Skip to content
Content Republic

Legal

Privacy Policy

Last updated: July 11, 2026

This Privacy Policy explains how Fencer The Movie, LLC ("we," "us," or "our") collects, uses, discloses, and protects personal information through the Fencer website (the "Site"). It is designed to comply with applicable U.S. federal and state laws, including the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), the California Unruh Civil Rights Act (non-discrimination), and applicable European laws, including the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR/Data Protection Act 2018.

1. Controller & Representatives

Fencer The Movie, LLC is the "controller" (GDPR/UK GDPR) and "business" (CCPA/CPRA) of personal information collected through the Site. Contact: privacy@content-republic.com.

EU Representative (GDPR Art. 27) & UK Representative (UK GDPR Art. 27). For inquiries from data subjects and supervisory authorities in the EEA or United Kingdom, Fencer The Movie, LLC has designated the following representative:

Hans Jörg Finsterwald
EU / UK Article 27 Representative for Fencer The Movie, LLC
Email: eu-rep@content-republic.com

Canadian Privacy Officer (PIPEDA / Québec Law 25 §3.1). Hans Jörg Finsterwald also serves as our designated privacy officer for individuals in Canada, including Québec, and may be contacted at privacy-ca@content-republic.com.

2. Information We Collect

  • Information you provide — name, email, country, U.S. state (if applicable), optional indication of investment interest in a potential Regulation Crowdfunding offering, and any messages you submit.
  • Consent record — the version of the consent text you accepted and the timestamp of your acceptance, kept to evidence lawful processing.
  • Technical data submitted with forms — your IP address and browser user-agent string at the time of submission, used for fraud prevention, security, and Reg CF / SEC recordkeeping.
  • Automatically collected — limited server-log data such as request paths, status codes, and timestamps, and authentication cookies strictly necessary to operate the Site.
  • From third parties — if administrative sign-in via Google is used by our staff (Google sign-in is not currently offered to public site visitors), we receive the signing-in staff member's name, email, and profile identifier from Google. We will update this section before enabling Google sign-in for public users.

We do not knowingly collect personal information from children under 16. We do not sell or share personal information for cross-context behavioral advertising, and we do not knowingly process sensitive personal information for purposes that require opt-out under the CPRA.

3. How We Use Information

  • to respond to your indication of interest and provide updates about the project;
  • to operate, secure, and improve the Site;
  • to comply with legal obligations, including securities-law recordkeeping; and
  • to establish, exercise, or defend legal claims.

4. Legal Bases (GDPR/UK GDPR)

  • Consent (Art. 6(1)(a)) — when you submit the interest form and opt in to updates;
  • Legitimate interests (Art. 6(1)(f)) — operating and securing the Site, fraud prevention (including IP/user-agent logging), and communicating with prospective collaborators and supporters;
  • Legal obligation (Art. 6(1)(c)) — compliance with applicable law, including U.S. securities regulations and Reg CF recordkeeping.

You may withdraw consent at any time without affecting the lawfulness of prior processing, by emailing the address in Section 16.

5. Sub-processors

We share personal information only with the following categories of processors, each bound by a written data-processing agreement and appropriate confidentiality and security obligations:

  • Hosting, database, authentication, and storage — Supabase Inc. (United States), via the Lovable Cloud platform operated by Lovable AB (Sweden / European Union).
  • Application hosting / CDN — Cloudflare, Inc. (United States, with EU points of presence).
  • Email (transactional, where used) — the provider configured by Lovable Cloud for outbound mail.
  • Professional advisors — legal and accounting counsel, bound by confidentiality.

We may also disclose information to regulators, courts, or law enforcement where required by law, and to a successor in connection with a corporate transaction. We do not sell personal information for money or other valuable consideration.

6. International Transfers

Personal information submitted through the Site is processed and stored in the United States. Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on:

  • the European Commission's Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (Module Two, controller-to-processor), incorporated by reference into our data-processing agreements with sub-processors;
  • the UK International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner's Office and in force since 21 March 2022 (or, at the parties' election, the UK International Data Transfer Agreement); and
  • for transfers from Switzerland, the Swiss Federal Data Protection and Information Commissioner's approval of the EU SCCs with the amendments set out in its 27 August 2021 guidance.

We have completed a Transfer Impact Assessment ("TIA") of each of our sub-processors, taking into account the guidance in EDPB Recommendations 01/2020 on supplementary measures. Where the TIA identifies risk, we apply supplementary measures such as encryption in transit and at rest, pseudonymization where feasible, and contractual audit rights. Copies of the applicable SCCs, the UK Addendum, and a summary of our TIA are available on request from the addresses in Section 1.

7. Retention

We retain personal information for the periods set out below and then delete or irreversibly anonymize it:

  • Newsletter / updates signups — until you unsubscribe, plus up to 12 months for backup and audit purposes.
  • Reg CF "Testing the Waters" indications of interest — at least 5 years from collection, consistent with SEC recordkeeping expectations. The IP address and browser user-agent submitted with an interest form share this 5-year window because they are part of the recordkeeping trail.
  • Other server logs and IP / user-agent records (not tied to an interest submission) — up to 24 months, then deleted or anonymized.
  • Consent records — for the life of the relationship plus 3 years, to evidence lawful processing.

8. Security

We implement reasonable administrative, technical, and physical safeguards designed to protect personal information, including TLS encryption in transit, encryption at rest by our hosting provider, role-based access controls, row-level security on our database, and multi-factor authentication on administrative accounts. No method of transmission or storage is 100% secure. In the event of a personal data breach affecting EEA or UK residents, we will notify the competent supervisory authority within 72 hours where required under GDPR Article 33 and affected individuals where required under Article 34.

9. Your Rights

EU/UK/EEA residents have rights to access, rectify, erase, restrict or object to processing, port their data, and withdraw consent, and may lodge a complaint with a supervisory authority (e.g., your local Data Protection Authority or the UK Information Commissioner's Office).

California residents (CCPA/CPRA) have rights to know, delete, correct, and limit use of sensitive personal information; to opt out of sale/sharing (we do not sell or share); and to non-discrimination for exercising these rights (consistent with the Unruh Civil Rights Act).

Residents of other U.S. states — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Florida (FDBR), New Jersey (NJDPA), New Hampshire (NHPA), Maryland (MODPA), Minnesota (MCDPA), Rhode Island (RIDTPPA), and Kentucky (KCDPA), as those laws come into force — have, to the extent applicable, rights to:

  • confirm whether we process their personal data and access a copy of it;
  • correct inaccuracies in their personal data;
  • delete personal data we hold about them;
  • obtain a portable copy of the personal data they provided; and
  • opt out of the "sale" of personal data, "targeted advertising," and "profiling in furtherance of decisions that produce legal or similarly significant effects."

We do not currently sell personal data, engage in targeted advertising, or conduct profiling with legal or similarly significant effects. Residents of Colorado, Connecticut, Virginia, Montana, Oregon, Texas, Delaware, Minnesota, New Jersey, New Hampshire, Kentucky, Rhode Island, and Maryland whose privacy request is denied have the right to appeal that decision by replying to our initial response or emailing privacy@content-republic.com with the subject line "Privacy Request Appeal." We will respond within the time required by the applicable state statute (typically 45 or 60 days) and, if the appeal is denied, provide contact information for the relevant state Attorney General's office.

To exercise any right, you may use either of the two methods below (CPRA §1798.130(a)(1)(A)):

We will verify your identity and respond within the time required by law. You may use an authorized agent where permitted.

10. Canada — PIPEDA and Québec Law 25

In addition to the general rights described above, individuals in Canada have the following rights and receive the following disclosures:

  • Privacy officer. Hans Jörg Finsterwald is our designated privacy officer for Canada (see §1). Requests and complaints may be sent to privacy-ca@content-republic.com.
  • Cross-border transfers (including Québec). Personal information collected through the Site is stored and processed outside Canada, including in the United States and the European Union, by our sub-processors (see §5). Information transferred outside Québec, and outside Canada generally, may be accessible to foreign courts, law enforcement, and national-security authorities under the laws of those jurisdictions. Before transferring personal information outside Québec, we conduct a privacy impact assessment as required by Law 25 § 17 and rely on contractual protections (including the EU Standard Contractual Clauses where applicable) to ensure the information receives adequate protection.
  • Automated decision-making (Law 25 § 12.1). We do not use personal information collected through the Site to render decisions based exclusively on automated processing. If that ever changes, we will update this Policy and provide the specific notice and human-review rights Law 25 requires.
  • Right to data portability (Law 25, in force September 22, 2024). On request, we will provide the personal information you have given us in a structured, commonly used technological format (for example, CSV or JSON), or transmit it to another organization you designate, to the extent technically feasible.
  • Right to de-indexing / cessation of dissemination. You may request that we stop disseminating your personal information, or de-index a hyperlink that gives access to it, where dissemination contravenes the law or a court order, subject to the balancing test in Law 25 § 28.1.
  • Breach reporting. If a confidentiality incident creates a risk of serious injury, we will notify the Office of the Privacy Commissioner of Canada (OPC) under PIPEDA and, for Québec residents, the Commission d'accès à l'information du Québec (CAI), as well as affected individuals, without undue delay and in the form required by law. We keep a register of confidentiality incidents for at least five years, as required by Law 25 § 3.8.
  • Complaints. If we do not resolve your concern, you may file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, for Québec residents, the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).

11. Cookies & Global Privacy Control

The cookie categories shown in our banner (Necessary, Analytics, Marketing) are pre-declared: the toggles reflect the categories we may use in the future, but any Analytics or Marketing scripts will load only after you opt in. Today, we use only cookies and similar technologies that are strictly necessary to operate the Site (for example, to maintain your login session and remember your cookie choice). We do not currently load advertising, cross-site tracking, or analytics scripts. You can review or change your choice at any time using the Cookie Preferences link in the footer.

Global Privacy Control (GPC). When and if we deploy any non-essential cookies or similar technologies, we will honor the Global Privacy Control browser signal (per CPRA regulations, 11 C.C.R. § 7025, and EDPB guidance on GDPR Article 21(5)) as a valid opt-out of the "sale" and "sharing" of personal information for cross-context behavioral advertising, and — for EEA/UK users — as an objection to processing based on legitimate interests for direct-marketing purposes. Because we do not currently sell or share personal information, GPC does not change our behavior today, but the signal is respected as it arrives.

Cookie inventory. The specific cookies and similar technologies we currently set are:

NameCategoryPurposePartyDuration
fencer_site_accessNecessarySigned cookie that records site-access authorization so the Site can gate previews before public launch. Strictly necessary; cannot be disabled.First-partySession / up to 30 days
sb-*-auth-tokenNecessaryAuthentication session for admin users signed into the backend (issued by our authentication provider). Not set for public visitors.First-partyUp to 7 days (refreshable)
fencer_cookie_prefsNecessaryStores your cookie-banner choice (accepted / rejected non-essential categories) so we do not re-prompt on every visit. Held in localStorage.First-party12 months

No Analytics or Marketing cookies are set today. If we introduce any, this inventory will be updated before those scripts load, and they will fire only after your opt-in.

12. Email Communications (CAN-SPAM / CASL)

Any commercial or newsletter-style email we send is designed to comply with the U.S. CAN-SPAM Act (15 U.S.C. § 7701 et seq.) and, for Canadian recipients, Canada's Anti-Spam Legislation ("CASL," S.C. 2010, c. 23). Every such message will:

  • identify Fencer The Movie, LLC as the sender, with truthful "From," "To," and routing information and a non-deceptive subject line;
  • clearly disclose that it is a commercial or promotional communication (or a "transactional or relationship message" as permitted);
  • include a working, no-cost unsubscribe mechanism honored within 10 business days (CAN-SPAM) and immediately for CASL where feasible; and
  • include a valid physical postal address for the sender.

Our postal address for CAN-SPAM and CASL identification purposes is:

Fencer The Movie, LLC
c/o Content Republic
content-republic.com

You can unsubscribe at any time by using the unsubscribe link in any message we send, or by emailing privacy@content-republic.com with the subject line "Unsubscribe."

13. Securities-Related Notice

Information submitted through the "Test the Waters" form is collected solely to gauge non-binding interest in a potential future offering and may be retained for recordkeeping in accordance with Rule 206 under the Securities Act of 1933 (Regulation Crowdfunding) and related guidance. No money is being solicited and none will be accepted at this time.

14. Non-Discrimination

Consistent with the California Unruh Civil Rights Act (Cal. Civ. Code § 51), applicable U.S. federal and state civil-rights laws, and EU/UK equality laws, we do not discriminate against users for exercising their privacy rights or based on any protected characteristic.

15. Changes

We may update this Policy from time to time. The "Last updated" date above reflects the most recent revision. Material changes will be highlighted on the Site.

16. Contact

Fencer The Movie, LLC — Attn: Privacy. privacy@content-republic.com