Legal
Protecting your privacy is something we take seriously. This policy sets out, in plain language, what personal information we hold, why we hold it, what we do with it, and what rights you have under the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
We do not sell your personal dataYour personal information is never sold, rented or traded to anyone. We share it only with the small number of processors and authorities set out in Section 4.
This policy applies from the date it is published on this website.
The operator of this Service acts as the data controller for the personal information described in this policy.
We have not appointed a Data Protection Officer. The Service does not meet the criteria set out in Article 37 GDPR that would make such an appointment mandatory.
Any question relating to data protection should be sent through the contact routes published on this website.
We gather only the information needed for the purposes explained in this policy. The categories we may hold are listed below.
| Category | Data elements | When collected |
|---|---|---|
| Identity data | First name, last name | When you subscribe or request a trial |
| Contact data | Email address, phone number | When you subscribe or request a trial |
| Account data | Username, hashed password, subscription status, plan type, activation date, expiry date | When your subscription is activated |
| Transaction data | Payment reference, amount, date, plan purchased | When payment is made |
| Device data | Device type, MAC address (for Smart TV apps and MAG boxes), IP address at login | At activation and at each login |
| Usage data | Connection timestamps, stream access records (what was watched and for how long) | While the service is in use |
| Communications data | The content of any support message you send us | When you contact support |
| Technical data | Browser, operating system, referring URL, pages viewed | When you visit this website |
No special category dataWe hold none of the special categories defined in Article 9 GDPR. That means nothing revealing racial or ethnic background, political views, religious belief, health information or biometric data. We also do not knowingly hold information about anyone under 18.
Your information is used only for the purposes below, and only where Article 6 GDPR gives us a lawful basis to do so.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Running and managing the Service | Identity, contact, account, device | Performance of contract — Art. 6(1)(b) |
| Taking payment and preventing repeat trials | Identity, contact, transaction | Performance of contract — Art. 6(1)(b) |
| Sending your credentials and activation details | Identity, contact, account | Performance of contract — Art. 6(1)(b) |
| Answering support requests | Identity, contact, account, communications | Performance of contract — Art. 6(1)(b) |
| Spotting and stopping fraud or abuse | Account, device, usage, transaction | Legitimate interests — Art. 6(1)(f) |
| Monitoring and improving service quality | Usage, technical, device | Legitimate interests — Art. 6(1)(f) |
| Service messages such as expiry reminders | Identity, contact, account | Legitimate interests — Art. 6(1)(f) |
| Meeting legal obligations | Identity, contact, transaction | Legal obligation — Art. 6(1)(c) |
| Website analytics | Technical, usage | Consent — Art. 6(1)(a) where required |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms and concluded they do not override them, taking account of what a subscriber would reasonably expect.
We do not use your information for automated decision-making or profiling that would have a legal or similarly significant effect on you.
We do not sell, rent or trade your information. It is shared only in the limited situations set out below.
A small number of third parties process personal data on our behalf as data processors — email delivery, payment handling and hosting infrastructure. Each is covered by a data processing agreement and may act only on our documented instructions and in line with GDPR.
We may pass information to competent authorities — data protection regulators, law enforcement, courts or other public bodies — where the law, a court order or a binding regulatory direction requires it. Where we are legally free to tell you about such a disclosure, we will.
If, after investigation, we conclude that an account is being used in a way that infringes copyright or is otherwise unlawful, we may pass relevant account information to rights holders or their authorised representatives to the extent the law requires.
Should the business be merged, acquired, or sold in whole or substantial part, customer information may pass to the acquiring party. We would tell you if that happened and if this policy changed as a result.
We aim to keep storage and processing inside the European Economic Area. Where a transfer outside the EEA is unavoidable — for instance a provider whose infrastructure sits elsewhere — we put appropriate safeguards in place, including Standard Contractual Clauses approved by the European Commission.
Information is kept only as long as the purpose requires, allowing for legal and regulatory retention duties.
| Data category | Retention period | Reason |
|---|---|---|
| Identity and contact data | Length of the relationship plus 3 years | Limitation period for contract claims |
| Transaction data | 7 years from the transaction | Revenue and accounting requirements |
| Account credentials | Active subscription plus 12 months | Fraud prevention and reactivation |
| Usage and access logs | 90 days | Monitoring, fraud detection, dispute handling |
| Support communications | 3 years from last contact | Continuity of support and dispute handling |
| Website analytics | 26 months | Service improvement and trend analysis |
Once information is no longer needed it is securely deleted or anonymised. Anonymised records, from which you cannot be identified, may be kept longer for statistical purposes.
This website uses cookies and comparable technologies. A cookie is a small text file stored on your device by a website. Cookies let a site recognise your device, hold your preferences and measure how the site is used.
| Cookie / type | Purpose | Duration | Category |
|---|---|---|---|
| Session cookie | Holds your session while you browse | Session | Strictly necessary |
| Cookie consent record | Remembers whether you accepted or declined | 12 months | Strictly necessary |
| Google Analytics (_ga) | Tells unique visitors apart | 2 years | Analytics |
| Google Analytics (_gid) | Shorter-term visitor measurement | 24 hours | Analytics |
| Google Analytics (_gat) | Limits the rate of requests to analytics servers | 1 minute | Analytics |
These are needed for the website to work. They hold no personally identifying information and cannot be switched off through cookie settings where they are essential to operation.
We may use analytics to understand how visitors move through the site — which pages get viewed, how long people stay, where they go next. Analytics cookies are set only where consent has been given. What they collect is aggregated and does not identify you.
Cookies can be managed or removed through your browser. Most browsers let you block cookies, accept them all, or warn you before one is stored:
As someone whose data we process, the GDPR and the Data Protection Act 2018 give you the rights below. Use the contact routes on this website to exercise any of them.
How we handle requestsVerified requests get a response within one month. Complex cases may take a further two months, where GDPR permits. We may confirm your identity before acting, and there is no charge unless a request is clearly unfounded or excessive.
We use appropriate technical and organisational measures to guard your information against unauthorised access, disclosure, alteration or loss. These include:
Passwords are stored hashed and are not readable in plain text. We do not store full payment card details — payment is handled by external providers under their own security standards.
No method of transmitting or storing data electronically is completely secure. If you think your account or your information may have been compromised, contact us through the support channels on this website.
Breach notificationIf a personal data breach occurs that is likely to risk your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, where the law requires. Where the risk to you is high, we will also tell you directly without undue delay.
This website may link to other websites, app stores and external services. This policy covers only our own website and service.
Follow a link elsewhere and that site's own privacy policy governs anything you provide there. We are not responsible for the privacy practices, security or content of third-party sites, and we suggest reading their policies before handing over any information.
Any player applications or software mentioned on this website are third-party products. They are not built, run or controlled by us, and their handling of personal data is governed by their own policies and terms.
The Service is for adults aged 18 and over. We do not knowingly collect information from anyone younger.
If you believe someone under 18 has given us personal information, contact us through the support channels available and we will take appropriate steps to remove it. By subscribing you confirm you are at least 18.
This policy may be updated from time to time to reflect:
Where changes are material we will update the date shown on this policy and, where appropriate, tell active users through the channels available. We suggest reviewing it periodically. Continuing to use the website or the Service after an update means you accept the revised version. The current version is always published here.
For any question about this policy, to exercise your data protection rights, or to raise a privacy concern, contact us through the support details on this website. General privacy enquiries get a response within 5 business days; formal GDPR rights requests within one calendar month.
Message us on WhatsApp or email [email protected] — general enquiries answered within 5 business days.
You may lodge a complaint with the Data Protection Commission at any time.