PLUM GAMES PRIVACY POLICY GUIDELINES

1. OUR DETAILS AS THE DATA CONTROLLER

The provision of our games (hereinafter "Games" or "Game" or "App"), whether via websites or through various app stores, is brought to you by Plum Games Corporation Limited. (the "Data Controller" of your personal data). Consequently, "We", "Us" and "Ours" refers to the Data Controller.


We are based outside the European and American Economic Area and have nominated the following representative to promptly respond to any requests by our customers and relevant authorities via post (or just email us):


Name: Mr. Mao Wen Lee

Address: Room 1803, Tower I, New World Tower, Central And Western, 18, Queen's Road Central

Hong Kong


You may email Us with regards to queries of any nature (in particular, to exercise Your Rights) at maowenlee.loveg@gmail.com


2. WHAT PERSONAL DATA IS PROCESSED AND THE LEGAL BASIS FOR PROCESSING

There are different types of information we obtain, whether directly from you or automatically via your device when you use the App. Essentially, we only obtain what is strictly necessary to provide you with our services, no more, no less.


Information, relating to you or your device, is either identified automatically by Our systems, provided to Us by the operating system of your device or is input by you manually when filling out certain fields, authorizing certain actions in the Apps.


INFORMATION YOU PROVIDE US WITH:


a. Data automatically collected or generated.


When someone visits, interacts with or uses our Services, including any e-mail or text messages sent to them by us or via our Services, we may collect or generate technical data about them. We collect or generate such data either independently or with the help of third party services, including through the use of “cookies” and other tracking technologies.


Such data consists of connectivity, technical or aggregated usage data, such as IP address, in-game identifier, game statistics, game preferences, unique advertising ID (e.g. IDFA; you may reset such ID based on the operating system instructions ), non-identifying data regarding a device, operating system, browser or App version, mobile carrier, locale and language settings, user activity on our Services, in-App or Game activity (such as game play content/product interaction and advertising data); diagnostic data (i.e. crash data and game performance data). We do not use such data to learn a person’s true identity or contact details, but mostly to have a better understanding on how our users typically use and engage with our Services. The use of such technical and device data also helps us and our partners to deliver interest-based or otherwise more effective advertisements and content, to optimize our ad management and our users' viewing experience), and to improve the overall performance and your user experience of our Services.


- Legal basis for processing:

Performance of the contract.

The App would not operate otherwise, you need this to connect to the Internet.

This data is used only for technical purposes - that is, to ensure the proper functioning and security of the App and to investigate possible security incidents.

Your consent to the provision of such identifiers given by default through the operating system of your device (Apple or Android, for instance). You are free to withdraw your consent by resetting those identifiers or opting out of interest based advertising.

This may be done via the settings of your handset and/or your browser. We respect those choices you make through the settings of your device.

Our legitimate interests in fraud prevention and potential unauthorized access from multiple devices/locations, ensuring the technical availability and security of the App.

We need to know this technical information so the App functions properly on your device.


b. Data received from you.


You may provide us Personal Data voluntarily, such as when you set up an account with us, contact us (through Facebook, Messenger, e-mail, in-game chat or any other channel, including any support services), when you post on our public forums or groups, when you provide us your e-mail address (such as when you sign-up to receive e-mail updates or gifts), when you participate in competition, contest, tournaments and other promotions, when you place any purchases in any of our Games, when you interact with other users through the in-game chat or when you choose to connect your Facebook, Google, Apple, LINE or similar account to any of our Games.


- Legal basis for processing:

Performance of the contract with you. Unless you sign up via other means (SNS, see below), We could not provide you with our services as a logged in user other than through some means of unique identification. You may still access Our App as a guest and link your account later.


We may contact you for marketing purposes of similar products and/or services. It will be in Our legitimate interests to do so, but you will always have a chance to opt out of such marketing communications prior to any such communication.


We will store just enough information to honour your opt-out preference in the future.

Your consent at the time of provision of the same. You can always change or replace your name and avatar within the App settings.

Your consent to receive freebies on that special day each year. We do not store the year of your birth, only the DD.MM. so to minimize the extent of personal data We hold about you.


c. Data received from Facebook and other channels


Once you connect the Games to your Facebook, Google, Apple, LINE or similar account, we will receive access to your public profile, including (to the extent you defined it as “public”), as applicable, your full name, (e-mail address provided to Facebook or Google or Apple or LINE), gender, photo, locale, time zone, and a list of your friends playing the Games. This will also allow us to present your and your friends’ public profile pictures inside the Games and to create your in-game friends list. In addition, we or our advertising partners may receive from Facebook and our other marketing channels general information concerning the performance of our advertising campaigns, such as the targeted age group or interests, and we or our partners may be able to link such general data to any other data in our possession.


If you access our Services through a third party such as Facebook, Google or Apple or LINE or connect our Services to any third-party account, you should also read their terms and conditions and privacy policies. If you are unclear about what information a third-party application is sharing with us, please visit that third-party application's website in order to learn more about their privacy practices.


- Legal basis for processing:

Performance of the contract with you.

Same as above, We could not otherwise provide you with our services as a registered user.


d. Transaction Data


In-Game purchases will typically be processed by the relevant platform provider (e.g. Apple, LINE, Google or Facebook), and we will not collect or store your financial data, e.g. your credit card numbers or bank account. We may still however receive your non-financial Personal Data related to the purchase, such as your name, billing address, e-mail address and the items purchased, in order to fulfil your purchase and for our accounting purposes.



- Legal basis for processing:

Partly, performance of the contract and partly our legitimate interests in fraud prevention and potential unauthorized access, ensuring the technical availability and security of the App.

Analysis of statistical information helps us to optimize the App in future updates, such usage does not affect your rights and freedoms and does not disclose any personal data of yourself or your contacts.

Performance of contract to respond to your queries and provide customer support. We do not use this information for anything else (for instance, we do not build your profile or target you based on your communication with us or with other users of the App).



3. WHAT WE DO WITH YOUR PERSONAL DATA

We protect your data and do not treat your personal data in any way that would surprise you (unless We told you about it and you made an informed decision to consent to such usage).


For instance, We encrypt the password created by you at the sign up stage and then store your personal data on secure servers that would prevent unauthorized access or destruction of your personal data.


We use the advertising identifiers in strict compliance with the requirements of the operating systems (for otherwise We would be in breach of their usage terms). Thus, We only use those advertising identifiers to meet our contractual obligations towards the parties that brought you to Us and vice versa (whether by you clicking on an advertising banner in our partners' apps, watching the ad or otherwise).


Unless you have asked us not to, We may rarely contact you by email about similar products and services to the App. Whenever We contact you, We would always give you the right to opt out prior to the first communication and at any time thereafter (see the section "Your Rights" below).


The purposes for processing the data provided by you include:

  • Providing you with Our services
  • Fraud prevention
  • Improving our services
  • Notifying you of any changes in our services

4. HOW LONG PERSONAL DATA IS STORED FOR

Depending on the type, your personal data is stored either until you delete the App or after six months of inactivity. Some data (such as IP addresses or blacklisted email addresses used for fraud) may be held for longer in our legitimate interests to protect our business from losses and also to respect your choice of opt-outs from marketing emails.


We are required by law to delete any information that is no longer necessary to provide Service to you. We assume that if you have not used our App for over six months ("Period of Inactivity"), you have left us indefinitely. We will delete any Personal Data that we have in our possession following the Period of Inactivity. But do not worry, you are always welcome to use our App again if you decide to come back.


5. SECURITY MEASURES USED BY US

Your data is stored on one of the secure servers that we rent and We use the recommended industry practices to keep your data secure. We use appropriate level of technical and organizational measures to prevent accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to personal data transmitted, stored or otherwise processed.


We currently use Alibaba Cloud Computing and Amazon (the " Hosting providers") to store your personal data. Those Hosting providers are in possession of various international security certificates that ensure safety of your data with them. You can read more on the security measures of Hosting providers by following the links:


Alibaba Cloud Computing: https://video-intl.alicdn.com/ISO%2027001_ws.pdf?spm=a2c6n.8119612.389044.1.2bb86f05c2pePI&file=ISO%2027001_ws.pdf


Amazon: https://d1.awsstatic.com/certifications/iso_27001_global_certification.pdf


Thus, having the appropriate security with the Hosting providers when storing your data, We have to ensure that access to such data is provided on a need-to-know basis. Access to the Hosting providers is controlled via various technical and organizational measures that include:

  • Two-factor authentication to access the Hosting providers;
  • Following the principle of least privilege;
  • All servers and services are subject to continuous monitoring. This includes the logging of personal access in the user interface.
  • Each employee has access to the systems/services only via his/her own employee access. The access rights involved are limited to the responsibilities of the respective employee and/or team.

6. CATEGORIES OF RECIPIENTS AND DATA PROCESSORS

We do not share your personal data with any third parties, except where We have to comply with Our legal obligation. Some of the data of our users is aggregated for statistical purposes and processed in the legitimate interests as stated in section 2 above.


This does not mean that We blindly follow disclosure orders. We will check each request to ensure it satisfies the relevant safeguards, contains a court order or is issued under a legislative measure for the prevention, investigation, detection or prosecution of criminal offences.


As stated above, We share your advertising identifiers with third parties to meet our contractual obligations and pay their dues or protect ourselves against claims for payment.


7. TRANSFER OF YOUR DATA ABROAD

While your data may be accessed from different parts of the world on our behalf, We do not actually transfer your personal data outside the EEA. To any extent that data is accessed from abroad, We follow set contractual safeguards and protections to ensure that your data is as safe abroad as it is within the EEA.


Where a third party accesses your data on our behalf or upon our instructions (be it inside or outside the EEA), We use the relevant legal basis to comply with the data protection legislation. In cases where there is no finding of an adequacy decision by the European Commission, we use model contracts to safeguard your rights and data.


8. SOCIAL NETWORK SERVICES (SNS)

When you log in to use any of Our Apps via an SNS (such as Facebook) you provide Us with certain information from you profile for that site. The information provided via SNS varies and depends on a particular SNS (for instance, Facebook provides information on your name, age range, picture, gender, friends list and email address). You can untick the boxes for information you prefer not to share with us during the sign up process.


You can find out more about these settings at the SNS where you play Our App (for instance, you can edit the privacy and settings of your apps with Facebook by following the link https://www.facebook.com/help/218345114850283?helpref=about_content.


Your activity when playing the App via an SNS will also be subject to the SNS' privacy policy for their part of data processing.


9. YOUR RIGHTS

You are entitled to the full spectrum of the rights under the General Data Protection Regulation and We will go out of our way to accommodate any valid request. You can either exercise your rights by deleting certain features through your device or by emailing us at maowenlee.loveg@gmail.com to exercise all the other rights.


You have a wide array of rights that we respect. Among those the right to:

  • Require access to your personal data;
  • Require rectification of your personal data;
  • Require erasure of your personal data;
  • Withdraw consent to processing of your personal data, where applicable;
  • Lodge a complaint with your national supervisory authority (in the EEA) if you believe that your privacy rights have been breached

You may be required to provide certain proof of identify so that We do not disclose personal data to those that are not entitled to it.


If your personal data is erased at your request or in accordance with our data retention policy, We only retain such information that is necessary to protect our legitimate interests or to comply with a legal obligation.


Please note, all requests should be emailed to Us at maowenlee.loveg@gmail.com or sent to us by post. Due to the sheer volume of messages, in-App customer support messages cannot be regarded as an effective method of notice to Us.


10. DO NOT TRACK (California OPPA)

There is no consensus on how mobile application companies should interpret the DNT signals. For the purposes of the OPPA, We do not currently respond to DNT signals whether that signal has been received on a computer or a mobile device.


11. COOKIES AND SIMILAR TECHNOLOGIES

We use certain cookies when you visit Our Websites, but We give you an opportunity to choose which of those optional, non-essential cookies you would want to keep. Check the relevant cookie policy for the website you are visiting.


12. CHILDREN'S PRIVACY

We never knowingly collect or solicit any information from anyone of 18 years and younger. The App and its content are not directed at nor made look to appeal to such persons. Parents or guardians that believe that We hold information about their children aged 18 and under may contact Us at maowenlee.loveg@gmail.com


13. OUR COMMITMENT

  • We will only collect and use your data where We have a legal basis to do so;
  • We will always be transparent and tell you about how we use your information;
  • When We collect your data for a particular purpose, We will not use it for anything else without your consent, unless other legal basis applies;
  • We will not ask for more data than needed for the purposes of providing our services;
  • We will adhere to the data retention policies and ensure that your information is securely disposed of at the end of such retention period;
  • We will observe and respect Your rights (in section 8 above) by ensuring that queries relating to privacy issues are dealt with promptly and transparently;
  • We will keep our staff trained in privacy and security obligations;
  • We will ensure to have appropriate technological and organizational measures in place to protect your data regardless of where it is held;
  • We will also ensure that all of our data processors have appropriate security measures in place with contractual provisions requiring them to comply with Our commitment;
  • We will obtain your consent and ensure that suitable safeguards are in place before personal data is transferred to other countries.

14. CHANGES TO THE PRIVACY POLICY

We will always notify you via email or otherwise should we update this privacy policy. We will update the "last modified" date at the bottom of this privacy policy to indicate the latest revision, as well as the changes made.


If we decide to make material changes to our Privacy Policy, we will notify you by placing a notice on our websites or by sending you a notice to the e-mail address we have on file for you. We may supplement this process by placing notices in our Apps and websites. You should periodically check this privacy policy page for updates.


Plum Games Corporation Limited

Attention: Data Protection

Room 1803, Tower I, New World Tower, Central And Western, Hong Kong Island, 18, Queen's Road Central, Hong Kong

Support Team: maowenlee.loveg@gmail.com