Back to Home

Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your information.

Effective Date: December 24, 2024 | Last Updated: December 24, 2024 | Version: 3.0 (Global Compliance Enhanced)

1. Introduction

Welcome to Casual Game Studio ("we," "our," or "us"). We are committed to protecting your privacy and ensuring transparency about how we handle your personal information. This Privacy Policy explains our practices regarding the collection, use, disclosure, and protection of your information when you use our games, websites, and services.

This policy applies to all our games, websites, and services (collectively, "Services"). By using our Services, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide Directly

2.2 Information Collected Automatically

2.3 Information from Third Parties

3. How We Use Your Information

We use the collected information for the following purposes:

3.1 Service Provision

3.2 Communication

3.3 Improvement and Analytics

3.4 Legal and Security

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds under the General Data Protection Regulation (GDPR):

4.1 Contract Performance (Article 6(1)(b) GDPR)

We process your personal data when necessary to perform our contract with you or to take steps at your request before entering into a contract. This includes:

4.2 Legitimate Interests (Article 6(1)(f) GDPR)

We process your personal data based on our legitimate interests, which we have balanced against your rights and freedoms. Our legitimate interests include:

You have the right to object to processing based on legitimate interests at any time.

4.3 Consent (Article 6(1)(a) GDPR)

We obtain your explicit consent for:

You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

4.4 Legal Obligation (Article 6(1)(c) GDPR)

We process your personal data to comply with legal obligations, including:

4.5 Vital Interests (Article 6(1)(d) GDPR)

In rare circumstances, we may process your personal data to protect your vital interests or those of another person, such as in emergency situations.

4.6 Public Task (Article 6(1)(e) GDPR)

This legal basis does not typically apply to our processing activities.

5. Information Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

5.1 Service Providers

We may share information with third-party service providers who help us operate our Services, such as:

5.2 Legal Requirements

We may disclose information if required by law or in response to:

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.

6. Data Retention

We retain your information for as long as necessary to:

We will delete or anonymize your personal information when it is no longer needed, unless we are required to retain it by law.

7. Your Rights and Choices

7.1 Rights for EEA, UK, and Swiss Residents (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under GDPR:

7.1.1 Right of Access (Article 15 GDPR)

You have the right to obtain from us confirmation as to whether or not personal data concerning you is being processed, and if so, access to the personal data and the following information:

7.1.2 Right to Rectification (Article 16 GDPR)

You have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you. You also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

7.1.3 Right to Erasure ('Right to be Forgotten') (Article 17 GDPR)

You have the right to obtain from us the erasure of personal data concerning you without undue delay where one of the following grounds applies:

Note: This right does not apply where processing is necessary for compliance with a legal obligation, for the performance of a task carried out in the public interest, or for the establishment, exercise, or defense of legal claims.

7.1.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to obtain from us restriction of processing where one of the following applies:

7.1.5 Right to Data Portability (Article 20 GDPR)

You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller where:

We will provide the data in JSON or CSV format upon request.

7.1.6 Right to Object (Article 21 GDPR)

You have the right to object, on grounds relating to your particular situation, to processing of personal data concerning you which is based on legitimate interests. We shall no longer process the personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms or for the establishment, exercise, or defense of legal claims.

Direct Marketing: You have the absolute right to object to the processing of your personal data for direct marketing purposes at any time.

7.1.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Currently, we do not engage in automated decision-making that produces legal effects or similarly significantly affects you.

7.1.8 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

7.1.9 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement if you consider that the processing of personal data relating to you infringes GDPR.

EU Supervisory Authorities: A list of supervisory authorities is available at: https://edpb.europa.eu/about-edpb/board/members_en

7.2 How to Exercise Your Rights

To exercise any of your rights under GDPR, please contact us at luu.hui.ting@gmail.com with the following information:

Response Time: We will respond to your request within one month of receipt. In complex cases, we may extend this period by up to two additional months, and we will inform you of any such extension within the first month.

Free of Charge: We will not charge a fee for exercising your rights unless your request is manifestly unfounded or excessive, particularly if it is repetitive.

7.3 General Access and Control

All users, regardless of location, have the right to:

7.4 Marketing Communications

You can opt out of marketing communications at any time by:

7.5 California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

7.5.1 Categories of Personal Information We Collect (CCPA)

In the past 12 months, we have collected the following categories of personal information:

7.5.2 Sources of Personal Information

7.5.3 Business Purposes for Collection

7.5.4 Sale and Sharing of Personal Information

We do not sell your personal information for monetary consideration. However, under the broad CCPA definition, some data sharing with advertising partners may be considered a "sale" or "sharing." You can opt-out of this by contacting us.

7.6 Virginia Privacy Rights (VCDPA)

If you are a Virginia resident, you have rights under the Virginia Consumer Data Protection Act (VCDPA):

7.7 Colorado Privacy Rights (CPA)

If you are a Colorado resident, you have rights under the Colorado Privacy Act (CPA):

7.8 Connecticut Privacy Rights (CTDPA)

If you are a Connecticut resident, you have rights under the Connecticut Data Privacy Act (CTDPA):

7.9 Canadian Privacy Rights (PIPEDA)

If you are a Canadian resident, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA):

7.10 Brazilian Privacy Rights (LGPD)

If you are a Brazilian resident, you have rights under the Lei Geral de Proteรงรฃo de Dados (LGPD):

7.11 Singapore Privacy Rights (PDPA)

If you are a Singapore resident, you have rights under the Personal Data Protection Act (PDPA):

7.12 Australian Privacy Rights

If you are an Australian resident, you have rights under the Privacy Act 1988:

7.13 South African Privacy Rights (POPIA)

If you are a South African resident, you have rights under the Protection of Personal Information Act (POPIA):

7.14 Japanese Privacy Rights

If you are a Japanese resident, you have rights under the Act on Protection of Personal Information (APPI):

8. Children's Privacy

8.1 Age Restrictions

Our Services have different age restrictions depending on your location:

8.2 Parental Consent

Where required by law, we obtain verifiable parental consent before collecting personal information from children. Parents may:

8.3 Limited Data Collection from Children

When we collect information from children (with appropriate consent), we:

8.4 Parental Rights and Controls

Parents and guardians can contact us at luu.hui.ting@gmail.com to:

8.5 School and Educational Context

If our services are used in an educational context, we may rely on schools to obtain appropriate consent from parents. We work with schools to ensure compliance with applicable laws including FERPA (Family Educational Rights and Privacy Act) in the United States.

9. International Data Transfers

Your personal data may be transferred to, stored, and processed in countries other than your country of residence. These countries may have different data protection laws than your country.

9.1 Transfers from the EEA, UK, and Switzerland

When we transfer your personal data outside the European Economic Area (EEA), United Kingdom, or Switzerland, we ensure an adequate level of protection for your personal data by implementing appropriate safeguards:

9.1.1 Adequacy Decisions

We may transfer your data to countries that have been deemed by the European Commission to provide an adequate level of data protection. Currently, these include:

9.1.2 Standard Contractual Clauses (SCCs)

For transfers to countries without an adequacy decision, we use Standard Contractual Clauses approved by the European Commission. These are contractual commitments between companies transferring personal data, binding them to protect the privacy and security of your data.

9.1.3 Additional Safeguards

Where appropriate, we implement additional technical and organizational measures to ensure the security of your data, including:

9.2 Your Rights Regarding International Transfers

You have the right to:

9.3 Specific Transfer Scenarios

We may transfer your data internationally in the following scenarios:

10. Security and Data Breach Notification

10.1 Security Measures

We implement comprehensive technical and organizational measures to protect your information:

10.1.1 Technical Safeguards

10.1.2 Organizational Safeguards

10.2 Data Breach Notification

In the event of a personal data breach, we will:

10.2.1 Regulatory Notification

10.2.2 Individual Notification

We will notify affected individuals without undue delay when a breach is likely to result in a high risk to their rights and freedoms. Notifications will include:

10.2.3 Breach Response Process

  1. Detection and Assessment: Immediate investigation and risk assessment
  2. Containment: Steps to prevent further unauthorized access
  3. Notification: Regulatory and individual notifications as required
  4. Investigation: Root cause analysis and impact assessment
  5. Remediation: Corrective actions and system improvements
  6. Documentation: Comprehensive record-keeping of the incident

10.3 Security Limitations

While we implement industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously work to improve our security posture.

11. Cookies and Similar Technologies

11.1 What Are Cookies

Cookies are small text files that are placed on your device when you visit our website or use our services. We also use similar technologies such as web beacons, pixels, and local storage.

11.2 Types of Cookies We Use

11.2.1 Strictly Necessary Cookies

These cookies are essential for the operation of our website and services. They enable basic functions such as page navigation and access to secure areas. The website cannot function properly without these cookies.

11.2.2 Performance and Analytics Cookies

These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously.

11.2.3 Functional Cookies

These cookies enable enhanced functionality and personalization, such as remembering your preferences and settings.

11.2.4 Marketing and Advertising Cookies

These cookies are used to deliver advertisements that are relevant to you and your interests. They may also be used to limit the number of times you see an advertisement and measure the effectiveness of advertising campaigns.

11.3 Cookie Consent and Management

We obtain your consent before placing non-essential cookies on your device, as required by applicable law. You can manage your cookie preferences through:

11.4 Browser Settings

Most web browsers allow you to control cookies through their settings preferences. However, if you limit the ability of websites to set cookies, you may impact your overall user experience.

11.5 Third-Party Cookies

Some cookies on our website are set by third-party services. We have no control over these cookies, and you should check the relevant third party's website for more information about their cookies and how to manage them.

12. Artificial Intelligence and Automated Decision-Making

12.1 Use of AI Technologies

We may use artificial intelligence and machine learning technologies to:

12.2 Automated Decision-Making

We may use automated decision-making processes, including:

12.3 Your Rights Regarding Automated Decisions

You have the right to:

12.4 AI Training and Data Use

We may use aggregated and anonymized data to train and improve our AI systems. This includes:

13. Biometric Data and Sensitive Information

13.1 Biometric Data

Currently, we do not collect biometric data (fingerprints, facial recognition, voice prints, etc.). If we introduce biometric features in the future, we will:

13.2 Sensitive Personal Information

We generally do not collect sensitive personal information such as:

13.3 Special Category Data (GDPR)

If we process special category data under GDPR, we will:

14. Third-Party Services and Integrations

Our Services may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you use.

14.1 Third-Party Service Providers

We work with the following categories of third-party service providers:

14.2 Data Processing Agreements

We enter into data processing agreements with our service providers that include:

14.3 Social Media Integration

Our services may integrate with social media platforms. When you interact with these features:

14.4 Third-Party Analytics and Advertising

Third-party analytics and advertising services may collect information through:

You can opt-out of interest-based advertising through:

15. Data Protection Impact Assessments (DPIA)

15.1 When We Conduct DPIAs

We conduct Data Protection Impact Assessments when processing is likely to result in high risk to individuals, including:

15.2 DPIA Process

Our DPIA process includes:

  1. Description: Detailed description of processing operations and purposes
  2. Necessity Assessment: Evaluation of necessity and proportionality
  3. Risk Assessment: Identification and assessment of risks to individuals
  4. Mitigation Measures: Measures to address identified risks
  5. Consultation: Consultation with stakeholders and data subjects where appropriate
  6. Review: Regular review and updating of assessments

15.3 Prior Consultation

If a DPIA indicates high risk that cannot be mitigated, we will consult with the relevant supervisory authority before beginning processing.

16. Records of Processing Activities

16.1 Processing Records

We maintain records of our processing activities including:

16.2 Record Availability

These records are available to supervisory authorities upon request and form the basis of our accountability under GDPR and other privacy laws.

17. Updates to This Policy

17.1 Policy Updates

We may update this Privacy Policy from time to time to reflect:

17.2 Notification of Changes

When we make changes, we will:

17.3 Material Changes

For material changes that significantly affect your rights or how we process your data, we may:

17.4 Acceptance

Your continued use of our Services after any changes constitutes acceptance of the updated policy. If you do not agree with the changes, you may discontinue use of our Services and request deletion of your data.

18. Contact Us

Data Controller

Company: Casual Game Studio

Email: luu.hui.ting@gmail.com

Data Protection Officer: luu.hui.ting@gmail.com

Response Time: We will respond to your privacy-related requests within 30 days (1 month under GDPR).

For EU/EEA Residents

EU Representative: If we are required to appoint an EU representative under Article 27 GDPR, their contact details will be provided here.

Supervisory Authority: You have the right to lodge a complaint with your local data protection authority if you are not satisfied with our response.

Lead Supervisory Authority: We will update this section with our lead supervisory authority information if applicable.

For UK Residents

UK Representative: If we are required to appoint a UK representative under UK GDPR, their contact details will be provided here.

UK Supervisory Authority: Information Commissioner's Office (ICO) - https://ico.org.uk/

For Swiss Residents

Swiss Representative: If we are required to appoint a Swiss representative, their contact details will be provided here.

Swiss Supervisory Authority: Federal Data Protection and Information Commissioner (FDPIC) - https://www.edoeb.admin.ch/

For California Residents

To exercise your CCPA rights, please contact us using the information above and specify which right you wish to exercise. We do not discriminate against consumers who exercise their CCPA rights.

How to Contact Us

When contacting us about privacy matters, please include:

  • Your full name and email address
  • The specific request or concern
  • Your country/region of residence
  • Any relevant account information (without passwords)

19. Definitions and Glossary

19.1 Key Terms

19.2 Legal Frameworks

19.3 Technical Terms

This Comprehensive Global Privacy Policy (Version 3.0) is effective as of December 24, 2024.

This policy provides comprehensive compliance with global privacy regulations including:

  • ๐Ÿ‡ช๐Ÿ‡บ GDPR (European Union General Data Protection Regulation)
  • ๐Ÿ‡ฌ๐Ÿ‡ง UK GDPR (United Kingdom General Data Protection Regulation)
  • ๐Ÿ‡จ๐Ÿ‡ญ Swiss DPA (Swiss Data Protection Act)
  • ๐Ÿ‡บ๐Ÿ‡ธ CCPA/CPRA (California Consumer Privacy Act & Privacy Rights Act)
  • ๐Ÿ‡บ๐Ÿ‡ธ VCDPA, CPA, CTDPA (Virginia, Colorado, Connecticut Privacy Acts)
  • ๐Ÿ‡จ๐Ÿ‡ฆ PIPEDA (Personal Information Protection and Electronic Documents Act)
  • ๐Ÿ‡ง๐Ÿ‡ท LGPD (Lei Geral de Proteรงรฃo de Dados)
  • ๐Ÿ‡ธ๐Ÿ‡ฌ PDPA (Personal Data Protection Act)
  • ๐Ÿ‡ฆ๐Ÿ‡บ Privacy Act 1988 (Australian Privacy Principles)
  • ๐Ÿ‡ฟ๐Ÿ‡ฆ POPIA (Protection of Personal Information Act)
  • ๐Ÿ‡ฏ๐Ÿ‡ต APPI (Act on Protection of Personal Information)
  • ๐Ÿ‡บ๐Ÿ‡ธ COPPA (Children's Online Privacy Protection Act)

Key Enhancements in Version 3.0:

  • โœ… Comprehensive coverage of 12+ global privacy laws
  • โœ… Detailed AI and automated decision-making policies
  • โœ… Enhanced data breach notification procedures
  • โœ… Biometric data and sensitive information protections
  • โœ… Expanded children's privacy safeguards
  • โœ… Data Protection Impact Assessment (DPIA) framework
  • โœ… Detailed processing records and accountability measures
  • โœ… Advanced security and technical safeguards

Contact Information: For any questions about this Privacy Policy, please contact us at luu.hui.ting@gmail.com

Legal Compliance: This policy has been designed to meet or exceed the requirements of the world's most stringent privacy regulations, ensuring your data is protected regardless of your location.