Privacy Policy
Last updated: 30 September 2026
This policy explains how we process personal data when you visit www.maximumedit.com, subscribe to our newsletter, buy a Maximum Edit package (the “Product”) or book a paid consultation (a “Consultation”). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the other applicable data protection laws.
1. Controller
SISU ENTERPRISE LIMITED, Unit 1603, 16/F The L. Plaza, 367-375 Queen’s Road Central, Sheung Wan, Hong Kong, Incorporation No. 77542421. Email: info@maximumedit.com.
2. Your videos stay on your computer
Maximum Edit edits your videos on your own computer. Your video files stay on your computer: they do not pass through our servers, and we never receive or store them, nor the projects you create with the Product. If you choose to share your screen during a Consultation, we see what you show us during the call.
The Product works with Claude, the artificial intelligence of Anthropic, on your own Claude subscription. When Claude works on an edit, the data it needs (for example your instructions and parts of your project such as transcripts) is exchanged directly between your computer and Anthropic, under your Claude account. Anthropic processes that data as an independent provider that you chose, under its own terms and privacy policy: it is not our processor, and we have no access to that data.
3. Data we collect
When you subscribe to the newsletter: your email address, the language of the website, the text of the consent box you ticked with the date and time, the IP address and country from which you sent the form, when we sent you the confirmation email, and when and from which IP address you confirmed your subscription.
When you buy a package:
- email address, first name, surname and the language of the website;
- the IP address, the browser (its identification string, called user agent, and its language settings) and the country from which you send the purchase form;
- for each acceptance you give at checkout (Terms and Conditions, Refund Policy, this Privacy Policy, and the request for immediate delivery with the acknowledgement that you lose the right of withdrawal): the date and time, the exact text of the box and the version of the document it refers to;
- your choice about marketing emails (section 5) and your cookie choice at the time of purchase;
- the payment status and order details that Whop sends us (order number, package, amount, currency and, if there is a refund or a payment dispute, its status, reason and deadlines).
We never receive your card or other payment details: you enter them on Whop’s checkout.
When we deliver your package: when the email with your download links was sent, the address and the files it linked to; the state of your links (expiry date, downloads per file and, if they were deactivated, when and why). When you download: for every attempt, the date and time, the file, the IP address, browser and country, and the result.
When you book a Consultation: the same data as for a purchase (including the request for the call to take place on the date you chose), plus the date, time and time zone of the call and your answers to the booking questions (for example what videos you make, where you publish them and what you want from the call). To apply the customer price, we check whether the email you enter is the one of a package you bought that was not refunded or disputed. Please do not include passwords or access codes in your answers. During the call, the video-call service processes your image, your voice, the name you join with and, if you choose to share it, your screen (section 6).
When you write to us: your messages and contact details.
When you browse: your cookie choice (me_consent) and, only with your consent, the analytics and marketing data described in section 6 and in the Cookie Policy. Our hosting and security providers process technical data such as the IP address, the page requested and browser information.
4. Purposes and legal bases
- Newsletter: sending you news about Maximum Edit (new editing models, graphics and 3D models) after you have confirmed your address: your consent (Article 6(1)(a) GDPR), which you give by ticking the box and clicking the link in the confirmation email (double opt-in). You can withdraw it at any time with the unsubscribe link in every email.
- Selling and delivering the Product, managing your links and supporting you: performance of a contract (Article 6(1)(b)). Confirming your request for immediate delivery is also a legal obligation (Article 6(1)(c)).
- Booking and holding a Consultation, including the check that decides the customer price: performance of a contract (Article 6(1)(b)).
- Proving the contract and the delivery, and answering chargebacks, payment disputes and legal claims: our legitimate interest in establishing, exercising and defending legal claims (Article 6(1)(f)).
- Preventing fraud and abuse (Cloudflare Turnstile on our forms, limits on repeated requests, download limits, the records of previous orders): our legitimate interest in protecting the website, our customers and our business (Article 6(1)(f)).
- Running and protecting the website and securing the sign-in to our admin area: our legitimate interest (Article 6(1)(f)).
- Marketing emails to customers about our own similar products: our legitimate interest (Article 6(1)(f)), within the rule described in section 5.
- Accounting, tax and other legal obligations: Article 6(1)(c).
- Analytics (Google Analytics 4 through Google Tag Manager) and advertising measurement and remarketing (Meta Pixel and Meta Conversions API): your consent (Article 6(1)(a)), given through the cookie banner.
- Email delivery (opens and clicks recorded by Brevo, section 6): our legitimate interest in knowing that our emails arrive and work (Article 6(1)(f)); for the newsletter, also in measuring its results.
5. Marketing emails to customers
If you buy a package or book a Consultation, we may send you emails about our own products and services similar to the one you bought, unless you refuse them: at checkout or at booking, with the link shown under the acceptance box, or later, at any time, with the unsubscribe link included in each email or by writing to us. Refusing is free and has no effect on your purchase or booking. (Article 13(2) of Directive 2002/58/EC; in Italy, Article 130(4) of Legislative Decree 196/2003.)
6. Service providers and other recipients
We share data only with the providers we need to run the service. Unless stated otherwise, they act as processors on our behalf.
- Whop (Whop, Inc., United States): checkout, payments, refunds and payment disputes. For the payment, Whop may act as an independent controller under its privacy policy.
- Brevo (France): sending our emails (delivery, consultations, newsletter confirmation) and managing the newsletter list. By Brevo’s default, the emails we send you contain a small invisible image that records when you open them, and their links go through a Brevo address that records clicks: we use this information only to check that our emails arrive and work and, for the newsletter, to measure its results.
- Google Cloud / Firebase (Google): the database (Cloud Firestore) of orders, bookings, subscribers and records, and the storage (Cloud Storage) of the Product’s files, which you download through temporary signed links.
- Netlify (United States): website hosting and server functions.
- Cloudflare (United States): the Turnstile anti-bot check on our forms, which processes technical signals such as the IP address and browser (see its Turnstile privacy addendum), and, where enabled, the DNS and security of the website.
- Clerk (Clerk, Inc., United States): sign-in to our admin area, for our staff only.
- Google Meet (Google) or Zoom (Zoom Communications, Inc., United States), depending on the call link we send you: the video-call service of the Consultation, chosen by us. It processes your image and voice, the name you join with and, if you choose to share it, your screen, together with technical data such as your IP address, only to hold the call; if we invite you from our calendar, it also receives your email address. Sharing your screen is optional. We do not record the call unless you agree (in that case we ask you beforehand).
- Google Analytics 4 and Google Tag Manager (Google Ireland Limited): only with your Analytics consent.
- Meta Platforms (Meta Pixel and Conversions API): only with your Marketing consent, to measure and optimise our ads on Facebook and Instagram and to show them to people who have visited the website (remarketing). We may send events such as the start of a checkout or a purchase and its value, with identifiers such as the IP address, browser information and your email and name in hashed form. Meta may also use this data for its own purposes, as described in its privacy policy.
To answer a chargeback, a payment dispute, a suspected fraud or a legal claim, we may share the records of your purchase with Whop, the card networks and banks involved, the competent authorities and our legal advisers, who process them as independent controllers. We do not sell personal data.
7. Transfers outside the EU
We are based in Hong Kong, and some providers are based in, or process data in, countries outside the EU/EEA, such as the United States. Where the GDPR requires it, these transfers rely on appropriate safeguards: the EU-U.S. Data Privacy Framework for certified providers, or the Standard Contractual Clauses approved by the European Commission, as set out in each provider’s terms. You can ask us for more information.
8. How long we keep data
- Newsletter: your address and subscription details while you are subscribed; after you unsubscribe we delete them within 24 months (including the record of your consent and of its withdrawal, which we keep so that we can prove it). A subscription that is never confirmed is kept for up to 24 months from the last request and then deleted.
- Orders, payments and evidence records (the order and payment details, acceptances, delivery, downloads and the technical log of the messages Whop sends us): 24 months from the purchase, then we delete them, unless a longer period is required by law (for example accounting and tax obligations) or a dispute or legal claim is still pending.
- Accounting records: for as long as accounting and tax law requires (currently 7 years).
- Checkouts and bookings started but not paid (the details entered in the form, the acceptances, the IP address, browser and country): to prevent fraud and to answer your requests, for up to 24 months from collection; then we delete them.
- Consultation answers: for up to 24 months from the call, then we delete them.
- Marketing emails to customers: until you object, and in any case no longer than 24 months from the purchase.
- Your messages: for as long as needed to handle your request.
- Your cookie choice: 6 months in the
me_consentcookie. - Anti-abuse data (to limit repeated requests: the times of the last confirmation emails sent to an address, stored with the address pseudonymised with a hash function): for up to 24 months from the last email sent to that address, then we delete them.
9. Your rights
You can ask us for access to your data, its rectification or erasure, the restriction of processing and data portability, and you can withdraw your consent at any time (newsletter: the unsubscribe link; cookies: “Cookie settings” in the footer), without affecting the processing carried out before. You can object at any time to marketing emails and, on grounds relating to your particular situation, to the other processing based on our legitimate interest; we keep the evidence records while a chargeback or legal claim is possible (Article 17(3)(e) GDPR).
To exercise your rights, write to info@maximumedit.com. We reply within one month and may ask you to confirm your identity. You can also lodge a complaint with the data protection authority of the EU country where you live or work; in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
10. No automated decisions, security and changes
We do not take decisions based solely on automated processing that produce legal effects on you. Download links stop working automatically when they expire, when the download limit is reached or when the payment is refunded or disputed; if this happens, write to us and a person will review your case.
We use appropriate technical and organisational measures, such as encrypted connections, download links with long random codes, signed confirmation links for the newsletter and an admin area restricted to authorised staff. If a personal data breach occurs, we notify the competent authority and, where the law requires it, you.
We may update this policy: we publish the new version on this page with its date and, if the changes are significant, we inform you by appropriate means.