Política de Privacidade
Este documento explica como a KoloPlus recolhe, utiliza, armazena e protege os seus dados pessoais em conformidade com as leis da Ucrânia e da União Europeia.
- 1 1. Introdução e definições
- 2 2. Responsável pelo tratamento
- 3 3. Que dados recolhemos
- 4 4. Finalidades do tratamento
- 5 5. Bases legais
- 6 6. Os seus direitos
- 7 7. Períodos de conservação
- 8 8. Partilha de dados
- 9 9. Segurança dos dados
- 10 10. Cookies e rastreadores
- 11 11. Crianças e menores
- 12 12. Alterações a esta política
- 13 13. Contactos do DPO
1. Introdução e definições
1.1. About this policy
This Privacy Policy (“Policy”) describes how KoloPlus (“Platform”, “we”, “us”) processes personal data when you use the website, mobile interfaces, game features, community tools, monetization modules, and related services.
1.2. Definitions
- Personal data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on personal data, including collection, recording, storage, use, disclosure, restriction, or deletion.
- Data controller — the entity determining the purposes and means of processing.
- Processor — an entity processing data on behalf of the controller.
- Data subject — the person whose data is processed.
- Consent — a freely given, specific, informed, and unambiguous indication of wishes.
- DPO — Data Protection Officer.
1.3. Legal framework
We process personal data under applicable law, including GDPR, the laws of Ukraine on personal data protection and electronic communications, and relevant EU platform regulation such as the Digital Services Act where applicable.
2. Responsável pelo tratamento
2.1. Controller details
- Name: KoloPlus
- Legal contact: legal@koloplus.com
- Privacy contact: privacy@koloplus.com
- Jurisdiction focus: Ukraine / EU
2.2. EU representation
Where required by GDPR, an EU representative or equivalent compliance contact may be designated for users in the European Union.
3. Que dados recolhemos
3.1. Data you provide directly
| Category | Examples | Required |
|---|---|---|
| Registration data | Email, nickname, password hash | Required |
| Profile data | Avatar, bio, gender, birth date | Optional |
| User content | Posts, comments, messages, media files | At your choice |
| Support communications | Tickets, complaints, appeals | As needed |
| Payment / payout data | Billing or payout details for monetization flows | Optional / conditional |
3.2. Data collected automatically
| Category | Examples | Purpose |
|---|---|---|
| Technical data | IP address, browser, OS, device resolution | Security, troubleshooting, analytics |
| Device data | Device identifier, model, locale | Personalization and fraud prevention |
| Usage data | Pages viewed, clicks, session duration | Service improvement |
| Approximate location | Country or city inferred from IP | Localization and compliance |
| Gameplay activity | Arena progress, quest events, achievements | Core functionality |
3.3. Third-party sources
- OAuth providers — public profile data and email where you sign in through a social or identity provider.
- Payment processors — transaction status and anti-fraud signals, without storing full card details where not needed.
- Advertising / analytics partners — aggregated or pseudonymous performance data.
4. Finalidades do tratamento
- to create and maintain your account;
- to deliver platform, gameplay, social, moderation, and support features;
- to protect users and detect fraud, abuse, and security incidents;
- to measure service performance and improve usability;
- to comply with legal obligations and regulator requests;
- to personalize interface language, settings, and certain content;
- to run monetization, payouts, and advertising workflows where enabled.
5. Bases legais
- Contract — when processing is necessary to provide the service you requested.
- Consent — for optional cookies, marketing preferences, and similar choices.
- Legitimate interests — for platform security, product analytics, abuse prevention, and internal administration, provided these do not override your rights.
- Legal obligation — where retention, disclosure, or verification is required by law.
6. Os seus direitos
- right of access to your data;
- right to rectification of inaccurate data;
- right to erasure where the law allows it;
- right to restriction of processing;
- right to data portability;
- right to object to certain processing based on legitimate interests;
- right to withdraw consent at any time, without affecting earlier lawful processing;
- right to lodge a complaint with a competent supervisory authority.
7. Períodos de conservação
- Account data — while the account remains active and for a limited period after deletion where needed for security, legal, or dispute handling.
- Logs and security events — for a limited retention window appropriate to fraud prevention and incident response.
- Support and appeal records — until closure and any required legal retention period.
- Financial / payout records — for legally required accounting and anti-fraud periods.
- Cookies — according to their technical lifespan and your settings.
8. Partilha de dados
- Infrastructure and service providers — hosting, CDN, security, monitoring, and email providers.
- Payment and monetization partners — to process eligible payments or payouts.
- Analytics / advertising vendors — only as configured by your consent where required.
- Regulators and law enforcement — when disclosure is legally required or necessary to protect rights, safety, or platform integrity.
Where cross-border transfers occur, we aim to use lawful transfer mechanisms and proportionate safeguards.
9. Segurança dos dados
- access controls and least-privilege principles;
- transport-layer security and secure session handling;
- logging, monitoring, and abuse detection;
- fraud prevention and rate limiting;
- periodic review of permissions and technical safeguards.
10. Cookies e rastreadores
| Type | Purpose | Consent required |
|---|---|---|
| Necessary | Authentication, security, consent memory, core functionality | No |
| Functional | Language, theme, interface preferences | Usually no / depends on local law |
| Analytics | Traffic analysis, performance measurement | Yes where required |
| Advertising | Personalized advertising and campaign measurement | Yes where required |
You can manage cookie choices through the consent banner, your account privacy settings where available, or your browser settings.
11. Crianças e menores
- minimum account age is 13 unless local law requires a higher age;
- for some jurisdictions, parental or guardian consent may be required for younger teens;
- we do not knowingly seek to collect personal data from children below the permitted age threshold.
12. Alterações a esta política
We may update this Policy to reflect legal, technical, product, or operational changes. Material changes may be communicated through the platform, by email, or by consent-related prompts where needed.
- v2.0.0 — GDPR / DSA oriented revision
- v1.0.0 — initial version
13. Contactos do DPO
- Email: privacy@koloplus.com
- Suggested subject: [Privacy Request] or [GDPR Request]
- General legal: legal@koloplus.com
- Support: support@koloplus.com