Bossa Privacy and Cookie Policy

Date of Last Revision: 15 March 2017

The following privacy and cookies policy sets out how we use data relating to you and applies to all use of your personal information by Bossa Studios Limited, a company registered in England and Wales under company number 07375707 and with our registered office at Zetland House, Unit E 2nd Floor, 5-25 Scrutton Street, London EC2A 4HJ, England (“we”, “us” or “our”). This privacy policy forms a part of and should be read in conjunction with the EULA distributed with the games we publish, and where you use our websites, our website terms of use, which can be found on our website here: http://www.bossastudios.com/terms-condition/.

This privacy and cookies policy (together with the documents referred to in it) sets out the basis on which any personal data we collect from you, or that you provide to us through our websites (including without limitation, bossastudios.com, worldsadrift.com, iambreadgame.com, and surgeonsim.com) and/or our games (together the “Service”), will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.

This policy does not apply to practices of companies that we do not own or control, or to individuals that we do not employ or manage.

We will only collect and process information about you in accordance with this privacy and cookies policy. By accessing the Service you authorise us to collect, store, access, transfer and use your information as described in this Policy.  We may make changes to this Policy in future, which will be posted on this page.  You should check this page from time to time to ensure you are aware of any changes.  Where appropriate we may notify you of changes by email or through our games or websites.

If you have any concerns over privacy, or this privacy and cookies policy contact us at feedback@bossastudios.com.

1. PERSONAL DATA WE MAY COLLECT ABOUT YOU

1.1. Data you supply (“Submitted Information”) includes:

1.1.1. We will obtain personal data about you (such as your name, address, telephone number, email address) whenever you contact or make a purchase from us, register an account with us, submit material through a form, or via part of the Service.

1.1.2. We may also obtain sensitive personal data about you if you voluntarily supply it through our Games or other parts of the Service.  If you volunteer such information, you will be consenting to our processing it for the purpose indicated when you supply it.

1.2. Data we collect includes:

1.2.1. We may monitor your use of our Service, including use of our games and websites, through cookies and similar tracking technologies. For example, we may monitor how many times you visit, which pages you go to, traffic data, your IP and MAC address, a unique device identifier, the browsers and devices you use to access our games and websites, your internet service provider, and the actions you take when playing our games or using our websites (“Analytics”).

1.2.2. Our Service may also collect information which you make available to us and which is stored on your device, or in your Steam account, or your Facebook or other social media or similar profiles, including contact information, images, video or other digital content such as records of your gameplay (“Content Information”).

2. HOW WE USE YOUR PERSONAL DATA

2.1. We will use your personal data for the purposes described to you at the time your data were obtained, and for the following purposes:

2.1.1. Submitted Information: to help us identify you and to open, run and monitor any accounts you hold with us; for administration; to process your orders and enquiries; to monitor and distribute material you contribute through our Service; and to send you information about our games and websites.

2.1.2. Analytics: to understand how, and how often, users play our games and use our websites, and to help us improve them.

2.1.3. Content Information: to allow you to connect with friends and other users, to share gameplay and other contributions you might make, and to make it easier for you to use the Service, for example by pre-populating forms and user accounts.

2.2. We may associate any category of information with any other category of information and will treat the combined information as personal data in accordance with this policy for as long as it is combined.  We will only use information collected about you in accordance with the Data Protection Act 1998.

2.3. From time to time we also monitor and record your telephone calls to us (for example in connection with customer support) and online chat functionality for training purposes and to improve the service to you.

2.4. We do not disclose information about identifiable individuals to advertisers, but we may provide them with anonymous aggregate information about our users (for example, We may inform them that 500 men aged under 30 have clicked on their advertisement on any given day). We may also use such aggregate information to help advertisers reach the kind of audience they want to target (for example, women in London). We may make use of the personal data We have collected from you to enable us to comply with our advertisers’ wishes by displaying their advertisement to that target audience.

DISCLOSURE OF YOUR INFORMATION

2.5. We may disclose some or all of the data we collect from you when you download or use the Service:

Category of data Recipient and Purpose
Submitted Information We may share your name and email address with the email service providers we use to keep you updated with news about our Service.

Information which you include within your public profile, or which you share through forums and other interactive messaging features through our Service, will be shared with other users of the Service.

Our online forums are operated by WP Engine (UK) Limited and WP Engine Ireland Limited, and you can find out more about the way WordPress Engine processes personal data here: https://wpengine.co.uk/privacy/.

We use Zendesk to manage our customer support queries, and you can find out how Zendesk, Inc processes personal information here: https://www.zendesk.com/company/customers-partners/#privacy-policy.

We use Mailchimp and Sendgrid to send emails and keep you informed, and you can find out more about how they process personal data here: https://mailchimp.com/legal/privacy/ and https://sendgrid.com/policies/privacy/.

If you make purchases through our websites or apps, your order and personal information you submit along with it, may be processed by Xsolla (USA), Inc. and you can find out more about how Xsolla processes personal information here: https://xsolla.com/privacypolicy/.

We use EasyAntiCheat to keep an eye on any cheating or suspicious activities in our games. EasyAntiCheat monitors the usage of our games on an anonymised basis and you can find out about their policies here https://support.easyanticheat.net/kb/privacy/?lr=en-us
Analytics Analytics information may be shared with advertisers on an anonymous aggregate basis.  We may also publicise anonymous, aggregate statistics through our websites or other channels although this will not include your personal data.

Our games integrate with Kissmetrics, PlayFab and Flurry Analytics.  Analytics data will be processed and tracked by those third party services, and you can find out more about the way they use this information at the following locations: https://www.kissmetrics.com/privacy/, https://playfab.com/privacy/, and here https://policies.yahoo.com/us/en/yahoo/privacy/index.htm.

Content Information Content Information which you supply through our Service will be shared with other users of the Service.  In some cases you may be able to select specific recipients (for example if you are sending a forum post, or a private message, to a particular forum or individual) then only those recipients will receive it, however in all other cases, your Content Information may be made publically available through the Service and other channels.

2.6. We may disclose your personal information to any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the Companies Act 2006.

2.7. We may also disclose your personal information to third parties:

2.7.1. In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.

2.7.2. If we or substantially all of our assets are acquired by a third party, in which case personal data held by us about our customers will be one of the transferred assets.

2.7.3. If we are under a duty to disclose or share your personal data in order to comply with any legal or regulatory obligation or request.

2.7.4. In order to enforce or apply the terms of agreements between us, to investigate potential breaches, or to protect the rights, property or safety of us, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.

3. WHERE WE STORE YOUR PERSONAL DATA

3.1. The data we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (“EEA”). It may also be processed by staff that operate outside the EEA and work for us or our suppliers. These staff may be engaged in the fulfilment of your orders, the processing of your payment details, the maintenance of the Service, and the provision of support services. By submitting your personal data, you agree to this transfer, storing or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy.

3.2. Where we have given you (or where you have chosen) a password that enables you to access certain parts of our Service, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.

3.3. Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted through our Service; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.

3.4. Certain features of our Service enable social networking, messaging, publishing, chat room or forum features or the creation and/or submission by you of material such as game worlds and virtual goods. Ensure when using these features that you do not submit any personal data that you do not want to be seen, collected or used by other users.

4. YOUR RIGHTS

4.1. If you believe we have information about you that you do not want us to have or that is incorrect please contact us as at feedback@bossastudios.com and we shall correct or remove the data as you request as soon as reasonably practicable. If you would like to receive a copy of the information we have about you, please note that an administration fee of £10 may be applicable.

4.2. We will usually inform you in advance if we intend to use your data, or to disclose it to any third party, for marketing purposes. If you prefer that we do not use your data in this way, let us know by writing to feedback@bossastudios.com or by checking boxes on the forms we use to collect your data.

5. EXTERNAL WEBSITES

5.1. If you follow a link to any third party websites or services, please note that we do not accept any responsibility or liability for the collection, storage or use of personal data by those third parties, and you should check the applicable privacy policies before you submit any personal data to those websites or use these services.

6. COOKIES

6.1. A cookie is a text file placed onto your device when you access our Games or Sites. We use cookies and other online tracking devices such as web beacons, and flash object storage to deliver, improve and monitor our Sites and Games, including in the following ways:

Cookie Purpose
PHPSESSID Unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
wp-settings Used to identify site settings.
wp-settings-time Used to identify site settings.
wpe-auth After log in this identifies your user account.
wordpress_logged_in_{HASH} After log in this identifies your user account.
comment_author_{HASH} When you submit a comment we store this information to populate this field for your next visit.
comment_author_email_{HASH} When you submit a comment we store this information to populate this field for your next visit.
comment_author_url_{HASH} When you submit a comment we store this information to populate this field for your next visit.

6.2. The information we obtain from our use of cookies will not usually contain your personal data. Although we may obtain information about your device such as your IP address, your browser and/or other internet log information, this will not usually identify you personally.

6.3. Our websites display a notice alerting you to our use of cookies and other similar technologies and linking to this privacy policy. If you use our webites after this notice has been displayed to you we will assume that you consent to our use of cookies or similar technologies for the purposes described in this privacy policy.

6.4. Please note that, if you choose to disable cookies or similar technologies on your device, you may be unable to make full use of our Service.

6.5. We work with third parties who may also set cookies on our website, for example Google Analytics, Google Adsense, Facebook, Twitter,YouTube, Kissmetrics and Wistia, which we use to display video content, enable social networking functionality and sharing, to deliver ads, and to monitor how visitors use our Service. These third party suppliers are responsible for the cookies they set on your device. For further information please visit the website of the relevant third party.

7. ADVERTISEMENTS AND AD SERVING TECHNOLOGY

7.1. Please note that we use third party providers of adverts and the adverts’ content is provided by these third parties and not Bossa. Examples of third party providers we may use from time to time are Flurry, AdMob, iAd and AdColony.

7.2. If you are using an iOS device, you can opt out of personalised adverts by visiting https://oo.apple.com.

7.3. Third party ad providers may use precise methods to collect information as a result of ad serving through the Service. These entities may collect and use data for this purpose including software, applications, hardware, browser information, internet and on-line usage information and in-game information. This data may be used and disclosed in accordance with these terms and the privacy policy of the company providing the ad serving technologies. You recognise and accept that the advertising companies who deliver ads for us may combine the information collected with other information they have independently collected from other services or products. These companies collect and use information under their own privacy policies. Although we take commercially reasonable steps to instruct such advertising companies to comply with these terms and conditions, we do not have access to or control of third party technologies.