Skip to document
English
Back to RedPatron

RedPatron legal

Privacy Policy

How RedPatron processes, protects and retains personal data.

Effective date: 4 August 2026
Document version: 1.1

SC EuroClothing SRL, Strada Primaverii 55, 507190 Sanpetru, Brasov, Romania, is the controller for the RedPatron service except where a provider acts independently. Contact privacy@redpatrons.de.

Data we process

  • account and profile data: email, handle, display name, language, country and declared date of birth;
  • authentication and security data: password hash, passkeys, MFA, sessions, IP, device, login and fraud signals;
  • age, identity and creator verification: provider reference, status, country, dates, expiry, review and limited evidence; raw ID or biometric data should remain with the verification provider unless lawfully necessary;
  • creator/business data: legal name, address, nationality, registry, authorised representatives, beneficial owners, tax identifiers and payout beneficiary;
  • content and communication: uploads, drafts, metadata, livestreams, messages, reports, consent and performer links;
  • transaction data: products, subscriptions, amounts, currency, taxes, provider transaction references, refunds, chargebacks, reserves and payouts; RedPatron does not intentionally receive or store full card numbers or CVV;
  • moderation and legal data: automated signals, human decisions, complaints, appeals, evidence, authority requests and audit logs;
  • cookie and usage data as described in the Cookie Policy.

Content, profile and moderation data may reveal sex life or sexual orientation. We process such data only with an applicable GDPR Article 9 condition and safeguards, including explicit consent where appropriate, establishment or defence of legal claims, or another valid condition documented for the purpose.

We process data to perform the user or creator contract; comply with tax, accounting, DSA, safety, payment and legal duties; pursue legitimate interests in security, fraud prevention, moderation, service improvement and legal claims where those interests are not overridden; and use consent for optional cookies, marketing, particular sensitive-data uses or features where required. Consent may be withdrawn prospectively.

Age and identity assurance

The method depends on country and risk. Social login is not automatically proof of age. We prefer a minimised result such as “adult verified”, provider reference and expiry rather than an ID image or biometric template. Creators and depicted persons receive stronger identity and age verification than declaration-only fan access.

Sharing

We share only necessary data with hosting/CDN/media, identity and age-assurance, moderation and child-safety, payment and payout, fraud/security, communications, analytics-consented, professional-adviser and tax/reporting providers. Payment providers such as Segpay, CCBill and Paxum may act under their own privacy notices. We may disclose data to competent authorities, courts, trusted bodies or affected rights holders where lawfully required. The current production Subprocessor List is published at /legal/subprocessors; a provider marked unapproved may not receive production data.

International transfers

Where data leaves the EEA, we use an adequacy decision, approved contractual safeguards or another lawful mechanism and assess supplementary protection. Service availability in a country does not itself authorise a data transfer.

Retention

Account data is retained while the account is active and then for the applicable limitation period. Transaction, tax and accounting records are retained for legally required periods. Creator, age, consent and compliance records are retained for provider, safety, legal-claim and recordkeeping periods. Content is deleted or de-identified after account/content deletion subject to paid-access wind-down, backup cycles, disputes and legal holds. The category-level periods and disposal rules are published in the Data Retention Schedule at /legal/retention.

Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection and may withdraw consent. You may request human review of a significant solely automated decision where the right applies. Submit requests to privacy@redpatrons.de. We verify identity proportionately, respond within legal deadlines and explain any refusal.

You may complain to the Romanian data-protection authority or the authority in your habitual residence, workplace or place of alleged infringement. Mandatory remedies remain available.

Security and incidents

We use encryption, access control, MFA, audit logging, private media storage, signed URLs, monitoring, backups and incident procedures. No method is completely secure. Where required, we notify the authority within 72 hours after becoming aware of a reportable breach and notify affected persons without undue delay when risk is high.

Minors

RedPatron is not offered to persons under 18. Suspected underage accounts or depictions are immediately restricted and handled through the safety process.

Changes

Material changes receive notice and renewed consent where legally required. Archived versions remain available through the Legal Center.