Last Updated: June 20, 2018
What Is Our Role Under the GDPR
The new European General Data Protection Regulation (GDPR) went into effect on May 25, 2018. It governs the way that businesses collect, use, and share personal data about individuals and requires businesses to process the data fairly and lawfully. The GDPR applies to all entities and individuals based in the EU and to entities and individuals, whether or not based in the EU, that process the personal data of EU individuals.
We only collect the information you choose to give us, and we process it with your consent, or on another legal basis. And no matter where you are, where you live, or what your citizenship is, we provide the same standard of privacy protection to all our users around the world, regardless of their country of origin or location.
When This Policy Applies
Who We Are
We are Chobolabs Inc. and we act as a data controller under the GDPR.
How Do We Collect and Use Information
Our primary goals in collecting information are to provide and improve our Services, to administer your use of the Services (including your Account, if you are an Account holder), and to enable you to enjoy and easily navigate our Services.
Account Information. If you choose to create an Account in connection with your use of the Services, we’ll collect certain information that can be used to identify you, such as your name, email address and phone number (“Personally Identifiable Information” or “PII”). We may also collect certain information that is not PII because it cannot be used by itself to identify you, such as your gender, date of birth and zip code. If you choose to create an Account through one of your SNS Accounts, you may have to provide us with your username (or userID) so that your identity can be authenticated by the SNS Account. When the authentication is complete, we’ll be able to link your Account with the SNS Account and access certain PII, such as your name and email address, and other PII that your privacy settings on the SNS Account permit us to access. We don’t receive or store passwords for any of your SNS Accounts.
Information Related to Use of the Services. Our servers automatically record certain information about how a person uses our Services (we refer to this information as “Log Data”), including both Account holders and non-Account holders (either, a “User”). Log Data may include information such as a User’s Internet Protocol (IP) address, browser type, operating system, the web page that a User was visiting before accessing our Services, the pages or features of our Services to which a User browsed and the time spent on those pages or features, search terms, the links on our Services that a User clicked on and other statistics. Also, if you use our App, we may also collect information related to your mobile device, such as model, operating system and resolution. We use this information to administer the Services and we analyze (and may engage third parties to analyze) this information to improve and enhance the Services by expanding their features. We also use the IP Address to generate aggregate, non-identifying information about how our Services are used.
Mobile Device Contact Information. If you choose to allow us access to your mobile device contacts via the App, we will use such contact information only to let you know if any of your contacts are using the Services to assist you and other Users in finding friends and contacts who use the Services. We will store this information until you delete your Account in accordance with the “Modifying Your Information” section below.
Inviting Friends to use the Services. If you wish to invite a friend to use the Services after you have become an Account holder, you may send your friend a message via the Services (i) via SMS or email, by inputting the friend’s mobile device telephone number or email address or by selecting the friend from your mobile device contacts, as applicable, (ii) by searching for friends on the Services or (iii) via your SNS Account. We will use the friend’s contact information only to facilitate your invitation and for no other purpose. Your friend can request that we remove his or her contact information from our database by contacting us at email@example.com.
Location Information. In some cases we collect and store information about where you are located, such as by converting your IP address into a rough geolocation. We may use location information to improve and personalize our Services for you.
What Information Do We Share with Third Parties
We will not share any PII that we have collected from you except as described below:
Users. If you choose to play the games made available via the Services, information related to your use of the games (e.g., ranking statistics, clan, clan description, clan members, clan statistics, list of friends on the Services) will be publicly viewable via the Services in connection with your nickname on the Services, name (first name and last name initial), profile avatar and personal description. Also, if you choose to engage in the chat or comment features of the Services, any User Content you make available in connection with these features will be viewable by other Users. We recommend that you guard your sensitive information.
Information Shared with Our Services Providers. We may engage third party service providers to work with us to administer and provide the Services. These third-party services providers have access to your PII only for the purpose of performing services on our behalf and are expressly obligated not to disclose or use your PII for any other purpose.
Information Shared with Third Parties. We may share aggregated information and non-identifying information with third parties for industry analysis, demographic profiling and other similar purposes.
Information Disclosed in Connection with Business Transactions. Information that we collect from our users, including PII, is considered to be a business asset. As a result, if we go out of business or enter bankruptcy or if we are acquired as a result of a transaction such as a merger, acquisition or asset sale, your PII may be disclosed or transferred to the third-party acquirer in connection with the transaction.
Information Disclosed for Our Protection and the Protection of Others. It is our policy to protect you from having your privacy violated through abuse of the legal systems, whether by individuals, entities or government, and to contest claims that we believe to be invalid under applicable law. However, it is also our policy to cooperate with government and law enforcement officials and private parties. Accordingly, we reserve the right to disclose any information about you to government or law enforcement officials or private parties as we, in our sole discretion, believe necessary: (i) to satisfy or comply with any applicable law, regulation or legal process or to respond to lawful requests, including subpoenas, warrants or court orders; (ii) to protect our property, rights and safety and the rights, property and safety of third parties or the public in general; and (iii) to prevent or stop activity we consider to be illegal or unethical.
Information We Disclose With Your Consent or at Your Request. We will share your PII with third-party sites or platforms, such as your SNS Accounts, if you have expressly requested that we do so.
Legal Basis for Processing Personally Identifiable Information (EEA Persons Only)
If you are from the European Economic Area, our legal basis for collecting and using the PII described above will depend on the Information concerned and the specific context in which we collect it.
However, we will normally collect and use PII from you where the processing is in our legitimate interests and not overridden by your data-protection interests or fundamental rights. Typically, our legitimate interests include improving, maintaining, providing, and enhancing our products and services; ensuring the security of the Services and our Websites; and for our marketing activities.
In some limited cases, we may also have a legal obligation to collect PII from you.
If we ask you to provide Information to comply with a legal requirement or to perform a contact with you, we will make this clear at the relevant time and advise you whether the provision of your Personally Identifiable Information is mandatory or not, as well as of the possible consequences if you do not provide your PII.
The Security of Your Information
We take reasonable measures to protect the information that we collect from or about you (including your PII) from unauthorized access, use or disclosure. Please be aware, however, that no method of transmitting information over the Internet or storing information is completely secure. Accordingly, we cannot guarantee the absolute security of any information.
Links to Other Sites
Modifying Your Information
You can access and modify the PII associated with your Account from within the Mayhem App. If you want us to delete your PII and your Account, please contact us at firstname.lastname@example.org with your request. We’ll take steps to delete your information as soon as is practicable, but some information may remain in archived/backup copies for our records or as otherwise required by law.
We retain Information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax, or accounting requirements).
When we have no ongoing legitimate business need to process your PII, we will either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your PII and isolate it from any further processing until deletion is possible.
Your PII may be transferred to, and maintained on, computers located outside of your state, province, country or other governmental jurisdiction where the privacy laws may not be as protective as those in your jurisdiction. If you’re located outside the United States and choose to provide your PII to us, we may transfer your PII to the United States and process it there.
Our Policy Toward Children
Our Services are not directed to children under 13 and we do not knowingly collect PII from children under 13. If we learn that we have collected PII of a child under 13 we will take steps to delete such information from our files as soon as possible.