Privacy Policy of PuzzleGarage.com

Last updated on 01/06/2020

Hello and welcome to the Puzzlegarage.com Privacy Policy which helps you to identify the type of relationship You may enter into with the Puzzlegarage.com.

This is Puzzlegarage.com Privacy Policy ("Puzzle Garage", "We", "Us", "Our") and it applies to the Puzzle Garage site (the "Site", "Puzzle Garage Service", "Service"). For General use of the Service, please see our Terms.

In order to provide you with the best Service and Experience exploring our Service, it is of vital importance that you fully understand Your relationship with Us because, if you reside anywhere in the world outside of the European Union, the European Economic Area (“EU/EEA”) or California state, USA, you agree to the terms of this Privacy Policy by using Puzzle Garage. If you reside in the EU/EEA or California, USA, please review this entire Privacy Policy, for information on specific options that apply to you.

We want to be sure that we took into account everything important to you, including:

  • the information that we collect with your permission,
  • how we use that information with your permission and
  • the ways You can control how that information is used or shared in order to protect your rights.

We will continue to evaluate this Privacy Policy and update it accordingly when there is a change and to comply with regulatory and legal requirements. Please check this Privacy Policy periodically for updates.

1. Who we are

If there are any questions regarding this Privacy Policy You may contact us using the information below:
FinalLevel OU, Pärnu mnt 158, 11317 Tallinn, the Republic of Estonia
Phone: +3726850075
E-mail: info@final-level.com

You also may submit inquiries regarding personal data protection, privacy and security matters to support@puzzlegarage.com.

2. We collect

You may visit our site anonymously.
If you choose to login on our website, next categories of data to and on behalf of you will be processed:

“Account data”
When you login on our site, basic contact details are collected: your e-mail address and name. Notice we don’t store any passwords because we’re using only OAuth third party providers. We assume no responsibility or liability in the event such third parties collect, use or share any information about You in violation of its own privacy policy, our agreement with it (if any) or any other applicable laws, rules or regulations.

“Configuration data”

  • Puzzles you’ve completed
  • Favorites puzzles list
  • Difficulty and time you’ve spent to complete puzzles
  • Progress for uncompleted puzzles you’ve played

“Log-in Data”
To log in to the site, You are required to consent with Terms of Services and this Privacy Policy. After login the following data are automatically logged at Puzzle Garage:

  • Your IP number in anonymized form.
  • The date and time of the latest login (based on Your consent).
After login You are issued with cryptographic token which is used both as a proof of Your consent and authorisation. This token is stored in Your cookie, and sent with each request by Your browser to Puzzle Garage.

3. What do we use your information for?

Any of the information we collect from you may be used for one or more of the following purposes:

  • To personalize your experience (the information will help Puzzle Garage better respond to your individual needs);
  • To improve our website (Puzzle Garage continually strives to improve our website offerings based on the information and feedback we receive from our Users);
  • To identify you as a an Puzzle Garage User;
  • To enable secure login for you in the Puzzle Garage Service;
  • To establish a primary channel of communication with you;
  • To produce and display cookie declarations.

If at any time You would like to stop sharing Your information, You can delete your data after login by clicking on "Delete my Data" or by contacting us at support@puzzlegarage.com.

4. Legal basis

EU General Data Protection Regulation (GDPR)
The processing of your data is either based on your consent or in case the processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract, cf. GDPR art. 6(1)(a)-(b) whatever is may be applicable.

If the processing is based on your consent, you may at any time withdraw your consent by simply deleting your personal data by clicking “Delete my Data” (in case of login) or by contacting us at support@puzzlegarage.com.

Children
We do not permit children under 13 years of age (or under 16 years of age for children residing in the EU/EEA) to register and does not knowingly collect any personal information from them. If you are under the age of 13 (or under the age of 16 if you reside in the EU/EEA), please do not register with Us. In the event that we learn affirmatively that we have obtained or collected information from or about children under 13 (or, where applicable, 16) years of age, we will use our best efforts to remove such information from our servers. If you are aware of any child under the age these age limits who have registered with us, please contact our Support Team by emailing at support@puzzlegarage.com.

California Consumer Privacy Act (CCPA)
CCPA is a law designed to protect the data privacy rights of citizens living in California. Under this law you have important rights, describing below:

How your data is being used
Please, review clauses 2,3 and 6 of current Privacy Policy. To see what data we collect and how we use it.

Opt out of having your personal information been used
Find out how your data is been used by third party, which is Google for our project: https://policies.google.com/privacy
You can choose to opt out of having your personal information sold or been used by third-parties and businesses, such as Google Doubleclick or Google Adsense.

By clicking on the button below you will restricts Google to use your personal data. Google will only show you non-personalized ads. Non-personalized ads are based on contextual information, such as the content of our website.

Delete all your personal data
If you authorized on Puzzle Garage, you can delete all you personal data from our servers. All End User Data, Configuration Data and System Generated Data will be erased after account deletion in 29 days.

5. How do we protect your information?

Puzzle Garage implements the following technical, physical and organizational measures to maintain the safety of your personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized use, unauthorized modification, disclosure or access and against all other unlawful forms of processing.

Availability
Puzzle Garage uses distributed system and doing it’s best to provide the best availability possible, but service is provided as is, and Puzzle Garage doesn’t responsible for any damage which might be caused by interruptions.

Confidentiality
All personnel are subject to full confidentiality and any subcontractors and subprocessors are required to sign a confidentiality agreement if not full confidentiality is part of the main agreement between the parties.

The personal data can be only accessed through private network over an encrypted connection and only from the limited set of IPs. Also any access by authorized personnel is logged. We do not store personal information outside of the private servers even temporarily.

Transparency
Puzzle Garage will at all times keep you informed about changes to the processes to protect data privacy and security, including practices and policies. You may at any time request information on where and how data is stored, secured and used. Puzzle Garage will also provide the summaries of any independent audits of the Service (if applicable).

Isolation
All access to personal data is blocked by default, using a zero privileges policy. Access to personal data is restricted to individually authorized personnel. Authorized personnel are granted a minimum access on a need-to-have basis.

The ability to intervene
Puzzle Garage enables your rights of access, rectification, erasure, blocking and objection mainly by providing built-in functions for data handling in the Service, and also by informing about and offering You possibility of objection when Puzzle Garage is planning to implement changes to relevant practices and policies.

Monitoring
Puzzle Garage uses security reports to monitor access patterns and to proactively identify and mitigate potential threats. Administrative operations, including system access, are logged to provide an audit trail if unauthorized or accidental changes are made. System performance and availability is monitored from both internal and external monitoring services.

Personal Data breach notification
In the event that your data is compromised, Puzzle Garage will notify you and competent Supervisory Authority(ies) within 72 hours by e-mail with information about the extent of the breach, affected data, any impact on the Service and Puzzle Garage's action plan for measures to secure the data and limit any possible detrimental effect on the data subjects.

6. How we use cookies

Authorization token (we generate unique cryptographically signed token on every request from the browser, we validate this token and associate it with the User’s name, email and favorites).

We use Google Analytics and Google Doubleclick For Publishers which also uses cookies: https://policies.google.com/privacy

7. Do we disclose any information to outside parties?

We do not sell, trade or otherwise transfer to outside parties any personally identifiable information.

This does not include trusted third parties or subcontractors who assist us in operating our website, conducting our business, or servicing you. Such trusted parties may have access to personally identifiable information on a need-to-know basis and will be contractually obliged to keep your information confidential.

We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect our or others’ rights, property, or safety. Furthermore, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.

Legally required disclosure
Puzzle Garage will not disclose Your data to law enforcement except when instructed by You or where it is required by law. When governments make a lawful demand for Your data from Puzzle Garage, Puzzle Garages trives to limit the disclosure. Puzzle Garage will only release specific data mandated by the relevant legal demand. If compelled to disclose your data, Puzzle Garage will promptly notify you and provide a copy of the demand unless legally prohibited from doing so.

8. Third party links

At our discretion, we may include or offer third party products or services on our website. These third party sites have separate independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked websites. Nonetheless, we seek to protect the integrity of our website and welcome any feedback about these websites.

9. Where do we store the information?

No stored data will be transferred, backed up and/or recovered by Puzzle Garage outside of the European Union.

Personal data location
All data are stored in databases and file repositories hosted in Falkenstein, Germany (Hetzner DC5). All data are automatically replicated in real time to secondary hot failover databases and file repositories Falkenstein, Germany (Hetzner DC5).

Databases are continuously backed up to enable restore to any point in time within a retention period of 29 days. Backups are stored on file storage in Falkenstein, Germany (Hetzner DC7).

Installation of software on cloud customer’s system
No installation of software is required to use the Service. The login-protected Service is accessible through a standard web browser.

10. Access, data portability, migration, and transfer back assistance

You may at any time obtain confirmation from Puzzle Garage as to whether or not personal data concerning you are being processed. You may at any time order a complete data copy, which you may transmit to another controller of the data. Your data will be delivered within 10 working days by Puzzle Garage as files in CSV format. Logical relations between datasets will be preserved in form of unique identifiers.

11. Request for rectification, restriction or erasure of the personal data

Rectification
You may at any time obtain without undue delay rectification of inaccurate personal data concerning you.

Restriction of processing personal data
You may at any time request us to restrict the processing of personal data when one of the following applies:
  • if you contest the accuracy of the personal data, for a period enabling Puzzle Garage to verify the accuracy of the personal data;
  • if the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead; or
  • if Puzzle Garage no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims.
Erasure
You may without undue delay request the erasure of personal data concerning you, and Puzzle Garage shall erase the personal data without undue delay when one of the following applies:
  • if the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • if you withdraw your consent on which the processing is based, and where there is no other legal ground for the processing;
  • if you object to the processing in case the processing is for direct marketing purposes;
  • if the personal data have been unlawfully processed; or
  • if the personal data have to be erased for compliance with a legal obligation in EU or national law.

12. Data retention

Data retention policy
All End User Data, Configuration Data and System Generated Data will be erased after account deletion in 29 days.

Data retention for compliance with legal requirements
You cannot require Us to change any of the default retention periods, except for the reasons for erasure as it is stated above, but may suggest changes for compliance with specific sector laws and regulations.

13. Accountability

We use logs all system updates, configuration changes and access to provide an audit-trail if unauthorized or accidental changes are made.You may request a data protection audit performed by an independent third party who is also accepted by Puzzle Garage. You may pay a Fee associated with the request plus applicable taxes as well as any other costs related to the audit as the case may be.

14. Cooperation

Puzzle Garage will cooperate with you in order to ensure compliance with applicable data protection provisions, e.g. to enable you to effectively guarantee the exercise of data subjects’ rights (right of access, rectification, erasure, blocking, opposition), to manage incidents including forensic analysis in case of security breach.

15. Terms of Service

Please also visit our Terms of Service section establishing the use, disclaimers, and limitations of liability governing the use of our web-site.

16. Changes to our Privacy Policy

If we decide to change our Privacy Policy, we will post those changes on this page, and/or update the Privacy Policy modification date above.

17. If you not satisfied

If you have any questions or comments about our Privacy Policy, or if you have an unresolved privacy or data use concern that you believe was not adequately addressed in our Policy, please contact Us at support@puzzlegarage.com.

Also You may at any time lodge a complaint with a supervisory authority regarding Puzzle Garage’s collection and processing of your personal data.

The Data Protection Inspectorate will continue to act as the supervisory authority in Estonia.

Data Protection Inspectorate, Väike-Ameerika 19, 10129 Tallinn, Estonia, www.aki.ee

Thank You for choosing Puzzle Garage and enjoy our puzzles collection! :)