PRIVACY POLICY
NEWCAM18.COM
This Privacy Policy explains how Netpan Ltd collects, uses, stores, shares and protects personal data in connection with NEWCAM18.COM, including data relating to registered users, website visitors, performers/content providers and persons depicted in content.
Last updated: September 2026
1. Data Controller and Contact Details
NEWCAM18.COM is operated by Netpan Ltd, which acts as the data controller for personal data processed for the purposes described in this Policy.
Company: Netpan Ltd
Registration number: 202777590
Registered address: Bulgaria, Sofia, str. Dospat 40, 1000
Privacy and data protection contact: [email protected]
2. Scope and Data Protection Framework
This Policy is intended to comply with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), the Bulgarian Personal Data Protection Act, applicable ePrivacy rules and other data protection laws that apply to our processing activities.
Where another law or binding payment-network, acquiring-bank, age-verification, recordkeeping or content-safety requirement requires us to collect, verify or retain information, we process only the information reasonably necessary for that purpose and subject it to appropriate safeguards.
3. Categories of Personal Data We Process
Depending on how you use the website and whether you are a visitor, registered user, performer/content provider or person depicted in content, we may process:
- Account and profile data: username, email address, account identifiers, account status and settings.
- Transaction and billing data: purchase amounts, transaction references, billing status, refunds, disputes and chargeback-related information. Full payment-card details are generally processed by our payment service providers rather than stored by us.
- Identity and age-verification data: legal name, date of birth, government-issued identification details or copies, verification results, and related evidence where required for performers/content providers or other persons who must be verified.
- Consent and content-compliance records: records showing consent to be depicted, consent to distribution/upload, any applicable consent to downloading, dates and versions of consent records, content identifiers, compliance reviews and takedown/appeal records.
- Content and live-service data: information necessary to operate, moderate and investigate live interactions and content, including content identifiers and moderation records.
- Technical and security data: IP address, browser and device information, timestamps, session identifiers, login/security events, fraud indicators and server/security logs.
- Communications and support data: messages, complaints, reports, privacy requests and correspondence with customer support or compliance teams.
- Cookie and similar-technology data: cookie identifiers and related preference, security, analytics or tracking data as described in Section 9.
We do not intentionally collect personal data from children. The website is intended exclusively for persons who are at least 18 years old.
4. Purposes of Processing and Legal Bases
We use personal data only where a lawful basis applies. Depending on the specific processing activity, the legal basis may be performance of a contract, compliance with a legal obligation, our legitimate interests, or consent.
| Purpose | Typical data | GDPR legal basis |
| Create and administer accounts; provide purchased or requested services | Account, profile, transaction and service data | Article 6(1)(b) — performance of a contract or steps requested before entering into a contract |
| Process payments, refunds and billing | Transaction and billing data | Article 6(1)(b) — contract; Article 6(1)(c) — legal obligations where applicable |
| Prevent fraud, account abuse, credential sharing, payment misuse and security incidents | Account, transaction, technical, device and security data | Article 6(1)(f) — legitimate interests in protecting users, the service and payment ecosystem; Article 6(1)(c) where a legal obligation applies |
| Verify identity and age of performers/content providers and other persons where verification is required | Identity documents, date of birth, verification results | Article 6(1)(c) where required by law; Article 6(1)(f) for compliance, safety, fraud prevention and card-network/acquirer requirements; Article 6(1)(b) where necessary to administer the performer/content-provider relationship |
| Maintain performer/content consent and compliance records | Consent forms, identity linkage, content identifiers, review records | Article 6(1)(c) where recordkeeping is legally required; Article 6(1)(f) for compliance, safety, evidence of consent and defence of legal claims; Article 6(1)(b) where relevant to a contractual relationship |
| Moderate content; investigate complaints, takedown requests and suspected illegal activity | Content identifiers, reports, communications, account and technical data | Article 6(1)(c) where required by law; Article 6(1)(f) — legitimate interests in safety, legal compliance and enforcement of platform rules |
| Respond to support and privacy requests | Contact, account, request and verification data | Article 6(1)(b), Article 6(1)(c) and/or Article 6(1)(f), depending on the request |
| Maintain accounting, tax, audit and legal records | Transaction, invoice, accounting and correspondence data | Article 6(1)(c) — legal obligation; Article 6(1)(f) — establishment, exercise or defence of legal claims where applicable |
| Use non-essential analytics or advertising/tracking technologies | Cookie/device identifiers and related usage data | Article 6(1)(a) — consent, where consent is required |
Where processing involves special categories of personal data under Article 9 GDPR, including biometric data used for the purpose of uniquely identifying a person or data revealing information about a person’s sex life, we process such data only where an applicable Article 9 condition is available. Where we rely on explicit consent, that consent is requested separately and may be withdrawn for future processing, without affecting processing already carried out lawfully.
Consent to appear in, distribute or otherwise use adult content is a content/performer consent record and is not automatically the same thing as GDPR consent for every related processing activity. We identify the appropriate data-protection legal basis separately.
5. Identity, Age, KYC and Consent Verification Records
For performers/content providers and other persons whose age, identity or consent must be verified, we may collect and retain verification records sufficient to demonstrate that:
- the person’s identity and age were verified using appropriate documentation or an approved verification process;
- the person was at least 18 years old when required by the applicable rules;
- the required written consent was obtained for depiction and for the applicable forms of distribution or use of the content;
- verification and consent records can be linked to the relevant performer/content provider and content or service activity; and
- records can be produced to authorized acquirers, payment networks, auditors, regulators or law-enforcement authorities where we are legally or contractually required to do so.
KYC, identification and consent records are kept in access-restricted systems and/or approved verification-provider environments. Access is limited to personnel and service providers who need the information for compliance, verification, security, dispute handling or legal purposes. We use safeguards designed to protect these records, including encrypted transmission, access controls, authentication, logging, confidentiality obligations and secure storage practices appropriate to the nature of the data.
If we use a third-party identity or age-verification provider, that provider may process verification data on our behalf or, in some circumstances, as an independent controller. Where required, additional information about that provider and its role will be made available at the point of verification.
6. Payments, Fraud Prevention and Billing Disputes
Payments are handled through payment service providers and acquiring/payment partners. We may receive transaction identifiers, payment status, masked payment details, fraud/risk indicators and information necessary to process refunds, respond to billing disputes or chargebacks, and comply with payment-network requirements.
Payment and anti-fraud providers may apply automated risk-analysis tools. Where a decision based solely on automated processing produces legal effects or similarly significant effects and Article 22 GDPR applies, affected individuals may have rights to obtain human intervention, express their point of view and contest the decision, subject to applicable exceptions.
7. Sharing of Personal Data
We do not sell or rent personal data. We may disclose personal data only where necessary and lawful, including to:
- payment processors, acquirers, banks and card networks;
- identity, age-verification and KYC service providers;
- hosting, infrastructure, security, anti-fraud, analytics, communications and customer-support providers;
- professional advisers, auditors and insurers where necessary;
- competent courts, regulators, supervisory authorities and law-enforcement bodies where required or permitted by law; and
- another entity in connection with a merger, acquisition, restructuring or transfer of business, subject to applicable data-protection requirements.
Processors acting on our behalf are required to process personal data only under appropriate instructions and contractual safeguards, including confidentiality and security obligations.
8. International Transfers Outside the EU/EEA
Some service providers or recipients may be located outside the European Union or European Economic Area, or may access personal data from countries outside the EU/EEA.
Where personal data is transferred to a country that has not been recognized by the European Commission as providing an adequate level of protection, we use an appropriate transfer mechanism where required, such as the European Commission’s Standard Contractual Clauses (“SCCs”), together with supplementary technical or organizational safeguards where appropriate. Where an adequacy decision applies, we may rely on that decision.
You may contact us at [email protected] to request information about the safeguards applicable to relevant international transfers, subject to lawful confidentiality restrictions.
9. Cookies and Similar Technologies
We may use cookies, local storage, pixels and similar technologies. These technologies may fall into the following categories:
- Strictly necessary cookies: required for core website functions such as authentication, security, fraud prevention, load balancing, session management and saving privacy/cookie choices.
- Preference/functionality cookies: remember user choices and improve requested functionality.
- Analytics cookies: help us understand website usage and performance.
- Advertising or other tracking technologies: used only where applicable and where the required consent has been obtained.
Strictly necessary cookies may be used without consent where permitted by applicable law. Non-essential cookies and tracking technologies that require consent are not activated until the user has made the required choice. Refusing non-essential cookies does not prevent use of the core service.
Where consent is the legal basis, users may withdraw or change that consent at any time through the website’s cookie/privacy settings. Withdrawal must be as easy as giving consent. Browser controls may also be used, although blocking strictly necessary cookies may affect website functionality.
Where third-party analytics or tracking tools are used, their identity, purpose, cookie duration and transfer information should be shown in the cookie settings or cookie notice available on the website.
10. Data Security
We apply technical and organizational measures designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, alteration or disclosure. Depending on the system and risk, these measures include HTTPS/TLS encryption in transit, access controls, least-privilege permissions, authentication, logging and monitoring, restricted administrative access, backup and recovery controls, secure development and patching practices, and contractual confidentiality obligations.
Payment-card information is handled through payment providers subject to applicable payment-security requirements. No system is completely secure, and we cannot guarantee absolute security.
11. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the service, satisfy legal and regulatory obligations, meet card-network/acquirer requirements, resolve disputes, enforce agreements and establish, exercise or defend legal claims.
- Account data: generally for the life of the account and for a limited period after closure where necessary for fraud prevention, disputes, legal claims or compliance.
- Accounting and transaction records: retained for the period required by applicable Bulgarian tax and accounting law. Certain accounting records and financial statements may be required to be kept for 10 years.
- KYC, identity, age-verification and performer/content consent records: retained for as long as the related content or performer/content-provider relationship remains relevant and thereafter for the period required by applicable law, recordkeeping obligations, payment-network/acquirer requirements and limitation periods for legal claims.
- Complaints, takedown, moderation and compliance records: retained for the period necessary to document the investigation, action taken, legal/compliance reporting and potential disputes.
- Security and fraud logs: retained for a limited period based on security, fraud-prevention and incident-response needs unless a longer period is required for an investigation or legal obligation.
- Cookie consent records: retained for the period necessary to demonstrate the user’s choice and then refreshed or deleted in accordance with the applicable consent-management settings.
When personal data is no longer required, we delete it, anonymize it, or securely restrict/archive it where continued storage is required by law.
12. Your GDPR Rights and How to Exercise Them
Where the GDPR applies, you may have the right to:
- request access to your personal data and a copy of it;
- request correction of inaccurate or incomplete personal data;
- request erasure of personal data where the legal conditions are met;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain personal data in a structured, commonly used and machine-readable format and request portability where applicable;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal; and
- exercise rights relating to certain solely automated decisions where Article 22 GDPR applies.
To exercise a privacy right, email [email protected] with enough information to identify the account or processing activity and the right you wish to exercise. We may request reasonable additional information to verify identity and protect personal data from unauthorized disclosure.
We normally respond without undue delay and within one month of receiving a valid request. Where permitted by GDPR, that period may be extended by up to two additional months for complex or numerous requests, in which case we will inform you of the extension and the reasons for it.
Rights are not absolute. We may refuse or limit a request where permitted by law, including where retention is required by a legal obligation or where data is necessary for the establishment, exercise or defence of legal claims. If we do so, we will explain the applicable reason where required.
13. Complaints and Escalation
If you have a privacy concern, please contact us first at [email protected] so that we can investigate and respond.
You also have the right to lodge a complaint with a competent data-protection supervisory authority. In Bulgaria, the supervisory authority is the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria. You may also complain to the supervisory authority in the EU/EEA Member State of your habitual residence, place of work or place of the alleged infringement, where applicable.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in law, regulation, payment-network requirements, technology or our services. The revised version will be posted on this page with a new “Last updated” date. Where legally required, we will provide additional notice or obtain renewed consent.