anthropic, to generate responses to the questions you send it, see Section 6 for exactly what data RAM does and does not draw on, including EAARTH DM. All are bound by data processing agreements, including AWS's GDPR Data Processing Addendum. We do not use analytics or advertising service providers.
  • Other users: your name, role, and production-related data may be visible to other members of the same production you are assigned to.
  • Law enforcement: where UK law requires us to disclose information, we will do so. See the highlighted note below for exactly what that does, and does not, cover.
  • Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred. You will be notified in advance.

What this means for EAARTH DM

Our messaging architecture is designed so that, once end-to-end encryption is live for a conversation, message content itself is not accessible to us, not even under compulsion. That is a deliberate architecture choice, not a refusal to cooperate with the law. Until that rollout is complete for a given conversation (see the DM Personal Terms, Section 3), message content is protected in transit and at rest but remains technically accessible to us, in the same way as any other data described in this policy, and could be disclosed if we are validly compelled to do so.

6. International Transfers

Your data is primarily stored on AWS servers in the EU/UK region. Where data is transferred outside the UK/EEA, we ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the ICO, to protect your information.

When you use our RAM AI assistant, the content of your question is sent to Groq, and, where separately configured, Anthropic, to generate a response. Depending on where you are asking from, RAM may also draw on relevant EAARTH OS platform data, such as your studio's knowledge base, current project details, or production status, to answer accurately. RAM does not have access to EAARTH DM message content: it cannot read, and is never given, anything said in an EAARTH DM conversation. Both Groq and Anthropic are US-based service providers. This transfer relies on the same kind of safeguard described above (Standard Contractual Clauses / the UK's International Data Transfer Addendum), applied to that specific provider.

7. Data Retention

We retain your personal data for as long as your account is active or as necessary to provide the Service. After account closure:

  • Account data is retained for 6 years for legal and financial compliance purposes.
  • Payment transaction records are retained for 7 years as required by UK financial regulations.
  • The selfie and ID photos used for identity verification are deleted immediately once the check is complete, we never store the images themselves. This is unchanged by the account-closure policy below.
  • If you withdraw your consent to identity verification (without closing your account), the extracted identity fields (legal name, date of birth, document number/type, verification status) and the associated verification-provider reference, including the biometric face reference held by our verification provider, are deleted immediately, not retained on a delay. This disables EAARTH DM until you re-verify, but keeps your wider EAARTH account.
  • If you close your account, your identity-verification and biometric data (legal name, date of birth, document type/number, verification status, and the biometric face reference held by our verification provider) is kept for 30 days, during which you can reactivate your account simply by logging back in, without redoing identity verification, because this data was never removed. If you do not reactivate within 30 days, this data is then permanently deleted, including instructing our verification provider to delete the underlying biometric face template. If you reactivate, none of this data was ever affected. Account deactivation itself (blocking sign-in) happens immediately on closure; only the deletion of this specific data is what is deferred, and only for 30 days.
  • Production data and documents may be retained for 6 years or deleted sooner at your request, subject to other users' rights in shared productions.
  • EAARTH DM message content is retained for as long as your account and the relevant conversation exist. Deleting a message removes its content from our systems (see DM Personal Terms, Section 10), but not copies already delivered to other participants. Closing your EAARTH account deactivates it immediately and starts the 30-day identity/biometric deletion window described above, but does not retroactively delete the content of messages you have already sent to other people, in the same way closing an account on any messaging service does not unsend messages you have already delivered. We do not currently operate an automatic time-based deletion policy for DM message content beyond this.
  • EAARTH DM message metadata, who you messaged, when, delivery timestamps, and individual read-receipt records, is kept in full detail for 24 months. After 24 months, this detail is automatically reduced: exact per-message timestamps are rounded down to the month they occurred in, and individual read-receipt records are permanently deleted, so what remains shows only that a conversation existed between particular participants in a given month, not a granular, second-by-second history of it. This does not affect message content itself, which is governed only by the bullet above. This automatic reduction does not happen where a specific conversation or user is under an active legal hold, for example, an ongoing dispute or an in-progress lawful request, in which case the detailed metadata is preserved in full until the hold is lifted.

8. Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten"), subject to legal retention requirements.
  • Restrict how we process your data in certain circumstances.
  • Object to processing based on legitimate interests.
  • Data portability, receive your data in a machine-readable format.
  • Withdraw consent at any time for processing based on consent.

For identity verification specifically: you can withdraw your consent at any time from your account settings. This deletes your verification data immediately and disables EAARTH DM until you re-verify, but does not delete your wider EAARTH account. To delete your account entirely, use account deletion, this deactivates your account immediately and, as described in Section 7 above, permanently deletes your identity verification records 30 days later unless you reactivate by logging back in within that window.

Automated decision-making (UK GDPR Article 22)

Our identity verification (Section 2) is a fully automated process: a liveness check, an automated reading of your ID document, and an automated match between that document's photo and your live selfie. A failed check blocks the outcome it gates, creating an account, using EAARTH DM, or a right-to-work confirmation, without a person needing to be involved in that specific decision. Under UK GDPR, you have the right not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you, and the right to request human review of it, to express your point of view, and to contest the outcome.

If your verification fails, you can request a human review directly from the verification screen. This creates a logged request that goes to a review queue our team monitors. A real person looks at the failure details, including which step failed, the reason given, and, where the check got that far, what was read from your document, and decides whether to approve your verification or confirm the automated result. We do not store the original selfie or ID photo (see Section 2), so a reviewer works from this failure detail rather than the original image, and may also take into account anything you tell us separately, for example through in-app chat, to help confirm your identity another way. As with other requests under this section, we aim to respond within 30 days.

To exercise any of these rights, please contact us through in-app chat. We will respond within 30 days. You also have the right to lodge a complaint with the ICO at ico.org.uk.

9. Cookies

This section lists every cookie we actually set, no more, no less:

  • Essential cookies (strictly necessary): refresh_token, an httpOnly session cookie that keeps you signed in across EAARTH's subdomains, and, on the admin panel only, adminAccessToken, a short-lived access token the admin interface reads to authenticate its own requests. Both are required for login and security and cannot be disabled without signing you out.
  • Functional cookie: sidebar_state, a first-party cookie used in parts of EAARTH OS that remembers whether a side navigation panel is expanded or collapsed. It stores only "true" or "false", identifies nothing about you, and is set only if you use that part of the interface.

We do not use analytics, advertising, or tracking cookies of any kind. No third-party analytics or advertising scripts run on the EAARTH platform today. If that changes, we will update this section and ask for your consent first, as UK PECR rules require for any non-essential cookie.

You can clear or block cookies through your browser settings at any time; doing so for the essential cookies above will sign you out.

10. Children

EAARTH OS is intended for professional use and requires all users to be at least 18. EAARTH DM's personal service has a lower minimum age of 16, with additional protections for users aged 16 and 17; see the DM Personal Terms of Use, Section 2. EAARTH OS and EAARTH DM share one account system, so each product's own minimum age is enforced separately: every time you use a feature belonging to a specific product, we check your age against the verified date of birth from your government ID, not simply the age you stated at signup. We do not knowingly collect personal data from anyone below the relevant minimum age for the product they are using. If you believe someone below that age has provided us with data, please contact us immediately through in-app chat.

11. Security

We implement industry-standard security measures including encryption in transit (TLS) and at rest, access controls, two-factor authentication options, and regular security audits. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within the timescale UK GDPR requires (normally within 72 hours of becoming aware of it), and will notify you directly, without undue delay, where the breach is likely to result in a high risk to you.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify users via email or an in-platform notice for material changes. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

For any privacy questions, requests, or concerns, if you can sign in to EAARTH, please use in-app chat, see Section 1.

If you do not have access to an EAARTH account, for example your account was permanently closed, you were never an EAARTH user, or another user's activity concerns you and you are not a user yourself, you can submit a data request directly at eaarth.app/data-request. That form covers access, deletion, and objection requests, and complaints, from anyone we cannot otherwise reach through the platform. Because we cannot verify your identity automatically the way we do for a signed-in account, a member of our team reviews and confirms identity by hand before acting on an access or deletion request submitted this way.

Eaarth Ltd
ICO Registration: ZC173483
Little Mead, Leighton Road, Great Billington, Leighton Buzzard, LU7 9BJ, England