← Back

Privacy Policy

Effective Date: June 20, 2026 · Last Updated: June 20, 2026 · Version 2026-06-20

DRAFT — Template for review by qualified legal counsel prior to use. Not legal advice.

1. Introduction

This Privacy Policy explains how Paradigm Pictures, operating under PWD Visuals Ltd. ("VenuScan", "we", "us"), based in Ontario, Canada, collects, uses, discloses, and protects personal information when you use the VenuScan web-based platform, the website at venuscan.io, and related services (the "Service"). VenuScan.io and its associated intellectual property are explicitly owned by Paradigm Pictures operating under PWD Visuals Ltd. This Policy applies to attendees who use the Service and to representatives of venues, organizers, and brands we work with. We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25, as well as the GDPR and CCPA/CPRA disclosures set out further below.

2. Accountability and Privacy Officer

We have designated a Privacy Officer responsible for our compliance with this Policy and applicable privacy law. You can reach the Privacy Officer at info@paradigmpictures.tv or by mail at Ontario, Canada. In Quebec, the Privacy Officer also acts as the person in charge of the protection of personal information.

3. Information We Collect

Information you provide

Information collected through your use of the Service

Information from third parties

4. How We Use Personal Information

5. Regional Insights Program

Event organizers may opt in to VenuScan Regional Insights, an aggregate reporting program for tourism and economic development partners. Accounts created before the program launched are opted out and stay that way unless they choose otherwise; accounts created since start opted in and are shown the program on an acknowledgment screen at signup, with a one-click switch to decline there. Either way an organizer can switch it off at any time in their settings, which excludes their future events.

When an organizer participates, we may share aggregate counts only: the number of attendees by postal-code area (FSA), event date, event type, and venue region. We never share attendee names, emails, phone numbers, individual records, or an organizer's audience list. Small groups are suppressed, so areas with too few attendees to be reported anonymously are withheld rather than published.

Your own record is included only if you did not use the postal-code reporting opt-out described in Section 3 — that opt-out excludes you regardless of the organizer's choice.

6. Lawful Bases (GDPR Art. 6)

7. Sub-processors

8. Retention

Active account data is retained while your account is open. After deletion we erase personal data within 30 days, except where retention is required by law (e.g. invoices: 7 years). Scan and redemption logs are kept for 24 months for security and dispute resolution.

9. International Transfers

Data may be processed in Canada, the EU/EEA, the UK, and the US. Where data is transferred outside your jurisdiction we rely on Standard Contractual Clauses or equivalent safeguards.

10. Your Canadian Rights (PIPEDA / Law 25)

You may request access to, correction of, or (where applicable) deletion of your personal information, withdraw consent, and — in Quebec — request data portability and information about automated decision-making. Contact our Privacy Officer above. You may also complain to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.

11. Your GDPR Rights

If you are in the EEA, UK or Switzerland you have the right to access, rectification, erasure, restriction, portability, objection, and to lodge a complaint with your supervisory authority. Email us to exercise any right.

12. Your CCPA / CPRA Rights

If you are a California resident you have the right to know what personal information we collect, to delete it, to correct it, to opt out of "sale" or "sharing" of personal information, and to limit use of sensitive personal information. We do not sell or share your personal information as those terms are defined under the CPRA. To exercise any right, email us with the subject line "CCPA Request".

13. Cookies

We use only strictly necessary cookies for authentication. We do not use advertising or third-party tracking cookies.

14. Security

Row-level security isolates each organization. Passwords are hashed; data in transit is TLS-encrypted; data at rest is encrypted by our hosting providers.

15. Children

The Service is not directed at children under 16, and we do not knowingly collect their data.

16. Changes

We will post material changes here and notify you in-app or by email.