Privacy Policy
Effective Date: August 26, 2025
This Privacy Policy explains how Azryo LLC ("we," "us," or "our") collects, uses, and protects your personal information when you use our creator subscription platform.
1. Data Controller
Azryo LLC
5830 E 2nd St, Ste 7000 #28002
Casper, Wyoming 82609, USA
Email: privacy@azryo.com
2. Legal Basis for Processing (GDPR)
We process your personal data only when we have a valid legal basis:
Consent (Article 6.1.a)
- Marketing communications and newsletters
- Non-essential cookies and analytics
- Promotional materials and offers
Contract Performance (Article 6.1.b)
- Account creation and management
- Service delivery and platform access
- Payment processing and transactions
- Customer support and communications
Legal Obligations (Article 6.1.c)
- Tax records and financial reporting
- KYC/AML compliance for creators
- USC 2257 record-keeping requirements
- Law enforcement cooperation when required
- Reporting content and related account data to the National Center for Missing & Exploited Children (NCMEC) and/or law enforcement agencies if our systems or moderators detect or suspect Child Sexual Abuse Material (CSAM) or other serious illegal content
Legitimate Interests (Article 6.1.f)
- Platform security and fraud prevention
- Service improvement and optimization
- Network and information security
- Enforcing terms of service and policies
You have the right to object to processing based on legitimate interests. Contact us at privacy@azryo.com to exercise this right.
3. Data We Collect
- Account Data: Username, email, phone number, profile information, subscription preferences.
- Financial Data: Payment methods, transaction history, subscription billing, creator earnings.
- Content Data: Uploaded media, messages, comments, AI-generated content markers.
- Usage Data: Login times, feature usage, content interactions, search history.
- Technical Data: IP address, device identifiers, browser type, operating system.
- Verification Data: Information used for identity and age verification, including verification status from didit for Creators and Fans (first paid purchase), and any documentation you choose to submit for verification or compliance purposes. We do not receive raw biometric data or ID images from didit; only a pass/fail style verification result.
- Communication Data: Support tickets, feedback, survey responses.
- Moderation Data: Classification results, flags, labels, and logs generated by our safety systems (such as AWS Rekognition, Microsoft PhotoDNA, and self-hosted Whisper) when analyzing content for potential policy violations.
We collect this data:
- Directly from you during registration, content uploads, purchases, or contact.
- Automatically through cookies, device logs, and analytics.
- From third parties such as payment processors, fraud prevention services, and verification providers.
4. How We Use Data
- To deliver services, subscriptions, and payouts (contractual necessity).
- To verify accounts, ensure compliance, and prevent fraud (legal obligation/legitimate interest).
- To verify the age of Customers (Fans) and Creators using didit, ensuring that only users aged 18+ can access or purchase age-restricted content.
- To personalize and improve platform features (legitimate interest).
- To send platform updates or marketing (with your consent where required).
- To comply with applicable laws and protect the platform community.
- To analyze uploaded content using automated and human moderation tools (including AWS Rekognition, Microsoft PhotoDNA, Whisper, and Cloudflare R2/CDN) in order to detect and prevent illegal or prohibited content, including CSAM.
5. Sharing & Transfers
- We share data only with trusted service providers such as payment processors, hosting/CDN services, analytics providers, and verification partners.
- If data is transferred internationally, we apply appropriate safeguards such as Standard Contractual Clauses.
- We do not sell personal data. For California users, we provide a "Do Not Sell or Share My Personal Information" right.
- Data may be disclosed if required by law, court order, or to protect safety and security.
Norviax LTD
We share relevant Creator and transaction data with Norviax LTD for the purpose of processing card payments, conducting KYC/AML checks, sanctions screening, handling chargebacks, and issuing fiat payouts related to Visa and Mastercard transactions.
Crypto Payment Processors
For cryptocurrency transactions, we share limited transaction details with our crypto payment processors so they can process crypto payments and, depending on Creator payout settings, settle funds to Azryo in fiat or cryptocurrency. We do not share your private keys and do not control on-chain transaction visibility.
5a. Specific Data Retention Periods
We retain your data only as long as necessary for the purposes collected:
| Data Type | Retention Period |
|---|---|
| Account Information | 90 days after account deletion |
| Payment Records | 7 years (tax/legal requirements) |
| User Content | 30 days after deletion request |
| IP Logs | 6 months |
| Support Tickets | 2 years after resolution |
| Email Communications | 3 years |
| USC 2257 Records | 5 years after content creation |
| Security Logs | 12 months |
| Cookie Data | As specified in cookie policy |
| Backup Data | 90 days (disaster recovery) |
Note: Some data may be retained longer if required by law or to defend legal claims.
6. Data Retention
- Account data is retained while your account is active, plus 30 days for account recovery.
- Financial records are kept for 7 years per legal requirements.
- Content is deleted within 30 days of account closure, except where legally required to retain.
- Analytics and usage data is anonymized and may be retained longer for platform improvement.
- We retain age-verification status, Model Release documentation, moderation logs, and card-network compliance records for as long as necessary to meet our legal and safety obligations, typically between 3 and 7 years, or longer where required by law, payment networks, or law-enforcement requests.
7. Your Rights
Depending on your location, you have various rights regarding your personal data under applicable privacy laws (including GDPR, CCPA, and other regulations):
Rights Available to You:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Deletion: Request erasure of your personal data
- Portability: Receive your data in a portable format
- Restriction: Limit how we process your data
- Objection: Object to certain processing activities
- Withdraw Consent: Withdraw previously given consent
- Non-Discrimination: Not be discriminated against for exercising rights
How to Exercise Your Rights:
- Email us at privacy@azryo.com
- Include "Privacy Rights Request" in the subject line
- Specify your location (country/state) for applicable laws
- Provide sufficient information to verify your identity
- Clearly specify which rights you wish to exercise
Response Timeline:
- GDPR (EU/UK): Within 30 days (extendable to 90 days for complex requests)
- CCPA (California): Within 45 days (extendable to 90 days with notice)
- Other Jurisdictions: As required by applicable local law
Verification Process:
To protect your privacy, we will verify your identity before processing requests. This may include:
- Confirming your account email address
- Requesting additional identifying information
- Matching information you provide with our records
Authorized Agents:
You may designate an authorized agent to make requests on your behalf. The agent must provide proof of authorization and you may need to verify your identity directly with us.
Supervisory Authorities:
If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection authority:
- EU Residents: Your local Data Protection Authority
- UK Residents: Information Commissioner's Office (ICO)
- California Residents: California Privacy Protection Agency
Exercise Your Privacy Rights
You have the right to control your personal data. Submit a request to access, delete, export, or manage your information in accordance with GDPR and CCPA regulations.
GDPR Rights (EU)
- Right to Access
- Right to Rectification
- Right to Erasure
- Right to Data Portability
CCPA Rights (California)
- Right to Know
- Right to Delete
- Right to Opt-Out
- Right to Non-Discrimination
8. Age Verification & NSFW Content
- All users must be 18+ to create accounts.
- When age verification is performed via didit, Azryo does not receive or store ID images or biometric data—only the verification status. If users submit documents directly to Azryo for compliance or secondary verification, those documents are stored securely and retained only as long as legally required. NSFW accounts require strict 18+ verification.
8a. Third-Party Service Providers
We work with trusted third-party providers to operate our platform. These providers are contractually bound to protect your data:
Infrastructure & Hosting
- Cloudflare - CDN and DDoS protection (Global)
Payment Processing
- Any third party approved by Azryo LLC which enables a User to make payments on the Platform
Communication & Support
- Email Service Provider - Transactional and marketing emails
- Customer Support Platform - Help desk and ticket management
Analytics & Monitoring
- Google Analytics - Website analytics and user behavior tracking
- Product Analytics Platform - Usage analytics and insights
- Error Monitoring Service - Application error tracking
Security & Compliance
- Google reCAPTCHA - Spam and bot protection on forms (only loaded on form pages)
- didit - Age verification and identity verification services
- KYC/AML Providers - Compliance verification
All third-party providers are vetted for security and sign Data Processing Agreements (DPAs) ensuring GDPR compliance.
9. Security
We use industry-standard protections including TLS encryption, hardened infrastructure, access controls, and ACID-compliant database practices to secure user data.
9a. Data Breach Notification
In the event of a data breach that may compromise your personal information:
- Notification Timeline: Regulatory authorities notified within 72 hours of discovery (GDPR requirement)
- User Notification: Affected users notified without undue delay when breach poses high risk to rights and freedoms
- Information Provided: Nature of breach, categories of data affected, likely consequences, and remedial measures taken
- Immediate Response: Breach contained, systems secured, and forensic analysis initiated
- Support Services: Dedicated support channel and credit monitoring services if applicable
- Law Enforcement: Cooperation with authorities and law enforcement as required
Current Security Status
- No data breaches reported in the last 12 months
- Last security audit: January 2025
- SOC 2 Type II compliant
- 99.9% uptime with security monitoring
Preventive Measures
- Multi-factor authentication required
- End-to-end encryption for sensitive data
- Regular penetration testing
- Employee security training programs
Report a Security Concern
If you discover a security vulnerability or have concerns about the safety of your data, please contact our security team immediately at security@azryo.com.
10. Cookies
We use cookies and similar technologies for essential functions, analytics, preferences, and marketing. Users can manage preferences via browser settings or our cookie banner.
10a. Cross-Border Data Transfer Details
As a US-based company serving global users, we transfer data internationally with appropriate safeguards:
Transfer Mechanisms:
- Standard Contractual Clauses (SCCs): EU Commission-approved clauses for EU-US transfers
- UK International Data Transfer Agreement: For UK data transfers
- Adequacy Decisions: Where applicable (e.g., Canada, Japan)
Data Locations:
- Primary Processing: United States (Wyoming)
- Backup Storage: United States, European Union
- CDN Cache: Global edge locations
Your Rights: You may request a copy of the safeguards we use for international transfers by contacting privacy@azryo.com
11. Updates
We may update this Privacy Policy from time to time. The effective date will be shown above. Significant changes will be communicated to users.
12. California Privacy Rights (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) regarding your personal information.
Your Rights Include:
- Right to Know: Request information about the personal data we collect, use, and disclose
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt-out of the sale of your personal information
- Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights
Information We Collect:
- Identifiers (name, email, IP address)
- Commercial information (transaction history)
- Internet activity (browsing behavior on our platform)
- Geolocation data (general location based on IP)
- Professional information (creator profiles)
Do Not Sell My Personal Information
Azryo does not sell personal information in the traditional sense. However, we may share data with service providers in ways that could be considered a "sale" under CCPA's broad definition.
Opt-Out of Data Sharing
To opt-out of any data sharing that might constitute a "sale" under CCPA:
Do Not Sell My Personal InformationNote: This opt-out is specific to CCPA requirements and does not affect essential service operations.
Additional Information for California Residents:
- To exercise your rights, follow the general process in Section 7 above
- You may specify "California Privacy Rights" in your email subject for faster routing
- California residents can make requests twice per 12-month period
- We cannot require you to create an account to exercise your rights
Annual CCPA Statistics: California residents may request information about our CCPA compliance metrics. In 2025, we received 0 verifiable consumer requests and fulfilled 0% within the statutory timeframe.
13. Contact Us
For questions, requests, or complaints regarding this Privacy Policy:
Azryo LLC
5830 E 2nd St, Ste 7000 #28002
Casper, Wyoming 82609, USA
Email: privacy@azryo.com