Pocket Gems Privacy Policy (for the EU/EEA)

Last revised: 25 May 2018

Pocket Gems, Inc., including its affiliates, Episode Interactive, LLC and Hype Bits, Inc., provides this Privacy Policy to inform you of our policies and procedures regarding the processing of Personal Data of users of (i) the websites located at http://pocketgems.com, https://episode.social/https://forums.episodeinteractive.com, https://home.episodeinteractive.com, https://www.episodeinteractive.com/
and https://wardragons.com/ (the “Sites“), including any services, features and content accessible or downloadable from the Sites, and (ii) any other Pocket Gems application, service or product licensed, downloaded or otherwise accessed by such users through third party websites or sources ((i) and (ii) collectively, the “Service”).

We are committed to protecting and respecting your privacy. This Privacy Policy (“Policy”) describes how we treat information that you provide to us or that we collect about you.

By “Personal Data”, we refer to data that relates to you as an identified or identifiable natural person. Personal Data include your name, your address, your telephone number, your email address, your age, your gender, or a part of your credit card number, for instance. Anonymous information, which we are not in a position to relate to you, does not qualify as Personal Data.

1. Controller’s name and contact details

Controller in the sense of the General Data Protection Regulation (GDPR) and other data protection or data privacy laws in the Member States of the European Union or the European Economic Area and other guidelines with a data protection nature regarding the Services is:

Pocket Gems, Inc.

220 Montgomery St., #750

San Francisco, CA 94104

United States of America

Phone: 415-371-1333

Email: privacy@pocketgems.com

The Controller is called “Pocket Gems”, “we”, “our” and “us” in this Policy.

The Representative of Pocket Gems pursuant to Art. 27 can be contacted at privacy@pocketgems.com.

2. Contact details of the Data Protection Officer (DPO)

The Data Protection Officer of Pocket Gems may be contacted at dpo@pocketgems.com.

3. General information on our data processing

We process Personal Data with your consent, when necessary for the performance of a contract with you, when processing is necessary for compliance with a legal obligation we are subject to, or based on our legitimate interests, except where such interests are overridden by the interests or fundamental rights and freedoms of you which require the protection of your Personal Data. This section applies to all detailed processing activities listed below.

3.1 Information Security

We and our employees understand the need for user privacy, and we maintain reasonable and appropriate security procedures to protect your information from loss, misuse and unauthorized access, disclosure, alteration and destruction, taking into due account the risks involved in the processing and the nature of the Personal Data. However, no security system is impenetrable, and we cannot guarantee the security of our systems or your information.

3.2 Information Sharing

We may share Personal Data with vendors or agents working on our behalf for the purposes described in this Policy. Any vendor or agent that we retain must comply with our data privacy and security requirements and are not allowed to use Personal Data they receive from us for any other purpose. We use service providers for cloud hosting, security monitoring and enforcement, advertising, marketing, recruiting, product testing, customer service, social networking and data analytics.

We may also share your Personal Data:

  • with other parties in connection with a company transaction, such as a merger, sale of company assets or shares, reorganization, financing, change of control or acquisition of all or a portion of our business or assets by another company or third party, or in the event of a bankruptcy, dissolution, or related or similar proceedings
  • as required by law or subpoena or if we reasonably believe that such action is necessary to comply with the law or the reasonable requests of law enforcement, to enforce our Terms of Service (https://pocketgems.com/terms-of-service/) or other agreements or to protect the security or integrity of our Sites and Services, and/or to exercise or protect the rights, property, or personal safety of Pocket Gems, our users, or others
  • among our affiliates, which may include companies owned by or under common ownership of Pocket Gems, all of which will be required to use your personal information as described in this Policy

3.3 Third country transfers

We transfer Personal Data to the following third countries:

Recipients Third countries Legal safeguards of Recipient
Host Provider USA DPAs, Privacy Shield
App Distributors USA DPAs, Privacy Shield
Advertising Partners USA DPAs, Privacy Shield
Customer Support Provider USA DPAs, Privacy Shield
Customer Support Agents Canada DPAs

To receive a copy of the respective safeguards, please contact us at privacy@pocketgems.com.

3.4 Children

We will not knowingly collect personal information from any child, or process such information, without parental consent. For the purpose of this Policy, a child means any individual who is under the age of 16 (or the minimum legal age to consent to the collection and processing of personal information where this is different under applicable law).

3.5 Retention periods

We will retain your Personal Data only as long as it is necessary to fulfill the respective purpose, unless we are required by law to store your Personal Data longer. After you have terminated your use of our Service, we may store your information in an aggregated and anonymised format. Notwithstanding the foregoing, we may also retain any Personal Data as reasonably necessary to comply with our legal obligations, allow us to resolve and litigate disputes, and to enforce our agreements.

3.6 Automated Decision-Making

We do not use automated-decision making, including profiling.

4. Use of our Site

On our Sites, we gather information either directly from you (e.g., when you provide certain information to us) or indirectly (e.g., through our Site’s technology).

4.1. Information collected indirectly

We indirectly collect a variety of information through your interaction with and use of our Sites. This information may include, but is not limited to, browser settings, data collected through automated electronic interactions, application usage data, demographic information, geographic or geo-location information, statistical and aggregated information (“Other Information”). The processing is necessary for the purpose of our legitimate interests in accordance with Article 6(1)(f) of the GDPR, as we need this information to keep user data safe by detecting certain threats, and to provide you with the best possible experience.

Statistical or aggregated information does not directly identify a specific person, but it may be derived from Personal Data. For example, we may aggregate Personal Data to calculate the percentage of users in a particular country.

If we combine Other Information with Personal Data, we will treat the combined information as Personal Data.

4.1.1 Tracking Data

Website traffic volume and patterns, such as the number of visitors to a given website or page on a daily basis is typically referred to as “Tracking Data”. This type of indirectly collected information is gathered through various means, such as an IP address, which is a number that is automatically assigned to your computer whenever you are surfing the Web. Web servers, the computers that “serve up” web pages, automatically identify your computer by its IP address. When you visit any of our Sites, our servers log your computer’s IP address.

To obtain these Tracking Data, we may use third party analytics providers. The Third Party Analytics Providers use “Cookies”, which are text files placed on your computer, to help us analyse how users use our Sites. The information generated by the Cookie about your use of our Sites, including your IP address, will be transmitted to and stored by Third Party Analytics Providers’ servers. On our behalf, the Third Party Analytics Providers will use this information for the purpose of evaluating your use of our Sites, compiling reports on website activity, and providing other services relating to website activity. The Third Party Analytics Providers will not associate your IP address with any other data held by them. Our third party analytics tool is provided by Google. You may learn how to opt-out from Google’s collection of information from you at https://tools.google.com/dlpage/gaoptout. You may also find further information at http://www.google.com/analytics/learn/privacy.html.

4.1.2 Our Cookies

Other types of indirectly collected information are stored in Cookies from us.

Some of our Sites use Cookies simply to store your account details so that you do not need to re-enter your information when re-joining our Sites. The use of Cookies is standard on the internet. Although most Web browsers automatically accept cookies, the decision of whether to accept or not is yours. You may adjust your browser settings to prevent the reception of cookies, or to provide notification whenever a cookie is sent to you. You may refuse the use of cookies by selecting the appropriate settings on your browser. However, please note that if you do this, you may not be able to access the full functionality of our Sites.

4.1.3 Third-party Cookies

Additionally, we may use third-party advertising companies to serve ads on our behalf. These companies may use cookies and action tags to measure advertising effectiveness. You can still decide whether you want to accept these cookies. You may adjust your browser settings to prevent the reception of third-party cookies, or to provide notification whenever such third-party cookies are sent to you. We use the following third-party cookies:

You may find a list of all cookies used on our site.

4.2. Information collected directly

We also collect Personal Data and other information that you voluntarily provide. It is entirely your decision to provide the requested information. However, certain features of our Sites may not be available in this case.

We keep all information collected directly confidential, and will only use the information for the particular purpose it is collected for. We will seek your specific permission for any additional use. We will never barter, trade, or sell access to your information without your specific consent.

4.2.1 User Accounts

When setting up an account on one of our Sites (“User Account”), you may be asked to provide Personal Data including, but not limited to, your name, email address, and your phone number.

As a user of our Sites, we may obtain your Personal Data when you register to use one of our Sites or services and products or when you provide feedback about our products or services. The processing is necessary to perform the contract with you according to Article 6(1)(b) of the GDPR. As a user, we will use your Personal Data, unless otherwise prohibited by law, for the following purposes:

  • To provide you with the products and services you request.
  • To communicate with you about your account or transactions with us and send you information about features on our sites or changes to our policies.
  • To provide support including, but not limited to, product updates, product patches and fixes and other similar communications.

Furthermore, we will use your Personal Data for our legitimate interests according to Article 6(1)(f) of the GDPR to notify you about information about features on our Sites, new product releases and service developments and to advertise our products and services in accordance with this Policy.

Any User Account data will only be stored until you decide to terminate your User Account. In case we are obliged to further store your Personal Data due to statutory retention requirements, your Personal Data will be barred for further use by us and only stored until such retention periods expire.

4.2.1 Personal Data provided by other means

Personal Data provided by you on our Sites by other means, e.g., via contact forms, will be stored in our service database and retained for the period necessary to fulfill our contractual obligations to you in accordance with Art. 6(1)(b) of the GDPR, unless a longer retention period is required by law.

5. Our casual app games

When playing our casual games, we gather certain Personal Data. This section applies to the following games:

  • Animal Voyage
  • Animal Voyage Android
  • Campus Life
  • Campus Life Android
  • Hidden Agendas
  • Runway Life
  • Secret Passages: Hidden Objects
  • Secret Passages: Hidden Objects Android
  • Tap Paradise Cove
  • Tap Paradise Cove Android
  • Tap Pet Hotel
  • Tap Pet Hotel Android
  • Tap Pet Shop
  • Tap Zoo
  • Tap Zoo Android

When you are playing one of the listed games, we process your IP address, your name and email address, your username, your in-game purchase history, your MAC address and other unique IDs, data about your device, and metrics on how you use our games.

We will also process any photos that you might share with our user support through the app, and any information you enter into free text fields, including chat messages. We will also process game events, like achievements, milestones or other timestamps within the game.

The Personal Data is necessary for us to provide you with the games and the full functionality. The legal basis for processing the data is our contract with you (Art. 6(1)(b) of the GDPR). Where the processing exceeds the necessity to fulfill our contract (when analysing how you use our game), the legal basis is our legitimate interest (Art. 6(1)(f) of the GDPR) to improve your experience with the game.

When you log into our game with your Facebook credentials, Facebook will share your registered email address with us. However, using your Facebook credentials is no requirement to use our games.

6. “Cliffhanger – Chat Stories”

When you are playing “Cliffhanger – Chat Stories”, we process your IP address, your in game purchase history, your MAC address and IMEI number, as well as your, interests and other demographic data (as this is necessary for the experience of the game).

Providing these Data is a contractual obligation, as we cannot provide you the game without this information. Our legal basis for processing the Personal Data is to perform our contract with you (Art. 6(1)(b) of the GDPR). We need this information to provide you with the game, and to identify you as our player.

We will also process any photos that you might share with our user support through the app, and any information you enter into free text fields, including chat messages. We will also process game data, like time spent on certain pages viewed, referring pages, and other analytics data.

Where the processing exceeds the necessity to fulfill our contract (e.g., when analysing how you use our game), the legal basis is our legitimate interest (Art. 6(1)(f) of the GDPR) to improve your experience with the game.

We might use your IP address and advertising IDs to send you direct marketing within the game, based on our legitimate interest (Art. 6(1)(f) of the GDPR). You have the right to object at any time to processing of your Personal Data for such marketing, including profiling.

7. “Episode Apps”

7.1 Users

When you are playing Episode Apps, we may process your IP address, your name and email address, your username, your phone number postal/billing address, your MAC address, IMEI number, data on the device used, and your in game purchase history. Providing these Data is a contractual obligation, as we cannot provide you the game without this information. Our legal basis for processing the Personal Data is to perform our contract with you (Art. 6(1)(b) of the GDPR).

We will also process any photos that you might share with our user support through the app, and any information you enter into free text fields, including chat messages. We will also process game events, like achievements, milestones or other timestamps within the game.

The Personal Data is necessary for us to provide you with the games and the full functionality. The legal basis for processing the data is also our contract with you (Art. 6(1)(b) of the GDPR).

We will also process data on how you use our website, including any referring URLs, search terms entered, and usage data. Where the processing exceeds the necessity to fulfill our contract (when analysing how you use our game), the legal basis is our legitimate interest (Art. 6(1)(f) of the GDPR) to improve your experience with the game.

When you log into our game with your Facebook or Google credentials, these providers will share your registered email address with us. However, using such credentials is no requirement to use our games.

We might use your email address to send you direct marketing, based on our legitimate interest (Art. 6(1)(f) of the GDPR). You have the right to object at any time to processing of your Personal Data for such marketing, including profiling.

7.2 Writers for Episode

When you are a writer for certain stories within the game (“Writer”), we will process additionally your billing address to the information you provide to us.

If you are a writer who enters our “Writer Payments” program, then we also process your name, e-mail, phone number, postal/billing address, your payment details, and your tax ID or other government-issued ID.

Providing this information is a contractual obligation, as we otherwise cannot fulfill our contractual obligations to our Writers. The legal basis for the processing is the performance of our contract with the respective Writer (Art. 6(1)(b) of the GDPR).

8. “War Dragons”

When you are playing “War Dragons”, we process your IP address, your email address and username, your password or other credentials to log into the game, your in game purchase history, your MAC address and IMEI number.

Providing these Data is a contractual obligation, as we cannot provide you the game without this information. Our legal basis for processing the Personal Data is to perform our contract with you (Art. 6(1)(b) of the GDPR). We need this information to allow you to log into the game, and to identify you as our player.

We will also process any photos that you might share with our user support through the app, and any information you enter into free text fields, including chat messages. We will also process game data, like time spent on certain pages viewed, referring pages, and other analytics data.

We will not process the content of your communication of other players within the game, other than providing messages to these players. We will store information on your team or league affiliation.

Where the processing exceeds the necessity to fulfill our contract (e.g., when analysing how you use our game), the legal basis is our legitimate interest (Art. 6(1)(f) of the GDPR) to improve your experience with the game.

We might use your email address to send you direct marketing, based on our legitimate interest (Art. 6(1)(f) of the GDPR). You have the right to object at any time to processing of your Personal Data for such marketing, including profiling.

9. Your rights

You have the right to access your Personal Data that we hold about you and to correct, update, amend, suppress, delete or otherwise modify any Personal Data where it is inaccurate, or has been processed in violation of the applicable data protection regulations, unless we have to keep the Personal Data for legitimate business or legal purposes. When updating your Personal Data, we may ask you to verify your identity before we can act upon your request.

You may object to the use or processing of your Personal Data or withdraw consent to use your Personal Data at any time.

You have the following rights:

  • The right to require free of charge (i) information whether your Personal Data is retained and (ii) access to and/or (iii) duplicates of the Personal Data retained. However, if the request affects the rights and freedoms of others or is manifestly unfounded or excessive, we reserve the right to charge a reasonable fee (taking into account the administrative costs of providing the information or communication or taking the action requested) or refuse to act on the request;
  • The right to request proper rectification, removal or restriction of your Personal Data;
  • Where processing of your Personal Data is based on legitimate interests according to Article 6(1)(f) of the GDPR, the right to object on grounds relating to your particular situation at any time. If you object we will no longer process your Personal Data unless there are compelling and prevailing legitimate grounds for the processing or the data is necessary for the establishment, exercise or defence of legal claims;
  • Where processing of your Personal Data is either based on your consent or necessary for the performance of a contract with you and processing is carried out by automated means, the right to receive the Personal Data concerning you in a structured, commonly used and machine-readable format or to have your Personal Data transmitted directly to another company, where technically feasible (data portability);
  • Where the processing of your Personal Data is based on your consent, the right to withdraw your consent at any time without impact to data processing activities that have taken place before such withdrawal or to any other existing legal justification of the processing activity in question; and
  • The right not to be subject to any automatic individual decisions which produces legal effects on you or similarly significantly affects you.

To exercise the rights referred to above, please contact us at privacy@pocketgems.com. You may take legal actions in relation to any breach of your rights regarding the processing of the Personal Data, as well as to lodge complaints before the competent authority.

10. Changes to this Policy

We may change this Policy at any time by posting the changed or modified version of the Privacy Policy on the Site. Any such changes or modifications will be effective immediately upon posting. If we make any changes to this Privacy Policy, we will change the Last Revised date above.