Effective date:
1 September 2024
-
Privacy Policy
This Privacy Policy (
i
) explains how
Grindstone s.r.o.
, with its registered seat at Pekná 13, Košice 040 01, Slovakia, Identification No. (IČO): 48 258 121
(“
We
”or“
Us
”or“
Our
”), acting as a controller, treats personal data in relation to Our games, websites, and any other services or software developed or published by Us (the“
Services
”)
and (
ii
) presents Your respective rights
.
-
This Privacy Policy applies to everyone who uses the Services (the ”
User
”or“
You
”or“
Your
”).
-
What personal data We process
-
We may collect and further process the following types of personal data (
i
) provided directly by You or (
ii
) obtained from third parties, listed
in Section 7 and 8
, or (iii) automatically as You use the Services:
-
contacts (e.g. name, e-mail);
-
identifiers (e.g. Steam ID, user ID);
-
approximate location;
-
usage data (e.g. app interaction, other usage data);
-
user content (e.g. gameplay content, user support);
-
diagnostics (e.g. crash logs, performance data, other diagnostic data); and/or
-
We do not knowingly process any special categories of personal data (sensitive data).
-
We adhere to the principle of data minimization, and when collecting gameplay related data, We store only an encrypted version of Your Steam ID. This means We cannot directly determine the original Steam ID holder linked to gameplay related data. As a result, most gameplay related data remains non-personal data (We are unable to link specific data to your identity).
-
Why We process Your personal data (legal bases and purposes)
-
We process your selected personal data because you have given us consent for one or more specific purposes, and/or the processing is necessary for:
-
Performance of a Contract:
Ensuring the fulfillment of a contract to which you are a party, including any pre-contractual obligations.
-
Compliance with Legal Obligations:
Adhering to laws and regulations to which we are subject.
-
Public Interest Tasks:
Carrying out tasks in the public interest.
-
Legitimate Interests:
Pursuing the legitimate interests of us or a third party.
-
We process Your selected personal data to:
-
Deliver and maintain the Services you use.
-
Understand how you use our Services to improve user experience.
-
Enhance and develop our Services based on user feedback and analytics.
-
Address and resolve any questions or issues you may have.
-
Fulfill our legal duties and responsibilities.
-
Cooperate with legal authorities as required.
-
Protect against and prevent harmful or fraudulent activities.
-
Safeguard our interests or those of a third party.
-
We may anonymize and aggregate the analytics and statistics generated by your use of the Services. The resulting insights may be used for our research and development purposes.
-
If You have any questions or need further clarification regarding the legal bases and purposes for processing Your personal data, please feel free to contact Us at any time.
-
How long We process Your personal data
-
We process Your personal data for the period necessary to fulfill the purposes outlined in
this Privacy Policy, unless a longer retention is required by law or storing of the data is needed with respect to Our potential legal claims. Following termination or deactivation of
Your account, We may retain Your personal data for a commercially reasonable time for
backup purposes.
-
Where is Your personal data processed
-
Our primary place of business is Slovakia. However, Your personal data may be processed at any location where any third party stated in this Privacy Policy operates (Section
8
).
-
When transferring personal data originating in the European Economic Area (EEA) outside of the EEA, We always make sure to have in place appropriate safeguards, such
as adequacy
decision
adopted by the European Commission.
-
Protecting Your personal data
-
We take reasonable steps to protect Your personal data against unauthorized access or disclosure, considering the current state of technology and the scope, context, and purposes of data processing. Our protection measures include:
-
Encryption:
We use encryption to protect data during transmission and storage.
-
Access Controls:
Only authorized personnel can access Your personal data.
-
Regular Audits:
We conduct regular audits to ensure data protection compliance.
-
We encourage You to register with a strong password and keep it confidential.
-
Data from Third Parties
-
In addition to data collected directly from You, We may also process Your data obtained from third parties. This includes data shared by external platforms through which You access Our services
.
-
External Platforms.
Our Services may be accessed on external platforms such as Steam, PlayStation Network, and Xbox Network. These platforms may share Your personal data with Us according to their terms and conditions. Your data will be shared with Us only if You enable the collection of optional data on Your device. For instance, when You agree to the collection of diagnostic data on Your Xbox console, We may receive additional information concerning Your console's settings, performance, usage, and detailed error reports. We process this data in accordance with the terms stipulated by the platform operator.
-
Please be aware that external platform operators may also process Your data independently, in accordance with their own privacy policies and terms of service. We recommend reviewing the terms and privacy policy of the platform You are using for further information.
-
Sharing Your personal data
-
We will not share Your personal data with third parties without Your consent, except
as
stated in this Privacy Policy. When sharing data, We always adhere to the
need-to-know principle.
-
Parties with whom We may share Your personal data:
-
Unity Software Inc. (game engine provider);
-
Valve Corporation (Steam operator);
-
An updated list of these parties may be requested from Us at any time.
-
Furthermore, We may access, retain and share Your personal data to comply with legal requirements. We may also access, retain and share Your personal data when it is necessary to: detect, prevent and address fraud and other illegal activity; to protect ourselves, You and others, including as part of investigations. Information We receive about You may be retained for an extended period of time when it is the subject of a legal request or obligation, official investigation, or investigation concerning possible violations of Our terms or policies, or to prevent harm.
-
Your rights
-
In particular, You have the right to do the following, in accordance with applicable laws:
-
Ask Us to confirm whether or not We process Your personal data and if We do, to
what extent.
-
Access Your personal data by obtaining a copy of the data undergoing processing.
-
Verify the accuracy of Your personal data and ask for it to be updated or
corrected.
-
Withdraw Your previously given consent. Please note that withdrawal of Your consent does not affect the lawfulness of any processing done on the understanding that You had given the consent before.
-
Object to the processing if the processing is carried out on a legal basis other than consent.
-
Restrict the processing of Your personal data. If You approach Us with such a
request, We will limit processing of Your personal data to the necessary minimum. In case the restriction is lifted and We continue processing Your personal information, We will inform You accordingly without undue delay.
-
Have Your personal data deleted or otherwise removed. If You approach Us with such a request, We will delete Your personal data without undue delay. Your
personal data will be deleted accordingly, provided that it is no longer necessary for provision of the Services or there is no other legal ground for
the
processing.
-
Receive Your personal data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any obstacle.
-
If You exercise any of Your rights according to this Section or applicable laws, We
will
communicate any rectification or deletion of Your personal data or restriction of
processing in accordance with Your request to each recipient with whom the data has been shared (Section
6
of this Privacy Policy), unless such communication proves impossible or involves disproportionate effort.
-
Besides, if You no longer wish to receive marketing materials from Us or You do not wish that Your personal data is used for
profiling
related to the Services, You can request that We cease the use of Your personal data for these purposes. In such a case, You will no
longer be able to benefit from some of the Services or specific features for which this category of processing is essential. Users may opt out from certain advertising features through applicable app and/or device settings.
-
Children’s privacy
-
The Services are not directed at children under the age of 16. We do not knowingly collect or solicit any data from anyone under the age of 16. If You believe that We might have any personal data from or about a child under 16, please contact us.
-
Notice for California residents
-
We do not respond to Do Not Track signals.
We do not track the Users over time and
across third party websites or online services and We are not aware of any third party that would do so.
-
Changes to this Privacy Policy
-
We
reserve the right to modify or update this Privacy Policy from time to time. We hereby asks You to review the current version of this Privacy Policy periodically. Your
continued use of the Services after any change to this Privacy Policy will constitute Your acceptance of such change. Should any of the changes of this Privacy Policy require Your consent, We will contact You in order to obtain such consent.
-
Contacts
-
If You wish to exercise Your rights regarding Our data processing activities and/or
obtain/provide any relevant information, please contact Us at grindstone@grindstone.sk When exercising Your rights, please note that We will need to verify Your identity (confirm ownership of
the respective e-mail).
-
You have the right to lodge a complaint regarding Our data processing activities, whereas t
he competent supervisory authority is
the Office for Personal Data Protection
seated in
Slovakia, which can be contacted at:
statny.dozor@pdp.gov.sk
.