Your Data, Your Rights, Our Commitment
Last updated: March 15, 2024
1. Information We Collect
Personal Information
We collect personal information that you provide directly to us when using our services, including:
- Contact Information: Name, email address, phone number, company name, job title, and business address
- Account Information: Username, password, profile information, and account preferences
- Professional Information: Industry sector, company size, role responsibilities, and professional interests
- Communication Data: Records of communications with our support team, feedback, survey responses, and event participation
- Billing Information: Payment details, billing address, tax identification numbers, and transaction history
- Marketing Preferences: Communication preferences, subscription settings, and consent records
- Technical Support Data: System configurations, error logs, and troubleshooting information
Usage Information
We automatically collect information about how you interact with our platform and services:
- Platform Analytics: Feature usage patterns, session duration, click-through rates, and user journey mapping
- Technical Data: IP address, browser type and version, operating system, device identifiers, and screen resolution
- Performance Metrics: Page load times, error rates, system performance data, and API usage statistics
- Location Data: General geographic location based on IP address for service optimization and compliance
- Referral Information: Source of website visits, search terms used, and referring websites
- Interaction Data: Mouse movements, scroll patterns, and form interaction data for user experience optimization
- Security Logs: Login attempts, security events, and access patterns for fraud prevention
Game Analytics Data
Through our platform, we process game analytics data on behalf of our clients as a data processor:
- Player Engagement Metrics: Session length, retention rates, feature adoption, and behavioral patterns
- Game Performance Data: Technical performance metrics, crash reports, and system compatibility information
- Community Sentiment: Aggregated feedback data, review sentiment analysis, and community engagement metrics
- Revenue Analytics: Purchase patterns, monetization metrics, and economic performance indicators
- Update Impact Data: Patch performance metrics, content engagement rates, and version adoption statistics
- Competitive Intelligence: Market positioning data, industry benchmarks, and comparative performance metrics
- Predictive Modeling Data: Historical patterns used for forecasting and trend analysis
2. How We Use Your Information
We process your personal information for the following legitimate business purposes:
- Service Delivery: To provide, maintain, improve, and personalize our analytics platform and related services
- Account Management: To create and manage your account, process payments, and provide customer support
- Communication: To send service updates, security alerts, marketing communications, and respond to inquiries
- Platform Analytics: To analyze usage patterns, optimize performance, and develop new features
- Security and Compliance: To protect against fraud, ensure platform security, and comply with legal obligations
- Business Operations: To conduct internal research, business analysis, and strategic planning
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
- Marketing and Sales: To provide relevant content, conduct market research, and improve our marketing efforts
- Quality Assurance: To monitor service quality, conduct testing, and ensure optimal user experience
- Data Processing Services: To process game analytics data on behalf of our clients according to their instructions
- Advisory Services: To provide consulting, strategic recommendations, and custom analysis
3. Legal Basis for Processing
We process your personal information based on the following legal grounds:
- Contractual Necessity: Processing necessary for the performance of our contract with you
- Legitimate Interests: Processing necessary for our legitimate business interests, balanced against your rights
- Legal Compliance: Processing required to comply with legal obligations
- Consent: Processing based on your explicit consent, which you may withdraw at any time
- Vital Interests: Processing necessary to protect vital interests in emergency situations
- Public Task: Processing necessary for tasks carried out in the public interest
- Data Controller Instructions: Processing game analytics data according to client instructions as data processor
4. Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:
- Service Providers: With trusted third-party vendors who assist in operating our platform, processing payments, or providing support services
- Business Partners: With authorized partners for joint marketing initiatives or integrated service offerings, with your consent
- Legal Requirements: When required by law, court order, or government regulation, or to protect our rights and safety
- Business Transfers: In connection with a merger, acquisition, sale of assets, or other business transaction
- Consent-Based Sharing: With your explicit consent for specific purposes or with designated third parties
- Emergency Situations: To protect the vital interests of individuals in emergency circumstances
- Aggregated Data: Anonymized and aggregated data for industry research, benchmarking, and market analysis
- Client Data Processing: Game analytics data shared according to client instructions and data processing agreements
- Professional Advisors: With lawyers, accountants, and other professional advisors under confidentiality obligations
5. Data Security and Protection
We implement comprehensive security measures to protect your information:
- Encryption: Data encrypted in transit using TLS 1.3 and at rest using AES-256 encryption
- Access Controls: Multi-factor authentication, role-based access controls, and principle of least privilege
- Security Monitoring: 24/7 security monitoring, intrusion detection, and automated threat response
- Regular Audits: Annual security assessments, penetration testing, and compliance audits
- Employee Training: Comprehensive security awareness training and background checks for all personnel
- Incident Response: Documented incident response procedures and breach notification protocols
- Data Backup: Regular encrypted backups with tested disaster recovery procedures
- Vendor Management: Security assessments and contractual requirements for all third-party providers
- Physical Security: Secure data centers with biometric access controls and environmental monitoring
- Network Security: Firewalls, VPNs, and network segmentation to protect against unauthorized access
6. Data Retention and Deletion
We retain your information for as long as necessary to provide our services and comply with legal obligations:
- Account Information: Retained while your account is active and for 7 years after account closure for legal compliance
- Usage Analytics: Retained for up to 3 years for service improvement and trend analysis
- Communication Records: Retained for 5 years for customer service and legal compliance purposes
- Financial Records: Retained for 10 years as required by tax and accounting regulations
- Game Analytics Data: Retained according to client agreements and data processing terms
- Security Logs: Retained for 2 years for security monitoring and incident investigation
- Marketing Data: Retained until consent is withdrawn or for 3 years from last interaction
- Legal Hold Data: Retained as required by litigation holds or regulatory investigations
- Backup Data: Retained in encrypted backups for up to 1 year for disaster recovery purposes
7. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
- Right of Access: Request access to your personal information and details about our processing activities
- Right to Rectification: Request correction of inaccurate or incomplete personal information
- Right to Erasure: Request deletion of your personal information under certain circumstances
- Right to Data Portability: Request a copy of your information in a structured, machine-readable format
- Right to Object: Object to certain types of processing, including direct marketing
- Right to Restriction: Request restriction of processing under certain circumstances
- Right to Withdraw Consent: Withdraw consent for processing based on consent at any time
- Right to Lodge Complaints: File complaints with relevant data protection authorities
- Right to Opt-Out: Opt out of the sale or sharing of personal information (where applicable)
- Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place:
- Adequacy Decisions: Transfers to countries with adequacy decisions from relevant authorities
- Standard Contractual Clauses: Use of approved standard contractual clauses for international transfers
- Binding Corporate Rules: Implementation of binding corporate rules for intra-group transfers
- Certification Schemes: Participation in approved certification schemes and codes of conduct
- Derogations: Reliance on specific derogations for necessary transfers
- Data Processing Agreements: Comprehensive agreements with international service providers
- Transfer Impact Assessments: Regular assessments of transfer risks and mitigation measures
9. Children's Privacy
Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take immediate steps to delete such information and terminate any associated accounts.
Parents and guardians who believe their child has provided personal information to us should contact us immediately using the contact information provided below.
10. Automated Decision-Making and Profiling
We may use automated decision-making and profiling for the following purposes:
- Service Personalization: Automated recommendations for platform features and content
- Fraud Prevention: Automated systems to detect and prevent fraudulent activities
- Risk Assessment: Automated evaluation of account security and compliance risks
- Marketing Optimization: Automated targeting and personalization of marketing communications
- Quality Assurance: Automated monitoring of service quality and user experience
You have the right to request human intervention, express your point of view, and contest automated decisions that significantly affect you.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
- Email Notification: Sending notice to your registered email address
- Platform Notice: Displaying prominent notices within our platform
- Website Publication: Posting the updated policy on our website
- Direct Communication: Contacting you through other communication channels as appropriate
Your continued use of our services after the effective date of any changes constitutes acceptance of the updated Privacy Policy.
12. Contact Information
If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or need to report a privacy concern, please contact us:
Data Protection Officer: privacy@faelthorn.com
General Inquiries: contact@faelthorn.com
Phone: +48 508 446 265
Mailing Address:
PatchPulse Sp. z o.o.
Bronisława Jamontta 2c, 87-100 Toruń, Poland
EU Representative: Available upon request for EU residents
Response Time: We will respond to privacy requests within 30 days