Privacy Policy
Last updated: 2026-05-18
1. Data controller
The data controller for personal data is [Company Name], registered with company number [Registration Number], with its registered office at [Full Address] (the « Operator »).
For any question relating to your data: [privacy@example.com]. Data Protection Officer (DPO): [dpo@example.com].
2. Data collected
Depending on your interaction with the Service, the Operator collects the following categories of data:
For any user
- Account identifiers: email address, username, password (bcrypt-hashed);
- Connection data: IP address, user agent, timestamps;
- Display and navigation preferences;
- Consent to age verification.
For paying viewer users
- Billing data (handled by Stripe — the Operator does not store your card number);
- Transaction and subscription history.
For Creators
- KYC documents: ID (front/back), verification selfie;
- Legal name, date of birth, country of residence;
- Bank details for payments (handled by Stripe Connect);
- For 18 U.S.C. § 2257 compliance: supporting documents for performers appearing in content.
3. Purposes and legal bases
Your data is processed for the following purposes:
- Service provision (legal basis: contract performance) — account creation, content access, support.
- Age verification and KYC (legal obligation) — compliance with ARCOM (France), UK OSA, 18 U.S.C. § 2257 (USA), AML.
- Payment and billing (contract performance + legal obligation) — transaction processing, fraud prevention, accounting.
- Content moderation (legal obligation + legitimate interest) — CSAM scanning, report handling, platform security.
- Service improvement (legitimate interest) — aggregated analytics, performance, abuse prevention.
- Operational communications (contract performance) — account notifications, service updates.
- Marketing communications (consent) — only with your explicit opt-in, unsubscribe at any time.
4. Recipients and subprocessors
Your data may be communicated to the following technical subprocessors, strictly to the extent necessary for the operation of the Service:
- Neon (USA / EU) — PostgreSQL database hosting;
- Cloudflare Stream (USA) — video delivery and transcoding;
- Backblaze B2 (USA) — file storage (KYC documents, media);
- Stripe (Ireland / USA) — payments and creator payouts;
- Resend (USA) — transactional emails;
- VPS host (OVHcloud) (France) — application infrastructure.
Each of these subprocessors provides sufficient guarantees within the meaning of the GDPR (Articles 28 and 44 et seq.). Transfers outside the EU are governed by standard contractual clauses or adequacy decisions.
5. Retention periods
- Active account data: retained as long as the account is active.
- Data after account deletion: erased within 30 days, except for legal obligations.
- KYC documents: retained for the entire duration of Creator status + 5 years after the last transaction (anti-money-laundering obligation).
- 2257 records: 7 years after the last publication of content (US obligation).
- Invoices and accounting data: 10 years (French Commercial Code, Article L. 123-22).
- Technical logs: 12 months maximum.
- Report data: 5 years after case closure.
6. Your rights (GDPR)
In accordance with the General Data Protection Regulation (EU 2016/679), you have the following rights regarding your personal data:
- Right of access: obtain a copy of your data.
- Right to rectification: correct inaccurate data.
- Right to erasure (« right to be forgotten »): subject to legal retention obligations.
- Right to restriction: temporarily suspend processing.
- Right to portability: receive your data in a structured format, or transfer it to another service.
- Right to object: in particular to marketing processing.
- Right to withdraw consent at any time, without retroactive effect.
- Right to define post-mortem directives regarding the fate of your data.
To exercise these rights: [privacy@example.com] or via your dashboard. Proof of identity may be requested. You will receive a response within one month.
If you believe your rights are not being respected, you may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, 75007 Paris, France (www.cnil.fr).
7. Cookies and trackers
The Service uses the following cookies:
- Strictly necessary cookies (no consent required): authentication (access_token, refresh_token), session preferences, age verification.
- Analytics cookies (consent required): anonymized usage statistics.
- Marketing cookies (consent required): currently not used.
You can configure your preferences via the cookie banner shown on your first visit, or at any time from the « Cookie preferences » link in the footer.
8. Security
The Operator implements appropriate technical and organizational measures to protect your data: TLS encryption in transit, bcrypt password hashing, isolation of sensitive data (isolated KYC), logging of access to sensitive data, principle of least privilege, and privacy by design.
In case of a data breach presenting a risk to your rights and freedoms, you will be notified as soon as possible in accordance with Article 34 of the GDPR.
9. Minors
The Service is strictly reserved for persons of legal age. No data is knowingly collected from minors. If you believe that a minor has accessed the Service, contact us immediately at [abuse@example.com].
10. Modifications
This policy may be modified. Any substantial modification is notified by email or via a banner on the Service at least 30 days before entering into force.
11. Contact
DPO: [dpo@example.com]
For any other question: [privacy@example.com]