Contents
- 1. INTRODUCTION & SCOPE
- 2. INFORMATION WE COLLECT
- 3. HOW WE USE YOUR INFORMATION
- 4. LEGAL BASIS FOR PROCESSING (GDPR)
- 5. HOW WE SHARE YOUR INFORMATION
- 6. DATA SECURITY
- 7. COOKIES & TRACKING TECHNOLOGIES
- 8. YOUR PRIVACY RIGHTS
- 9. INTERNATIONAL DATA TRANSFERS
- 10. DATA RETENTION
- 11. CHILDREN'S PRIVACY
- 12. THIRD-PARTY LINKS & SERVICES
- 13. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
- 14. CONTACT US
Your Privacy Matters
This Privacy Policy explains how SirenCY collects, uses, shares, and protects your personal information. We are committed to transparency and compliance with global privacy regulations including GDPR, CCPA, and the Australian Privacy Act.
1. INTRODUCTION & SCOPE
1.1 About This Policy
This Privacy Policy ("Policy") describes how QOSMIC CO PTY LTD (ABN 28 667 365 479), registered business name X SIREN MEDIA, operating the SirenCY brand (collectively, "SirenCY," "Company," "we," "us," "our") collects, uses, discloses, stores, protects, and processes personal information when you use our website at sirency.com, our dashboard platform, mobile applications, APIs, and all related services (collectively, the "Services").
1.2 Acceptance
BY ACCESSING OR USING OUR SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THE PRACTICES DESCRIBED IN THIS PRIVACY POLICY. If you do not agree to this Policy, you must not use our Services.
1.3 Scope
This Policy applies to:
- All users of our website and Services
- Creators, models, and staff members
- Applicants and prospective users
- Visitors to our website
- Individuals who communicate with us
1.4 Changes to This Policy
We may update this Policy from time to time. Changes are effective immediately upon posting. Your continued use constitutes acceptance of the updated Policy. We encourage you to review this Policy periodically.
2. INFORMATION WE COLLECT
2.1 Information You Provide Directly
Account & Profile Information:
- Full legal name, display name, username
- Email address, phone number
- Date of birth (for age verification)
- Profile photos, avatar images
- Government-issued identification documents
- Social media handles and profiles
- Biographical information
Application Information (Creators/Staff):
- Portfolio content (images, videos, samples)
- Previous work experience
- Platform account credentials (with your authorization)
- Performance history and metrics
- References and testimonials
Financial Information:
- Bank account details for payments
- PayPal, Payoneer, or other payment accounts
- Tax identification numbers
- Billing addresses
- Transaction history
Content Data:
- Photos, videos, audio files you upload
- Captions, descriptions, metadata
- Messages and communications through our platform
- Content strategies and plans
- Performance analytics and reports
Communication Data:
- Emails, messages, and correspondence
- Support tickets and inquiries
- Feedback and survey responses
- Phone call recordings (with notice)
2.2 Information Collected Automatically
Device & Technical Information:
- IP address and approximate geolocation
- Device type, model, and manufacturer
- Operating system and version
- Browser type and version
- Unique device identifiers
- Screen resolution and display settings
- Language and timezone preferences
Usage Information:
- Pages viewed and features used
- Time spent on pages and interactions
- Click patterns and navigation paths
- Search queries within our platform
- Login times, session duration, frequency
- Error logs and performance data
- Referring websites and exit pages
2.3 Information from Third Parties
- Platform APIs: Data from OnlyFans, social media, and connected services (with your authorization)
- Payment Processors: Transaction verification and payment status
- Identity Verification: Age and identity verification results from third-party services
- Analytics Providers: Aggregated usage data and insights
- Public Sources: Publicly available information
- Business Partners: Information shared through partnerships
2.4 Sensitive Information
We may collect sensitive information including:
- Government ID for identity verification
- Biometric data for verification (with consent)
- Adult content (for creators in our management program)
We handle sensitive information with enhanced security measures.
3. HOW WE USE YOUR INFORMATION
3.1 To Provide and Operate Our Services
- Create and manage your account
- Process applications and onboarding
- Manage creator accounts on third-party platforms
- Provide customer support
- Process transactions and payments
- Deliver content and features you request
3.2 To Improve and Develop Our Services
- Analyze usage patterns and trends
- Develop new features and services
- Conduct research and analytics
- Test and optimize performance
- Personalize your experience
- Train machine learning models
3.3 For Business Operations
- Generate invoices and financial reports
- Track performance metrics
- Train staff and develop best practices
- Create case studies and marketing materials (anonymized or with consent)
- Maintain business records
3.4 For Communication
- Send service-related notifications
- Provide performance reports and analytics
- Send marketing communications (with consent)
- Respond to inquiries and requests
- Notify you of changes to our Services or Terms
3.5 For Legal and Security Purposes
- Verify identity and prevent fraud
- Enforce our Terms of Service
- Comply with legal obligations
- Respond to legal requests
- Protect our rights and property
- Ensure the safety and security of our users
3.6 Training and Sample Content
We may use content, strategies, and anonymized data for:
- Training our staff and new team members
- Developing educational materials and best practices
- Creating reference examples for operational use
- Demonstrating service capabilities to potential clients
- Internal quality assurance and process improvement
4. LEGAL BASIS FOR PROCESSING (GDPR)
For users in the EEA, UK, and other jurisdictions requiring a legal basis, we process personal data under:
4.1 Contract Performance
Processing necessary to provide Services you've requested, manage your account, and fulfill our contractual obligations.
4.2 Consent
Where you've given explicit consent, such as for marketing communications, certain data sharing, or optional features. You may withdraw consent at any time.
4.3 Legitimate Interests
Processing necessary for our legitimate business interests, including:
- Fraud prevention and security
- Service improvement and analytics
- Direct marketing to existing customers
- Business administration and operations
- Legal claims and disputes
4.4 Legal Obligation
Processing necessary to comply with laws, regulations, court orders, or legal processes.
4.5 Vital Interests
Processing necessary to protect someone's life or safety in emergency situations.
6. DATA SECURITY
6.1 Security Measures
We implement industry-standard security measures to protect your data:
- Encryption: TLS/SSL for data in transit; AES-256 for data at rest
- Access Controls: Role-based access with multi-factor authentication
- Monitoring: Continuous security monitoring and intrusion detection
- Auditing: Regular security assessments and penetration testing
- Training: Security awareness training for all staff
- Incident Response: Documented breach response procedures
6.2 Data Breach Response
In the event of a data breach affecting your personal information, we will:
- Notify affected users within 72 hours of discovery (GDPR requirement)
- Notify relevant supervisory authorities as required
- Take immediate steps to contain and mitigate the breach
- Investigate the incident and implement preventive measures
- Provide information about steps you can take to protect yourself
6.3 Your Security Responsibilities
You are responsible for:
- Maintaining the confidentiality of your login credentials
- Using strong, unique passwords
- Enabling two-factor authentication when available
- Notifying us immediately of any unauthorized access
- Keeping your contact information up to date
6.4 No Absolute Security
While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security of your data. You transmit data at your own risk.
8. YOUR PRIVACY RIGHTS
Depending on your location, you may have the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your data ("right to be forgotten").
Request that we limit how we use your data.
Receive your data in a structured, machine-readable format.
Object to processing, including direct marketing.
Withdraw consent at any time where processing is based on consent.
Not be subject to solely automated decisions with significant effects.
8.1 How to Exercise Your Rights
To exercise any rights, contact us at:
- Email: anyro@sirency.com or sirenxmedia@gmail.com
- Subject: "Privacy Rights Request"
We will respond within 30 days (or as required by law). We may need to verify your identity.
8.2 Right to Complain
You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
8.3 Limitations
Some requests may be subject to limitations:
- We may retain certain data for legal compliance
- Deletion requests don't affect data already distributed or used per our Terms
- We may require verification of identity
- Excessive or unfounded requests may be refused or charged
9. INTERNATIONAL DATA TRANSFERS
9.1 Where We Process Data
Your data may be processed in:
- Australia (our primary location)
- United States (cloud services: Vercel, Supabase)
- European Union (for EU data subjects where applicable)
- Other locations where our service providers operate
9.2 Transfer Safeguards
When transferring data internationally, we implement appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all service providers
- Adequacy decisions where applicable
- Binding Corporate Rules where relevant
- Your explicit consent for specific transfers
9.3 Australia-Specific
We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Cross-border disclosures are made in accordance with APP 8.
10. DATA RETENTION
10.1 Retention Periods
We retain personal data only as long as necessary:
| Data Type | Retention Period |
|---|---|
| Account Information | Duration of account + 3 years |
| Application Data (rejected) | 12 months from decision |
| Financial/Tax Records | 7 years (legal requirement) |
| Communication Records | 3 years from last interaction |
| Content Data | Duration of agreement + 1 year |
| Analytics Data | 26 months (Google Analytics default) |
| Training/Sample Materials | Indefinitely (anonymized) |
| Legal Hold Data | Duration of legal matter + resolution |
10.2 Deletion Process
When data is no longer needed, we:
- Securely delete or destroy the data
- Anonymize data where full deletion isn't feasible
- Remove data from active systems and backups
10.3 Exceptions
We may retain data longer if:
- Required by law or regulation
- Necessary for legal claims or disputes
- Required for legitimate business purposes
- You've consented to extended retention
11. CHILDREN'S PRIVACY
Our Services are strictly for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18.
11.1 No Collection from Minors
We do not knowingly collect, use, or disclose personal information from individuals under 18 years of age. Our Services are not directed at minors.
11.2 Discovery of Minor's Data
If we discover that we have collected personal information from someone under 18:
- We will immediately delete such information
- We will terminate the associated account
- We may report to relevant authorities if required
11.3 Reporting
If you believe we have collected information from a minor, please contact us immediately at sirenxmedia@gmail.com.
12. THIRD-PARTY LINKS & SERVICES
12.1 Third-Party Websites
Our Services may contain links to third-party websites, applications, and services. This Privacy Policy does not apply to those third parties. We encourage you to read their privacy policies before providing any information.
12.2 Social Media Features
Our Services may include social media features and widgets. These features may collect information about your interactions and are governed by the privacy policies of those companies.
12.3 Third-Party Integrations
When you connect third-party accounts (OnlyFans, social media, etc.), those services have their own privacy practices that apply.
12.4 No Endorsement
Links to third-party services do not imply endorsement. We are not responsible for their content, privacy practices, or security.
13. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
13.1 Your California Rights
- Right to Know: Request information about data collected, used, shared, or sold
- Right to Delete: Request deletion of personal information
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out of Sale/Sharing: We do not sell personal information
- Right to Limit Sensitive Data Use: Limit use of sensitive personal information
- Right to Non-Discrimination: We won't discriminate for exercising rights
13.2 Categories of Information Collected
In the past 12 months, we have collected:
- Identifiers (name, email, IP address, device IDs)
- Personal information (financial data, phone number)
- Commercial information (transaction history)
- Internet/network activity (usage data, browsing)
- Geolocation data
- Professional information
- Inferences from the above
13.3 Shine the Light
California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not share personal information for such purposes.
13.4 Do Not Track
California Business & Professions Code Section 22575 requires disclosure regarding Do Not Track signals. Our Services do not currently respond to DNT signals.
13.5 How to Exercise Rights
California residents may submit requests via:
- Email: anyro@sirency.com or sirenxmedia@gmail.com
- Subject: "California Privacy Request"
We will verify your identity and respond within 45 days.
14. CONTACT US
Contact Information
For questions, concerns, or requests regarding this Privacy Policy:
QOSMIC CO PTY LTD - Privacy
Registered business name: X SIREN MEDIA
ABN: 28 667 365 479
Email: sirenxmedia@gmail.com
Privacy Inquiries: anyro@sirency.com
Website: www.sirency.com
Correspondence address: 470 St Kilda Rd, Melbourne VIC 3004, Australia
Data Protection Officer
For GDPR-related inquiries, contact our DPO at: anyro@sirency.com
Response Time
We aim to respond to all privacy inquiries within 30 days.
By using SirenCY's Services, you acknowledge that you have read, understood, and agree to this Privacy Policy.
© 2026 QOSMIC CO PTY LTD. All Rights Reserved.