PRIVACY POLICY
Effective Date: 1 April 2025 | Last Updated: 1 April 2025
1. Introduction
Powerfantasy HK Limited ("Powerfantasy", "we", "us", or "our"), a company incorporated under the laws of the Hong Kong Special Administrative Region of the People's Republic of China, is committed to protecting the privacy and personal data of its users.
This Privacy Policy explains how we collect, use, disclose, transfer, and protect personal data in connection with our games, applications, websites, and related online services (collectively, the "Services"). It applies to all users of our Services, regardless of location.
This Privacy Policy should be read together with our Terms of Use. By using the Services, you acknowledge that you have read and understood this Privacy Policy.
We are committed to complying with applicable data protection and privacy laws, including:
- The Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong ("PDPO")
- The European Union General Data Protection Regulation ("GDPR") and the UK GDPR, where applicable
- The California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), where applicable
- The Children's Online Privacy Protection Act ("COPPA"), where applicable
- Other applicable data protection laws in jurisdictions where we operate
2. Who We Are and How to Contact Us
For the purposes of applicable data protection laws, the data controller responsible for your personal data is:
Powerfantasy HK Limited
RM 1911 LEE GARDEN ONE, 33 HYSAN AVENUE CAUSEWAY BAY, HONG KONG
Data Protection / Privacy Inquiries: support@powerfantasygames.com
For EEA/UK users, if you have concerns about how we handle your personal data, you also have the right to contact your local data protection authority (see Section 11).
3. Information We Collect
We collect personal data in the following categories, depending on how you interact with our Services:
3.1 Information You Provide to Us
- Account Information: When you create an account, we collect your username, email address, date of birth, and password (stored in encrypted form).
- Profile Information: Nickname, avatar, biography, signature, and other optional profile details you choose to provide.
- Communications: Messages, chat records, support tickets, survey responses, and other communications you send to us or through the Services.
- Payment Information: When you make a purchase, payment transaction data is processed by our third-party payment processors. We do not store full credit card numbers. We may retain limited transaction records (e.g., transaction ID, amount, currency, date) for accounting and legal compliance purposes.
- User-Generated Content: Content you create or upload within the Services, including in-game content, forum posts, and feedback.
3.2 Information Collected Automatically
- Device Information: Device type, model, operating system, unique device identifiers (e.g., IMEI, IDFA, Android Advertising ID), IP address, browser type, and language settings.
- Usage Data: Game progress, in-game statistics, features used, time spent in the Services, session information, and interaction logs.
- Log Data: Server logs, error reports, crash data, and diagnostic information.
- Cookies and Tracking Technologies: We use cookies, pixel tags, and similar technologies as described in Section 6.
- Location Data: General location information derived from your IP address. We do not collect precise GPS location without your explicit consent.
- Anti-Cheat and Device Integrity Data: We integrate third-party anti-cheat software and security monitoring tools into our Services. These tools automatically collect information from your device, including hardware specifications and identifiers, operating system and software configuration, in-game process and memory state, network connection data, and gameplay behaviour patterns. This information is used solely to detect cheating, unauthorised software modifications, fraud, and other violations of our Terms of Use. The specific third-party anti-cheat providers used and details of the data they collect are listed in our third-party service provider list available at https://www.powerfantasygames.com/sdk-list or by contacting support@powerfantasygames.com.
3.3 Information from Third Parties
- Social Login: If you connect the Services to a third-party account (e.g., Apple, Google, Facebook), we may receive your name, email address, profile picture, and friend list from that service, subject to your privacy settings on that platform.
- Analytics Partners: Aggregated and anonymised analytics data from third-party analytics providers to help us understand usage of the Services.
- Anti-Cheat and Security Providers: Information provided by anti-cheat systems and security tools designed to detect fraud and cheating.
3.4 Children's Data
Our Services are not directed to children under 13 years of age. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe that your child under 13 has provided us with personal data, please contact us at support@powerfantasygames.com immediately, and we will take steps to delete such data from our systems.
For users between 13 and 17 years of age (or the applicable age of majority in their jurisdiction), certain features of the Services may require parental consent. We apply additional safeguards to personal data collected from users in this age group, including limiting data collection, restricting targeted advertising, and providing parental controls where required by applicable law (including COPPA).
4. How We Use Your Information
We use the personal data we collect for the following purposes:
- Account Management: To create and manage your account, verify your identity, and provide access to the Services.
- Service Delivery: To operate, maintain, and improve the Services, including game features, updates, and customer support.
- Personalisation: To personalise your experience, including tailored content and in-game recommendations.
- Communications: To send you service-related notices, updates, security alerts, and support messages. Where you have consented, to send you promotional and marketing communications.
- Analytics and Research: To analyse usage patterns, conduct research, and improve our Services and user experience.
- Safety and Security: To detect, investigate, and prevent fraudulent transactions, cheating, abuse, security incidents, and other harmful or illegal activities.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
- Payment Processing: To process purchases and manage transactions.
- Advertising: Subject to applicable consent requirements, to serve contextual and interest-based advertising within the Services. We will obtain your consent for targeted advertising where required by applicable law.
Our legal bases for processing personal data under the GDPR (for EEA/UK users) include:
- Performance of a Contract: Processing necessary to provide the Services to you (e.g., account management, game delivery).
- Legitimate Interests: Processing based on our legitimate business interests, such as security, fraud prevention, and service improvement, where these are not overridden by your interests.
- Consent: Where you have given your explicit consent (e.g., marketing communications, targeted advertising, certain cookies).
- Legal Obligation: Processing necessary to comply with applicable laws.
5. Information Sharing and Disclosure
We do not sell your personal data to third parties. We may share your personal data with:
- Service Providers: Third-party companies that assist us in operating the Services, including cloud hosting providers, payment processors, analytics services, customer support platforms, anti-cheat systems, and marketing services. These parties process data only as instructed by us and are contractually required to maintain appropriate data security.
- Business Partners: With your consent, we may share certain information with partners to provide joint offerings or services.
- Affiliates and Group Companies: We may share data within the Powerfantasy group of companies for the purposes described in this Privacy Policy.
- Legal and Regulatory Authorities: Where required by applicable law, court order, or government request, or where necessary to protect our rights, property, or safety or the rights, property, or safety of others.
- Business Transactions: In connection with a merger, acquisition, reorganisation, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Services if your personal data becomes subject to a different privacy policy.
A list of key third-party service providers and SDKs used in our Services is available at https://www.powerfantasygames.com/sdk-list or by contacting support@powerfantasygames.com.
6. Cookies and Tracking Technologies
We and our third-party partners use cookies, web beacons, pixel tags, and similar tracking technologies on our websites and in our applications. These technologies help us:
- Keep you logged in and remember your preferences.
- Understand how you use the Services and measure performance.
- Provide personalised content and advertising.
- Detect and prevent fraud and security incidents.
You can manage your cookie preferences through your browser settings or through our cookie preference centre (where available). Please note that disabling certain cookies may affect the functionality of the Services.
For users in the EEA/UK, we obtain your consent before setting non-essential cookies (such as analytics or advertising cookies), in accordance with the ePrivacy Directive and applicable national law.
We do not use cookies or tracking technologies to track users on third-party websites without appropriate consent.
7. International Data Transfers
Your personal data may be transferred to, stored in, and processed in countries other than your country of residence, including Hong Kong, Singapore, and other jurisdictions where our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.
For transfers of personal data from the EEA or UK, we implement appropriate safeguards as required by the GDPR and UK GDPR, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission, as applicable.
- Adequacy decisions by the European Commission or UK Secretary of State, where available.
- Other appropriate safeguards as permitted under applicable law.
For transfers from Hong Kong, we ensure that overseas transfers are made only in compliance with the PDPO, including ensuring comparable levels of protection are in place.
For more information about our international transfer mechanisms or to obtain a copy of the relevant safeguards, please contact support@powerfantasygames.com.
8. Data Retention
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements.
In general:
- Account Data: Retained while your account is active and for a reasonable period thereafter to allow account reactivation, after which it is deleted or anonymised.
- Transaction Records: Retained for up to seven (7) years for tax, accounting, and legal compliance purposes.
- Communication Records: Support tickets and communications are retained for up to three (3) years.
- Log and Usage Data: Typically retained for up to twelve (12) months.
When we no longer need personal data, we will securely delete or anonymise it. You may request deletion of your personal data at any time, subject to applicable legal requirements (see Section 10).
9. Data Security
We implement a range of technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, including:
- Encryption of personal data in transit and at rest using industry-standard protocols (e.g., TLS/SSL).
- Access controls and multi-factor authentication for internal systems.
- Regular security assessments, penetration testing, and vulnerability management.
- Staff training on data protection and security practices.
- Incident response procedures for detecting and responding to security breaches.
Despite our efforts, no method of transmission or storage is completely secure. If you suspect any unauthorised access to your account or personal data, please contact us immediately at support@powerfantasygames.com.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and/or the relevant supervisory authority in accordance with applicable law.
10. Your Rights and Choices
Subject to applicable law, you have the following rights regarding your personal data:
- Access: You have the right to request a copy of the personal data we hold about you.
- Correction: You have the right to request correction of inaccurate or incomplete personal data.
- Deletion: You have the right to request deletion of your personal data, subject to certain exceptions (e.g., legal obligations).
- Opt-Out of Marketing: You may opt out of receiving promotional communications at any time by following the unsubscribe instructions in our emails or by contacting us.
- Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Data Portability: Where technically feasible, you may request a copy of your data in a structured, commonly used, and machine-readable format.
To exercise your rights, please contact us at support@powerfantasygames.com or through the in-game support function. We will respond to requests within 40 days as required under the PDPO, or within the timeframes required by applicable law in your jurisdiction.
We may request verification of your identity before processing your request. In some circumstances, we may charge a reasonable fee or decline requests that are manifestly unfounded or excessive.
11. Additional Rights for EEA and UK Users (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the GDPR and UK GDPR:
- Right to Erasure ("Right to Be Forgotten"): You may request that we erase your personal data where it is no longer necessary, where you withdraw consent, or where processing is unlawful.
- Right to Restriction of Processing: You may request that we restrict the processing of your personal data in certain circumstances.
- Right to Object: You may object to processing based on legitimate interests or for direct marketing purposes.
- Rights Related to Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, unless necessary for a contract or based on your consent. Our Services do not currently make such decisions.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at https://edpb.europa.eu/. UK residents may contact the Information Commissioner's Office (ICO) at https://ico.org.uk/.
To exercise your GDPR rights, please contact our Data Protection Officer at support@powerfantasygames.com.
12. Additional Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share information.
- Right to Delete: You have the right to request deletion of personal information we have collected, subject to certain exceptions.
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: We do not sell your personal information as defined under the CCPA. We do not share personal information for cross-context behavioural advertising without your consent.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit our use of sensitive personal information to purposes permitted by applicable law.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To exercise your CCPA rights, please contact us at support@powerfantasygames.com or use the in-app request function. We will respond to verifiable consumer requests within 45 days, with a possible extension of an additional 45 days where reasonably necessary.
You may designate an authorised agent to make requests on your behalf. We may require verification of your identity and of the agent's authorisation.
For the 12 months preceding the Last Updated date of this Privacy Policy, we have not sold or shared personal information as defined under the CCPA.
13. Third-Party SDK and Advertising
Our Services may integrate third-party software development kits (SDKs) for analytics, advertising, social login, and other features. These third-party SDKs may independently collect and process personal data in accordance with their own privacy policies.
Where required by applicable law (including the EU Digital Markets Act for designated Gatekeepers), we will present you with clear consent banners before activating data sharing with third-party advertising or analytics platforms.
A full list of third-party SDKs integrated in our Services is available at https://www.powerfantasygames.com/sdk-list or by contacting support@powerfantasygames.com.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by:
- Posting the updated Privacy Policy on our Services with a revised effective date.
- Sending an email notification to the address associated with your account, where required by applicable law.
- Displaying a prominent in-app notice.
Your continued use of the Services after the effective date of the updated Privacy Policy constitutes your acceptance of the changes. If you do not agree to the updated Privacy Policy, please discontinue use of the Services.
15. Governing Law
This Privacy Policy is governed by the laws of the Hong Kong Special Administrative Region of the People's Republic of China. Any disputes arising from or relating to this Privacy Policy shall be subject to the dispute resolution mechanism set out in our Terms of Use.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Team: