OVERVIEW
Marios Karagiannis(“Karios Games”,”we”,”our”,”us”) takes the privacy of our customers (“Customer” or “you” or “your”) seriously. We recognise that privacy is an important issue, so we design and operate our services with the protection of your privacy in mind. This privacy policy (“Policy”) explains how your information is collected, used, and disclosed by Karios Games and its subsidiaries, and any parent and affiliated companies (“Karios Games”, “us” or “we”) with respect to the services referred to in this Policy. This Policy applies to the games listed in Appendix A of this policy (collectively the “games”). This Policy does not apply to websites, applications or services that display or link to different privacy statements.
HOW WE COLLECT AND USE INFORMATION
Via PlayFab:
- Karios Games complies with the PlayFab Acceptable Use Policy available at https://playfab.com/acceptable-use/ (the “Acceptable Use Policy”) which is incorporated herein by this reference and which may be updated from time to time.
- The PlayFab Services shall be subject to the Microsoft privacy statement available at https://privacy.microsoft.com/en-us/privacystatement. Karios Games agrees to the use of its data in accordance with Microsoft’s privacy statement.
- PlayFab will collect data from End Users through use of the PlayFab Services. All data (including all text, sound, video, or image files) that are provided to PlayFab through use of the PlayFab Service and all data PlayFab collects from our End Users through the use of the PlayFab Services is considered “Game Data.” PlayFab may use the Game Data for the purpose of providing, improving and adding new features to the PlayFab Services. PlayFab may also develop, use, distribute and publish information and statistics derived from the Game Data for use on an anonymized, aggregate basis; provided, that no such information will contain statistics or other information that is specifically attributable to the overall performance of the Games. This use of the Game Data will not result in the distribution or publication of any personally identifiable information.
- Karios Games agrees that we comply with all laws relating to privacy of End Users and will protect the privacy and legal rights of the End Users of our Game. By using our Game you (the end user) consent to transfer and use of data and information to PlayFab in connection with our Game and PlayFab Services, including but not limited to user names, passwords, or other login information or personal information. The data will be available for use by PlayFab.
- Game Data may be transferred to, and stored and processed in, the United States or any other country in which PlayFab, its Affiliates or its subcontractors operate. We appoint PlayFab to perform any such transfer of Game Data to any such country and to store and process personal data to provide the PlayFab services.
PlayFab GDPR Terms
The terms of this Section (the “GDPR Terms”) apply to the extent the Game Data includes information related to an identified or identifiable natural person that is subject to the European Union General Data Protection Regulation (the “GDPR”). Lower case terms used but not defined in this Addendum such as “personal data,” “personal data breach,” “processing,” “controller,” “processor,” “subprocessor” and “data subject” will have the same meaning as set forth in Article 4 of the GDPR. These GDPR Terms do not apply where PlayFab is a controller of the personal data of its customers.
- Compliance with the GDPR and Processing of Personal Data. Karios Games and PlayFab agree to comply with all applicable provisions of the GDPR. Karios Games agree we are the controller of personal data and PlayFab is the processor of such personal data, except when Karios Games acts as a processor of personal data, in which case PlayFab is a subprocessor. PlayFab will process personal data only on Karios Games’ documented instructions. Karios Games agrees that these Terms of Service, any other written Service Agreement with PlayFab, and Karios Games’ use and configuration of features in the PlayFab Services are Karios Games’ complete and final documented instructions to PlayFab for the processing of personal data. In any instance where the GDPR applies and Karios Games are a processor, Karios Games warrant to PlayFab that Karios Games’ instructions, including appointment of PlayFab as a processor or subprocessor, have been authorized by the relevant controller.
- Processing Details. We and PlayFab acknowledge and agree that:
a) the nature and purpose of the processing is to provide the PlayFab Service pursuant to these documented instructions;
b) the subject matter of the processing is limited to personal data within the scope of the GDPR;
c) the duration of the processing shall be for the duration of our right to use the PlayFab Service and until all personal data is deleted, or returned in accordance with our instructions;
d) the types of personal data processed by the PlayFab Service include those expressly identified in Article 4 of the GDPR;
e) the categories of data subjects are employees, contractors, collaborators, and End Users;
f) PlayFab will process and transfer the personal data only on these documented instructions, unless required to do so by the European Union or member state law to which PlayFab is subject; in such a case, PlayFab shall inform us of that legal requirement before processing (unless that law prohibits such information on important grounds of public interest); and
g) PlayFab will ensure that its personnel engaged in the processing of personal data (i) will comply with subsection (f) herein and (ii) have committed to maintain the confidentiality of any personal data even after their engagement ends.
3.Data Subject Rights; Assistance with Requests. PlayFab makes the personal data of data subjects available to us and provide us the ability to fulfill data subject requests under the GDPR, both in a manner consistent with the functionality of the PlayFab Service and PlayFab’s role as a processor. PlayFab shall comply with our reasonable requests to assist with our response to such a data subject request. If PlayFab receives a request from our data subject to exercise one or more of its rights under the GDPR in connection with a game for which PlayFab is a data processor or subprocessor, PlayFab will redirect the data subject to make its request directly to us. We will be responsible for responding to any such request, including, where necessary, by using the functionality of the PlayFab Service.
4. Records of Processing Activities and Reasonable Assistance. PlayFab shall maintain all records required by Article 30(2) of the GDPR and, to the extent applicable to the processing of personal data on our behalf, make them available to us upon request. PlayFab will provide us reasonable assistance in compliance with the obligations of Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to PlayFab.
5. Data Security. We and PlayFab implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia, as appropriate:
a) the pseudonymization and encryption of personal data;
b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and
d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.
PlayFab’s security measures will be set forth in a PlayFab Security Policy. PlayFab will make that policy available to us, along with descriptions of the security controls in place for the PlayFab Services and other information we reasonably request regarding PlayFab security practices and policies. We are responsible for making an independent determination as to whether the technical and organizational measures for the PlayFab Services meets our requirements. We acknowledge and agree that (taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing personal data as well as the risks to individuals) the security practices and policies implemented and maintained by PlayFab provide a level of security appropriate to the risk with respect to our personal data. We are responsible for implementing and maintaining privacy protections and security measures for components that we provide or control.
6. Notice and Controls on use of Subprocessors. PlayFab may hire third parties to provide certain limited or ancillary services on its behalf. PlayFab will provide us a list of subprocessors upon request. We consent to the engagement of these third parties and PlayFab Affiliates as subprocessors of personal data if such consent is required under law. PlayFab will inform us of new subprocessors it engages. We may object to new subprocessors by providing written notice to PlayFab that includes an explanation of the grounds for objection.
PlayFab is responsible for its subprocessor’s compliance with PlayFab’s obligations in these GDPR Terms. When engaging any subprocessor, PlayFab will ensure via a written contract that the subprocessor may access and use personal data only to deliver the services PlayFab has retained them to provide and is prohibited from using personal data for any other purpose. PlayFab will ensure that subprocessors are bound by written agreements that require them to provide at least the level of data protection required of PlayFab by this Addendum.
7. Personal Data Breach. PlayFab shall notify us without undue delay after becoming aware of a personal data breach. Such notification will include that information a processor must provide to a controller under Article 33(3) to the extent such information is reasonably available to PlayFab.
PlayFab shall make reasonable efforts to assist us in fulfilling our obligation to notify the relevant supervisory authority and data subjects of a personal data breach under Articles 33 and 34 of the GDPR.
8. Audit. PlayFab will conduct audits of its compliance with these GDPR terms as required by Article 28 of the GDPR. Each audit will be performed by qualified, independent, third party and/or internal security auditors at PlayFab’s selection and expense. Each audit will result in the generation of an audit report (“PlayFab Audit Report”), which PlayFab will make available to us upon request. The PlayFab Audit Report will be PlayFab’s Proprietary Information and will clearly disclose any material findings by the auditor. PlayFab will promptly remediate issues raised in any PlayFab Audit Report to the satisfaction of the auditor.
9. Transfer of personal data. We agree we are certified to the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks or have another legal transfer mechanism for the transfer of personal data in accordance with applicable law. All transfers of personal data to a third country or an international organization will be subject to appropriate safeguards as described in Article 46 of the GDPR and such transfers and safeguards will be documented according to Article 30(2) of the GDPR. PlayFab is certified to the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks and the commitments they entail. PlayFab agrees to notify us in the event that it makes a determination that it can no longer meet its obligation to provide the same level of protection as is required by the Privacy Shield principles.
Full terms of use of PlayFab can be found here: https://playfab.com/terms/
Via Skillz
The game may also include the Skillz SDK which supports the multiplayer functionality of the game. The privacy policy of Skillz can be found here: http://corp.skillz.com/privacy-policy/
For iOS devices that support this functionality, the privacy policy of Apple Pay is also included in the privacy policy of Skillz.
Customer User of Data other than PlayFab and Skillz:
Karios Games does not store data gathered through PlayFab service or Skillz. The aforementioned companies store and process all data according to their privacy policies detailed above.
HOW WE DISCLOSE OR SHARE INFORMATION WITH OTHERS
Except as described in this policy, we do not rent, sell, or share personally identifiable information collected through our applications with other people or nonaffiliated companies unless we have your consent, or under the following circumstances:
- to comply with laws or to respond to lawful requests and legal process;
- to protect the rights and property of Karios Games, our agents, customers, users, and others including to enforce our agreements, policies and terms of use;
- in an emergency to protect the personal safety of Karios Games, its customers, or any person;
- in connection with or during negotiation of any merger, sale of company assets, financing or acquisition of all or a portion of our business to another company.
We may also share aggregated or anonymized information in a form that does not directly identify you with any third parties.
INTERNATIONAL TRANSFER
We may, in the process of providing services to you, transfer information that we collect about you, to affiliated entities, or to other third parties across borders and from your country or jurisdiction to other countries or jurisdictions around the world. If you are located in the European Union or other regions with laws governing data collection and use that may differ from U.S. law, please note that you are transferring information and permitting the transfer of information,to a country and jurisdiction that does not have the same data protection laws as your jurisdiction, and you consent to the transfer of information to the U.S. and the use and disclosure of information about you as described in this Privacy Policy.
CHANGES TO THIS PRIVACY POLICY
We may change this Privacy Policy at any time. We will post all changes to this Privacy Policy on this page and will indicate at the top of the page the modified policy’s effective date.
CONTACT US
If you have any questions or suggestions regarding this Privacy Policy, please contact us at privacy@kariosgames.com
APPENDIX A: Games covered by this policy
- MonsterUp Colors for iOS