<strong>EU additional terms:</strong> If you are based in the European Union (“EU”) and use any of the Website, Materials and Services, these additional terms (“GDPR Terms”) supplement and form part of Grinding Gear Games’ Privacy Notice.
The General Data Protection Regulation (“GDPR”) regulates the collection, processing and transfer of EU individuals’ personal data (as defined in the GDPR).
The personal information described in our privacy notice is personal data under the GDPR.
Grinding Gear Games is committed to complying with the GDPR when dealing with personal data of our website visitors and service users based in the EU.
For the purposes of the GDPR, Grinding Gear Games is the data controller (as defined in the GDPR) when processing personal data collected by it when you use any of the Website, Materials and Services.
Grinding Gear Games is happy to assist with any questions regarding its collection and use of data.
Any requests for further information should be sent to email@example.com.</p>
<strong>Processing personal data:</strong> The personal data Grinding Gear Games may process consists of the personal information described in its Privacy Notice.
This personal data may be processed for the purposes outlined in that privacy notice.
The legal basis for Grinding Gear Games’ processing of personal data depends on the type of personal data and the specific context in which it collects it.
However, Grinding Gear Games normally processes personal data only where (a) it has your consent to do so, (b) where it needs to process personal data to perform a contract with you (e.g.
to provide the Website, Materials or Services to you), or (c) where the processing is necessary for the purposes of Grinding Gear Games’ legitimate interests (except where such interests would be overridden by your fundamental rights and freedoms which require the protection of personal data).</p>
<p>In addition to the above, Grinding Gear Games may process any of your personal data where such processing is necessary for compliance with applicable laws or regulations.</p>
<p>You do not have to provide Grinding Gear Games with some information that is automatically collected when you use any of the Website, Materials and Services, e.g.
However, you must provide us with (a) your email address and username or (b) a username and Steam Account ID when using the Materials and Services.
The consequence of not providing one or the other of these is that Grinding Gear Games will not be able to set you up a Member Account in order to log into the Website or PoE.</p>
<strong>Your rights:</strong> Your rights in relation to your personal data under the GDPR include (subject to any legal exceptions):</p>
<li>right of access - if you ask Grinding Gear Games, it will confirm whether it is processing your personal data including the purposes, categories, source and use of the data and any automated processing of profiling being applied and provide you with a copy of that personal data.</li>
<li>right to rectification - if the personal data Grinding Gear Games holds about you is inaccurate or incomplete, you have the right to have it rectified or completed.
Grinding Gear Games will take every reasonable step to ensure personal data which is inaccurate is rectified.
If Grinding Gear Games has shared your personal data with any third parties, it will tell them about the rectification where possible.</li>
<li>right to erasure – Grinding Gear Games will delete your personal data when it is no longer needed for the purposes for which you provided it.
You may request that Grinding Gear Games delete your personal data and it will do so if deletion does not contravene any applicable laws.
If Grinding Gear Games has shared your personal data with any third parties, it will take reasonable steps to inform those third parties to delete such personal data.</li>
<li>right to withdraw consent - if the basis of Grinding Gear Games’ processing of your personal data is consent, you can withdraw that consent at any time.</li>
<li>right to restrict processing - you may request that Grinding Gear Games restrict or block the processing of your personal data in certain circumstances.
If Grinding Gear Games has shared your personal data with third parties, it will tell them about this request where possible.</li>
<li>right to object to processing - you may request that Grinding Gear Games stops processing your personal data at any time and it will do so to the extent required by the GDPR.</li>
<li>right to data portability - you may obtain your personal data from Grinding Gear Games that you have consented to give it or that is necessary to perform a contract with you.
Grinding Gear Games will provide this personal data in a commonly used, machine-readable and interoperable format to enable data portability to another data controller.
Where technically feasible, and at your request, it will transmit your personal data directly to another data controller.</li>
<li>the right to complain to a supervisory authority - you can report any concerns you have about Grinding Gear Games’ privacy practices to the relevant data protection supervisory authority e.g.
in the United Kingdom, this is the Information Commissioner’s Office.</li>
<p>Where personal data is processed for the purposes of direct marketing, you have the right to object to such processing, including profiling related to direct marketing.
If you would like to exercise any of your above rights, please contact us at firstname.lastname@example.org.
If you are not satisfied by the way your query is dealt with by Grinding Gear Games, you may refer your query to your local data protection supervisory authority.</p>
<strong>Children:</strong> Grinding Gear Games does not intend to collect personal data from children aged under 16.
If you have reason to believe that a child under the age of 16 has provided personal data to Grinding Gear Games through use of any of the Website, Materials and Services, please contact Grinding Gear Games at email@example.com.</p>
<strong>International transfer of data:</strong> The personal data Grinding Gear Games collects in relation to the Website, Materials and/or Services may be transferred to, and stored in, a country operating outside the European Economic Area (“EEA”).
Under the GDPR, the transfer of personal data to a country outside the EEA may take place where the European Commission has decided that the country ensures an adequate level of protection.
In the absence of an adequacy decision, Grinding Gear Games may transfer personal data provided appropriate safeguards are in place.</p>
<p>Some of the personal data Grinding Gear Games collects is processed in New Zealand (where its registered office is located).
New Zealand is recognised by the European Commission as a country that ensures an adequate level of data protection and Grinding Gear Games relies on this decision in transferring personal data to New Zealand.</p>
<p>Some of the personal data Grinding Gear Games collects is processed by us and/or third-party data processors in other countries, including the United States.
These third-party data processors are set out at www.pathofexile.com/third-parties.
For personal data processed in the United Sates, the European Commission has determined that the United States ensures an adequate level of protection for personal data transferred from the EU to organisations in the United States under the EU-U.S.
Grinding Gear Games has verified that its United States-based data processors have self-certified under the EU-US Privacy Shield framework or that it has entered into Standard Contractual Clauses as published by the European Commission with its third-party processors.
The Standard Contractual Clauses provide specific guarantees around transfers of personal data and Grinding Gear Games rely on the Standard Contractual Clauses in transferring personal data to these third-party processors.</p>
<strong>Data retention policy:</strong> Personal data that Grinding Gear Games collects and processes will not be kept longer than necessary for the purposes for which it is collected, or for the duration required for compliance with applicable law, whichever is longer.
Grinding Gear Games has a retention policy which is available on request.</p>
<strong>Contacting us:</strong> You can contact Grinding Gear Games as set out in our privacy notice.
The name and contact details of Grinding Gear Games’ European representative for the purposes of Article 27 of the GDPR are as follows: </p>
<strong>EU representative: BM Data Services Limited</strong>
<strong>Contact email: firstname.lastname@example.org</strong>
<strong>Contact telephone: +44 (0) 203 289 8497</strong>