Back to Home

GDPR Compliance

General Data Protection Regulation

Last Updated: January 2025

1. Our Commitment to GDPR

Maori Legend Games is committed to complying with the General Data Protection Regulation (GDPR) and protecting the privacy rights of all our users, particularly those in the European Economic Area (EEA). This document outlines how we meet our obligations under GDPR and how you can exercise your data protection rights.

We believe that data protection and cultural respect go hand in hand. Just as we honor Maori traditions and indigenous heritage, we honor your right to privacy and control over your personal information.

2. Legal Basis for Processing

Under GDPR, we must have a legal basis to process your personal data. We process your information based on:

2.1 Consent

When you accept our cookie policy, create an account, or opt-in to communications, you provide consent for us to process your personal data for specified purposes. You have the right to withdraw consent at any time.

2.2 Contract Performance

Processing is necessary to provide you with our social gaming services and fulfill our obligations under our Terms and Conditions.

2.3 Legitimate Interests

We process certain data based on our legitimate interests in operating and improving our platform, preventing fraud, and ensuring security, provided these interests do not override your rights and freedoms.

2.4 Legal Obligations

We process data to comply with legal requirements, such as age verification laws and record-keeping obligations.

3. Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

3.1 Right to Access (Article 15)

You have the right to request a copy of the personal data we hold about you. We will provide this information in a structured, commonly used, and machine-readable format within 30 days of your request.

3.2 Right to Rectification (Article 16)

You can request that we correct any inaccurate or incomplete personal data we hold about you. We will make corrections within 30 days and notify any third parties with whom we shared the data.

3.3 Right to Erasure / "Right to be Forgotten" (Article 17)

You can request deletion of your personal data when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • Erasure is required for compliance with a legal obligation

3.4 Right to Restriction of Processing (Article 18)

You can request that we restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

3.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller where technically feasible.

3.6 Right to Object (Article 21)

You can object to our processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.

3.7 Right Not to be Subject to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal or similarly significant effects.

3.8 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

4. How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at:

  • Email: support@maorilegendgames.com
  • Subject Line: "GDPR Data Request"
  • Include: Your full name, email address, and specific request

We will respond to your request within 30 days. If we need additional time, we will inform you of the extension and the reasons for it. There is no fee for exercising your rights unless your request is manifestly unfounded or excessive.

5. Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our GDPR compliance and handle data protection matters. You can contact our DPO directly:

  • Email: dpo@maorilegendgames.com
  • Address: Data Protection Officer, 225 Queen Street, Auckland 1010, New Zealand

6. Data Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Pseudonymization and encryption of personal data
  • Ongoing confidentiality, integrity, and availability of processing systems
  • Ability to restore availability and access to data in a timely manner
  • Regular testing and assessment of security effectiveness
  • Staff training on data protection and security
  • Incident response and breach notification procedures

7. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach.

If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, providing information about:

  • The nature of the personal data breach
  • The likely consequences of the breach
  • The measures we have taken or propose to take
  • Contact information for our Data Protection Officer

8. International Data Transfers

Your personal data may be transferred to and processed in countries outside the EEA, including New Zealand. We ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions recognizing equivalent data protection standards
  • Binding corporate rules for intra-group transfers
  • Appropriate technical and organizational security measures

9. Children's Data

We do not knowingly process personal data of individuals under 18 years of age. Our age verification systems are designed to prevent minors from accessing our services. If we discover that we have inadvertently collected data from a minor, we will delete it immediately.

10. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR. The supervisory authority in your jurisdiction can be found at:

EU Data Protection Authorities: https://edpb.europa.eu/about-edpb/board/members_en

However, we encourage you to contact us first so we can address your concerns directly.

11. Updates and Changes

We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated through our website and, where appropriate, via email to registered users.

Your Data, Your Rights

At Maori Legend Games, we respect your privacy rights as much as we respect Maori cultural traditions. Your personal data is protected with the same care and reverence we apply to indigenous heritage.

12. Contact Information

For any GDPR-related questions, requests, or concerns:

  • Email: support@maorilegendgames.com
  • DPO Email: dpo@maorilegendgames.com
  • Address: 225 Queen Street, Auckland 1010, New Zealand
Return to Maori Legend Games