Privacy Policy
Welcome! This is our Privacy Policy, which describes how we collect and process personal and non-personal data. If you have any questions about this policy, you may reach out to us at privacy@puzzlebox.se.
This document was last updated on 2022/11/24.
About us
Puzzlebox Studios AB ("Puzzlebox Studios", "Puzzlebox", "we", "us"), with organization number 559401-8060, is a privately owned company incorporated under the laws of Sweden, whose main business activity is the development and publishing of entertainment products in formats including, but not limited to, mobile device software, personal computer software, home video game console software, websites, and web applications. Any inquiries about the company not relating to this policy may be directed to contact@puzzlebox.se.
Summary
This policy describes
- How we collect data about you, as a user of our products.
- What kind of data we collect.
- When and where we collect this data.
- How this data is used by us and by any third parties, where applicable.
- The purpose of the collection
When interacting with products and services provided by us ("Products", "Services"), including but not limited to current and future websites such as puzzlebox.se ("Websites"), current and future apps and games such as Fruit Mash™ ("Apps", "Games"), we will collect and store some data about you, the user. The purpose of this data collection and the usage of the data is explained in this policy.
The data we collect may be divided into two types:
- Personal Data: this is personal data which may be used to identify the user as an individual. Such data includes, for example, first and last name, email address, birth date, and similar information about the user.
- Non personal data: this is data generated by the user which does not in and of itself, partially or as a whole, identify any particular individual. Such data includes, for example, activity logs describing actions taken by the user when interacting with an application or website, dates and times when the user interacted with an application or website, and similar information.
Puzzlebox Studios does not collect any Personal Data about you, the user, unless the collection of such data is necessary in order for us to provide you with a specific service or functionality. In each case where the collection of Personal Data is necessary, the type of data being collected and the purpose of collection will be provided to you, the user, along with a link to this policy, and consent will be requested before the collection of said data may commence. In each case, you may opt out from using the specific service or functionality before any Personal Data is collected.
Many of our apps and games incorporate advertisements that are shown to you, the user, from time to time. By collecting an identifier that is unique to your device, a so called "advertising identifier", we, through our advertising partners, are able to provide you with personalized ads. The usage of such an identifier to tailor your experience based on your previous activity elsewhere is generally referred to as "tracking". As this requires the collection of Personal Data (the advertising identifier), we will always ask for your consent before serving you with personalized ads.
When you use our apps, play our games, or interact with any of our websites, we collect non personal data of the following kinds:
- Anonymous usage data: data describing actions taken by you within the app, game, or website, along with the time and date of the action. Does not contain any information that identifies you as an individual. This data is used solely for the purposes of improving the Products and services that we provide.
- Anonymous performance data: data containing information about the general performance of the app, game, or website while running on your device, as well as information about performance-related events such as application crashes, freezes, or other errors. This data may include general information about any devices and/or web browsers that the app, game, or website runs on, but does not include any information that identifies you as an individual. This data is used solely for the purposes of improving the products and services that we provide.
We adhere to the GDPR (General Data Protection Regulation), and as a matter of principle apply the same rules to all our users, no matter their country of origin. Among other things, this means that you, the user, have the right to have your data rectified, erased, or restricted, as well as the right to request access to your data, and to object to our usage of your personal data. These rights are explained in greater detail in the following sections. If you would like to exercise these rights, please contact us at privacy@puzzlebox.se.
Glossary
- Products / Services: (used interchangeably) any product or service provided by us with which you interact, such as an app, game or website.
- Data Subject: an individual who we collect data about. In the context of this policy, this is you, the user.
- Data Controller: this is us. We control the data that we collect in the sense that we decide how to process it.
- Processing (of data): a more general term for handling data: using, storing, and transferring all classify as processing data.
- Data Processor: a third party who performs data processing on our behalf.
Applicability
This policy applies to any person whose data is processed by Puzzlebox Studios in any capacity. This includes anyone who
- Uses any of our Apps or Games,
- Visits any of our Websites, or
- Comes into contact with us via any other media, such as by email, telephone, or social media.
Furthermore, this policy applies at any time when Puzzlebox Studios processes the data of any person or persons as outlined in the paragraph above, and shall continue to apply for as long as said data continues to be processed.
Legal grounds for processing of personal data
All processing of personal data must adhere to rules and regulations in order to be lawful. Puzzlebox Studios relies on principles laid out in GDPR Article 6 - Lawfulness of processing to support our processing of personal data. The applicable principles are given further detail below.
Consent:
Our processing of personal data is lawful if the Data Subject (in this case you, the user) has consented to the processing, and the specific purpose(s) of the processing.
Therefore, when consent to process personal data is given, we shall only use the personal data for the purposes which you have agreed to. Should the need to use the same personal data for other purposes arise, new consent will be requested.
Performance of contract:
Our processing of personal data is lawful if it is necessary for the performance of a contract in which the Data Subject (in this case you, the user) is a party.
This applies, for instance, when you enter into an agreement to receive or use a service provided by us which relies on the processing of your personal data. An example of this would be if you created a user account within one of our Apps or Games, which would require us to process your contact information (email and/or username) in order to provide you with the account and login services.
Legal obligation:
Our processing of personal data is lawful if it is required by law under the jurisdiction in which we operate, or if we are otherwise legally compelled to do so.
This applies to, for example, the keeping of financial records for taxation purposes (if and when such records contain personal data).
Legitimate interest:
Our processing of personal data is lawful if it serves our legitimate interests. In short, this means that:
- There is a clear benefit to the processing of the personal data.
- The processing of the personal data does not impact the privacy of the Data Subject (in this case you, the user).
- The Data Subject should reasonably expect that their data will be processed in this way.
This applies to, for example, the usage of transaction records to prevent fraud, or the usage of network access logs to prevent abusive behaviour.
It is important to note that the interests or the fundamental rights and freedoms of the Data Subject takes precedence. If you have reason to believe that our legitimate interests for processing is overridden by your interests or fundamental rights and freedoms, you have the right to object to our processing of your data under the condition of legitimate interest. To do so, please reach out to us at privacy@puzzlebox.se.
Your rights
The GDPR establishes several rights that the Data Subject (in this case you, the user) has in relation to the Data Controller (in this case us). These rights are meant to help you maintain control over your data, and to gain transparency into how it is used, and by whom. GDPR only applies to citizens of the European Union, but we apply these rights equally to all our users, no matter where they originate from. In this section, we outline the rights which you have as a user of our Services.
Note that not all rights established in the GDPR are applicable. For instance, we do not perform any automated decision making or profiling based on your personal data without explicit consent; therefore, GDPR Article 22 does not apply.
Right to be informed
These two articles together describe the right to be informed. What this means is that you, as a Data Subject, have the right to be informed about what personal data we, as the Data Controller, process about you, and the purpose and legal grounds of that processing. This includes both personal data collected directly by us from you (GDPR Article 13), and personal data retrieved from third parties about you (GDPR Article 14).
This policy serves to inform you of what data we collect about you, both directly and indirectly, along with the purpose and legal grounds of that processing. Should any additional processing of personal data occur, not described herein, we will notify you separately.
Right of access
As a Data Subject, you have the right of access. In short, this means that you may request from us the following information:
- Confirmation as to whether or not we process any personal data about you
- The purposes of the processing
- The types of personal data being processed
- The source of the personal data
- Who your personal data has been shared with
If you would like to exercise this right, contact us at privacy@puzzlebox.se. Note that, in order to service your request, we require that you provide us with a means of identification and sufficient proof of identity. See the explanation on this below.
Right to rectification
As a Data Subject, you have the right to rectification. In short, this means that you may request that we update any personal data we have that you believe to be correct or incomplete in any way.
If you would like to exercise this right, contact us at privacy@puzzlebox.se. Note that, in order to service your request, we require that you provide us with a means of identification and sufficient proof of identity. See the explanation on this below.
Right to erasure
As a Data Subject, you have the right to erasure (also known as the "right to be forgotten"). In short, this means that you may request that we delete any personal data we store about you. Additionally, we are obliged to delete your data if:
- You withdraw your consent or object to processing (which would be equivalent to requesting that your data be deleted),
- It is no longer necessary to keep it in order to serve the purpose for which it was originally collected,
- The legal grounds upon which we rely in order to process your data are found to be invalid, or have ceased to apply, or
- We are legally compelled to do so
If you would like to exercise this right, contact us at privacy@puzzlebox.se. Note that, in order to service your request, we require that you provide us with a means of identification and sufficient proof of identity. See the explanation on this below.
Right to restriction of processing
As a Data Subject, you have the right to restriction of processing. In short, this means that you may request your personal data to be restricted, in the sense that it may not be used for any purpose without your consent, while still being stored by us. This right is only applicable under certain circumstances:
- If you contest the accuracy of the personal data. If so, the personal data may be restricted until such time that the accuracy of the data can be verified.
- If the processing of your personal data should be unlawful, but you do not want it to be erased. Note that we do not process any data unlawfully under normal circumstances, as per this policy, but this case would apply if, for example, you withdraw your consent to processing, and no other legal grounds to justify our processing of your data.
- We no longer need your personal data, but they are required by you for the establishment, exercise or defence of legal claims, and must therefore not be deleted.
- You have objected to processing, and the outcome of your objection has not yet been established.
If you would like to exercise this right, contact us at privacy@puzzlebox.se. Note that, in order to service your request, we require that you provide us with a means of identification and sufficient proof of identity. See the explanation on this below.
Right to data portability
As a Data Subject, you have the right to data portability. In short, this means that you have the right to receive a copy of your personal data in a standardized machine-readable format. You may also choose to have it directly transmitted to another party, where that is technically feasible.
If you would like to exercise this right, contact us at privacy@puzzlebox.se. Note that, in order to service your request, we require that you provide us with a means of identification and sufficient proof of identity. See the explanation on this below.
Right to object
As a Data Subject, you have the right to object. In short, this means that you have the right to object, based on your particular situation, to any processing of your personal data that we perform, provided that that processing is based solely on the principle of legitimate interest. In other words, it does not apply if you have consented to the processing (which is generally the case).
If you would like to exercise this right, contact us at privacy@puzzlebox.se. Note that, in order to service your request, we require that you provide us with a means of identification and sufficient proof of identity. See the explanation on this below.
Means of identification and sufficient proof of identity
If you wish to exercise any of the above listed rights, we require that you provide us with the following along with your request:
- A means of identification: this is something that identifies who the request pertains to, and is something that we can use to find your personal data with. This could be an email address, a device identifier, a username, or similar.
- Sufficent proof of identity: this is something that establishes beyond reasonable doubt that you, as the individual making the request, are the legitimate owner of the personal data being requested. This will depend on the means of identification. For instance, if the means of identification is an email address, then it may suffice to submit the request from that same email address, provided that the authenticity of the email can be verified. If the means of identification is a device identifier, then any documentation that constitutes proof of ownership of that device will suffice.
This is necessary in order for us to be able to guarantee that your personal data does not fall into the wrong hands, or is otherwise accessed by unauthorized individuals.
If you are unsure what consititutes a valid means of identification or sufficient proof of identity in your case, don't hesitate to reach out and ask. You may also submit your request without this information, in which case we will do our best to help you determine what would constitute valid means of identification and sufficient proof of identity in your particular case.
Who we share your data with
- We have your consent to do so.
- To comply with your instructions.
- It is necessary in order to provide you with the Services.
- The data has been sufficiently anonymized or aggregated, to the extent that you may not be personally identified.
- We are legally required to do so, under the laws and regulations of any of the jursdictions in which we operate.
We store and process all data that we collect on servers owned and operated by Google within the European Union, but some of the third parties which we have engaged as Data Processors and share your data with may operate in jurisdictions outside the European Union. Some of these countries may not have the same protection laws as those within the European Union, but we take steps in order to ensure that your data is sufficiently protected, such as requiring that these companies have adequate privacy policies and adhere to EU model agreements (Standard Contractual Clauses) which have been pre-approved by the European Commission.
The following is a list of companies that we share data with.
Company | Types of data shared | Purpose |
---|---|---|
Device Identifiers 1 , Usage logs, Purchase history, Location data | Storage, Analytics | |
Unity Technologies | Device Identifiers 1 , Usage logs | Ads, Analytics |
IronSource | Device Identifiers 1 | Ads |
How long we keep your data
The duration Puzzlebox Studios stores your data depends on the type of data and its usage.
- Data used to provide you with a Service: Some of the services which we provide you requires the collection and use of personal data. This data will be retained by us for as long as is necessary in order to provide you with the service, and for as long as we have your consent to do so.
- Data used by us to improve our products: When you interact with any of our products, we may collect some usage data in order to improve the product. This data is retained up to a maximum of twelve months.
- Data used for compliance and/or legal reasons: In instances where we are required to retain a copy of your data for compliance and/or legal reasons, we shall do so only to the extent and duration that is required by us in order to fulfill our legal obligations.
Third Party Links
The Services that we provide may include links to third party content, such as
- Clickable Advertisements
- Links to social media
- Links to third party websites, apps or games
Puzzlebox Studios is not responsible for the content of these links, nor are we responsible for how your data will be processed by the companies that provide the services that these links direct you to, should you choose to visit them. Furthermore, the fact that we include a link to a third party does not mean that we endorse that third party in any way.
In each case, we ask that you review the privacy policy of the company responsible for the content of any third party links, and direct any questions or concerns about your privacy to them.
Security
Puzzlebox Studios adheres to industry standard security practices in order to safeguard our internal systems and the data we store. All our systems are built on verified technologies, receive regular security updates, and runs in secure environments managed by our trusted infrastructure partners.
In addition to this, we employ the principle of least privilege for our internal processes. This means that no person or entity is granted more privileges than required to fulfill its intended role or function. In other words, each individual or entity that needs access to protected data in order to carry out its intended role or function is only able to access the specific data required for the role or function to be carried out. This principle ensures that sensitive data is not unintentionally shared with unauthorized parties, even if they are otherwise trusted.
Minors
The privacy of minors is regulated under several different laws and regulations, such as GDPR and COPPA. Which regulations apply depends on the country of origin of the minor. Puzzlebox Studios complies with these laws by not offering any of our Services to children under the minimum age, as established by the applicable regulations. The minimum age varies by country, and is listed in the table below. If you are under the minimum age listed for your country, we ask that you do not interact with any of our Services.
Countries | Minimum Age |
---|---|
Croatia, Germany, Hungary, Ireland, Luxembourg, Netherlands, Poland, Romania, Slovakia, Slovenia, Switzerland | 16 |
Czech Republic, France, Greece | 15 |
Austria, Bulgaria, Cyprus, Italy, Lithuania, Spain, | 14 |
Belgium, Denmark, Estonia, Finland, Latvia, Malta, Norway, Portugal, Sweden, United Kingdom | 13 |
Rest of the world | 13 |
Puzzlebox Studios does not knowingly collect or process personal data of any person under the ages listed above. If you have reason to believe that we possess the personal data of a child under the minimum ages listed above, please reach out to us at privacy@puzzlebox.se.
Complaints
If you have any concerns regarding how we process your data, you may
- Reach out to us directly at privacy@puzzlebox.se. We take your privacy very seriously and are happy to answer any questions you may have.
- Submit a complaint to your local data protection authority. A list of data protection authorities may be found here.
Thank you!