Acceptable Use Policy

Version 1.0 · Effective Date: October 15, 2025

1. Purpose

The purpose of this policy is to establish a strategic and regulatory framework for the acceptable use of Seacrets' technological and IT assets, ensuring their protection against misuse, unauthorized access, operational negligence, and threats both internal and external, whether intentional or accidental.

This policy contributes to preserving the confidentiality, integrity, and availability (C-I-A) of critical information and systems through the application of responsible practices by all authorized users.

The policy is part of Seacrets' Information Security Management System (ISMS) and is aligned with:

  • The international standard ISO/IEC 27001:2022, as the foundation for ISMS design
  • The technical and organizational controls defined in ISO/IEC 27002:2022
  • The NIST Cybersecurity Framework (CSF) risk management approach, with emphasis on identification, protection, detection, response, and recovery

It also complements other corporate policies.

2. Scope

This acceptable use policy is mandatory for all persons who access, use, or administer the technological assets and digital environments operated by Seacrets, regardless of their contractual relationship or access modality.

The following are expressly included:

External Users:

Includes content creators, fans, affiliates, advertisers, commercial partners, and any third party accessing systems via web interface, mobile application, API, or other authorized mechanisms.

Internal and External Collaborators:

Comprises employees, contractors, content moderators, service providers (e.g., identity verification, hosting, payments), customer support personnel, and consultants with access to Seacrets systems or information.

Systems, Channels, and Covered Assets:

The policy applies to all use, interaction, or administration of:

  • Web platform, mobile applications, backoffice, and REST APIs
  • Cloud infrastructure (IaaS, PaaS, SaaS), payment systems, databases, and analytics tools
  • Corporate equipment and networks, support channels, administration dashboards, and authorized BYOD devices

This policy is enforceable both within and outside Seacrets' physical environment, including remote work, remote access, and use from personal or shared devices.

3. Guiding Principles

This policy is governed by the following fundamental principles, which must be respected by all users and collaborators in their interaction with Seacrets' systems, data, and digital platforms:

#PrincipleOperational Description
1LegalityAny use of technological assets that violates local, federal, or international laws is expressly prohibited, including but not limited to criminal law, intellectual property, child protection, data protection, telecommunications, AML/CFT, and human rights regulations.
2Respect & ConsentSeacrets applies zero tolerance to conduct involving: non-consensual sexual content distribution (NCSC), child exploitation (CSAM), non-consensual deepfake pornography, human trafficking, grooming, or sexual coercion. Any evidence will be blocked and reported.
3ConfidentialityUsers and collaborators must protect personal, financial, or sensitive data they access, in accordance with the Privacy Policy, Data Classification Policy, and applicable regulatory framework (GDPR, LGPD, CPRA, Law 787).
4SecurityUse of the platform implies acceptance of security controls including multi-factor authentication (MFA), data encryption, and active monitoring. It is strictly prohibited to: upload or distribute malware, manipulate scripts, evade firewalls, or attack systems.
5Transparency & TraceabilityAll activity is logged and subject to audit to comply with: monitoring obligations under AML/CFT and FATF policies, payment gateway requirements (VDMP, ECP, Mastercard BRAM), and Digital Services Act (DSA-EU) traceability and reporting requirements.

4. Prohibited Content and Activities

Every user of Seacrets' technological assets, platforms, or systems—including collaborators, affiliates, and external users—must refrain from performing, facilitating, or permitting any activity that:

  • Violates the law
  • Infringes fundamental rights

4.1 Expressly Prohibited Conduct:

1. Revenge Porn, Non-Consensual Deepfakes, and Unauthorized Recordings

Non-consensual sexual content, deepfake pornography without consent, and recordings made without explicit authorization.

2. Incitement to Hate, Violence, or Discrimination

Distribution of content or messages promoting hate or violence based on:

  • Race or ethnicity
  • Religion or beliefs
  • Migration status, disability, or other protected attributes

3. Financing of Illicit Activities

Use of the platform or its payment channels for:

  • Money laundering (ML)
  • Terrorist financing (TF)
  • Irregular cryptocurrency handling
  • Transactions to/from jurisdictions sanctioned by OFAC, UN, or the EU

4. Financial Fraud and Identity Impersonation

False or contradictory statements made to evade KYC/AML controls.

5. Spam, Manipulation, or Consumer Deception

Unsolicited mass sending (violation of CAN-SPAM, TCPA), deceptive or abusive practices infringing CFPB UDAAP rules, hidden advertising, false testimonials, or performance metrics manipulation.

6. Intellectual Property Rights Infringement

Upload or distribution of content without corresponding rights, licenses, or assignments. Violation of trademarks, image rights, exclusivity agreements, or distribution contracts.

7. Technical Interference, Manipulation, or System Attacks

Attempts to access systems or information without authorization (intrusion), DDoS attacks, traffic sniffing, port scanning, spoofing, malicious bot usage, intentional introduction of malware, exploits, reverse shells, or other threats.

5. Acceptable Use for Users

All activities performed by External Users (Content Creators, Fans, Affiliates, Advertisers) must be governed by the following criteria of legality, consent, traceability, and respect. This table establishes what is permitted, what is required, and what is expressly prohibited by functional category:

CategoryPermittedRequiredProhibited
Consensual Adult ContentUpload, stream, and monetize explicit content provided all participants are legal adults.– Identity verification (KYC) – Digital signed consent evidence – Pre-publication review (moderation + AI)– Depictions of minors, real or simulated – Coercion, non-simulated violence, non-consensual content – Bestiality, necrophilia, incest, non-authorized deepfakes
Payments & WithdrawalsReceive income from subscriptions, pay-per-view, tips, or commissions.– Complete KYC/AML – Tax compliance per jurisdiction– Structuring payments to evade limits – Use of stolen cards, mule accounts, or fake accounts – Shared or borrowed accounts
CommunicationsInteract via private messaging, forums, comment sections, and live streams.– Non-offensive language – Respect for other participants – Proper use of "Report" button for abuse– Harassment, threats, hate speech – Doxing, sexual extortion, or blackmail – Unsolicited mass sending (SPAM) or traffic manipulation

Every action on the platform generates technical traceability (logs, IP, timestamp, content hash) and may be audited in compliance with the Digital Services Act (EU), the Patriot Act (USA), international payment gateway requirements, and our internal protection and moderation policies.

6. Acceptable Use for Employees and Contractors

Seacrets personnel—including employees, consultants, contractors, moderators, external support staff, and technical providers—must strictly comply with the following standards for use of systems and technological resources as an essential condition of trust, professional integrity, and regulatory compliance.

6.1 Mandatory Best Practices

1. Personal and Controlled Access

Access must be performed exclusively with individual credentials assigned by the IT or IAM team. Sharing passwords, physical tokens, OTP codes, or sessions with other persons is strictly prohibited, even if they are on the same team.

2. Device Security

Every device used to access corporate systems (laptop, smartphone, tablet) must:

  • Have encrypted disk storage (BitLocker, FileVault, or equivalent MDM)
  • Enable automatic lock after inactivity
  • Have updated antivirus software and patch management

3. Software Installation and Use

Only previously approved and documented programs and extensions by the IT or Security team are permitted. Use of pirated software, cracked licenses, emulators, unauthorized proxies, or any tool that bypasses security controls is prohibited.

4. Digital Conduct and Social Media

All personal expression on social media must remain clearly dissociated from corporate identity. It is prohibited to:

  • Publish or forward confidential user, system, or partner information
  • Share sensitive content captured from internal systems (screenshots, customer names, metrics, etc.)

5. Active Supervision

All digital activities of personnel may be recorded and audited in compliance with the Information Security Policy, Privacy Policy, and principles of proportionality, necessity, and transparency. Violations are forwarded directly to the Compliance Committee and may result in contractual, disciplinary, or legal sanctions.

7. Data Protection and Privacy

Every user, collaborator, or provider with access to Seacrets systems, content, or records must handle information in accordance with the principles and controls established in:

  • The Privacy Policy
  • The information classification system based on ISO/IEC 27001 and ISO/IEC 27701

7.1 Specific Treatment Rules

Personal, financial, or sensitive data—including images, biometric identities, payment tokens, interaction histories, KYC data, metadata, and geolocation data—must be classified at least as CONFIDENTIAL (CONF).

When containing sensitive PII (e.g., sexual orientation, gender identity, explicit payment history, or intimate communications) or involving financial data subject to PCI DSS, they must be labeled as HIGHLY CONFIDENTIAL (HCONF).

Any transfer, download, viewing, or use of this information must be performed through secure channels (e.g., HTTPS, VPN, corporate tools with TLS/AES-256 encryption).

7.2 Prohibited Activities:

Export or download of information without functional justification validated by Compliance or Legal.

8. Monitoring and Moderation Mechanisms

Seacrets employs a multi-layer supervision approach to detect, prevent, and escalate any content or activity that violates internal policies, international regulations, or industry standards. This architecture combines artificial intelligence, human review, and independent quality control.

LayerTool / ProcessCoverageSLA / Operational Metric
AutomaticAI algorithms for CSAM detection, PhotoDNA hash-matching, AML/CFT rules, and anti-spam.100% of uploads, streams, messages, and transactions.Initial detection in <5 minutes from publication or event.
Human24/7 active review by Trust & Safety team, including context analysis, appeals, and reinforced manual moderation.Content reported or flagged as critical by AI, users, or rule system.Review time ≤12 hours from priority alert.
Audit (QA)Random sampling supervised by Compliance and internal audit of at least 5% of moderated content.Evaluation of moderation quality, biases, and false negatives.False Negative Rate (FNR) ≤0.3%.

9. Reporting and Response Procedure

9.1 Report Reception Channel

Reports may be submitted for free via:

  • The "Report" button integrated in profiles, content, live streams, or chats
  • Email: [email protected]

9.2 Operational Process

StepAction
1. ReceptionThe system or support team receives the report and assigns a unique ID for traceability.
2. Risk ClassificationRed: potential CSAM, minors, non-consensual content, credible threats, or ML/FT. Orange: spam or impersonation. Green: user disputes, questionable content, or abusive language.
3. Temporary ActionIf the incident is classified as red, content and/or account blocking is applied within a maximum of 2 hours.
4. InvestigationThe case is assigned to corresponding teams: Trust & Safety for operational review; MLRO and Legal if ML/FT indicators, court orders, PEPs, or cross-border incidents are involved.
5. Resolution NotificationThe reporter receives a follow-up email or message within 5 business days, indicating: action taken, possible escalation, appeal rights (if applicable).

All reports are stored encrypted for a minimum of 12 months in accordance with the principle of proportional retention and under Compliance team control.

10. Governance and RACI

The Acceptable Use Policy is part of Seacrets' comprehensive compliance, security, and digital ethics framework. Its correct implementation, maintenance, and supervision is structured through differentiated functions, assigned responsibilities, and independent audit controls.

Below is the RACI matrix (Responsible, Accountable, Consulted, Informed) for critical functions:

Function / ActivityAcceptable Use PolicyContent ModerationIncident ManagementTraining & AwarenessAnnual Review / Improvement
Board of DirectorsA/RIIIA/R
CISO / CTOCA/R (systems & tools)CCC
Trust & SafetyRACAC
MLRO (AML Reporting Officer)CCA/R (AML/FT)CC
Compliance OperationsACCRA
Internal AuditIIR (testing & validation)IA

Legend:

  • A: Accountable – Ultimate responsibility for decision-making
  • R: Responsible – Executes assigned actions
  • C: Consulted – Participates with specialized expertise
  • I: Informed – Must be informed of progress or result

This structure ensures the principle of separation of critical functions (SoD), promotes accountability, and enables compliance with external auditors, payment acquirers, and regulatory authorities.

11. Training and Awareness

Continuous training is an essential component to ensure sustained compliance with this policy. Seacrets applies a preventive approach adapted to critical roles, ensuring each stakeholder group understands their obligations, inherent risks, and consequences of policy violations.

Program / ModuleTarget AudienceFrequencyKPI / Performance Target
Induction: Acceptable Use Policy (2 hours)All personnel (employees, contractors, moderators)During onboarding (day 1-5)≥95% of participants pass with minimum defined score.
CSAM Detection Drill and Immediate ResponseTrust & Safety teamOnboardingMTTR (Mean Time to Respond) <1 hour in critical events.

All attendance records, assessment results, and corrective actions are documented in the compliance system and form part of the personnel file. Repeated non-compliance or failure to participate in mandatory training may result in temporary access suspension or contractual sanctions.

12. Compliance and Sanctions

Non-compliance with this Acceptable Use Policy activates corrective, disciplinary, or legal measures proportionate to the gravity of the conduct, potential or actual impact, and the offender's profile (user, collaborator, or provider).

12.1 Measures Applicable to Users (Creators, Fans, Affiliates)

Seacrets may impose progressive or immediate measures in case of confirmed violations or reasonable evidence, including:

  • Formal warning or correction request
  • Temporary or permanent demonetization of content or channel
  • Account suspension pending investigation resolution
  • Permanent termination of platform access without refund
  • Report to competent authorities (LEA) in cases of:
  • Suspected child exploitation (CSAM)
  • Financial crimes (ML/FT)
  • Credible threats, human trafficking, or other illicit activities

12.2 Internal Measures for Employees and Contractors

Serious or repeated violations by personnel with access to Seacrets systems or data result in:

  • Written reprimand and corrective action plan
  • Temporary suspension of access or critical functions
  • Immediate contract termination, especially in cases of:
  • Unauthorized disclosure of confidential information
  • Complicity in cover-up practices, sabotage, or control evasion
  • Identity simulation or institutional impersonation

12.3 Penalties for Providers, Partners, or Third Parties

Contracts with service providers, technological tools, payment processing, or identity verification contain binding compliance clauses. Upon non-compliance:

  • Economic penalties, service suspensions, or contract termination are activated
  • Other relevant actors (payment networks, acquirers, partners) are notified when applicable
  • Legal action may be exercised for damages from fraudulent, negligent, or cover-up conduct

All sanctions are documented and recorded in the compliance system. The Compliance Committee and Legal oversee their execution in accordance with principles of legality, equity, and traceability.

13. Review and Continuous Improvement

This Acceptable Use Policy is part of Seacrets' comprehensive compliance and digital security framework and is subject to periodic reviews to ensure its validity, effectiveness, and alignment with emerging risks and applicable regulatory environment.

13.1 Review Frequency

The policy will be reviewed at minimum once every 12 months or earlier if any of the following circumstances occur:

Regulatory Changes:

  • Digital Services Act (EU) entry or amendments
  • EU 6th AML Directive (EU 2018/1673)
  • COPPA (USA) reforms, Law 787 (Nicaragua), or other sectoral regulations

Platform Functional Evolution:

  • Introduction of new risk vectors or technological exposure, such as:
  • Interactive 4K streaming functionality
  • Automated monetization mechanisms
  • Expansion to high-risk jurisdictions

Operational Risk Events or Non-Compliance:

  • Security breaches associated with system misuse
  • Acceptable use violation rate exceeding 0.5% monthly
  • Relevant findings from internal or external audit

13.2 Update Procedure

Policy review will be led by the Compliance area, together with the CISO and Trust & Safety.

Any modification must be:

  • Approved by the Board of Directors
  • Communicated to users, employees, and relevant third parties with a minimum of 15 calendar days notice before entry into force

A version history and change rationale will be maintained for audit and regulatory purposes.

14. Version History

VersionDescriptionDateApproved By
0.9 – DraftInternal circulation01-01-2025Legal Office
1.0 ReleaseInitial publication10-15-2025Board of Directors