1. Data Controller
Insightplaymingl Interactive Oy ("we", "our", "us") is the data controller responsible for your personal data when you use insightplaymingl.live and its associated services. Our offices are located at Mannerheimintie 44 A, 00260 Helsinki, Finland.
2. Personal Data We Collect
We collect the following categories of personal data:
- Account Information: username, email address, date of birth, encrypted password.
- Technical Data: IP address, browser type and version, time zone, operating system, device identifiers.
- Usage Data: game sessions, spin history, XP progression, feature interactions, navigation paths.
- Communications: support tickets, email correspondence, contact form submissions.
- Marketing Preferences: opt-in status for newsletters and promotional content.
3. How We Use Your Data
We process your personal data to:
- Provide, operate, and maintain the Service and your account.
- Track XP, dynasty tier progression, and virtual rewards.
- Analyze gameplay patterns to improve game balance and user experience.
- Respond to support requests and communicate service updates.
- Detect, prevent, and address fraud, abuse, or security incidents.
- Comply with legal obligations, including age verification and consumer protection.
- Deliver opt-in marketing communications (only with explicit consent).
4. Legal Basis (GDPR)
We rely on the following legal bases under the EU General Data Protection Regulation:
- Contract: processing necessary to provide the Service you requested.
- Legitimate Interests: security, fraud prevention, and service improvement.
- Consent: marketing communications, optional cookies, and analytics.
- Legal Obligation: compliance with Finnish and EU regulations.
5. Sharing Your Data
We do not sell your personal data. We may share data with the following categories of recipients:
- Cloud hosting providers (within the European Economic Area).
- Analytics providers (Google Analytics 4, with IP anonymization enabled).
- Customer support tools (zendesk-style ticketing systems).
- Legal authorities when required by law or court order.
6. Data Retention
We retain personal data only as long as necessary:
- Account data: for as long as your account is active, plus 24 months thereafter.
- Technical logs: 12 months for security and debugging.
- Support communications: 36 months.
- Marketing data: until you withdraw consent.
7. Your Rights Under GDPR
You have the right to:
- Access your personal data.
- Rectify inaccurate or incomplete data.
- Erasure ("right to be forgotten").
- Restriction of processing.
- Data portability in machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time.
- Lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).
To exercise any of these rights, contact us at [email protected].
8. Security Measures
We implement industry-standard technical and organizational measures including TLS 1.3 encryption in transit, AES-256 encryption at rest, bcrypt password hashing, regular security audits, principle-of-least-privilege access controls, and continuous monitoring for suspicious activity.
9. International Transfers
Your personal data is primarily processed within the European Economic Area. Where transfers outside the EEA occur, we rely on European Commission Standard Contractual Clauses and adequacy decisions to ensure equivalent protection.
10. Children's Privacy
The Service is strictly limited to users 18 years of age or older. We do not knowingly collect personal data from minors. If we discover that a minor has registered, we will promptly delete the account and associated data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-platform notice at least 30 days before taking effect.
12. Contact
For any privacy-related inquiry, contact our Data Protection Officer at [email protected] or in writing at Mannerheimintie 44 A, 00260 Helsinki, Finland.