Home »
Procedure for Submitting a Request to Exercise Data Subject Rights and Delete User Account
1. GENERAL PROVISIONS
These internal rules and procedures for technical and organizational measures for processing and satisfying requests for the exercise of data subject rights and for deleting user accounts, briefly called “The Procedure”, regulate the organization of handling requests to exercise personal data rights of users of CASUALINO LTD. and specifically the platform/service “VIP Games”.
The Procedure specifies the order for submitting requests from data subjects to the
administrator in connection with their individual rights under the General Data Protection Regulation (GDPR) and the right to delete a user account, as well as the responsibilities of the administrator and processors who have the right and obligation to serve these requests.
The purpose of the Procedure for handling requests related to the exercise of individual rights of data subjects and deletion of user accounts in VIP Games is to provide users with a maximally facilitated, accessible, and transparent process for submitting requests to realize individual rights under GDPR including the withdrawal of consent, while simultaneously ensuring the protection of the interests of platform users, the interests of the Administrator, and maximum protection of the confidentiality, integrity, and availability of personal data.
Depending on the specific situation, CASUALINO LTD may process data as an administrator or processor.
The rules are prepared in accordance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 concerning the protection of the processing of personal data.
2. CONDITIONS FOR EXERCISING RIGHTS
Rights are exercised through a written statement to the Administrator, sent to the email address [email protected].
The statement includes: name, details about the user profile such as: username, email address and / or identification number of an account on the social network from which access to the service VIP Games is made, as well as other data identifying the corresponding physical person; description of the request; date of submission and correspondence address.
CASUALINO LTD processes personal data in compliance with the General Data Protection Regulation, which provides certain restrictions in exercising rights by data subjects. Even if the request contains the necessary information for consideration, there may be a legal obstacle to its fulfillment.
The Administrator assists in the exercise of the rights of the data subject and does not refuse to take action on them, unless unable to identify the data subject.
When the administrator has reasonable concerns regarding the identity of the physical person submitting a request to exercise rights, the administrator may request additional information to confirm their identity.
3. METHOD OF SUBMITTING A “REQUEST TO EXERCISE RIGHTS OF A DATA SUBJECT”
Data subjects can submit a request to exercise rights of a data subject and delete a user account in one of the following ways:
The rights can be exercised by the data subject through a written statement to the email address [email protected] in free text, containing sufficient information to allow the administrator to fulfill it.
If the contact information with the applicant is not filled in or if the applicant does not send the request from an email address registered to the respective user account, and additional information from the data subject is needed, the request will be considered after the applicant contacts the administrator again.
When describing the request, it is advisable for the applicant to specify:
- what information is requested to be provided;
- why personal data should/could be corrected or deleted – in this regard, the administrator may require additional documents or information;
- the format for providing personal data when the right to portability is exercised and the recipient of the data
- against what actions regarding the processing of your personal data you object.
After we verify the identity of the person making the request and the person to whom the data relates, we will delete all data we process for them, in accordance with the Privacy Policy of the Administrator.
4. ADMINISTRATOR’S OBLIGATION TO PROCESS REQUESTS RELATED TO THE EXERCISE OF INDIVIDUAL RIGHTS
The Administrator assists in the exercise of the rights of the data subject and does not refuse to take action on them, unless unable to identify the data subject.
When the Administrator has reasonable doubts regarding the identity of the user submitting a request to exercise rights, the Administrator may request additional information to confirm their identity.
The Administrator provides the data subject with information on the actions taken in connection with a request to exercise rights, without undue delay and in all cases within one month of receiving the request.
If necessary, the period may be extended by another two months, taking into account the complexity and number of requests.
Refusal to take action on the request is permissible in cases of manifestly unfounded or excessive requests.
5. HOW TO EXERCISE YOUR RIGHTS GRANTED BY GDPR?
5.1. Exercising your rights
You can exercise all the rights you have, to correct, change, or delete information about you. If you want to exercise any of the rights described in this section, to review, delete or modify the information we have about you, or if you have additional questions, send us an email at [email protected]. We will respond to your request within thirty (30) days.
5.2. List of rights under GDPR
5.2.1. Right to information
You have the right to be informed about the collection and use of your personal data.
If you want to see your personal information that we have stored, send us an email at [email protected], with the subject “Data Export”.
5.2.2. Right to access
You have the right to access your personal data.
You can access and update some of your information through your profile settings. If you have chosen to link your profile to an external social network, like Facebook or Google, you can change your settings and remove permissions for the app by changing your profile settings.
5.2.3. Right to rectification
You have the right to rectify or to have inaccurate personal data corrected.
If you are unable to change such personal information through your profile settings, send us an email at [email protected] with the subject “Update my data”. You are responsible for updating your personal information.
5.2.4. Right to erasure
You have the right to have your personal data erased. This right is also known as the “right to be forgotten”. The right is not absolute and applies only in certain circumstances.
If you want your profile to be closed and your personal data deleted, send us an email at [email protected], with the subject “Profile Deletion”. Please include your profile details such as: username, email address and / or identification number of an account on the social network from which you access our services. We will respond to your request within thirty (30) days.
5.2.5. Right to restrict processing
You have the right to request a restriction or prohibition on the use of personal data.
This is not an absolute right and applies only in certain circumstances. When processing is restricted, we are allowed to store personal data, but not use it.
If you want to stop receiving promotional emails from us and our partners or third parties, click on the “Unsubscribe” link in the email. If you want to withdraw your consent to receive personalized offers, you can do so by changing your profile settings. If you do not want to receive notifications, you can turn them off by visiting the “Settings” page on your mobile device.
5.2.6. Right to data portability
You have the right to receive and reuse your personal data for your own purposes across different services. The right only applies to the information you have provided us.
You can request copies of your personal data that you have provided to us in a structured, commonly used and machine-readable format.
5.2.7. Right to object
Individuals have the right to object to:
- processing based on legitimate interests or performance of a task in the public interest / exercise of official authority (including profiling);
- direct marketing (including profiling);
- processing for purposes of scientific/historical research and statistics.
5.2.8. Rights related to automated decision making and profiling
If you do not want to be subject to profiling, you can opt out through your profile settings.
6. CONNECTING WITH A REPRESENTATIVE OF CASUALINO AD
The user must contact us at [email protected] by sending us an official request for deletion of a profile from the email used for registration on the VIP Games platform, confirming in the same letter the name of the profile they wish to be deleted. If the user has not linked their account with their email, but has used another method of registration, they must add an email as an additional method of connecting to the account, so we can use this email as the official communication channel with them regarding their personal data and requests for account deletion. After adding an email to their account, they can request deletion, data export, or other actions related to their personal data by writing to us at [email protected] from the email added to their account and confirming the username of the account they wish to be deleted.
Upon receiving a request for account deletion at a different email address, the user is notified that an official request for account deletion can only be accepted at [email protected], to be forwarded to the department authorized to handle personal data and its deletion. If the user does not write an email to [email protected] with the necessary data to confirm their account, their request is not considered received and is not processed.
7. VERIFYING OWNERSHIP OVER A USER ACCOUNT
To verify ownership of the account, the user must confirm the information about their registration. This information is necessary for our team to exclude possibilities for various types of abuse through the submission of a request for the deletion of an account that does not belong to the requester. Such abuse may be discovered in cases of stolen or transferred to another account, as well as confused information about the account name.
7.1. Registration with email
The user must confirm the email that was used to register their account by writing to us from the same email. The request is not accepted if the user contacts us from a different email than the one used for registration.
7.2. Registration with a Facebook, Google, Twitter account
If the user has added an email login method to the same registration, the procedure described for registration with an email applies.
If the user has not linked their account with their email, but the account only has a Facebook, Google, or Twitter account as a registration method, they must add an email as an additional method of connecting to the account, so we can use this email as the official communication channel with them. After adding an email to their account, they can request deletion, data export, or other actions related to their personal data by following the procedure described for registration with an email.
7.3. Mobile guest account
If the user has added an email login method to a registration made as a mobile guest account, the procedure described for registration with an email applies.
If the user has not linked their account with their email, but the account is registered only as a mobile guest account, they must add an email as an additional method of connecting to the account, so we can use this email as the official communication channel with them and a way to confirm ownership of the account. After adding an email to their account, they can request deletion, data export, or other actions related to their personal data by following the procedure described for registration with an email.
Official correspondence related to exercising rights under personal data, confirming or refusing to delete a player’s profile, can only be conducted via the email present in the user’s account for the purpose of their identification.
We reserve the right, if deemed necessary, to additionally contact the user through the internal company system for managing user accounts on the VIP Games platform for the purpose of collecting additional information or confirming the request for deletion, but this does not cancel the obligation to write exclusively and only from the registered email to submit, confirm, or reject a request for action related to the personal data of the user.
8. REGISTRATION OF A VALID REQUEST
After confirming all the necessary information for account deletion at the email [email protected] by the user, the request is considered officially received and accepted for processing. The user receives an email with information that their request has been received and forwarded to the team authorized to work with personal data and will be processed within 30 calendar days.
9. DEADLINES
The period for processing a request for account deletion is the legally established period of 30 calendar days, counted from the date of sending the confirmation by our side. Before proceeding with the deletion of the account, a member of the department authorized to work with personal data checks all the information provided by the user, as well as their recent activity on the VIP Games platform.
In case of data on recent activity – played games, successful or unsuccessful attempts to purchase in the platform store or other type of activity that certifies the use of the account after the request was sent, a member of our team may request additional confirmation for the deletion of the account, as the user may have changed their mind and may not wish for it to be deleted.
10. REASONS FOR EXTENDING THE PERIOD
Reasons that might lead to an extension of the period for account deletion are:
- Recent activity related to changes in the player’s profile – uploaded photos, changed status, changed username;
- Games played after the request was received;
- Attempts at purchases or successful purchases in the platform store;
- Lack of response, or delayed response, upon making an additional inquiry to clarify the identity of the user or the conditions of the request to exercise rights.
11. PROCEDURE FOR ACCOUNT DELETION
11.1. Technical procedure
A member of the team, authorized to work with personal data, who has a special level of access to the internal company system for managing user accounts, initiates the procedure of anonymizing the account through a series of software tools.
11.2. Data subject to deletion
- analytics id, referral id, affiliate id, ip address, device, online status, password, email, fb id, google id, twitter id, mobile id, avatar, age, city, country, sex, status, level, inventory, stats, gallery, wallet
11.3. Data subject to anonymization
- a random username is generated
11.4. Data subject to preservation
- Data on purchases
- Data on participation in games
- Data on participation in chat and friend lists
- Data on participation in rankings
- Data on user ID
11.5. Notification of the user
After deleting the user’s account and their personal data, a member of our team, authorized to handle personal data, sends a confirmation via the official email, used for communication with the user, responding to the email from which the request for deletion was sent, stating that the user’s account and personal data have been deleted from our system.