Last updated: 1 November 2018
This document explains how we collect, store and use information from you and how we will protect your privacy rights. It covers: (1) any of our websites, including http://improbable.io/ and any forums and social network or similar accounts; (2) any of our products or services (including SpatialOS) on any platforms; and (3) any of our products or services (including support services) which may be accessible via a web application, third party platform or social network.
Who are we?
Our Services are not intended for children and we do not knowingly collect data relating to children.
Information which we collect
The information we collect about you can include the following categories of personal data.
- “Account Data”: identity data such as your name and date of birth, your email address, the name of your organisation and any user name (such as a user account or forum user name) used to identify yourself in any Services
- “Payment Data”: financial/payments data which you provide for the purpose of paying for our Services (this may be stored and used by us or by our payment processors acting on our behalf)
- “Service Usage Data”: details of any digital platform accounts used to access our Services (e.g. your SteamID), any other information which you supply to us via the Services (including via any third parties), technical or other details about any device which you use to access the Services, including IP address, MAC address; Unique Device Identifier (UDID) or equivalent, operating system, browser type, engine type, and/or other hardware or software, details of your use of our Services including, but not limited to: navigation data, metrics information about when and how you use the Services, developer and non-developer generated logs, traffic data, and your geographical location data
- “Other Data”: other personal or business information you give us in order to help you with any queries or support matters via our forums, customer support services, or via any other means
How we use your personal data
We only use your personal data where we are allowed to by law. For example, this may include: (a) to notify you about changes to our Services; (b) to improve or modify our Services based on how you use them and to ensure that content from our Services is presented in the most effective manner for you; (c) where we need it to perform any contract we have with you; (d) for payment processing (either by us or by payment processors on our behalf); (e) to allow you to participate in interactive features of our Services; (f) where we need to use it for our legitimate interest (or those of a third party); g) where we need to comply with any legal or regulatory obligations; and (h) to prevent or detect fraud or abuse of our Services.
Where you wish to withdraw your opt-in consent for any direct marketing, you can use the unsubscribe button in the relevant email or email us at firstname.lastname@example.org.
Purposes for which we use your personal data
We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate and set these out in the description of how we use the data. We may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data.
|Type of data
||Description of how we use this data
||Lawful basis for processing
||To help you access and use the Software and Services and to ensure technical functionality of the above and to prevent any fraudulent use of the Software and/or Services
Performance of a contract
||To process any payments and to prevent or detect any fraudulent payment
||Performance of a contract
Compliance with legal obligations
|Service Usage Data
||To provide, personalise, and improve your experience with the Software or Service and other services and products provided by Improbable (including for third party products and services)
||Performance of a contract
||To provide customer support and/or communicate with you in relation to the Software or Services
Where we store your personal data
You agree that personal data we obtain from you and your users may be processed by our service providers, who may be based in countries outside of the EEA, for the purposes of providing you with the Software and Services. Such countries may not have laws offering the same level of protection for personal data as those inside the EEA. However, where such transfers of data occur we will take steps to prevent the transfer of personal data without adequate safeguards being put in place and will ensure that your and your users’ personal data collected in the EEA and transferred internationally is afforded the same level of protection as it would be inside the EEA. For further information on the adequate safeguards adopted by us for the international transfer of personal data, please contact email@example.com.
If you have a password which enables you to access certain parts of our Services, you are responsible for keeping this password confidential. Please don’t share it with anyone.
The transmission of information via the Internet is not completely secure. Although we will do our best to protect your personal information, we cannot guarantee the security of your data transmitted to our servers via any of our Services; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
Improbable takes cyber security seriously. We are committed to safeguarding our information and that which is entrusted to us by our partners. Our commitment is demonstrated through our award of a Cyber Essentials Plus badge.
How long will you use my personal data for?
We will only retain your personal data for as long as necessary to fulfil whatever purpose we collected it for. When we think about how long might be relevant, we’ll consider the amount, nature and sensitivity of your personal data as well as the potential risk of any unauthorised use or disclosure.
By law, we can keep different personal data for different periods of time. For example, we can keep certain basic information for six years after you stop being a customer for tax purposes.
Sharing your information with third parties
We may share your information with third party partners who work with us to provide the Services to you in order to support, improve or amend any Services. We may also share your information with partner data analysis and advertising services, our third party cloud service providers (such as Google Cloud or AWS), our professional advisers and HM Revenue and Customs.
Except with your consent, we do not disclose personal information about identifiable individuals to advertisers. We may provide them with aggregate and/or anonymised information about our users to help advertisers reach the kind of audience they want to target. We may make use of the information we have collected from you to enable us to comply with our advertisers’ wishes by displaying their advertisement to that target audience.
Please remember that any communications you have via our Services (or products using our Services) may reveal your screen name, other details about you and the content of any communications by you to other users. We are not responsible for the activities of other users or other third parties whom you choose to provide your information to or otherwise interact with (whether via our Services or otherwise).
Other ways in which we may share your information
We may disclose your personal information to any member of the Improbable Group. We may disclose your personal information to third parties if we sell or buy businesses or assets, in which case we may disclose your personal information to the prospective or actual seller or buyer of such business or assets. If we or substantially all of our assets are merged with or acquired by a third party, personal information held by us about our customers will be one of the transferred assets. We may share or disclose your personal information with third parties: (a) if we are under a legal duty to do so; (b) to enforce any terms and conditions applying to any of the Services; or (c) to protect our rights and property or the safety of our customers or others.
Links to third party sites
Our Services may, from time to time, contain links to and from the websites or services of partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites or services may have their own privacy policies and we do not accept any responsibility or liability for these policies, nor do we endorse such websites or services. We advise that you check any relevant terms before you submit any personal information to these third parties.
We are the data controller responsible for your data. If you are a European Union citizen, you have the following rights.
- Right of Access – the right to be informed of and request access to the personal data we process about you
- Right to Rectification – the right to request that we amend or update your personal data where it is inaccurate or incomplete
- Right to Erasure – the right to request that we delete your personal data
- Right to Restrict – the right to request that we temporarily or permanently stop processing all or some of your personal data
- Right to Object –
- the right, at any time, to object to us processing your personal data on grounds relating to your particular situation
- the right to object to your personal data being processed for direct marketing purposes
- Right to Data Portability – the right to request a copy of your personal data in electronic format and the right to transmit that personal data for use in another party’s service
- Right not to be subject to Automated Decision-making – the right to not be subject to a decision based solely on automated decision making, including profiling, where the decision would have a legal effect on you or produce a similarly significant effect
Please email us at firstname.lastname@example.org if you wish to exercise any of these rights. We will aim to respond to all legitimate requests as soon as we reasonably can and in any event within 30 days. If we think that it will take us longer than 30 days, we’ll let you know why and keep you updated. Where you make any requests, we might ask for specific information to confirm your identity as a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. This might include asking for further information in relation to your request to be able to speed up our response. Usually, you will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
It is important that the personal data we hold about you is accurate. Please let us know if your personal data changes.
We always appreciate the chance to answer any of your queries first but we should remind you that you have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk).