Privacy Policy
Last updated: 2026-08-02 · ASM Media Group LLC
1. Introduction, Scope, and Effective Date
This Privacy Policy ("Policy") explains how ASM Media Group LLC ("ASM Media Group", "LetShoot", "we", "us", or "our"), operator of the website letshoot.ai and the associated creator portal (together, the "Platform"), collects, uses, discloses, retains, secures, and destroys personal data. This Policy is effective as of «[TO BE SET: effective date]» and was last updated on «[TO BE SET: last-updated date]».
LetShoot is a strictly adult-only (18+) service. Through the Platform, age- and identity-verified adult content creators upload photographs of themselves so that the Platform can train a per-creator artificial-intelligence likeness model — a "digital clone" — of that same consenting creator, and can then generate new adult and sexually explicit still images and videos depicting only that creator's own verified likeness. Creators may distribute or sell that generated content on third-party adult platforms. We clone only your own verified likeness, only with your explicit consent, and never the likeness of any other person.
Because the service necessarily processes intimate, sexual, and biometric information about identified individuals, we treat privacy and data protection as core safety functions rather than mere legal formalities. This Policy describes the specific safeguards we apply to biometric identifiers, sexually explicit content, government-issued identification, and payment information.
This Policy applies to all visitors to letshoot.ai, to registered creators, and to agency, staff, and administrative users of the portal, wherever located, including in the United States, the European Economic Area ("EEA"), the United Kingdom, and Latin America. Where the law of your jurisdiction grants you additional or specific rights, the applicable country- or state-specific sections of this Policy govern with respect to your data.
This Policy does not govern how third-party adult platforms, payment card networks, banks, or other independent services handle your personal data once you interact with them directly; those parties act under their own privacy notices, and we encourage you to read them.
This Policy is a legally binding statement about our data practices. It is not legal advice to you, and it does not replace any separate Terms of Service, Consent and Biometric Release, or 18 U.S.C. § 2257 records that also apply to your use of the Platform.
2. Who We Are — Controller, Data Protection Officer, and EU/UK Representatives
The data controller (and, under U.S. law, the "business" and the responsible party) is ASM Media Group LLC, a limited liability company operating LetShoot. Our registered mailing address is «[TO BE SET: ASM Media Group LLC full US street address]». General privacy inquiries may be sent to soporte@letshoot.ai.
For content that is sexually explicit, ASM Media Group LLC acts as the "producer" and maintains the records required under 18 U.S.C. §§ 2257 and 2257A. The Custodian of Records is «[TO BE SET: custodian of records name]», located at «[TO BE SET: custodian of records US street address]». These records are maintained separately and are subject to the retention rules in Section 8.
Our Data Protection Officer ("DPO"), who oversees compliance with the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and biometric-privacy laws, may be contacted at «[TO BE SET: DPO name]», «[TO BE SET: DPO email]», «[TO BE SET: DPO postal address]».
Our representative in the European Union for the purposes of Article 27 GDPR is «[TO BE SET: EU Article 27 representative name and full EEA address]». EEA data subjects may address this representative on all matters relating to the processing of their personal data.
Our representative in the United Kingdom for the purposes of Article 27 UK GDPR is «[TO BE SET: UK Article 27 representative name and full UK address]». UK data subjects may address this representative on all matters relating to the processing of their personal data.
Where we determine the purposes and means of processing your personal data, we are the controller. Where we process data strictly on documented instructions of a creator or agency (for example, an agency managing content on behalf of a creator who has consented), the allocation of controller/processor roles is set out in our Terms of Service and any applicable data processing agreement.
3. Key Definitions
"Personal data" (or "personal information") means any information relating to an identified or identifiable natural person, including online identifiers, images, and biometric data.
"Sensitive data" / "special-category data" means the categories that receive heightened protection under law, including biometric data used to uniquely identify a person, data concerning a person's sex life or sexual orientation, health data, and government-issued identification numbers, as well as "sensitive personal information" under U.S. state laws.
"Biometric identifier" and "biometric information" have the meanings given under the Illinois Biometric Information Privacy Act, 740 ILCS 14/ ("BIPA"), the Texas Capture or Use of Biometric Identifier Act, Tex. Bus. & Com. Code § 503.001 ("CUBI"), and the Washington biometric-privacy statute, RCW 19.375, and include a scan of face geometry and any mathematical representation (a "face template" or embedding) derived from your images.
"AI likeness model" (or "model" / "digital clone") means the per-creator machine-learning model (including its trained weights, such as a LoRA adapter or equivalent) that encodes the visual likeness of a single consenting creator so that new images and videos of that creator can be generated.
"Generated content" means still images or videos produced by the Platform using your AI likeness model. "Source content" means the photographs and videos you upload of yourself for verification and model training.
"Process" or "processing" means any operation performed on personal data, including collection, recording, storage, use, generation, disclosure, and erasure. "Controller", "processor", "sub-processor", "consent", "sell", and "share" carry the meanings given under the applicable data-protection law.
4. Personal Data We Collect
Identity and account data: your name, chosen username or stage name, email address, password (stored only as a salted hash), account role (creator, agency, staff, or administrator), and account preferences and settings.
Age- and identity-verification data (sensitive): your date of birth; images of a government-issued photo identification document (such as a passport or driver's license) and the identification number and document details it contains; a verification selfie or short video; and the results and audit records of the verification check. This data is collected because we are legally required to confirm that every depicted person is an adult and is the same person as the creator.
Biometric data (sensitive): a scan of your face geometry and the mathematical face template(s) derived from your source content, together with the trained AI likeness model that encodes your appearance. Section 5 describes this category in detail.
Content data (sensitive — sexual content): the source photographs and videos you upload of yourself, which may be nude or sexually explicit; the generated images and videos created from your model; associated prompts, tags, captions, and metadata; and content-moderation classifications and cryptographic hashes.
Payment and transaction data: subscription and purchase history, plan and pricing tier, billing status, and payment tokens or transaction identifiers. Full card numbers are entered directly with our payment processors (CCBill and/or Epoch) and are not stored by us; we retain only tokens, the last four digits, card brand, and transaction records needed for billing, refunds, chargebacks, and anti-fraud and anti-money-laundering ("AML") compliance.
Technical, usage, and communications data: IP address, device and browser characteristics, approximate location derived from IP or timezone (used to offer the site in your language), pages viewed and actions taken, security and audit logs, cookie and similar-technology identifiers, and the content of support tickets and messages you send to us.
We collect this data directly from you when you register, verify your age and identity, upload content, request generations, make payments, and contact support; automatically through your use of the Platform; and, in limited cases, from our identity-verification, payment, and fraud-prevention providers acting on our behalf.
5. Biometric Data and the AI Likeness Model
To create your digital clone, we extract a scan of your facial geometry from the photographs you upload of yourself and derive one or more mathematical face templates (embeddings). Those templates are used to train and refine your per-creator AI likeness model, and both the templates and the trained model weights are biometric identifiers and biometric information under BIPA, CUBI, and RCW 19.375, and special-category data under Article 9 GDPR.
Purpose limitation. We collect, use, and store your biometric data for one purpose only: to build, maintain, and operate your own AI likeness model so that you can generate adult content of yourself. We do not use your biometric data for identity surveillance, watchlists, demographic analysis, advertising, or any purpose unrelated to producing your requested content.
No facial recognition against others. We do not use your face template to identify or match you against any external database, any other user, or any person in the wild. Face-geometry processing is used solely to confirm that your verification selfie matches your ID (age/identity assurance) and to train your own model — never to recognize third parties.
No shared or foundation-model training. Your source content, face templates, and model weights are never used to train, fine-tune, or improve any shared, multi-tenant, general-purpose, or third-party foundation model. Each creator's model is trained only on that creator's own consenting data and is logically isolated to that creator's account.
No sale and no profit from biometrics. Consistent with BIPA § 15(c), we do not sell, lease, trade, or otherwise profit from your biometric identifiers or biometric information. Biometric data is disclosed only to the narrow set of processors that provide storage and generation compute strictly on our behalf and under contract (see Section 9), and never for their own purposes.
Written policy, consent, and destruction. In accordance with BIPA § 15(a), we maintain a publicly available written policy establishing a retention schedule and destruction guidelines for biometric data (see Section 8). We obtain your separate, informed, written consent (a "biometric release") before collecting or generating any biometric identifier, as described in Section 7.
Model portability and deletion. Because your model weights encode your biometric likeness, they are subject to the same access, deletion, and destruction rights as your other biometric data. When your biometric data must be destroyed, the associated model weights are destroyed with it, and no further generations are possible thereafter.
6. Purposes of Processing and Legal Bases
The table below states, for each purpose, the main data categories involved, the GDPR/UK GDPR legal basis, and the corresponding basis under U.S. law. Where we rely on a legal obligation or on our legitimate interests, we have carried out the required balancing and can provide further detail on request.
Account creation, authentication, and service delivery — Identity and account data. GDPR: Art. 6(1)(b) performance of a contract. U.S.: providing the service you requested.
Age and identity verification — Government ID, selfie/video, date of birth. GDPR: Art. 6(1)(c) legal obligation (18 U.S.C. §§ 2257/2257A and adult-content laws), Art. 6(1)(f) fraud prevention, and Art. 9(2)(a) explicit consent for any special-category data involved. U.S.: legal compliance and fraud prevention.
Biometric processing and AI likeness model training — Face geometry, face templates, model weights. GDPR: Art. 9(2)(a) explicit consent, supported by Art. 6(1)(b). U.S.: BIPA/CUBI/RCW 19.375 written consent/release.
Generating adult content of your own likeness — Source content, model, prompts, generated content. GDPR: Art. 6(1)(b) contract and Art. 9(2)(a) explicit consent for data concerning your sex life. U.S.: providing the requested service with your consent.
Content moderation, CSAM/NCII prevention, and provenance labeling — Uploaded and generated content, hashes, moderation logs. GDPR: Art. 6(1)(c) legal obligation, Art. 6(1)(f) legitimate interest in platform safety, and Art. 9(2)(g) substantial public interest. U.S.: legal compliance and safety.
Payments, billing, refunds, chargebacks, and AML — Payment tokens, transaction data, verification data. GDPR: Art. 6(1)(b) contract and Art. 6(1)(c) legal obligation (AML/tax). U.S.: legal compliance and completing transactions.
Customer support and dispute handling — Contact data, account data, relevant content. GDPR: Art. 6(1)(b) contract and Art. 6(1)(f) legitimate interest. U.S.: servicing your account.
Security, logging, and abuse prevention — Device, IP, usage, and audit logs. GDPR: Art. 6(1)(f) legitimate interest in securing the Platform. U.S.: security and integrity.
Legal compliance and records retention — 2257 records, tax and AML records, legal-hold data. GDPR: Art. 6(1)(c) legal obligation. U.S.: legal compliance.
Service and transactional communications — Email address, account events. GDPR: Art. 6(1)(b) contract. U.S.: servicing your account.
Optional marketing communications — Email address, preferences. GDPR: Art. 6(1)(a) consent. U.S.: opt-in, with an unsubscribe link in every message.
Limited product improvement and troubleshooting — Aggregated, de-identified, or strictly necessary operational data only. GDPR: Art. 6(1)(f) legitimate interest, with the strict exclusion that biometric data, model weights, and sexual source/generated content are never used to train shared or foundation models. U.S.: internal operations consistent with this Policy.
7. Consent, Its Separation, and Withdrawal
We obtain your consent through separate, unbundled, affirmative opt-ins rather than a single blanket agreement. At minimum, you provide distinct consents for: (a) biometric collection and creation of your AI likeness model (the biometric release); (b) the generation of adult and sexually explicit content depicting your own likeness; and, separately, (c) any publication, distribution, or export of specific generated content, and (d) optional marketing communications. Consenting to one does not imply consent to the others.
Create-versus-publish consent. Consent to create generated content is distinct from consent to publish or distribute it. You control whether any particular piece of generated content leaves the Platform, and you may withhold or revoke distribution consent for specific content without affecting your ability to keep generating privately.
Explicit and informed. Before any biometric or sexual-content processing, we present clear information about what data is collected, why, how long it is kept, and who receives it, and we record the fact, scope, and timestamp of your consent.
Withdrawal. You may withdraw any consent at any time through your account settings or by writing to soporte@letshoot.ai. Withdrawal is as easy as giving consent, takes effect prospectively, and does not affect the lawfulness of processing carried out before withdrawal.
Consequences of withdrawal or deletion. Because the service is defined by generating content from your own biometric model, withdrawing biometric consent or requesting deletion means we can no longer train or run your model and can no longer generate new content of you; the model weights will be scheduled for destruction as described in Section 8. Certain records that we are legally required to keep (for example, § 2257 identity records, and payment/AML/tax records) will be retained for the periods stated in Section 8 even after you withdraw consent, and may not be deleted before those periods expire.
Where processing is necessary for a legal obligation (such as age verification, § 2257 record-keeping, CSAM detection and reporting, or AML), we do not rely on consent for that specific processing, and it will continue as required by law regardless of the status of your other consents.
8. Data Retention and Destruction Schedule
We keep personal data only as long as necessary for the purpose for which it was collected, and then delete or de-identify it, except where a longer period is required by law. This section is also our written biometric retention-and-destruction schedule for the purposes of BIPA § 15(a).
Biometric data (face geometry, face templates, and AI likeness model weights): destroyed when the initial purpose for collection has been satisfied, or within three (3) years of your last interaction with the Platform, whichever occurs first, and in any event promptly after you withdraw biometric consent or successfully request deletion. The associated model weights are destroyed together with the underlying biometric data.
Source and generated sexual content: retained while your account is active and you continue to use the model, and deleted following account closure or a deletion request, subject to the legal carve-outs below. You may delete individual pieces of content at any time.
Account, profile, and communications data: retained for the life of your account and for a limited period afterward to handle disputes and finalize closure, then deleted or de-identified.
Legal carve-outs (retained even after deletion of other data). Records required under 18 U.S.C. §§ 2257/2257A (identity and age-verification records for depicted performers) are retained for at least seven (7) years, or as otherwise required by that law and its regulations. Where we file a CyberTipline report, the report and its contents are preserved for at least ninety (90) days under 18 U.S.C. § 2258A and, at NCMEC's or law enforcement's request, for as long as required, and related evidence is retained for at least one (1) year consistent with our legal obligations. Payment, billing, AML, and tax records are retained for the periods required by financial-services and tax law (generally five to seven years). Data subject to a legal hold or an active investigation is retained until the hold is lifted.
Backups. Deletions are propagated to routine backups on our normal backup-rotation cycle; encrypted backups are overwritten within «[TO BE SET: backup retention/rotation period, e.g., 30–90 days]», after which residual copies are permanently unrecoverable. During that window, restored data is re-deleted on the next cycle and is not returned to production use.
Method of destruction. Biometric data and model weights are destroyed by secure, irreversible deletion (including cryptographic erasure of encryption keys where applicable). We do not retain de-identified copies of biometric identifiers, and we do not re-derive templates from deleted source content.
9. Recipients and Sub-Processors
We do not sell your personal data. We disclose personal data only to the service providers and sub-processors that help us operate the Platform, each bound by contract to process data solely on our documented instructions, to implement appropriate security, and not to use your data for their own purposes or to reuse, resell, or combine it with other data.
Supabase — database, authentication, and file storage for account data, verification data, content metadata, and (in encrypted form) content, hosted in the United States.
Vercel — website and portal hosting, delivery, and edge/serverless compute, in the United States.
GPU and generative-AI compute provider — «[TO BE SET: name of GPU/generation provider]» — performs model training and image/video generation on our behalf; receives source content, face templates, and model weights strictly to run your model, under contractual terms prohibiting any use to train shared or foundation models and prohibiting any independent use.
Identity- and age-verification provider — «[TO BE SET: name of ID/age-verification provider, if any]» — processes government ID and selfie data to confirm age and identity.
CCBill and/or Epoch — payment processing; they collect card details directly and act as independent controllers for their own payment, fraud, and card-network compliance purposes; we receive only tokens and transaction records.
Resend — transactional and, where you have opted in, marketing email delivery; receives your email address and message content.
Other recipients. We may disclose data to our professional advisers (lawyers, auditors) under confidentiality; to NCMEC, law enforcement, and card networks where legally required or to prevent serious harm (see Section 16); and to a successor entity in a merger, acquisition, or asset sale, subject to this Policy. A current list of sub-processors is available on request, and we will give notice of material changes so that EEA/UK data subjects may object where applicable.
10. International Data Transfers
We are based in, and our primary infrastructure (Supabase, Vercel) is located in, the United States. If you access the Platform from the EEA, the United Kingdom, Latin America, or elsewhere, your personal data will be transferred to and processed in the United States and potentially other countries where our sub-processors operate.
For transfers of EEA and UK personal data to the United States, we rely, as applicable, on the EU-U.S. Data Privacy Framework and its UK Extension (where the recipient is certified), and otherwise on the European Commission's Standard Contractual Clauses ("SCCs") and the UK International Data Transfer Addendum ("IDTA") or Addendum to the SCCs.
Where we rely on SCCs or the IDTA, we conduct a transfer impact assessment ("TIA") and apply supplementary measures — including encryption in transit and at rest, access controls, data minimization, and policies for handling government-access requests — to ensure an essentially equivalent level of protection.
You may request a copy of the relevant transfer safeguards by contacting our DPO at the details in Section 2. For transfers involving Latin American users, we apply comparable contractual and security safeguards consistent with applicable local data-protection laws.
11. Your Rights under GDPR and UK GDPR
If you are in the EEA or the United Kingdom, you have the following rights, subject to conditions and exemptions in law: the right to be informed; the right of access to your personal data; the right to rectification of inaccurate data; the right to erasure ("right to be forgotten"); the right to restrict processing; the right to data portability; the right to object to processing based on legitimate interests or to direct marketing; and rights in relation to automated decision-making.
Where processing is based on consent (including biometric and sexual-content processing), you have the right to withdraw that consent at any time, as described in Section 7, without affecting the lawfulness of prior processing.
Automated decision-making. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Automated tools are used for content moderation and fraud/abuse detection, but adverse actions (such as account suspension or content refusal) are subject to human review, and you may contest a decision and request human intervention by contacting us.
To exercise your rights, contact us at soporte@letshoot.ai or our DPO or Article 27 representatives (Section 2). We will verify your identity in a privacy-protective manner and respond within one (1) month, extendable by two further months for complex requests, and we will tell you if an exemption prevents us from fully complying.
You have the right to lodge a complaint with a supervisory authority. EEA residents may complain to the authority in their country of residence, place of work, or place of the alleged infringement; UK residents may complain to the Information Commissioner's Office (ICO). We would, however, appreciate the chance to address your concern first.
12. U.S. State Privacy Rights (CCPA/CPRA and Others)
If you are a resident of California or another U.S. state with a comprehensive privacy law, you have rights that may include: the right to know and access the personal information we have collected about you and the categories of sources, purposes, and recipients; the right to correct inaccurate personal information; the right to delete personal information, subject to legal exceptions; the right to data portability; and the right to be free from unlawful discrimination for exercising your rights.
Do Not Sell or Share. We do not sell your personal information and we do not share it for cross-context behavioral advertising. Because we do not engage in such sales or sharing, there is nothing to opt out of in that respect; if this ever changes, we will provide a "Do Not Sell or Share My Personal Information" mechanism before doing so.
Limit the Use of Sensitive Personal Information. We collect sensitive personal information (including government identifiers, biometric information, precise-adjacent location, and information about your sex life or sexual orientation) solely to provide the service you requested, to verify age and identity, to comply with law, and to ensure safety and security — all of which are permitted uses that do not trigger the right to limit. We do not use or disclose sensitive personal information to infer characteristics about you or for any purpose beyond those permitted uses.
Global Privacy Control (GPC). We honor recognized opt-out preference signals, including the Global Privacy Control, as a valid request to opt out of any sale or sharing to the extent applicable to your browser or device.
Sensitive nature of our data. Given that our service concerns sexual content and biometric identifiers, we apply heightened protection to all such data and limit access to authorized personnel on a strict need-to-know basis.
To exercise these rights, contact us at soporte@letshoot.ai. We will verify your request (and any authorized agent) consistent with applicable regulations, respond within the statutory timeframe (generally 45 days, extendable once by 45 days), and not discriminate against you for exercising your rights. If we deny a request, you may appeal by replying to our response where your state law provides an appeal right.
13. Notice at Collection
At or before the point of collection, this Section serves as our notice of the categories of personal information we collect and the purposes for which they are used.
Categories collected: identifiers (name, username, email, account ID); government identifiers and age-verification data; biometric information (face geometry, templates, and likeness model); commercial and payment information (tokens, transactions); internet and network activity (usage, device, IP); geolocation (approximate, from IP/timezone); sensory/content information (uploaded and generated images and videos, including sexually explicit content); professional information (creator/agency role); and inferences limited to operating the service.
Purposes of use: providing and operating the Platform; verifying age and identity; training and running your AI likeness model and generating your content; content moderation and legal-safety obligations; processing payments and preventing fraud and money laundering; security and troubleshooting; customer support; legal compliance and record-keeping; and, only with your opt-in, marketing.
We retain each category for the periods described in Section 8. We do not sell or share personal information as those terms are defined under California law. This notice is provided in addition to, and incorporates, the more detailed disclosures throughout this Policy.
14. Cookies and Similar Technologies
We use cookies and similar technologies (such as local storage) to keep you signed in, remember your language and settings, secure the Platform against fraud and abuse, and understand aggregate usage so we can improve reliability.
We categorize these technologies as strictly necessary (required for authentication, security, and core functionality; always active), functional/preference (such as remembering your language, which may be set automatically based on your approximate location or timezone), and analytics (privacy-respecting, aggregate measurement). We do not use advertising or cross-context behavioral-advertising cookies.
Where required by law (for example, in the EEA and UK), we request your consent for non-essential cookies through a consent banner before setting them, and you can change your choices at any time via the cookie settings link. You can also control cookies through your browser settings, though disabling strictly necessary cookies may prevent the Platform from functioning.
We honor the Global Privacy Control and similar signals as described in Section 12.
15. Children, Age Verification, and the Only-Your-Own-Likeness Rule
The Platform is exclusively for adults aged 18 or older (or the age of majority in your jurisdiction, if higher). We do not knowingly permit access to, or collect personal data from, anyone under 18, and we do not knowingly process any content depicting a minor.
Every creator must complete age and identity verification before uploading content or training a model. Verification is designed to confirm both that you are an adult and that you are the same person depicted in the content — enforcing our foundational rule that we clone only your own verified likeness.
Only-your-own-likeness. You may upload and train a model only on images of yourself. Uploading images of any other person, or attempting to generate content depicting anyone other than your own verified self, is strictly prohibited and may result in immediate termination and referral to authorities. We do not create or host models or content depicting non-consenting individuals.
If we learn that we have inadvertently collected data from a person under 18, or that any content depicts a minor, we will act immediately in accordance with Section 16, including preservation, reporting to NCMEC, and permanent removal.
Parents or guardians who believe a minor has provided us data may contact soporte@letshoot.ai so we can investigate and delete it.
16. Content Provenance, CSAM/NCII, and Legal Disclosures
AI-provenance labeling. Content generated by the Platform is AI-generated and depicts a digital clone. We apply provenance signals to generated content (which may include embedded metadata and/or durable markings) so that it can be identified as AI-generated, consistent with emerging AI-transparency and synthetic-media disclosure laws.
Zero tolerance for CSAM. We prohibit any child sexual abuse material ("CSAM") absolutely. We use automated detection (including hash-matching and classifiers) and human review, and if we detect apparent CSAM we preserve the material and associated data and report it to the National Center for Missing & Exploited Children ("NCMEC") CyberTipline as required by 18 U.S.C. § 2258A, cooperating with law enforcement. Related records are retained as described in Section 8.
Non-consensual intimate imagery (NCII). Consistent with the TAKE IT DOWN Act and comparable laws, we prohibit non-consensual intimate imagery, including realistic digital forgeries ("deepfakes") of any person other than the consenting creator. If you are depicted in intimate content on the Platform without your consent, you may submit a removal request to soporte@letshoot.ai, and we will remove the reported content and any identical copies within forty-eight (48) hours of a valid request.
DMCA / copyright. If you believe content infringes your copyright, you may send a notice to our designated DMCA agent: «[TO BE SET: DMCA agent name, address, email, and phone]». We respond to valid notices and counter-notices under the Digital Millennium Copyright Act and terminate repeat infringers.
Card-network compliance. Because we accept Visa and Mastercard through CCBill/Epoch, we maintain the consent, age-verification, content-review, and complaint/removal controls required by card-network rules for adult content, and we may disclose limited data to processors and networks to meet those obligations.
Other legal disclosures. We may access, preserve, and disclose personal data where we reasonably believe it is required by law, subpoena, or court order; necessary to enforce our Terms; or necessary to protect the rights, safety, or property of any person, including to prevent imminent harm.
17. Data Security
We implement technical and organizational measures appropriate to the sensitivity of the data we hold, including encryption in transit (TLS) and at rest, hashing of passwords, network and application access controls, role-based access with least-privilege and need-to-know limits for staff and agency users, audit logging, and segregation of biometric data and § 2257 records.
Access to biometric identifiers, government IDs, and sexual content is restricted to authorized personnel who require it to operate the service or meet legal obligations, and such access is logged. Our generation and storage sub-processors are bound to equivalent security standards.
No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security, and you are responsible for keeping your account credentials confidential and using a strong, unique password.
In the event of a personal-data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authorities and affected individuals as required by applicable law (including GDPR/UK GDPR 72-hour authority notification and applicable U.S. state breach-notification laws), and we maintain an incident-response process for that purpose.
18. Contact, Complaints, and Changes to This Policy
For any privacy question, request, or complaint, contact us at soporte@letshoot.ai, or write to ASM Media Group LLC at «[TO BE SET: ASM Media Group LLC full US street address]». EEA and UK data subjects may also contact our DPO and our Article 27 representatives at the details in Section 2.
We aim to resolve concerns directly. You also have the right to complain to your competent data-protection authority (for the UK, the Information Commissioner's Office; for the EEA, your local supervisory authority) or, in the United States, to your state Attorney General or applicable privacy agency.
The law governing this Policy and any dispute relating to it, to the extent permitted, is that of «[TO BE SET: governing-law state, e.g., State of Florida]», without prejudice to the mandatory data-protection rights available to you under the laws of your own country or state.
We may update this Policy to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "last updated" date, post the revised Policy on letshoot.ai, and, where required, notify you (for example, by email or in-portal notice) and obtain any fresh consent needed, particularly for biometric or sexual-content processing. Your continued use of the Platform after a change takes effect signifies acceptance of the updated Policy to the extent permitted by law.