1. Purpose
The purpose of this policy is to establish a strategic and regulatory framework for the acceptable use of Seacrets' technological and IT assets, ensuring their protection against misuse, unauthorized access, operational negligence, and threats both internal and external, whether intentional or accidental.
This policy contributes to preserving the confidentiality, integrity, and availability (C-I-A) of critical information and systems through the application of responsible practices by all authorized users.
The policy is part of Seacrets' Information Security Management System (ISMS) and is aligned with:
- The international standard ISO/IEC 27001:2022, as the foundation for ISMS design
- The technical and organizational controls defined in ISO/IEC 27002:2022
- The NIST Cybersecurity Framework (CSF) risk management approach, with emphasis on identification, protection, detection, response, and recovery
It also complements other corporate policies.
2. Scope
This acceptable use policy is mandatory for all persons who access, use, or administer the technological assets and digital environments operated by Seacrets, regardless of their contractual relationship or access modality.
The following are expressly included:
External Users:
Includes content creators, fans, affiliates, advertisers, commercial partners, and any third party accessing systems via web interface, mobile application, API, or other authorized mechanisms.
Internal and External Collaborators:
Comprises employees, contractors, content moderators, service providers (e.g., identity verification, hosting, payments), customer support personnel, and consultants with access to Seacrets systems or information.
Systems, Channels, and Covered Assets:
The policy applies to all use, interaction, or administration of:
- Web platform, mobile applications, backoffice, and REST APIs
- Cloud infrastructure (IaaS, PaaS, SaaS), payment systems, databases, and analytics tools
- Corporate equipment and networks, support channels, administration dashboards, and authorized BYOD devices
This policy is enforceable both within and outside Seacrets' physical environment, including remote work, remote access, and use from personal or shared devices.
3. Guiding Principles
This policy is governed by the following fundamental principles, which must be respected by all users and collaborators in their interaction with Seacrets' systems, data, and digital platforms:
| # | Principle | Operational Description |
|---|---|---|
| 1 | Legality | Any use of technological assets that violates local, federal, or international laws is expressly prohibited, including but not limited to criminal law, intellectual property, child protection, data protection, telecommunications, AML/CFT, and human rights regulations. |
| 2 | Respect & Consent | Seacrets applies zero tolerance to conduct involving: non-consensual sexual content distribution (NCSC), child exploitation (CSAM), non-consensual deepfake pornography, human trafficking, grooming, or sexual coercion. Any evidence will be blocked and reported. |
| 3 | Confidentiality | Users and collaborators must protect personal, financial, or sensitive data they access, in accordance with the Privacy Policy, Data Classification Policy, and applicable regulatory framework (GDPR, LGPD, CPRA, Law 787). |
| 4 | Security | Use of the platform implies acceptance of security controls including multi-factor authentication (MFA), data encryption, and active monitoring. It is strictly prohibited to: upload or distribute malware, manipulate scripts, evade firewalls, or attack systems. |
| 5 | Transparency & Traceability | All activity is logged and subject to audit to comply with: monitoring obligations under AML/CFT and FATF policies, payment gateway requirements (VDMP, ECP, Mastercard BRAM), and Digital Services Act (DSA-EU) traceability and reporting requirements. |
4. Prohibited Content and Activities
Every user of Seacrets' technological assets, platforms, or systems—including collaborators, affiliates, and external users—must refrain from performing, facilitating, or permitting any activity that:
- Violates the law
- Infringes fundamental rights
4.1 Expressly Prohibited Conduct:
1. Revenge Porn, Non-Consensual Deepfakes, and Unauthorized Recordings
Non-consensual sexual content, deepfake pornography without consent, and recordings made without explicit authorization.
2. Incitement to Hate, Violence, or Discrimination
Distribution of content or messages promoting hate or violence based on:
- Race or ethnicity
- Religion or beliefs
- Migration status, disability, or other protected attributes
3. Financing of Illicit Activities
Use of the platform or its payment channels for:
- Money laundering (ML)
- Terrorist financing (TF)
- Irregular cryptocurrency handling
- Transactions to/from jurisdictions sanctioned by OFAC, UN, or the EU
4. Financial Fraud and Identity Impersonation
False or contradictory statements made to evade KYC/AML controls.
5. Spam, Manipulation, or Consumer Deception
Unsolicited mass sending (violation of CAN-SPAM, TCPA), deceptive or abusive practices infringing CFPB UDAAP rules, hidden advertising, false testimonials, or performance metrics manipulation.
6. Intellectual Property Rights Infringement
Upload or distribution of content without corresponding rights, licenses, or assignments. Violation of trademarks, image rights, exclusivity agreements, or distribution contracts.
7. Technical Interference, Manipulation, or System Attacks
Attempts to access systems or information without authorization (intrusion), DDoS attacks, traffic sniffing, port scanning, spoofing, malicious bot usage, intentional introduction of malware, exploits, reverse shells, or other threats.
5. Acceptable Use for Users
All activities performed by External Users (Content Creators, Fans, Affiliates, Advertisers) must be governed by the following criteria of legality, consent, traceability, and respect. This table establishes what is permitted, what is required, and what is expressly prohibited by functional category:
| Category | Permitted | Required | Prohibited |
|---|---|---|---|
| Consensual Adult Content | Upload, stream, and monetize explicit content provided all participants are legal adults. | – Identity verification (KYC) – Digital signed consent evidence – Pre-publication review (moderation + AI) | – Depictions of minors, real or simulated – Coercion, non-simulated violence, non-consensual content – Bestiality, necrophilia, incest, non-authorized deepfakes |
| Payments & Withdrawals | Receive income from subscriptions, pay-per-view, tips, or commissions. | – Complete KYC/AML – Tax compliance per jurisdiction | – Structuring payments to evade limits – Use of stolen cards, mule accounts, or fake accounts – Shared or borrowed accounts |
| Communications | Interact via private messaging, forums, comment sections, and live streams. | – Non-offensive language – Respect for other participants – Proper use of "Report" button for abuse | – Harassment, threats, hate speech – Doxing, sexual extortion, or blackmail – Unsolicited mass sending (SPAM) or traffic manipulation |
Every action on the platform generates technical traceability (logs, IP, timestamp, content hash) and may be audited in compliance with the Digital Services Act (EU), the Patriot Act (USA), international payment gateway requirements, and our internal protection and moderation policies.
6. Acceptable Use for Employees and Contractors
Seacrets personnel—including employees, consultants, contractors, moderators, external support staff, and technical providers—must strictly comply with the following standards for use of systems and technological resources as an essential condition of trust, professional integrity, and regulatory compliance.
6.1 Mandatory Best Practices
1. Personal and Controlled Access
Access must be performed exclusively with individual credentials assigned by the IT or IAM team. Sharing passwords, physical tokens, OTP codes, or sessions with other persons is strictly prohibited, even if they are on the same team.
2. Device Security
Every device used to access corporate systems (laptop, smartphone, tablet) must:
- Have encrypted disk storage (BitLocker, FileVault, or equivalent MDM)
- Enable automatic lock after inactivity
- Have updated antivirus software and patch management
3. Software Installation and Use
Only previously approved and documented programs and extensions by the IT or Security team are permitted. Use of pirated software, cracked licenses, emulators, unauthorized proxies, or any tool that bypasses security controls is prohibited.
4. Digital Conduct and Social Media
All personal expression on social media must remain clearly dissociated from corporate identity. It is prohibited to:
- Publish or forward confidential user, system, or partner information
- Share sensitive content captured from internal systems (screenshots, customer names, metrics, etc.)
5. Active Supervision
All digital activities of personnel may be recorded and audited in compliance with the Information Security Policy, Privacy Policy, and principles of proportionality, necessity, and transparency. Violations are forwarded directly to the Compliance Committee and may result in contractual, disciplinary, or legal sanctions.
7. Data Protection and Privacy
Every user, collaborator, or provider with access to Seacrets systems, content, or records must handle information in accordance with the principles and controls established in:
- The Privacy Policy
- The information classification system based on ISO/IEC 27001 and ISO/IEC 27701
7.1 Specific Treatment Rules
Personal, financial, or sensitive data—including images, biometric identities, payment tokens, interaction histories, KYC data, metadata, and geolocation data—must be classified at least as CONFIDENTIAL (CONF).
When containing sensitive PII (e.g., sexual orientation, gender identity, explicit payment history, or intimate communications) or involving financial data subject to PCI DSS, they must be labeled as HIGHLY CONFIDENTIAL (HCONF).
Any transfer, download, viewing, or use of this information must be performed through secure channels (e.g., HTTPS, VPN, corporate tools with TLS/AES-256 encryption).
7.2 Prohibited Activities:
Export or download of information without functional justification validated by Compliance or Legal.
8. Monitoring and Moderation Mechanisms
Seacrets employs a multi-layer supervision approach to detect, prevent, and escalate any content or activity that violates internal policies, international regulations, or industry standards. This architecture combines artificial intelligence, human review, and independent quality control.
| Layer | Tool / Process | Coverage | SLA / Operational Metric |
|---|---|---|---|
| Automatic | AI algorithms for CSAM detection, PhotoDNA hash-matching, AML/CFT rules, and anti-spam. | 100% of uploads, streams, messages, and transactions. | Initial detection in <5 minutes from publication or event. |
| Human | 24/7 active review by Trust & Safety team, including context analysis, appeals, and reinforced manual moderation. | Content reported or flagged as critical by AI, users, or rule system. | Review time ≤12 hours from priority alert. |
| Audit (QA) | Random sampling supervised by Compliance and internal audit of at least 5% of moderated content. | Evaluation of moderation quality, biases, and false negatives. | False Negative Rate (FNR) ≤0.3%. |
9. Reporting and Response Procedure
9.1 Report Reception Channel
Reports may be submitted for free via:
- The "Report" button integrated in profiles, content, live streams, or chats
- Email: [email protected]
9.2 Operational Process
| Step | Action |
|---|---|
| 1. Reception | The system or support team receives the report and assigns a unique ID for traceability. |
| 2. Risk Classification | Red: potential CSAM, minors, non-consensual content, credible threats, or ML/FT. Orange: spam or impersonation. Green: user disputes, questionable content, or abusive language. |
| 3. Temporary Action | If the incident is classified as red, content and/or account blocking is applied within a maximum of 2 hours. |
| 4. Investigation | The case is assigned to corresponding teams: Trust & Safety for operational review; MLRO and Legal if ML/FT indicators, court orders, PEPs, or cross-border incidents are involved. |
| 5. Resolution Notification | The reporter receives a follow-up email or message within 5 business days, indicating: action taken, possible escalation, appeal rights (if applicable). |
All reports are stored encrypted for a minimum of 12 months in accordance with the principle of proportional retention and under Compliance team control.
10. Governance and RACI
The Acceptable Use Policy is part of Seacrets' comprehensive compliance, security, and digital ethics framework. Its correct implementation, maintenance, and supervision is structured through differentiated functions, assigned responsibilities, and independent audit controls.
Below is the RACI matrix (Responsible, Accountable, Consulted, Informed) for critical functions:
| Function / Activity | Acceptable Use Policy | Content Moderation | Incident Management | Training & Awareness | Annual Review / Improvement |
|---|---|---|---|---|---|
| Board of Directors | A/R | I | I | I | A/R |
| CISO / CTO | C | A/R (systems & tools) | C | C | C |
| Trust & Safety | R | A | C | A | C |
| MLRO (AML Reporting Officer) | C | C | A/R (AML/FT) | C | C |
| Compliance Operations | A | C | C | R | A |
| Internal Audit | I | I | R (testing & validation) | I | A |
Legend:
- A: Accountable – Ultimate responsibility for decision-making
- R: Responsible – Executes assigned actions
- C: Consulted – Participates with specialized expertise
- I: Informed – Must be informed of progress or result
This structure ensures the principle of separation of critical functions (SoD), promotes accountability, and enables compliance with external auditors, payment acquirers, and regulatory authorities.
11. Training and Awareness
Continuous training is an essential component to ensure sustained compliance with this policy. Seacrets applies a preventive approach adapted to critical roles, ensuring each stakeholder group understands their obligations, inherent risks, and consequences of policy violations.
| Program / Module | Target Audience | Frequency | KPI / Performance Target |
|---|---|---|---|
| Induction: Acceptable Use Policy (2 hours) | All personnel (employees, contractors, moderators) | During onboarding (day 1-5) | ≥95% of participants pass with minimum defined score. |
| CSAM Detection Drill and Immediate Response | Trust & Safety team | Onboarding | MTTR (Mean Time to Respond) <1 hour in critical events. |
All attendance records, assessment results, and corrective actions are documented in the compliance system and form part of the personnel file. Repeated non-compliance or failure to participate in mandatory training may result in temporary access suspension or contractual sanctions.
12. Compliance and Sanctions
Non-compliance with this Acceptable Use Policy activates corrective, disciplinary, or legal measures proportionate to the gravity of the conduct, potential or actual impact, and the offender's profile (user, collaborator, or provider).
12.1 Measures Applicable to Users (Creators, Fans, Affiliates)
Seacrets may impose progressive or immediate measures in case of confirmed violations or reasonable evidence, including:
- Formal warning or correction request
- Temporary or permanent demonetization of content or channel
- Account suspension pending investigation resolution
- Permanent termination of platform access without refund
- Report to competent authorities (LEA) in cases of:
- Suspected child exploitation (CSAM)
- Financial crimes (ML/FT)
- Credible threats, human trafficking, or other illicit activities
12.2 Internal Measures for Employees and Contractors
Serious or repeated violations by personnel with access to Seacrets systems or data result in:
- Written reprimand and corrective action plan
- Temporary suspension of access or critical functions
- Immediate contract termination, especially in cases of:
- Unauthorized disclosure of confidential information
- Complicity in cover-up practices, sabotage, or control evasion
- Identity simulation or institutional impersonation
12.3 Penalties for Providers, Partners, or Third Parties
Contracts with service providers, technological tools, payment processing, or identity verification contain binding compliance clauses. Upon non-compliance:
- Economic penalties, service suspensions, or contract termination are activated
- Other relevant actors (payment networks, acquirers, partners) are notified when applicable
- Legal action may be exercised for damages from fraudulent, negligent, or cover-up conduct
All sanctions are documented and recorded in the compliance system. The Compliance Committee and Legal oversee their execution in accordance with principles of legality, equity, and traceability.
13. Review and Continuous Improvement
This Acceptable Use Policy is part of Seacrets' comprehensive compliance and digital security framework and is subject to periodic reviews to ensure its validity, effectiveness, and alignment with emerging risks and applicable regulatory environment.
13.1 Review Frequency
The policy will be reviewed at minimum once every 12 months or earlier if any of the following circumstances occur:
Regulatory Changes:
- Digital Services Act (EU) entry or amendments
- EU 6th AML Directive (EU 2018/1673)
- COPPA (USA) reforms, Law 787 (Nicaragua), or other sectoral regulations
Platform Functional Evolution:
- Introduction of new risk vectors or technological exposure, such as:
- Interactive 4K streaming functionality
- Automated monetization mechanisms
- Expansion to high-risk jurisdictions
Operational Risk Events or Non-Compliance:
- Security breaches associated with system misuse
- Acceptable use violation rate exceeding 0.5% monthly
- Relevant findings from internal or external audit
13.2 Update Procedure
Policy review will be led by the Compliance area, together with the CISO and Trust & Safety.
Any modification must be:
- Approved by the Board of Directors
- Communicated to users, employees, and relevant third parties with a minimum of 15 calendar days notice before entry into force
A version history and change rationale will be maintained for audit and regulatory purposes.
14. Version History
| Version | Description | Date | Approved By |
|---|---|---|---|
| 0.9 – Draft | Internal circulation | 01-01-2025 | Legal Office |
| 1.0 Release | Initial publication | 10-15-2025 | Board of Directors |