2. YOUR RIGHTS IN RELATION TO YOUR PERSONAL DATA
The EU’s General Data Protection Regulation, or GDPR as it is more commonly referred to, gives you certain rights to your Personal Data. These rights can be found in chapter 3 of the GDPR and include:
Right of Access – You have the right to request information concerning if we process your Personal Data and if we do, you have the right to know what kind of Personal Data;
Right of Rectification – You have the right request that we correct and rectify any inaccurate or incomplete Personal Data concerning you;
Right to Erasure – You have the right to request that we delete your Personal Data. Note that we may retain information needed to resolve disputes, enforce our user agreements, protect our legal rights and comply with technical and legal requirements and constraints related to the security and operation of our Properties;
Right to Restriction of Processing – You have the right to request that we temporarily or permanently cease processing of some or all of your Personal Data;
Right to Data Portability – You have the right to receive a copy of your Personal Data for the purpose of transferring them to another service provider;
Right to not be the subject of Automated Decision Making – You have the right not to be subject to a decision based solely on automated processing. Including profiling, which produces legal effects on you or otherwise significantly affect you;
Right to Withdraw Consent – You may at any time withdraw your consent to the processing of any Personal Data based on your consent, without it affecting the lawfulness of any processing done before you withdrew your consent; and
Right to Object – You have the right to object to our processing of your Personal Data for a certain purpose or to object to your Personal Data being used for direct marketing.
If you wish to exercise any of the above rights regarding your Personal Data as mentioned above, please contact us at firstname.lastname@example.org.
We provide certain privacy controls in your user account to help you take advantage of those rights, including the option to remove certain types of Personal Data.
If you have concerns regarding the processing of your Personal Data, we hope you can work with us to solve them. However, you can also contact the Swedish Data Protection Authority or your local Data Protection Authority. The Swedish Data Protection Authority can be reached through the following address:
Phone: +46 (0)8 6576100
Mail: Integritetsskyddsmyndigheten, Box 8114, SE-10420 Stockholm, Sweden
3. THE DATA WE COLLECT AND USE
Below, we describe the Personal Data we collect and how we collect it. Furthermore we set out the reasons we process your Personal Data (the purpose of processing) and the legal basis for our processing.
3.1 The Personal Data we collect from you
a) We collect Identity Data. This includes your names, usernames, or similar identifiers as well as your titles and preferred genders.
b) We collect Contact Data. This includes your home address, email address, phone number and other data you provide Expansive Worlds with for the purpose of enabling contact.
d) We collect Technical Data. This includes your internet protocol (IP) address, your login data, browser type and version, hardware information, time zone setting and location, browser plug-in types and versions, operating system and other technology on the device you use to access the Properties or communicate with us. In cases of the Properties malfunctioning on your device, technical data may also include specific device information, such as the location of the file on your device.
e) We collect Profile Data. This includes your username, password, preferences, feedback and survey responses.
f) We collect Usage Data. This includes information about how you use the Properties, such as time spent playing and which games.
g) We collect Marketing and Communication Data. This includes your preferences in receiving marketing and communications from us and our third-party partners.
h) We collect Aggregated Data. This includes statistical or demographic data derived from all users’ Personal Data, but which is not considered Personal Data in the eyes of the law due to the fact that this data no longer can be used to directly or indirectly reveal your identity. May comprise information from the other data categories, but in an aggregated and anonymized fashion.
3.2 How we use your Personal Data and our legal basis
a) We process your Identity, Contact, Transaction, Profile, Usage, Marketing and Communications and Technical Data for the Purpose of delivering relevant Properties’ content as well as related advertisements to you and measure or understand the effectiveness of the advertising we serve you. Our legal basis for this processing is: Necessary for our Legitimate Interests (to define types of users and to keep the Properties updated and relevant and to develop our business and inform our marketing and growth strategy).
b) We process your Identity and Contact Data for the Purpose of registering you as a user of the Properties. Our legal basis for this processing is: Performance of a contract with you.
c) We process your Identity, Contact, Transaction, Technical, Usage, Profile and Marketing and Communications Data for the purpose of making suggestions and recommendations to you about games, new content and other services available through the Properties that may be of interest to you. Our legal basis for this processing is: Necessary for our legitimate interests (to develop the Properties and its related products and services).
d) We process your Identity, Contact, Transaction and Marketing and Communications Data for the purpose of processing payments, fees and charges, verifying your identity and details of your payment method or credit card account, communicating with you regarding related information. Our legal basis for this processing is: Performance of a contract with you, Necessary for our legitimate interests (to process payments and verification purposes).
f) We process your Identity, Contact, Technical and Usage Data for the purpose of administrating and protecting our business and our services such as support, reporting and hosting data, data analysis, system maintenance, testing and troubleshooting. Our legal basis for this processing is: Necessary to comply with a legal obligation, Necessary for our legitimate interests (for running our business, administering our CRM, providing administration and IT services, network security and to prevent fraud and in the context of a business reorganization or group reconstructing exercise).
g) We process your Identity, Contact, Usage, Marketing and Communications and Aggregate Data for the purpose of providing third party game developers with information about who engaged with their games and to what extent and to increase the value for both developers and players. Our legal basis for this processing is: Necessary for our legitimate interests (to provide increased value to exhibitors and attendees), Consent.
h) We process your Identity, Technical and Usage Data for the purpose of improving and correcting the Properties, bug-fixing, improving performance for different devices and operating systems, and to ensure optimal use. Our legal basis for this processing is: Necessary for the performance of a contract with you, Necessary for our legitimate interest (to ensure the functioning of the Properties which we provide, and ensure reasonable performance).
4. SHARING YOUR PERSONAL DATA
We share your Personal Data with the third parties as described below:
b) With vendors and partners engaged by Expansive Worlds to provide you with goods or services you have requested or online advertising selected by us;
c) To show to other users of the Properties such as usernames, leaderboards, and chat messages;
d) Third party service providers who have been appointed as data processors to perform functions and services on our behalf and who will be provided only with the necessary data to perform those services on our behalf, but who are not authorized to use such data for any other purposes (e.g. web hosting services, payment processing, information technology systems, customer relationship management, crash report analysis, publisher or developer revenue calculation and reporting, marketing, auditing and administration);
e) To our advisors or insurers in the event of a claim, dispute or otherwise when deemed necessary;
f) If we are required to do so by law or pursuant to legal process or to comply with any applicable rules or regulations (including, but not limited to, stock exchange market rules), or in response to a request from a law enforcement authority or other government official; and
Please note that any information, including Personal Data, that you reveal in a bulletin board, message board, chat room or other public forum is publicly viewable and accessible.
We may share Aggregated Data with our third-party publishers, developers and service providers. This Aggregated Data does not contain Personal Data and consists of statistics including but not limited to relating to usage of the Properties, event attendance and event participation.
5. TRANSFERS TO COUNTRIES OUTSIDE THE EU AND EEA
We transfer and share your information to third parties (including service providers operating on our behalf) which are located in countries outside the European Union (“EU”) and/or the European Economic Area (“EEA”) which may not have the same level of data protection laws as those in the country where you are located. When your data is sent to a country outside the EU/EEA that is not subject to an adequacy decision by the EU Commission, the transfers will only occur if we have entered into EU Commission approved standard contractual clauses with the receiving entity, which is deemed to offer sufficient safeguards with respect to the protection of the privacy and fundamental rights and freedoms of individuals, and we judge that your Personal Data enjoys equivalent protection as if in the EU/EEA.
6. KEEPING YOUR DATA SAFE
We implement the appropriate technical and organizational measures to ensure that your Personal Data is collected, processed and stored as securely as possible. However, there is no such thing as perfect security and complete online or offline security can never be guaranteed, so you should always take care when sharing your information online.
We have implemented various policies including pseudonymization, encryption, access and retention policies to guard against unauthorized access and unnecessary retention of Personal Data. We enforce contractual measures by way of non-disclosure agreements, data processing agreements and other contractual clauses designed to keep your Personal Data safe in accordance with the GDPR.
7. DATA RETENTION AND DELETION
The Properties are not directed to children under the age of 16. We do not knowingly collect Personal Data from children under 16 years old in the Properties or in connection therewith. If you are under 16 years, please do not use or access the Properties.
If we learn that we have collected and processed Personal Data of a child under the age of 16 years, we will take reasonable steps to ensure the erasure of the Personal Data from our systems. This may require us to delete the child’s account to the Properties.
9. HOW TO CONTACT US
Expansive Worlds AB
SE-10061 Stockholm, Sweden