VOID WEAVER
The Controller of the personal data collected through the video game VOID WEAVER (the “Game”) is:
Binatomy S.r.l. — Via Mentana 9, 57125 Livorno (LI), Italy — VAT and Tax Code IT02071300491 — email: info@binatomy.com.
For any request concerning the processing of personal data, the data subject may contact the Controller at the email address indicated above.
This Privacy Policy applies to the processing of personal data of users (the “Users” or “Data Subjects”) who access and use the Game via the website voidweaver.online and, following release, through the Android and iOS applications. The Game is currently made available to users residing in the European Union; any extension to a non-EU audience will require an update to this Policy.
The Game can also be used without creating an account (guest mode); in that case, the only data processed is that described in section 3.5 (local device storage) below. The categories of data processed in connection with the Game's various features are described below.
If the User chooses to create an account, the following is collected: email address; password (managed and encrypted directly by Firebase; the Controller does not have access to the password in plain text); nickname or display name, chosen by the User or automatically derived from the prefix of the email address; unique account identifier (UID), automatically generated by Firebase.
Purpose: account creation and management, authentication, and association of Progress Data with the User. Legal basis: performance of a contract (Art. 6(1)(b) GDPR), represented by the Terms and Conditions accepted by the User.
The following is collected and stored: personal records (best score, best wave, best combo, best “no damage” run, best “no shop” run, best time, wave reached at best score); cumulative statistics (total kills, bosses defeated, dash kills, perfect waves, matches played, total playtime); recent match history (score, wave, date); types of bosses defeated; in-game economy data (Shards earned/spent, upgrade levels); account level and experience points (EXP); trophies with unlock date; “meta” game data (unlocked ships/weapons/drones/moves, equipped loadout, gacha fragments, chosen avatar, redeemed notification rewards); nickname, email, and display name, rewritten on each save, together with the relevant update timestamp.
Purpose: enable persistent cloud saving of game progress and synchronization across devices. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
If a score exceeds a certain threshold, the following data is made publicly visible to all Users of the Game: nickname, score, wave reached, account level, equipped ship, “Alert” level, UID, and timestamp. A dedicated leaderboard also exists for co-op pairs.
Purpose: competitive and entertainment functionality inherent to the nature of the Game. Legal basis: performance of a contract, with specific acceptance by the User at the time of account creation (Art. 6(1)(b) GDPR); the User is informed that such data is publicly visible and undertakes, under the Terms and Conditions, not to use their real name or third parties' identifying data as a nickname.
The Controller may issue broadcast announcements, readable by all Users, and may assign targeted rewards, which include the recipient's UID solely for the purpose of correctly attributing the reward.
Purpose: service communications and delivery of the Game's reward features. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
The following is stored locally on the User's device (via localStorage or browser cache): game settings (language, music/sound effects volume, FPS display, graphics quality); User selections (equipped ship, skin, avatar); a local cache copy of Progress Data, for technical caching purposes; technical flags (first launch seen, cache-owner UID, gacha “pity” counter, leaderboard display name).
Purpose: technical operation of the Game, offline/fast-loading experience. Legal basis: the Controller's legitimate interest in the correct technical operation of the Service (Art. 6(1)(f) GDPR), as this data is strictly necessary for the functionality requested by the User themselves (similarly to technical cookies, for which consent is not required under Art. 122 of the Italian Data Protection Code).
To start a cooperative game session, a room code is generated and, via the Firestore infrastructure (rooms/{code} collection), technical “signaling” data required to establish a direct WebRTC connection between the two devices is exchanged (offers, answers, and ICE candidates), which by their technical nature include the device's IP address and network information. This data is standard for the operation of the WebRTC protocol and strictly necessary to establish the connection. Gameplay data exchanged during the co-op session (positions, inputs) travels directly between the two devices (peer-to-peer) and is not stored on the Controller's servers.
Purpose: delivery of the cooperative gameplay feature. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Through the application's technical plugins (Capacitor), the Game detects the access platform (web, Android, iOS), the device's touch support, and the system language (via the standard navigator.language), solely for the purpose of technical interface adaptation. Vibration (haptics) and screen-orientation detection are device features triggered locally and do not involve any data collection by the Controller.
Purpose: proper operation and adaptation of the Game to the device used. Legal basis: the Controller's legitimate interest (Art. 6(1)(f) GDPR).
The Controller does not collect: GPS location data; address book contacts; images or video from the camera; audio recordings from the microphone; photographs or other personal media of the User; payment data, as the Game does not include in-app purchases. The Controller also does not use any analytics or personalized telemetry system (Firebase Analytics, Google Analytics, and proprietary behavioral tracking systems are not used).
The Game may display advertisements served by third parties through Google AdMob (in the Android and iOS applications) and Google AdSense (in the desktop web version). Depending on Google's respective policies, these services may involve: the collection of the device's advertising identifier and standard ad-request data, in the case of AdMob; the use of cookies and the collection of standard browsing data, in the case of AdSense.
The advertising formats envisaged include rewarded ads (in exchange for which the User obtains an in-game benefit, such as an extra chance or a new attempt), interstitial ads, and banners.
As of the date of this Policy, the Controller has not yet implemented a Consent Management Platform (“CMP”) certified under the Google EU User Consent Policy and the IAB Europe Transparency & Consent Framework (TCF). Accordingly, until such a system is activated, no personalized advertising and no non-essential cookies or advertising identifiers will be activated for Users accessing the Game from the EEA (European Economic Area), in compliance with European consent requirements (the ePrivacy Directive and the GDPR).
Once the CMP is activated, EEA Users will receive, on first access, a granular consent request through which they will be able to: accept or refuse personalized advertising; accept or refuse the installation of cookies and non-technical advertising identifiers; withdraw consent at any time via a dedicated function accessible from the Game's settings. In the absence of consent, non-personalized ads may still be shown on the basis of the Controller's legitimate interest, where permitted by the law in force at the time of activation, or no ads may be shown at all, depending on the technical configuration adopted.
This section will be updated as soon as the CMP becomes technically operational, without this entailing any substantive change to the commitments made in this Policy.
With regard to data collected through AdMob and AdSense, Google LLC acts as an independent data controller, as such data is also used for Google's own purposes (operation and improvement of the advertising network). For information on the processing carried out by Google for such purposes, please refer to Google's privacy policy, available at policies.google.com/privacy.
To operate the Service, the Controller relies on the following third-party providers:
Provider
Service used
Role with respect to processing
Google Ireland Limited / Google LLC
Firebase Authentication and Firestore (authentication, progress saving, leaderboard, co-op signaling)
Data processor on behalf of Binatomy S.r.l., under the Google Cloud Data Processing Addendum
Google Ireland Limited / Google LLC
Google AdMob (in-app mobile advertising)
Independent data controller for its own advertising purposes
Google Ireland Limited / Google LLC
Google AdSense (web advertising)
Independent data controller for its own advertising purposes
For Firebase services, Google acts as a data processor under the Google Cloud Data Processing Addendum, which incorporates the Standard Contractual Clauses approved by the European Commission for the transfer of data to third countries, where applicable.
The providers referred to in Section 5 may process data on infrastructure located outside the European Economic Area, including in the United States. Such transfers are carried out on the basis of the Standard Contractual Clauses adopted by the European Commission, as supplemented by additional safeguards implemented by the providers, to ensure a level of protection of personal data that is adequate and substantially equivalent to that provided for under the GDPR.
Progress Data and account data are retained for the entire lifetime of the account, unless the User requests deletion. Upon deletion of the account, which may be requested at any time in accordance with the procedures set out in Section 9 below, identifying personal data (email, nickname, UID) and the associated Progress Data are deleted; the Controller may retain, for the period strictly necessary and in any case not exceeding what is required by law, aggregated or anonymized data with no identifying value, or data whose retention is necessary to comply with legal obligations or to establish, exercise, or defend a legal claim.
WebRTC signaling data (co-op) is purely technical and transient in nature and is not retained beyond the duration of the connection session. Data stored in local device memory persists until the application is uninstalled, the cache is manually cleared by the User, or the account is deleted.
The Game is not directed at an audience of children under 14 years of age and does not solicit account creation from them. As set out in the Terms and Conditions, account creation is permitted for individuals who are at least 14 years old, or for younger children whose account is created and managed by a parent or legal guardian. Should the Controller become aware of the processing of personal data of a child under 14 that occurred without the consent of a parent or legal guardian, it will promptly delete such data.
For underage Users, the Controller does not enable interest-based personalized advertising, regardless of the implementation status of the consent management platform referred to in Section 4.1.
Pursuant to Articles 15-22 of the GDPR, the User has the right to obtain from the Controller, where applicable: access to their personal data; rectification of inaccurate data; erasure of data (“right to be forgotten”); restriction of processing; portability of data in a structured, commonly used format; objection to processing based on the Controller's legitimate interest; withdrawal of consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
The User may request deletion of their account and related data directly from the Game's settings, where this functionality is available, or by sending a request to info@binatomy.com, specifying the email address associated with the account. The Controller will respond to the request within the time limits set out in applicable law (as a rule, within one month of receipt of the request).
The User also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it), as the competent supervisory authority for the Italian territory, or with the supervisory authority of the EEA Member State of their habitual residence, place of work, or the place where the alleged infringement occurred.
The Controller adopts technical and organizational measures appropriate to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the data processed, including entrusting the authentication and data storage infrastructure to Google Firebase, which applies its own security and encryption standards, in particular for the management of login credentials.
The Controller reserves the right to modify this Policy at any time, in particular following regulatory developments or changes to the Game's features (including, by way of example, activation of the advertising consent management platform referred to in Section 4.1, expansion of the Service to non-EU countries, or the introduction of any purchase features). Material changes will be communicated to registered Users via an in-app notice or by email, indicating the date of update.
For any request concerning the processing of personal data, or to exercise the rights referred to in Section 9, the data subject may contact the Controller at info@binatomy.com.