1. Who we are (Data Controller)
Fun Fiesta Loungz ("we", "us", "our", "the Platform") operates the website funfiestaloungz.com, an educational social-gaming platform that uses virtual credits only and offers no real-money play. For the purposes of the EU General Data Protection Regulation 2016/679 ("GDPR"), the Polish Personal Data Protection Act of 10 May 2018, and any other applicable data-protection law, the Data Controller is Fun Fiesta Loungz, ul. Tamka 3/1, 91-403 Łódź, Poland (head office) and Aviapolis, Teknobulevardi 3–5, 01530 Vantaa, Finland (secondary office), operated by Afterburn Łukasz Spierewka (NIP 7252301429). All privacy enquiries must be directed to privacy@funfiestaloungz.com.
This Policy is exhaustive and binding. By accessing the Platform you acknowledge that you have read, understood, and accepted every provision below. If you do not agree, you must cease using the Platform immediately.
2. The data we process
2.1 Data stored locally in your browser. The core of the Platform stores data exclusively in your browser's localStorage and a single language cookie. This data never reaches our servers and is fully under your control:
- ffl_user — email address, display name, and registration timestamp (registered users only)
- ffl_users — the list of accounts created on this device, including a base64-encoded password hash (this is not encryption and must not be treated as secure storage of a sensitive password)
- ffl_credits — your virtual-credit balance (no monetary value)
- ffl_lang — your selected language
- ffl_cookies — your cookie/consent choice
- ffl_tut_* / ffl_guide_* — flags recording that you have seen a game's tutorial
2.2 Data you actively send to us (server-side). When, and only when, you voluntarily submit the contact form, the data you type is transmitted to our server and stored there in a plain server-side data file for the sole purpose of responding to you. The fields collected are: name, email address, subject, message, the date and time of submission, and the IP address from which the submission was made. We deduplicate by email address. We do not use this data for marketing, we do not sell it, and we do not share it with third parties except where strictly required by law.
2.3 Standard server logs. Like virtually every website, our hosting provider may automatically record technical request logs (IP address, timestamp, user-agent, requested URL) for security, fraud-prevention, and operational-integrity purposes. These logs are processed under our legitimate interest and are retained only as long as necessary.
2.4 No special-category data. We do not knowingly collect special categories of personal data (Article 9 GDPR) such as health, ethnicity, religion, or biometric data. Do not submit such data to us.
3. Legal bases for processing (Article 6 GDPR)
We process personal data only where a lawful basis applies:
- Consent — Art. 6(1)(a): cookies/localStorage, age confirmation, and the storage of your contact-form submission are based on your freely given, specific, informed, and unambiguous consent, which you may withdraw at any time.
- Contract — Art. 6(1)(b): providing the optional account and credit-persistence features you request.
- Legitimate interests — Art. 6(1)(f): securing the Platform, preventing fraud and abuse, maintaining server logs, and answering your enquiries. We have balanced these interests against your rights and freedoms and concluded they do not override them.
- Legal obligation — Art. 6(1)(c): where we must retain or disclose data to comply with applicable law, regulation, or a binding order of a competent authority.
4. Your rights (Articles 15–22 GDPR)
Subject to the conditions in the GDPR, you have the right to:
- Access (Art. 15) — obtain confirmation of, and a copy of, the personal data we hold about you;
- Rectification (Art. 16) — have inaccurate data corrected without undue delay;
- Erasure / "right to be forgotten" (Art. 17) — have your data deleted where the conditions are met;
- Restriction (Art. 18) — restrict processing in defined circumstances;
- Data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format;
- Objection (Art. 21) — object to processing based on legitimate interests;
- Not be subject to automated decision-making (Art. 22) — we do not carry out automated decision-making or profiling that produces legal or similarly significant effects;
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
To exercise any right, email privacy@funfiestaloungz.com. We will respond within one month (Art. 12(3)), extendable by two further months for complex requests. We may require proof of identity before acting. Most browser-stored data you can erase yourself at any time via your browser settings or the reset button on our Cookie Policy page.
5. Retention
Browser-stored data persists on your device until you clear it. Contact-form submissions are retained for up to twenty-four (24) months from the date of last contact, after which they are deleted, unless a longer period is required to establish, exercise, or defend legal claims. Server logs are retained for the shortest period consistent with security and legal requirements.
6. Disclosure and international transfers
We do not sell personal data. We may disclose data to: (a) our hosting/infrastructure provider acting as a processor under a written agreement compliant with Art. 28 GDPR; and (b) competent authorities where legally compelled. Where any transfer outside the European Economic Area occurs, it will be protected by an adequacy decision or appropriate safeguards under Chapter V GDPR (e.g. Standard Contractual Clauses).
7. Security
We implement appropriate technical and organisational measures (Art. 32 GDPR) proportionate to the risk. However, no method of transmission or storage is perfectly secure. The base64 password hash used by the optional local account feature is obfuscation, not strong encryption; you must not reuse an important password. You use the Platform at your own risk to the maximum extent permitted by law.
8. Personal-data breaches
Where a breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within seventy-two (72) hours of becoming aware of it (Art. 33), and will notify affected individuals without undue delay where the breach is likely to result in a high risk (Art. 34).
9. Children
The Platform is strictly for persons aged eighteen (18) or over. We do not knowingly process the data of minors. If we learn that we have inadvertently collected data from a minor, we will delete it promptly.
10. Changes to this Policy
We may amend this Policy at any time. The "Updated" date reflects the latest version. Material changes will be signposted on the Platform. Continued use after changes constitutes acceptance.
11. Complaints and supervisory authority
You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your residence, place of work, or place of the alleged infringement. The relevant lead supervisory authority is: the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
12. Contact
Data Controller: Fun Fiesta Loungz, ul. Tamka 3/1, 91-403 Łódź, Poland (head office) and Aviapolis, Teknobulevardi 3–5, 01530 Vantaa, Finland (secondary office), operated by Afterburn Łukasz Spierewka (NIP 7252301429). Privacy contact: privacy@funfiestaloungz.com.