Astrofish Games Ltd Privacy Notice

Effective Date: 14 January 2025

Introduction

Astrofish Games Ltd ("we," "us," "our") is dedicated to protecting your privacy. This Privacy Notice outlines how we collect, use, disclose, and safeguard your personal information when you visit our website astrofishgames.com or interact with us through other channels. Please read this document carefully to understand our practices regarding your personal data.

Our Contact Details

  • Email: contact@astrofishgames.com

  • Address:
    Astrofish Games Ltd
    16 Beaufort Court Admirals Way, Docklands, London, United Kingdom, E14 9XL
    United Kingdom

Information We Collect

Personal Information

When you contact us via email, contact forms, or social media, we may collect the following personal information:

  • Name

  • Email Address

Additionally, if you opt-in to receive marketing materials, we will collect and store your email address for marketing purposes.

Technical Information

When you use our website, we may automatically collect certain technical data, including:

  • IP Address

  • Browser Type and Version

  • Operating System

  • Device Type

  • Referring URL

  • Pages Visited

  • Clicks and Scrolls

  • Search Queries

  • Timestamps

Additionally, we use tracking technologies such as Google Analytics and UTM parameters to understand user interactions and improve our services.

How We Use Your Information

We process your personal data based on the following lawful bases:

Legitimate Interests

  • Website Security and Functionality: Ensuring the security and proper functioning of our website.

  • Performance Analysis: Analyzing site performance and visitor behavior to enhance user experience.

  • Fraud Prevention: Preventing fraud, spam, and other cyber threats.

Specific Purposes

  • Support Requests: Responding to your inquiries and providing support.

  • Operational Purposes: Maintaining business records for operational, legal, and compliance needs.

  • Recruitment: Managing recruitment inquiries and processes.

  • Product Enquiries: Addressing questions about our products and services.

  • Commission Enquiries: Handling inquiries related to commissions.

  • User Journey Attribution: Tracking user journeys and attributing marketing efforts using Google Analytics and UTM parameters.

  • Marketing Communications: Sending you marketing materials if you have opted in to receive them.

Marketing Communications

Consent-Based Marketing

  • Opt-In Consent: We provide a tick box on our contact form for users to consent to receiving marketing materials. This box is disabled by default, and users must actively tick the box to opt in. By default, users are opted out of marketing communications.

  • Storing Consent: If you opt-in, your email address will be stored in our Customer Relationship Management (CRM) system, which is provided by a third-party service provider that complies with GDPR standards, or in a secure spreadsheet on our internal computer systems. This data is used solely for sending you marketing materials related to our products and services.

  • Third-Party CRM Details:
    We utilize a third-party CRM to manage and store your marketing data securely. This CRM acts as a data processor on our behalf, and we have established a Customer Data Processing Addendum (CDPA) with them to ensure your data is handled in accordance with GDPR requirements.

  • Managing Your Preferences: You can manage your marketing preferences or withdraw your consent at any time by contacting us at contact@astrofishgames.com or using the unsubscribe link provided in our marketing emails.

Analytics and Tracking Technologies

Squarespace Analytics

Our website is hosted and powered by Squarespace. When you use our website, Squarespace may automatically collect certain technical data to power our site analytics, including:

  • Information about your browser, network, and device

  • Web pages you visited prior to coming to this website

  • Your IP address

  • Clicks

  • Internal links

  • Pages visited

  • Scrolling

  • Searches

  • Timestamps

Squarespace Data Storage: Squarespace collects and stores analytics data in an aggregated form, meaning individual user data is combined with other data to generate insights about website performance and visitor behavior. While certain technical information such as IP addresses, browser types, and device details may be collected, this data is not used to personally identify individual users.

Data Usage: Squarespace needs this data to run our website, protect, and improve its platform and services. They analyze the data in a de-personalized and aggregated form, ensuring your privacy is maintained.

Google Analytics

We use Google Analytics, a web analytics service provided by Google LLC ("Google"), to help us understand how visitors interact with our website. Google Analytics uses UTM (Urchin Tracking Module) parameters to track user journeys and attribute marketing efforts.

Google Analytics cookies are only activated after you have provided consent via our cookie banner. If you do not consent, Google Analytics will not track your session.

If you wish to change your preferences, please clear your cookies or manage your settings through your browser.

Data Collected:

  • Device Information: Device type, operating system, browser type.

  • Usage Data: Pages visited, time spent on pages, clicks, scrolls, and navigation paths.

  • UTM Parameters: Information from UTM tags used in URLs to track the effectiveness of marketing campaigns.

Data Processing and Storage:

  • Aggregated Data Processing: All data collected via Google Analytics is processed in an aggregated manner. We do not export or store personal data outside of Google Analytics.

  • No Personal Data: We do not collect or process personally identifiable information (PII) through Google Analytics.

  • Data Security: Google Analytics data is stored securely within Google's infrastructure and is subject to Google's privacy policies.

Data Retention:

  • Retention Period: Astrofish Games Ltd configures the data retention settings in our Google Analytics account. Typically, data is retained for up to 26 months, but this period can be adjusted based on our data retention policies.

Legal Basis:

Consent: We use Google Analytics to measure the effectiveness of our marketing campaigns, track how users find and interact with our website, and optimize our advertising efforts. Google Analytics cookies are only activated if you provide consent via our cookie banner. If you do not consent, Google Analytics will not track your session.

You can change your preference at any time by clearing your cookies or adjusting your browser settings.

User Consent:

  • Cookie Consent: We obtain your consent through our cookie banner before activating Google Analytics cookies. You can manage your cookie preferences at any time.

Your Choices:

  • Opt-Out: You can opt-out of Google Analytics tracking by installing the Google Analytics Opt-Out Browser Add-on.

IP Anonymization:

  • Enhanced Privacy: We have enabled IP anonymization in our Google Analytics settings. This means that the last octet of your IP address is truncated before being stored or processed, ensuring that your IP address cannot be used to personally identify you.

Google Analytics Privacy Policy: For more information on how Google handles your data, please refer to the Google Analytics Privacy Policy.

Cookies and Similar Technologies

Our website uses cookies and similar technologies to enhance your browsing experience. Squarespace and Google Analytics handle most of the cookie management. Key points include:

  • Functional and Required Cookies: Always active to ensure website security and functionality.

  • Analytics and Performance Cookies: Activated upon your consent via our cookie banner to monitor site traffic and user behavior.

  • Marketing Cookies: Used to deliver relevant marketing messages based on your interactions with our website.

For detailed information, please refer to The Cookies Squarespace Uses and Google's Cookie Policy.

Managing Cookie Preferences
If you wish to change your cookie settings or withdraw consent, you can do so by clearing your browser cookies and revisiting our website to see the cookie banner again. You can also manage your cookies through your browser settings or install third-party browser extensions that provide cookie management options.

Data Sources

We collect personal information directly from you through:

  • Contact Forms: Accessible at astrofishgames.com/contact

  • Emails and Social Media: Information provided when you contact us via email or social platforms. We do not store personal information outside the respective platforms (e.g., Facebook, Discord, X [formerly Twitter]).

Contact Form Handling:

  • Storage: Information submitted through our contact form is sent to our Gmail account (contact@astrofishgames.com), which is controlled solely by Astrofish Games Ltd.

  • Access Control: Only authorized personnel within Astrofish Games Ltd have access to the Gmail account.

  • Data Security: We implement security measures to protect data stored in our Gmail account, including encryption and secure access protocols.

Third-Party CRM Handling:

  • Data Processor: We utilize a third-party Customer Relationship Management (CRM) system to manage and store your marketing data securely. This CRM acts as a data processor on our behalf, and we have established a Customer Data Processing Addendum (CDPA) with them to ensure your data is handled in accordance with GDPR requirements.

  • Security Measures: The CRM provider implements appropriate technical and organizational measures to protect your personal data, including encryption, access controls, and regular security assessments.

  • Subprocessors: The CRM provider may engage subprocessors to assist in data processing. We ensure that any subprocessors also comply with GDPR requirements through our CDPA.

Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Notice, unless a longer retention period is required or permitted by law. Specifically:

  • Contact Form Messages: Retained for up to 5 years.

  • Marketing Data: Retained as long as you remain subscribed to our marketing communications or until you withdraw your consent.

  • Other Data: Stored based on legitimate interests and operational needs.

Data Security

We implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:

  • Encryption: Data transmitted to and from our website is encrypted using SSL/TLS protocols.

  • Access Controls: Access to personal data is restricted to authorized personnel only.

  • Secure Storage: Data stored in our Gmail account, CRM system, and third-party platforms like Squarespace and Google Analytics is protected through their respective security measures.

  • Regular Monitoring: We regularly monitor our systems for vulnerabilities and unauthorized access.

Data Breach Notification

In the event of a data breach, Astrofish Games Ltd has established procedures to manage and mitigate the impact:

  • Notification to Affected Individuals:
    If a breach affects individuals who have provided a valid email address through our contact form or are existing clients, we will notify them directly via email.

  • Website Notifications:
    For breaches involving personal information stored on third-party platforms (e.g., Squarespace, Google Analytics), or if we are unable to contact affected individuals directly, we will post a notification on our website.

  • Email Address Compromise:
    If our primary email address (contact@astrofishgames.com) is compromised, we will:

    • Post a prominent notification on our website.

    • Provide an alternative contact method (e.g., alternative email address or contact form) for affected individuals to reach out to us.

  • ICO Notification:
    If the breach poses a high risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach. Additionally, affected individuals will be informed without undue delay.

Your Data Protection Rights

Under the UK Data Protection Act 2018 and the UK GDPR, you have the following rights:

  1. Right of Access: Request copies of your personal data.

  2. Right to Rectification: Request correction of inaccurate or incomplete data.

  3. Right to Erasure: Request deletion of your personal data under certain conditions.

  4. Right to Restrict Processing: Request limitation of data processing under specific circumstances.

  5. Right to Object: Object to data processing based on legitimate interests.

  6. Right to Data Portability: Request transfer of your data to another organization or to yourself.

  7. Right to Withdraw Consent: Withdraw consent where processing is based on consent.

To exercise these rights, please contact us at contact@astrofishgames.com. We aim to respond within one calendar month without charging a fee.

How to Complain

If you have concerns about our data processing practices:

  1. Contact Us: Reach out using the contact details provided above.

  2. ICO Complaint: If unsatisfied with our response, you may file a complaint with the Information Commissioner's Office (ICO):

Changes to This Privacy Notice

We may update this Privacy Notice periodically to reflect changes in our practices or legal requirements. The Effective Date at the top will indicate the latest version. We encourage you to review this Privacy Notice regularly.

Third-Party Services

Our website is hosted by Squarespace and uses Google Analytics for tracking and analytics. Additionally, we utilize a third-party Customer Relationship Management (CRM) system to manage and store your marketing data securely. For more information on how these third parties handle your data, please refer to their respective Privacy Policies and Google Analytics Privacy Policy.

Cross-Border Data Transfers
Some of our third-party service providers (e.g., Google, Squarespace, and our CRM provider) may process personal data outside the UK/EU. We ensure that all such data transfers comply with GDPR through mechanisms such as the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) adopted by the European Commission.

Google Workspace Data Processing

We use Google Workspace to manage our business communications and store your contact information securely. Google acts as a data processor on our behalf, and we have entered into a Customer Data Processing Addendum (CDPA) with Google to ensure your data is handled in compliance with GDPR requirements. This agreement outlines Google's responsibilities in processing your personal data, including implementing robust security measures and adhering to data subject rights.

Data Privacy Statement for Ground Runner: Trials

Our game, available on platforms such as Steam and the Meta Quest Store, does not collect or process any personal data from players. These platforms may collect user information in accordance with their respective privacy policies; however, as developers, we only receive aggregated sales and performance data from these platforms. We do not have access to any personal data, such as names, email addresses, or payment details, ensuring compliance with GDPR and other applicable data protection laws. For more information on how these platforms handle user data, please refer to the privacy policies of Steam and Meta.