Privacy Policy

Version 1.0 · Effective: October 15, 2025

1. Purpose

This Privacy Policy is designed to protect personal data processed by Seacrets in connection with the operation of its platform, digital products, and services, guaranteeing to all users transparency regarding what data is collected and how it is used, confidentiality through appropriate security measures, and effective control over their rights of access, rectification, portability, objection, consent withdrawal, and deletion.

Seacrets is committed to complying with the General Data Protection Regulation (GDPR), Lei Geral de Proteção de Dados (LGPD), California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA), Biometric Information Privacy Act (BIPA), and standard contractual data protection clauses imposed by payment networks and technology partners.

2. Scope

This policy applies to all individuals and entities that interact with the Seacrets ecosystem, including unauthenticated visitors, registered creators, fans, employees, contractors, and third-party service providers. All channels are covered including websites, mobile applications, APIs, and third-party infrastructure.

3. Legal Bases for Processing

Seacrets only processes personal data when it has a valid legal basis in compliance with applicable data protection laws. Each processing operation is justified by one or more of the following legal bases:

Legal BasisExamples of Associated Processing
Contract ExecutionAccount creation and management for Creators or Fans. Payment processing, subscriptions, and transfers. Service-related notifications.
Legitimate InterestFraud detection and prevention. Identity theft detection. Platform misuse prevention. Infrastructure security. Log retention for legal defense.
Free, Specific, and Informed ConsentPromotional communications and newsletters. Non-essential cookies (analytics, advertising, personalization). Identity verification through facial recognition or biometrics per BIPA and similar laws.
Compliance with Legal ObligationIdentity verification and KYC/AML procedures. Record retention per tax, commercial, or regulatory requirements. Reports to law enforcement and financial intelligence units.

When processing is based on consent, the User may withdraw it at any time without affecting the lawfulness of processing prior to revocation.

4. Data We Collect

Seacrets collects personal data to provide services, ensure platform security, comply with legal obligations, and improve user experience. The following are the main data categories:

CategoryData DetailsSource of Collection
IdentificationName or account alias. Date of birth. Official document (ID/Passport). Facial biometric selfie and biometric metadata.User directly, KYC Provider
FinancialPayment tokens. Payment history, chargebacks, and billing records.External Payment Processors
ContentPhotos, videos, and live streams uploaded. Titles, descriptions, tags. Metadata (date, IP, camera used, device, etc.).User, Creator, Seacrets Platform
DeviceIP address. Operating system and browser type. Device model and screen resolution. Unique identifiers (device ID, cookies, SDK).User Browser, Integrated Analytics Tools
LocationEstimated geolocation by IP (Geo-IP). GPS coordinates (if authorized on platform).User Device, Location Providers
Usage DataPages visited and links clicked. Content viewing time. Connection frequency and timing. Telemetry data.Seacrets Platform, Analytics Tools

In no case do we request or process data from minors. Access to Seacrets is strictly restricted to individuals over 18 years of age (or the legal age of majority in their jurisdiction).

5. Additional Sources

In addition to data provided directly by users or generated by platform use, Seacrets may obtain personal information from trusted external sources exclusively for verification, regulatory compliance, and risk prevention. These sources include identity verification providers, national and international sanctions lists (OFAC, UN Security Council, PEP lists), anti-fraud bureaus, and public records. All consultations are conducted under valid legal bases with principles of proportionality, purpose limitation, and data minimization.

6. Purposes of Processing

Seacrets processes personal data solely for specific, legitimate, and proportionate purposes. Each purpose corresponds to an applicable legal basis and is limited to the minimum necessary for fulfilling operational, regulatory, and security objectives.

6.1 Service Provision and Maintenance

User account management (Creators and Fans). Access to key features such as streaming, private messaging, subscriptions, payment processing, and technical support. Experience personalization (language, content and advertising settings, session security).

6.2 Compliance with Regulatory and Contractual Obligations (KYC/AML and Payment Networks)

Identity verification, risk analysis, money laundering prevention, and terrorism financing prevention. Compliance with mandatory policies established by payment networks (Visa, MasterCard) and payment service providers regarding adult content, identity verification, and financial traceability. Legal retention of records required by 18 U.S.C. §2257, tax regulations, regulatory standards, and anti-fraud measures.

6.3 Abuse Prevention, Fraud Detection, and Serious Risk Mitigation

Detection and blocking of non-consensual content, child sexual abuse material (CSAM), deepfakes, and impersonation. Automated review using artificial intelligence algorithms plus human moderation. Monitoring of suspicious accounts, chargebacks, and control evasion attempts.

6.4 Marketing and Product Improvement

Sending promotional notifications, newsletters, or campaigns relevant to user preferences. Evaluation of platform behavior (engagement, abandonment, viewing metrics) to improve features and user experience. Statistical analysis and audience segmentation without direct identification except with consent. Use of generated data to train, evaluate, and optimize proprietary or third-party artificial intelligence models and other automated operational support systems.

6.5 Compliance with Legal Requirements and Right Defense

Response to court, administrative, or police orders. Data preservation in compliance with legal obligations in regulatory investigations. Exercise of right of defense in claims, fraud cases, or contractual disputes.

7. Sharing and Recipients

Seacrets shares personal data only with authorized third parties when necessary to fulfill legitimate, contractual, or legal purposes, under adequate guarantees of security, confidentiality, and proportionality.

RecipientJustification for AccessApplied Guarantees
Payment Processors, Banks, Card AssociationsProcess transactions, subscriptions, and creator payouts.SCCs, TLS encryption in transit, financial access segmentation.
KYC/AML Verification ProvidersVerify identity, age, and user financial risk. Comply with KYC/AML regulations and payment network policies.DPA agreements, IP whitelisting, prior legal validation.
Analytics ServicesObtain usage metrics, navigation, retention, and platform behavior data.IP pseudonymization, disabled advertising functions, aggregated data only.
Judicial, Regulatory, or Police AuthoritiesComply with legal orders, DSA (EU), FOSTA-SESTA (USA), Law 787 (Nicaragua) investigations.Exclusive channel with audit logs, legal validation, and signed documentation.
Third Parties in Corporate Operations (M&A)Ensure operational and contractual continuity in restructuring, acquisition, or merger.NDA, prior legal review, advance user notice when legally required.

Seacrets does not sell, rent, or transfer personal data for commercial purposes outside this Privacy Policy. We do not share information with data brokers, third-party advertising networks, or social platforms without prior explicit consent.

8. International Transfers

Given that Seacrets operates with global infrastructure and is legally incorporated as a Limited Liability Company (LLC) in the United States, personal data we collect may be transferred, stored, and processed outside the data subject's country of residence, including in jurisdictions that may not have equivalent protection levels.

In accordance with international data protection principles, Seacrets ensures that all cross-border transfers are conducted under a legal framework guaranteeing lawfulness of processing, adequate security, purpose limitation, data minimization, and proactive accountability.

8.1 Jurisdiction-Specific Application

European Union / European Economic Area (EEA): Pursuant to GDPR (Articles 44-49), all transfers outside the EEA are conducted through Standard Contractual Clauses (SCCs) approved by the European Commission, Transfer Impact Assessments (TIA), end-to-end encryption and pseudonymization, and supervision by the Data Protection Officer with GDPR Article 30 documentation.

Brazil: Per LGPD (Articles 33-36), specific contractual clauses and technical measures equivalent to country of origin are used, transfers are grounded in consent/contract/legitimate interest/legal compliance, and Brazilian data subject rights per ANPD directives are guaranteed.

United States: Seacrets complies with CCPA/CPRA for California residents, BIPA (Illinois) for biometric data, and privacy policies required by Visa, Mastercard, Paxum, and other acquirers for adult content platforms.

Latin America: When processing data of subjects in jurisdictions with local data protection laws, Seacrets applies principles of legality, informed consent, and confidentiality, with transfers limited to declared purposes and supported by contractual agreements or applicable legal basis, implementing international security standards.

8.2 Global Technical and Organizational Guarantees

All international transfers are conducted under protocols including end-to-end encryption (TLS 1.2+/AES-256), restricted and segmented access control, periodic compliance audits, and impact assessments where required. Seacrets does not transfer data to jurisdictions lacking adequate safeguards without applying complementary protective measures, in accordance with EDPB recommendations and ISO/IEC 27701 on privacy management.

9. Retention

Seacrets retains personal data only for as long as necessary to fulfill processing purposes, applicable legal obligations, or defense against contractual or regulatory claims. After that period, data is deleted, anonymized, or retained in blocked status per applicable law.

9.1 Established Timeframes

Age and identity verification records (18 U.S.C. §2257) and KYC/AML: Retained for a minimum of 7 years from the creator's or data subject's last recorded activity, per sectoral, tax, and compliance standards.

Access logs, activity, and session logs: Retained for 18 months for security, fraud prevention, legal defense, and sensitive content incident traceability.

Deleted content or closed accounts: All associated content will be deleted or anonymized within 180 days maximum, unless a court order, competent authority requirement, internal investigation, or payment network contractual obligations/regulatory audits exist.

9.2 Applied Principles

Data Minimization: Only data strictly necessary for legal or contractual compliance is retained. Blocking and Restricted Access: During post-closure retention periods, data remains inaccessible except by the compliance team. Secure Deletion: Permanent deletion mechanisms are implemented per Secure Erase (NIST SP 800-88) for digital storage units and certified physical destruction for physical media if any exists.

10. Information Security

Seacrets periodically reviews its retention policies and timeframes, considering data type, associated risk, and evolution of international regulatory frameworks (GDPR, LGPD, CPRA, etc.).

10.1 Implemented Measures

Data Encryption: Military-grade data encryption. TLS 1.3 for encryption of communications in transit between clients, servers, and external services.

Secure Network Architecture: Logical network segmentation to isolate critical environments. Use of WAF (Web Application Firewall) and intrusion detection/prevention tools (IDS/IPS). Continuous log monitoring and anomalous traffic detection.

Access Control and Privileges: Least-privilege principle to limit data access by role. Mandatory multi-factor authentication (2FA) for all administrative personnel. Access control group policies with periodic review and auditing.

Incident Management: Seacrets maintains a Cybersecurity Incident Response Plan (CSIRP) including early detection and containment, forensic analysis, remediation and recovery, and internal/external communication.

11. Cookies and Similar Technologies

Seacrets uses cookies and tracking technologies (pixels, SDKs, device identifiers) to improve user experience, ensure session security, and analyze platform usage.

11.1 Cookie Types Used

Functional Cookies: Essential for basic site operation, such as maintaining active sessions, language preferences, or content configuration.

Authentication Cookies: Necessary to verify user identity on login, prevent unauthorized access, and maintain secure sessions.

Analytics Cookies: Allow collection of aggregated data on navigation, content interaction, viewing time, and technical errors to improve user experience and platform performance.

11.2 Preference Management

Users may manage, restrict, or delete cookies from browser or device settings. Disabling essential cookies may affect complete functionality of certain features like secure authentication, payment systems, or content playback. Seacrets respects individual browser configuration where technically feasible.

12. Minors and Parental Controls

The Seacrets platform is exclusively for individuals over 18 years of age and who have reached the legal age of majority in their jurisdiction.

12.1 Implemented Protection Measures

Strict Age Verification: Users must accept and confirm they are of legal age to access the platform. Registration incorporates date of birth validation for creators. Seacrets automatically prevents creator account creation if the system identifies the user as a minor. Monetized accounts require document verification and biometric selfie as part of KYC.

Recommendations for Legal Guardians: Use specialized software (Qustodio, Net Nanny, Kaspersky Safe Kids, etc.) to reinforce blocking by categories, domains, or schedules.

Seacrets maintains a zero-tolerance policy for minor access. Violating accounts will be blocked, and when applicable, competent authorities will be notified per local and international minor protection and digital abuse prevention laws.

13. Data Subject Rights

Seacrets guarantees all personal data subjects full exercise of their rights per transparency, control, and accountability principles established in GDPR, LGPD, CPRA, and local applicable laws.

RightHow to ExerciseStandard Response Time
Access and RectificationUser panel or email: [email protected]30 days
Deletion / CancellationAccount closure request from panel or support email30 days
Objection and Processing LimitationConfigure marketing preferences or cookie panelImmediate
Data PortabilityRequest encrypted JSON export via email45 days
No Purely Automated DecisionsRequest human review for automatic KYC or risk filter blocks30 days

13.1 Additional Considerations

Requests must include sufficient information to verify the requestor's identity. In some cases, we may request additional documentation to protect security and prevent impersonation. Exercise of rights is free, except for manifestly unfounded or excessive requests, where reasonable administrative fees may apply.

14. Automated Decisions and Profiling

Seacrets uses technology to maintain platform security, integrity, and legality. Some moderation or initial blocking decisions may be automated, but all are subject to human review when significant effects apply.

14.1 Authorized Automated Applications

Algorithmic Risk Models: Detect fraud attempts, identity spoofing, bulk account creation, or unusual behavior implying financial or reputational risk.

Prohibited Content Detection (Hash-Matching): Automatic comparison of user-uploaded files against databases of illegal or sensitive content (CSAM, non-consensual deepfakes, authority-flagged content).

KYC Verification Systems with Biometrics: Automated document validation and selfie verification to confirm age and identity, with human intervention on rejection.

14.2 Offered Guarantees

Appeal Channel: Any automated action resulting in account block, suspension, or demonetization can be contested through a human review channel accessible from the help center or email [email protected].

No Purely Automated Decisions with Legal Effects: Seacrets does not take decisions exclusively based on automation that produce legal effects or significantly impact individuals without authorized personnel evaluation.

15. Governance, DPIA and Continuous Improvement

Seacrets maintains a privacy governance framework based on proactive accountability, continuous risk evaluation, and systematic improvement of data protection practices.

Seacrets conducts a Data Protection Impact Assessment (DPIA) whenever new functionalities are developed or implemented involving sensitive data processing (biometrics, sexual orientation, verified identity), systematic or mass user activity monitoring, or AI/automated decisions with significant impact. DPIAs are also conducted when relevant changes occur in processing context, including new providers, analytics tools, monetization structures, or distribution channels.

DPIAs are documented internally per corporate privacy policy and updated with any technical, regulatory, or strategic changes affecting risk levels.

15.1 Policy Review and Continuous Improvement

This Privacy Policy will be reviewed at least annually as part of compliance and internal audit cycles. It will be updated ahead of schedule in case of substantial regulatory changes, binding authority recommendations, relevant security incidents, data breaches, or business model redefinition.

Any modifications will be approved by the legal department and Compliance Committee, published on Seacrets official website, and notified to users where regulation requires.

16. How to Contact Us

Data Protection Officer (DPO)

Email Address: [email protected]

17. Changes to This Policy

Seacrets may modify this Privacy Policy to reflect legal updates, technology changes, new data processing, or business operation adjustments.

When material modifications affect user rights, data nature, or processing purpose, the following procedure applies:

Advance Notification with minimum 15 calendar days notice via registered user email (if available) and prominent in-app and website banner visible on login.

During that period, users may review changes and exercise rights if disagreeing with the new version.

All prior versions will be archived and available upon request, and change history may be consulted for audit or compliance purposes.

18. Version History

VersionDescriptionDateApproved By
0.9-DraftInternal circulation01-01-2025Legal Office
1.0Initial publication10-15-2025Board of Directors