Skip to main content
Heduno logoHome
Back

Privacy and Cookie Policy

Effective date: 10 June 2026

By using Heduno, you acknowledge that you have read and understand this Policy.

1. Who we are and where you will see us

1.1 Heduno is operated by Wick Entertainment Limited (company no. 13853762, registered office C/O Alexander & Co, Centurion House, 129 Deansgate, Manchester, England, M3 3WR), trading as "Heduno" ("we", "us", "our"). We are the data controller of the Personal Data we process in connection with Heduno and the services we provide through it (the "Services").

1.2 One controller across all domains. You may use Heduno on heduno.com, on a heduno-hosted Creator page, or on a Creator's own domain (for example, creatorname.com). Wherever you see the Service, Wick Entertainment Limited (trading as Heduno) is the controller of your Personal Data — not the individual Creator. You have a single Heduno Account and a single record across all domains.

1.3 You can contact us about this Policy or your Personal Data at privacy@heduno.com.

2. Scope and age

2.1 This Policy applies to Personal Data we process about Fans, Creators, individuals who feature in a Creator's Content ("Content Collaborators"), and our business contacts. It is provided alongside, but does not form part of, the Terms of Service.

2.2 Heduno is strictly for individuals aged 18 or over. By using the Services you confirm you are 18 or over.

3. What is Personal Data

3.1 "Personal Data" means information that identifies or could reasonably be linked to a particular person. Anonymised or aggregated data that cannot be linked to you is not Personal Data and is not covered by this Policy.

4. The Personal Data we process

We process the following categories of Personal Data about Users and Content Collaborators:

CategoryWhat it includes
User DataCreators / Content Collaborators: full name, alias, address, country of residence, email, phone, a copy of the government ID document provided to our verification provider (which, for Creators and Content Collaborators, we access and hold as Records Custodian — see clause 6.3), a selfie/short clip used for verification, social/website handles, and signatures on release forms where you feature in Content. Fans: email, phone.
Verification DataData generated by our verification provider during age and identity checks: the result (pass/fail and reason) and process metadata (e.g. start/finish time). See clause 6.
Account DataProfile name, password, avatars/banners, your Subscriptions, followers and referrals, posts, comments, chat messages, and support queries.
Financial DataPayment-card details (tokenised — see note below), billing address, Wallet balance and top-ups, and (for Creators) payout details, tax identifiers and any tax forms.
Transaction DataPayments, Wallet debits and credits, Creator earnings, payout requests and failed payments.
Custom Request DataThe free-text briefs and any details you include when you commission a Custom Request, which may contain information you choose to provide.
Technical DataIP address (and country code) and user-agent.
Face Recognition DataUsed by our verification provider during age/identity checks. It is collected by and remains with the provider; we do not receive, hold or have access to it.

Tokenisation note: card Payments are securely processed by our payment processor. We do not receive your full card number, expiry or security code.

5. How we collect your Personal Data

5.1 We collect it: directly from you (when you register, transact or contact us); automatically through your use of the Services (Transaction, Technical and cookie data); and from our service providers (for example, the verification result we receive from our age/identity provider).

6. Age assurance — how it works and what we process

6.1 Account creation does not require age assurance. When you register as a Fan, we collect only your User Data; you can browse non-adult (SFW) areas without an age check.

6.2 Age assurance is triggered at your first purchase or Subscription. We use a specialist identity-verification provider for ID checks, and specialist age-estimation and card-check providers, in each case acting as our processors.

6.3 What we receive, and what we do not. Our verification provider carries out the age and identity checks. We distinguish between three kinds of data:

(a) Biometric / Face Recognition Data (used in facial age estimation and liveness checks): this is collected and processed by our provider only. It stays with the provider, and we do not receive, hold or have access to it.

(b) Government ID documents of Creators and Content Collaborators: because Heduno is the Records Custodian for age and identity verification (see the Creator Terms and the USC 2257 Statement), we access and hold these identity records for Creators and for individuals appearing in Collaborative Content. This is necessary for our custodian, payout and legal-compliance obligations.

(c) Age assurance of Fans (verifying that a Fan is over 18 to access adult Content): for this purpose we receive only the verification result and process metadata — a pass/fail outcome and information such as the method used and the time of the check. We do not receive or store the underlying ID document or biometric data of Fans verified for age assurance.

If you are in a US state with a biometric-privacy law (including Illinois, Texas and Washington), before any facial-recognition processing takes place we will tell you that biometric identifiers are being collected, the purpose and the retention period, and we will obtain your consent; the data is used only for age/identity assurance, is not sold or disclosed except to the provider for that purpose, and is retained and destroyed in line with our and the provider's biometric retention schedule.

6.4 Re-authentication. We may ask you to re-authenticate periodically. Where you have consented, the provider may retain your Face Recognition Data so you do not need to resubmit your ID. You can withdraw that consent at any time by emailing privacy@heduno.com; doing so does not stop you re-authenticating, but you may need to provide your ID again.

6.5 Audit-trail data. Separately from any identity data held by our verification provider, and separately from the Creator identity records we hold as Records Custodian, we keep a minimal audit record of each age-assurance check: a verification reference or token, the method used, the date and time, and the result. This audit record allows us to demonstrate that a valid check took place, and to apply any periodic re-verification required in your jurisdiction. It does not itself contain identity documents or biometric data.

6.6 Attempts by under-18s. Heduno is strictly for adults. If our age-assurance process indicates that a person attempting to access adult Content is, or may be, under 18, access is refused and the adult Content is not shown. We do not create an account-holder profile for a person we identify as under 18, and we delete data collected during the attempt except where we are required to retain limited records to comply with our legal obligations (for example, to prevent repeat attempts, or where we are required to report). Any suspected attempt to access by a child, and any child sexual abuse material, is handled under our safety processes and reported to the relevant authorities as described in clause 7 of the Terms of Service.

7. Why we use your Personal Data and our lawful bases

7.1 We rely on the following UK GDPR lawful bases. Some processing relies on more than one.

PurposeLawful basis
Creating and operating your Account; fulfilling transactions between Fans and Creators; processing Creator earnings; providing support and communicating about the ServicesPerformance of a contract
Age assurance (operating the verification/estimation waterfall and keeping records of it)Legal obligation (compliance with our duties under the Online Safety Act 2023), supported, for biometric processing, by the substantial-public-interest condition for special-category data
Retaining Face Recognition Data for optional re-authenticationConsent
Recognising referrals under the Referral Programme (referral code or link captured at registration; no cookies)Performance of a contract
Moderating Content and messages; removing illegal Content and suspending accountsLegal obligation and performance of a contract
Reporting illegal activity to authorities and relevant organisationsLegal obligation, legitimate interests and public interest
Detecting and preventing fraud, protecting security and our and others' rights; maintaining a record of banned usersLegitimate interests (and, for security monitoring, substantial public interest)
Tax and financial reportingLegal obligation
Sale, merger or reorganisation of our businessLegitimate interests

8. Cookies and similar technologies

8.1 We use cookies and similar storage-and-access technologies. UK rules changed on 5 February 2026 (the Data (Use and Access) Act 2025), and we apply the categories below.

8.2 Strictly necessary (no consent needed): cookies required to run the Service, such as session, login/authentication and security cookies.

8.3 Consent-exempt but with information and opt-out (under the 2026 exceptions): (a) first-party analytics used only by us to measure and improve the Service; (b) cookies that remember your appearance or functionality preferences; and (c) cookies for emergency assistance. We tell you about these and let you opt out free of charge; we do not use any of them for advertising.

8.4 Non-essential cookies — consent first. We set any non-essential cookies only after you have given consent through our cookie banner. The banner offers "Accept all" and "Reject all" with equal prominence, sets no non-essential cookies before you choose, and lets you change or withdraw consent at any time.

8.5 We do not use cross-site tracking, we do not sell your Personal Data, and we do not share it for cross-context behavioural advertising.

9. Automated decision-making

9.1 Age estimation produces an automated pass/fail result. Where you do not pass, you can move to the next stage of the waterfall, including human-reviewable government-ID verification, so there is always a non-automated route. We do not otherwise make decisions that produce legal or similarly significant effects about you solely by automated means.

10. Sharing your Personal Data

10.1 We share Personal Data with:

  • Service providers (processors) acting on our behalf under data-processing agreements — including our payment processor, our identity-verification and age-estimation/card-check providers, our automated content-moderation provider, our hosting provider, and our email provider. A current list of the specific providers we use is available on request at privacy@heduno.com and is maintained in our sub-processor register, which we may update from time to time as our providers change; and

  • Authorities and reporting organisations, including UK law enforcement, the National Crime Agency (including CEOP), the Internet Watch Foundation, HMRC, the ICO, and — where relevant — the US National Center for Missing & Exploited Children (NCMEC).

11. International transfers

11.1 Some of our providers process data outside the UK and the EEA. Where we transfer Personal Data internationally we use a transfer mechanism recognised under the applicable law — an adequacy decision where one applies, or otherwise the UK International Data Transfer Agreement (IDTA) / UK Addendum (for UK data) and the EU Standard Contractual Clauses (for EEA data), in each case with a transfer risk assessment. You can ask us for details at privacy@heduno.com.

12. Your rights

12.1 Subject to the usual conditions, you have the right to: access your Personal Data; have it corrected; have it erased; restrict or object to processing; data portability; and withdraw consent where we rely on it (without affecting earlier processing). You can also complain to the ICO (ico.org.uk), though we would welcome the chance to resolve matters first.

13. Exercising your rights

13.1 To exercise any right, email us at privacy@heduno.com. To protect your data, we may need to verify your identity before responding, and may ask for proof of authority if someone makes a request on your behalf.

14. Your choices and control

14.1 Editing your details. You can update the fields available in your Account settings; for anything not editable in-product, email privacy@heduno.com.

14.2 Notifications. We send account and transactional notifications (for example, a new subscriber or a renewal) and may send direct-marketing emails. You can manage optional notifications in your notification preferences; you cannot opt out of essential transactional, security or legal notices.

15. How long we keep your Personal Data

15.1 We keep Personal Data only as long as necessary for the purpose it was collected, then delete or anonymise it. In practice: account data for the life of your Account; trust-and-safety data for as long as needed to investigate, report and enforce; compliance records (including identity and tax records) for the period the law requires (in some cases up to 7 years); and data needed for legal claims for the relevant limitation period.

15.2 Verification data — what is kept, by whom. Retention of age and identity data depends on who you are and why you were checked:

Creators and Content Collaborators: we hold identity and age verification records as Records Custodian for the period required by law (see clause 6.3 and the USC 2257 Statement).

Fans verified for age assurance: we keep only the audit record described in clause 6.5 (a verification reference or token, method, time and result) — not the underlying ID document or biometric data, which we do not receive for this purpose.

Jurisdiction-specific rules. Where the law of your jurisdiction imposes stricter requirements, those apply. For example: in Ohio, verification documents are not retained after the check is complete other than as permitted for account-holders, and account-holders are re-verified periodically as required by law; in France and Italy, age checks are performed on a minimal-data, per-access basis through our provider, and we retain only the audit record needed to evidence that a valid check took place.

16. Data Protection Officer and contact

16.1 You can contact our privacy team, and our Data Protection Officer, at privacy@heduno.com (or by post at our registered office, marked for the DPO).

16A. European Union and EEA data subjects

16A.1 If you are in the European Union or EEA, the EU General Data Protection Regulation applies to our processing of your Personal Data. The lawful bases in clause 7 apply, read against the EU GDPR. You have the same rights set out in clause 12, and you may lodge a complaint with the supervisory authority in your member state.

16A.2 As we are established in the United Kingdom and not in the EU, we are appointing an EU representative under Article 27 GDPR. This Policy will be updated with their contact details once appointed; in the meantime, EU and EEA data subjects can contact us at privacy@heduno.com.

17. US State privacy disclosures

17.1 These disclosures apply where a US state privacy law (such as the California Consumer Privacy Act as amended (CCPA/CPRA), or the privacy laws of Virginia, Colorado, Connecticut, Texas, Utah and other states) applies to our processing of your Personal Data.

17.2 What we do and do not do. We do not sell your Personal Data and we do not share it for cross-context behavioural (targeted) advertising. We do not sell sensitive personal information. We use sensitive personal information (including any biometric data handled by our verification provider) only for the age- and identity-assurance purposes described in this Policy.

17.3 Your rights. Subject to the applicable state law and verification of your identity, you may have the right to: know and access the Personal Data we hold about you; correct it; delete it; obtain a portable copy; opt out of any sale, sharing or targeted advertising and of certain profiling; limit the use of sensitive personal information; and not be discriminated against for exercising these rights. To exercise any right, email privacy@heduno.com. You may use an authorised agent. If we deny your request you may appeal by replying to our decision; if an appeal is denied you may contact your state Attorney General.

18. Changes to this Policy

18.1 We may update this Policy and will post the revised version on Heduno. Where changes are material, we will take reasonable steps to notify you.