1 Data we collect and purposes of data processing
1. We may collect, record and analyze information of Visitors to our website.
2. We also record Usage Data. It is information collected automatically through xocsgo website (or third-party services employed in xocsgo), which can include: the IP addresses or domain names of the computers utilized by the Users who use xocsgo, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page) and the details about the path followed with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
3. We use this information in aggregate to assess the popularity of the web pages on our website and how we perform in providing content to you. When combined with other information, we know about you from previous visits, the data possibly could be used to identify you personally, even if you are not signed into our website.
4. Processing of this information is relied on our legitimate interests. It is necessary for managing and running our business to efficiently and effectively provide quality services including client support, developing and improving services, determining who may be interested in them.
5. We may process information only if there is a legitimate interest. We do so after having given careful consideration to:
6. whether the same objective could be achieved through other means;
7. whether processing (or not processing) data might cause you harm;
8. whether you would expect us to process your data and consider it reasonable for us to do so.
9. For example, we may process your data for the following purposes :
10. To create anonymous, aggregated statistics about the use of our website, products, services and other programmes, which we may share with third parties and/or make available to the public.
11. To develop and improve new and existing products and services, recommendations, advertisements and other communications, and learn more about our users’ preferences in general.
12. When you contact us, whether by telephone or email, you give us your implicit consent because you reasonably expect us to reply. We collect the data you give us in order to reply with the information you need. We record your request and our reply in order to increase the efficiency of the organization of our client support service. We keep personally identifiable information associated with your message, such as your name, email address and mobile telephone number, so as to be able to track our communications with you in order to provide you with high quality service.
1. In order to provide services to our Users, we collect their Personal Data.
2. During the creation of your account on our website, you provide us with your country, name, last name, patronymic name, date of birth and email. Also, there is an option to sign in with Steam or other third-party account, in this case you provide us with your Steam ID or Trade URL.
3. We process this information on the basis that there are a contract (When you complete the registration of an account on our website a contract is formed between you and us) between us, legal obligations (International anti-money laundering counter terrorism financing legislation, provisions of the gaming license) and our legitimate interests (prevention fraud).
4. This information is used by us to identify our Users, provide you with services, prevent fraud create and manage User accounts, payments and withdrawals, respond to any User complaints, prevent and detect improper use of our systems, prevent crime, detect, investigate, and report crime, manage risk for us and our Users, comply with any laws and regulations that apply to us, provide you with billing, mailings, notification, support, marketing actions, the ability to restore account in case of loss, and to meet other obligations. Also we may use it in order to provide you with suggestions and advice on services and how to obtain the most from using our website. We use such data in ways you would reasonably expect and which have a minimal privacy impact.
5. Processing of Personal Data for marketing purposes is relied on the consent obtained from you.
2 Compliance with General Data Protection Regulation (GDPR)
1. For Visitors and Users located in the European Economic Area (EEA) privacy rights are granted and all processing of Personal Data is performed in accordance with regulations and rules of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, known as the General Data Protection Regulation (GDPR).
2. We process Personal Data as a Controller, as defined in the GDPR:
xocsgo, with which, you as a User, have entered into an agreement when you created your User account at xocsgo Website, will be the Controller of User Data, as outlined above in the “User” section. Also, xocsgo will be the Controller for Visitor Data, as outlined above in “Visitor” section.
3 The rights of Users
1. Users may exercise certain rights regarding their Data processed by Data Controller.
2. In particular, Users have the right to do the following:
Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data. Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent. Further details are provided in the dedicated section below. Access their Data. Users have the right to learn if Data is being processed by Data Controller, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing. Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected. Restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, Data Controller will not process their Data for any purpose other than storing it. Have their Personal Data deleted or otherwise removed. Users have the right, under certain circumstances, to obtain the erasure of their Data from Data Controller. Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that the Data is processed by automated means and that the processing is based on the User's consent, on a contract which the User is part of or on pre-contractual obligations thereof. Lodge a complaint. Users have the right to bring a claim before their competent data protection authority.
3. When we receive any request to access, edit or delete personally identifiable information, we shall first take reasonable steps to verify your identity before granting you access or otherwise taking any action. This is important to safeguard your information.
4. Where Personal Data is processed for the purposes of the legitimate interests pursued by Data Controller, Users may object to such processing by providing a ground related to their particular situation to justify the objection.
5. Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time without providing any justification by following the “unsubscribe” link they will find on all the email marketing messages we send them. Alternatively, you can contact us at email [email protected] .
6. Any requests to exercise User rights can be directed to Data Controller through the contact details provided in this document. These requests can be exercised free of charge and will be addressed by Data Controller as early as possible and always within one month.
4 Data Retention
1. Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
2. We will keep your data for the period that you are a User of xocsgo. If you are no longer a User of xocsgo, we will keep your data for the minimum length of time required to comply with the purposes set out in this policy and relevant legal or regulatory obligations.
Personal Data collected for purposes related to the performance of a contract between Data Controller and the User shall be retained until such contract has been fully performed. Personal Data collected for the purposes of Data Controller’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by Data Controller.
3. Data Controller may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, Data Controller may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority.
4. Any information about the Visitors is deleted on an annual basis. Your information will be deleted if you did not communicate with the support team for more than 12 (twelve) months.
5. Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
5 Information Security
1. We care to ensure the security of Personal Data. We follow generally accepted industry standards to protect the information submitted to us, both during transmission and once we receive it. We maintain technical, physical, and administrative security measures to provide reasonable protection for your Personal Data. When we or our contractors process your information, we also make sure that your information is protected from unauthorized access, loss, manipulation, falsification, destruction or unauthorized disclosure. This is done through appropriate administrative, technical and physical measures.
2. We always use Pseudonymization as a method of securing Personal Data we process as the Processor.
3. There is no 100% secure method of transmission over the Internet or electronic storage. We therefore cannot guarantee its absolute security.
6 Personal Data and non-identifying aggregated data we share with others
1. We may share your Personal Data within the affiliated companies and with other organizations.
2. We use Google Analytics to monitor and analyze web traffic. Google Analytics is a web analysis service provided by Google LLC. (“Google”). Google utilizes the Data collected to track and examine the use of our website, to prepare reports on its activities and share them with other Google services. Google may use the Data collected to contextualize and personalize the ads of its own advertising network.
3. We work with third party service providers which provide website development, hosting, maintenance, sending emails, marketing, technical support and assistance, processing credit card payments, IT and cyber security services, law enforcement agencies, regulators and other authorities, credit reference agencies, fraud prevention agencies, identity verification agencies and third parties necessary to provide products or services which you have requested.
4. We may need to share your Personal Data with the third parties that provide those services. Where your Personal Data are transferred outside of the European Economic Area (“EEA”), we require that appropriate safeguards are in place. These contractors may have access to, or process Personal Data on behalf of us, as part of providing those services to us. We limit the information provided to these service providers to the extent it is reasonably necessary for them to perform their functions.
5. We guarantee that we have Data Processing Agreements in place with our service providers, ensuring compliance with the GDPR and our contracts with them requiring to maintain the confidentiality of such information. All data transfers inside and outside of the EEA are being done in accordance with these Data Processing Agreements. All data transfers are performed in accordance with the strictest security regulations.
7 Use of site by children
1. We do not provide services or market to children.
2. The Service is not directed to persons under the age of 18. Users declare themselves to be adult according to their applicable legislation.
3. We collect data about all Users and Visitors regardless of age. We do not expect that some of those users and visitors will be children.
Date of update 10/27/2020