This notice explains how DSLS PARTNERS LTD, of Chrysanthou Mylona 1, Panayides Building, 2nd Floor, Flat/Office 1, 3030 Limassol, Cyprus (“OnStat”, “we”) handles personal data for its websites, accounts, billing, support, security, and Service. It also explains the more limited circumstances in which OnStat processes creator, fan, subscriber, chatter, and message-participant data on a business customer’s instructions.
This notice does not replace a customer’s own privacy notice. When a customer determines why and how connected-platform data is processed, that customer is normally the controller and OnStat is its processor. Contact the relevant creator or agency first for requests about that data. Legal roles always depend on the facts.
1. Who is responsible
OnStat is the controller for:
- website visitors and marketing contacts;
- customer account owners, Authorized Users, support contacts, and business prospects;
- billing, payment, tax, fraud-prevention, and legal-compliance records;
- security, audit, request, and abuse-reporting records; and
- product telemetry and demonstrably anonymized service measurements that OnStat determines for its own legitimate purposes.
A customer is normally the controller for personal data synchronized from or sent to a creator platform, campaign, Telegram destination, or other integration. OnStat processes that data under the customer’s instructions and the Data Processing Addendum.
OnStat may be a separate or joint controller if it independently determines a new purpose or essential means beyond the customer’s instructions. We will document that role and provide any additional notice required by law rather than relying on a contractual label.
Controller and privacy contact: [email protected]
2. Personal data we handle
2.1 Website, account, and team data
- name, business name, email, password hash, tenant and membership identifiers;
- profile image/avatar and display preferences;
- role, permissions, invitations, login and refresh-token records;
- API-key identifier, prefix, status and last-use metadata; OAuth client, authorization, selected account/scope, token-family, approval, refresh, revocation and expiry metadata;
- early-access/waitlist email, name, professional role and, where collected, answers about creator-account scale, link volume, revenue band and traffic sources;
- contact preferences, support messages, feedback, and survey responses;
- IP address, device/browser information, page activity, referral source, and timestamps;
- audit events, request logs, security alerts, and suspected-abuse signals.
We do not store plaintext account passwords. Authorized session and refresh credentials are security-sensitive personal data and are handled as described in the Security Measures.
2.2 Billing and commercial data
- plan, subscription period, creator-account count, revenue-based tier information;
- payment, invoice, promo-code, credit, and prepaid-balance records;
- checkout and provider identifiers, payment status, amount, currency, network, and blockchain transaction identifiers where relevant;
- for a requested approved-refund payout, requester authority/identity evidence, minimized destination account or wallet identifiers, ownership/control evidence, compliance status, conversion/fee and provider payout records; and
- payment-provider webhook payloads and anti-fraud information.
The hosted payment provider may offer card or crypto checkout and collects the corresponding card, wallet, transaction, fraud-prevention, and compliance details under its own notice. OnStat does not receive wallet private keys or seed phrases and does not intend to store full card numbers or card security codes.
2.3 Connected creator-account and Customer Data
Depending on enabled features, a customer may instruct OnStat to process:
- platform account identifiers, username, profile and creator metadata;
- authenticated session cookies, fingerprint/cookie values, user-agent details, WebSocket tokens, and dynamic request-signing configuration required for a connection;
- fan or subscriber identifiers, usernames, display names, avatar URLs, subscription dates, spend, tips, purchases, creator/performer indicators, and profile signals;
- transaction identifiers, amounts, fees, taxes, descriptions, payer details, and status;
- private message text, tip text, dialog previews, media identifiers/previews, raw message or chat payloads, sender/recipient information, and timestamps;
- lists, campaigns, funnels, promotions, posts, comments, mass-action and automation configuration and results;
- media identifiers and metadata, and minimized thumbnails or technical previews used by vault, messaging, or analytics functions; and
- agency, creator, chatter, and team-member activity within the customer tenant.
The standard Service does not accept or persist original adult photo or video files from a connected creator platform. It may persist minimized thumbnails or technical previews used by vault, messaging, or analytics features. Some legacy preview URLs are not yet protected by tenant-bound, short-lived delivery, so Customers must treat them as confidential and avoid sharing them. OnStat may temporarily proxy original media bytes to an authorized user without persistent storage. OnStat is not offered as a public adult-content gallery or general media-hosting service.
The adult-creator context, messages, purchases, profiles, and creator/performer indicators may reveal or allow inferences about a person’s sex life, sexual orientation, occupation, finances, or private relationships. These may be special-category or otherwise sensitive data. The customer must identify a valid legal basis and any additional Article 9 or local law condition before instructing processing.
2.4 Campaign, click, and attribution data
- requested URL and link/campaign identifiers;
- allowlisted UTM and sub identifiers, platform click IDs carried in the requested URL, and referrer;
- IP address, user agent, an OnStat-generated event identifier, and event time;
- approximate country, region, and city derived from IP;
- selected destination, redirect, postback, delivery, and conversion events; and
- attributed fan/account identifiers where a customer matches a click to a subscriber or transaction.
Customers control their campaigns and are responsible for notices, consent, lawful basis, destination terms, and postback configuration. OnStat acts as controller only for its own website analytics and security purposes, and ordinarily as processor for customer campaign attribution.
Under OnStat's standard campaign-redirect design, the redirect does not create _fbp,
_fbc, or another advertising identifier in the visitor's browser. When a customer enables
an advertising or postback integration, OnStat may use a platform click identifier already
contained in the requested link and other allowlisted request and event data to send the
customer-configured event server-to-server to the customer-selected recipient. The
standard advertising payload excludes raw creator-platform account, creator, and fan
identifiers, message and media content, detailed adult-platform activity labels, complete
URLs, and unfiltered query parameters. Attributed fan/account identifiers may still be used
inside OnStat to provide Customer's attribution dashboard and must not be repurposed as an
advertising matching identifier.
2.5 AI feature data
AI Analytics may process a user’s question, selected schema and account context, generated queries, aggregate results, and limited sample rows. Dialogs AI may send chunks of private message text to the configured model provider to generate an answer and citations. We store AI requests, outputs, queries, job status, and diagnostic records according to the retention schedule.
AI features can therefore process personal and sensitive information contained in Customer Data. Each must be deliberately used as a product instruction under the Terms. Ordinary AI Analytics does not require a separate legal opt-in under the agreed feature-instruction model. Dialogs AI processing begins only after a Customer user deliberately requests a summary or answer in the Dialogs AI interface; a versioned activation record is planned but is not represented as already deployed.
2.6 Browser extension data
OnStat Connect uses browser cookie and storage permissions to authenticate the user, obtain creator-platform session cookies and related connection parameters, and send those values to OnStat. Details appear in the OnStat Connect Extension Privacy Notice.
2.7 API, OAuth and MCP connection data
When a Customer creates an API key or connects an external AI client through OAuth/MCP, OnStat processes credential identifiers and hashes, client name and redirect host, selected accounts and technical data scopes, approval/acknowledgement records, token-family status, tool or endpoint name, bounded query shape, timestamps, result status, and security/audit metadata.
Depending on the selected scope and request, the external client may receive aggregate analytics, structured business records, private message text, CRM notes, team contact information, or team finance information. The external client and its provider may retain prompts, conversations, memory, logs, results, or other copies under the Customer’s relationship with that provider. The Customer’s downstream-recipient, credential, scope, revocation, and security obligations appear in the Terms.
2.8 Shared Portal data
A Customer may create a token-based partner or chatter portal. Depending on Customer configuration, the portal may display creator/account names, campaigns, clicks, conversions, fan labels or usernames, sales, amounts, revenue, costs, rates, commissions, balances, payouts, comments, activity, and related analytics. A chatter portal may also accept claims, withdrawals, comments, or proposed manual sales.
OnStat processes the portal/token identifier, Customer and intended partner/chatter, visibility and action configuration, expiry/revocation state, access count and time, and minimized request/security metadata. Action records may identify the chatter or other actor and the affected sale or record. The raw bearer token must not be placed in ordinary audit or legal-event records.
For displayed Customer Data, the Customer is normally the controller and OnStat its processor. For core portal security, abuse prevention and contract evidence, OnStat may act as controller for minimized access and security metadata. Portal Users should read the Shared Portal Access Terms and Privacy Notice and contact the Customer first about commissions, payouts, assignments, or Customer-controlled records.
3. Where data comes from
We collect data:
- directly from customers, Authorized Users, website visitors, and support contacts;
- from the OnStat Connect browser extension;
- from connected creator platforms and their authenticated endpoints;
- from campaign links, browsers, redirect requests, Telegram invite attribution, and customer-configured postbacks;
- from Customer-created API calls and Customer-approved OAuth/MCP clients;
- from Shared Portal links and actions supplied or configured by Customers;
- from payment, email, infrastructure, security, and analytics providers; and
- from customers that upload, synchronize, or instruct processing about creators, fans, subscribers, message participants, and agency personnel.
If you are a fan, subscriber, message participant, or creator who did not give data directly to OnStat, the relevant creator, agency, or other customer is normally the source and controller. That customer is responsible for giving the Controller privacy information required for its processing, ordinarily through its own privacy notice or another lawful and reasonably accessible channel, and for documenting any exception on which it relies. OnStat does not ordinarily contact every individual represented in Customer Data or collect a separate fan authorization on the customer's behalf. We make this notice available to explain OnStat's role and assist the customer as required by the DPA.
4. Why we use data and our legal bases as controller
Where GDPR/UK GDPR applies, OnStat relies on the following bases for its controller processing:
| Purpose | Typical data | Legal basis |
|---|---|---|
| Create accounts, authenticate users, provide purchased Service and support | account, membership, support, service configuration | contract; steps requested before contract |
| Process an early-access request and send the requested beta/access update | waitlist contact, professional role and submitted qualification responses | steps requested before contract; legitimate interests in evaluating B2B demand where applicable |
| Bill, maintain balances, administer plans and process an eligible approved-refund payout | account, revenue tier, payment, invoice, verified destination and compliance data | contract; legal obligation for tax/accounting and, where applicable, AML/sanctions or other payment compliance; legitimate interests in preventing fraud |
| Secure the Service, prevent fraud and abuse, investigate incidents | IP/device, authentication, audit and request records | legitimate interests in security and fraud prevention; legal obligation where applicable |
| Communicate service and legal notices | contact and account information | contract; legal obligation; legitimate interests |
| Improve reliability and product usability | telemetry, support themes, demonstrably anonymized metrics | legitimate interests, balanced against user rights |
| Operate optional website analytics | cookie/device and page activity | consent where required; otherwise legitimate interests only where local law permits |
| Respond to legal process and protect rights | account, audit, transaction, and relevant Customer Data | legal obligation; legitimate interests in claims and compliance |
| Send requested or permitted B2B marketing | business contact and engagement data | consent where required; otherwise legitimate interests, with opt-out |
Joining the waitlist requests the access or beta-status communications described at the collection form. It does not by itself authorize unrelated newsletters, promotions, or third-party marketing. Where a separate marketing consent is required, OnStat will request it separately and record the wording, channel, time, and withdrawal status.
We do not rely on “legitimate interests” as a blanket basis for customer-directed fan profiling or sensitive adult-context processing. The customer must document its own purpose, Article 6 basis, and—where applicable—Article 9 condition, ePrivacy consent, and DPIA.
Where we rely on consent, it may be withdrawn at any time without affecting earlier lawful processing. Where we rely on legitimate interests, a summary of the relevant balancing assessment is available on request unless disclosure would prejudice security or others’ rights.
For cross-customer benchmarking or generalized improvement derived from Customer Data, we use identifiable or pseudonymous data only under a separate written Customer opt-in. Without that opt-in, we use only statistics demonstrated to be anonymized so that neither a Customer nor an individual is reasonably identifiable. Removing direct identifiers or hashing an ID does not by itself make data anonymous.
5. How customers instruct processor activities
Enabling, configuring, or using a connection, account, data source, analytics module, messaging function, account action, campaign, attribution function, automation, AI feature, query, export, retention setting, deletion control, or other documented configuration is an instruction to process Customer Data to provide that feature and, where applicable, perform the selected action. Support requests, API calls, approved OAuth grants, and MCP tool requests may also be documented instructions.
We may provide a feature-specific notice or require an additional confirmation where a feature introduces a materially different purpose, recipient, data category, or risk, including the transfer of private messages to an external AI provider. A customer’s instruction does not replace consent or an opt-out required from a website visitor for non-essential analytics, a tracking link, or onward advertising delivery.
The DPA describes subject matter, duration, categories, subprocessors, transfers, security, rights assistance, deletion, audits, and incident notification. OnStat will inform the customer if an instruction appears unlawful unless prohibited from doing so.
6. Automated processing
OnStat can calculate metrics, attribute conversions, group or segment users, detect anomalies, suggest queries or insights, and execute customer-configured rules and account actions. AI outputs and recommendations can be wrong.
Standard operational analytics and segments may use subscription status, purchases, spend, engagement, message or account activity, and similar service-use information. OnStat does not intentionally infer, label, score, rank, segment, target, or predict a person's sex life, sexual orientation, health, biometric identity, ethnicity, beliefs, or another special-category or comparably sensitive characteristic as part of the standard Service. Sensitive information may nevertheless appear incidentally in Customer-provided messages, notes, profiles, or purchases. We process that information as a processor only as necessary to provide the customer-configured feature and do not use it for OnStat advertising, cross-customer analytics, or generalized model training. A purpose-built sensitive profiling feature would require a separate legal and product launch review and additional contract, notice, safeguards, and controls before use.
OnStat does not intend to make solely automated decisions about individuals that produce legal or similarly significant effects for its own controller purposes. Customers must not configure the Service for such decisions and must provide meaningful human review, transparency, and a contest mechanism where required.
7. Recipients and subprocessors
We disclose data only as needed to:
- infrastructure, storage, security, monitoring, email, support, payment, and AI providers;
- customer administrators and Authorized Users according to configured roles;
- Customer-selected API, OAuth, MCP, AI, postback, export, and other recipients for the data and accounts that Customer authorizes;
- intended partner, chatter, contractor, or other Shared Portal recipients for the fields and actions Customer configures;
- professional advisers, auditors, insurers, and transaction counterparties under confidentiality protections;
- law-enforcement, regulators, courts, or affected persons where law requires or permits; and
- protect a person from exploitation, abuse, or imminent harm.
The current provider categories, locations, and functions appear in the Subprocessor List. AI providers receive Customer Data only when the relevant feature is enabled. A connected platform receives actions and data selected by the customer under that platform’s own terms.
IOOI Sp. z o.o. provides the hosted Inqud payment flow and acts as an independent controller or recipient for its own payment, fraud-prevention, AML/KYC, accounting, and legal obligations. It may receive checkout and transaction identifiers, amount, currency, payment status, wallet/network information, and technical or compliance data. Its processing is described in the Inqud Privacy Notice.
OnStat has disabled Google Analytics on marketing pages until a consent-management control can prevent loading where consent is required. If enabled after that control is deployed, Google may receive cookie or device identifiers, page and referrer information, and interaction events for OnStat's own website-analytics purpose.
When the application displays a GIF directly from GIPHY, Inc., the viewer's browser requests that media from GIPHY. GIPHY therefore receives the viewer's IP address, device/request metadata, and the requested GIF identifier under the GIPHY Privacy Policy.
OnStat uses a locally downloaded DB-IP Lite database for IP geolocation. The lookup runs locally and does not send the queried IP address to DB-IP.
A Customer-selected AI client or other recipient is not automatically an OnStat Subprocessor. Revoking its OnStat connection prevents future authorized access through that connection but may not delete copies already retained by the recipient. Customer must use the recipient’s contract and controls to address those copies.
Advertising, analytics, and postback platforms connected with Customer's own credentials are Customer-selected recipients rather than OnStat subprocessors for that delivery unless a separate agreement expressly says otherwise. Customer controls the destination and event mapping and must address the recipient's controller/processor terms, lawful basis, notice, consent or opt-out, transfer, retention, and deletion requirements.
We do not sell personal data for money. Some analytics or advertising identifiers may constitute “sharing”, targeted advertising, or a sale under certain U.S. state laws even without monetary payment. OnStat must deploy the required opt-out and honor browser-based preference signals before using such processing in an applicable jurisdiction.
8. International transfers
Primary production hosting is currently designed for AWS’s eu-central-1 region. A provider,
support team member, customer, or subprocessor may nevertheless access or process data from
another country.
Where GDPR/UK GDPR requires a transfer mechanism, OnStat will use an adequacy decision, European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum or other valid mechanism, and supplementary safeguards as appropriate. Customers can request relevant transfer documentation, subject to confidentiality and security restrictions.
This section must be updated if the contracting entity, corporate access locations, or provider regions change.
9. Retention
We keep personal data only for its documented purpose and use the following default periods or criteria, unless a shorter Customer setting, Order Form, or mandatory law applies:
| Category | Default period or criterion |
|---|---|
| Customer account and core Customer Data | Subscription/Agreement term plus a limited 30-day window to request export or reactivation; after the window, data may be permanently deleted from active systems |
| Connected-platform cookies, tokens, and connection material | Only while the account is connected and needed; delete promptly on disconnect, compromise, or termination |
| API/OAuth/MCP credentials | Active connection term; revoke usable material promptly; minimized approval and revocation evidence follows the security-audit period |
| Shared Portal credentials | Active until the configured expiry or manual/automatic revocation event. Customers must promptly revoke access when the recipient's authority ends or compromise is suspected |
| API/MCP, portal-action, authentication, and security audit metadata | Normally 12 months |
| Click and attribution events with identifiers | Normally 90 days; de-identified aggregates may be retained longer |
| Request logs and reconciled raw payment webhook payloads | Normally 90 days |
| Notifications | Normally 30 days |
| Dialogs AI jobs, copied message chunks, sessions, answers, and citations | Normally 30 days |
| AI Analytics questions, generated SQL, outputs, and response logs | Up to 365 days under the current design; shorter Customer controls are planned |
| Temporary investigation/diagnostic datasets | Normally 14 days |
| Waitlist and marketing contacts | Until opt-out or up to 24 months after last meaningful engagement; only a minimal suppression record after opt-out |
| Support tickets and ordinary correspondence | Normally 24 months after closure |
| Contracts, invoices, payment ledger, tax and accounting records | The applicable statutory period |
| Abuse, safety, IP, fraud, and legal matters | Case duration plus the applicable claims, preservation, or reporting period |
| Website analytics | Disabled until the required consent-management control is deployed; if enabled, the disclosed vendor configuration and retention period apply |
| Protected backups | Until overwritten under the normal backup cycle; restricted to legal, security, and disaster-recovery purposes |
Legal holds, disputes, safety investigations, fraud, or mandatory law may require longer retention. OnStat will restrict use to that purpose. Hashing or pseudonymizing an identifier does not by itself make data anonymous. Customer exports and copies outside the Service are controlled by Customer. The periods above are default policy targets; specific legacy data may require deletion or migration work disclosed through the applicable support process.
When a paid subscription ends, access to paid features ends immediately. During the next 30 days, Customer may request a standard export or reactivate the subscription, subject to the Terms. Each generated export download link expires after 24 hours; while the 30-day window remains open, Customer may request a replacement link.
After that period, OnStat may permanently delete Customer Data from active systems without further notice. Protected backup copies may remain until overwritten under the normal backup cycle, but are restricted from ordinary use and retained only for applicable legal, security, and disaster-recovery purposes.
10. Security
We use access controls, tenant scoping, password hashing, transport encryption, private networking, backups, monitoring, and other safeguards. Customer-specific Security Measures are supplied with the DPA or Order Form, through an authenticated Trust Center, or on request subject to appropriate confidentiality restrictions.
No system is completely secure. Customers must protect endpoint devices, browser profiles, exports, Authorized User access, and connected-platform credentials. Please report suspected security issues to [email protected].
The supplied Security Measures identify the storage layers that currently use encryption and the known limitations; OnStat does not claim universal database or creator-session encryption at rest.
11. Your rights
Depending on location and context, an individual may have rights to:
- be informed and access personal data;
- correct inaccurate data;
- delete or restrict processing;
- receive portable data;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent;
- object to certain solely automated decisions; and
- complain to a data-protection authority.
Submit requests about OnStat’s controller processing to [email protected]. We may verify identity and authority, ask for enough context to locate records, and withhold or limit disclosure where law protects another person, confidentiality, security, or legal privilege. Authorized agents must prove authority.
For Customer Data, contact the relevant creator or agency customer first and use the privacy contact stated in that customer's notice where possible. If you cannot identify or reach the customer, contact [email protected] with enough non-sensitive context for us to locate the relevant tenant. We will route the request or assist the controller under the DPA and may communicate directly where required by law. We will not disclose another tenant’s data without valid authority.
EU/EEA individuals may complain to their local supervisory authority; UK individuals may complain to the Information Commissioner’s Office. California and other U.S. state residents may have additional access, deletion, correction, portability, opt-out, appeal, and non-discrimination rights where the relevant statute applies. OnStat will not discriminate for exercising a privacy right.
12. Cookies and similar technologies
OnStat uses cookies, browser storage, pixels, and similar technologies as follows:
| Technology/category | Purpose | Type and current duration |
|---|---|---|
refresh_token | Keep an authenticated user signed in and rotate/revoke sessions | Strictly necessary, HttpOnly and Secure in production; up to 7 days by current default |
| Access token in application memory | Authenticate API requests | Strictly necessary; short-lived and not persistent browser storage |
currentTenantId and UI preferences | Remember the selected workspace, theme, onboarding, filters, columns, and layouts | Functional; until removed or browser data is cleared |
| Google Analytics / GA4 identifiers (Google Ireland Limited / Google LLC as applicable) | Measure marketing-site visits, navigation, devices, and campaign performance | Currently disabled; if enabled after consent controls are deployed, non-essential analytics under the disclosed configuration |
| OnStat Connect extension storage | Store OnStat authentication, tenant selection, theme, and connection state | Necessary/functional; until logout, removal, expiry, or extension data is cleared |
| Creator-platform cookies read by the extension | Establish the Customer-authorized creator-account connection | Requested integration; retained only while the account is connected and needed |
The standard OnStat campaign redirect does not set _fbp, _fbc, or another advertising
cookie. It may process platform click identifiers already included in a requested tracking
link and send an allowlisted event server-to-server under the relevant Customer's
instruction. This server-side design is not a statement that the Customer's tracking link
or onward disclosure is exempt from applicable notice, consent, opt-out, or other legal
basis requirements.
Where consent is required, non-essential technologies remain disabled until a control is available to obtain and withdraw that consent. Rejecting optional cookies will not block the core website or paid Service. Browser or device settings alone may not remove records already received; use the privacy contact for applicable rights.
13. Minors
The Service is for adults and business users only. It is not directed to anyone under 18. Customers must not connect an underage account, process content involving a minor, or use the Service to contact, profile, exploit, or facilitate access to a minor.
If you believe data or content involving a minor is present, do not send the material by ordinary email and do not download or copy suspected illegal content. Send only safe, non-content identifiers to the safety contact below. We may preserve and report information where law requires.
14. Third-party sites and platforms
OnStat is an independent third-party management and analytics service used with creator-authorized accounts. OnStat is not affiliated with or endorsed by OnlyFans. Customers must comply with applicable platform terms. OnStat may restrict or disable functionality in response to platform requirements, security controls, or legal risk.
Links, creator platforms, Telegram, payment checkouts, and other integrations have separate privacy practices. OnStat does not control their independent collection or decisions.
15. Changes
We may update this notice to reflect law, vendors, security, or product changes. The version and effective date will be updated. We will provide prominent or direct notice of a material change where required and will seek new consent when a new purpose legally requires it. Archived versions will be retained.
16. Contact
Privacy: [email protected] Legal notices: [email protected] Security: [email protected] Safety/abuse: [email protected] Postal address: Chrysanthou Mylona 1, Panayides Building, 2nd Floor, Flat/Office 1, 3030 Limassol, Cyprus