Privacy Policy
At Luckyrealm.funr, we respect your privacy and are committed to protecting your personal data. This policy explains how we handle your information when you play our games, use our website, or interact with our other platforms.
The site is operated by Orrenex s.r.o., a company incorporated under the jurisdiction of Czech Republic, with company registration number 240 68 314 and registered address at Rybna 716/24, 110 00 Prague 1.
As the data controller for this site, we are responsible for determining the purposes and means of processing your personal data in accordance with relevant data protection legislation.
We reserve the right to update this Privacy Policy if legal or operational changes emerge. We encourage you to review this page periodically.
1. Information that we collect
To provide a secure social gaming experience, we collect the following categories of data:
- Registration data: email address;
- Financial Data: credit card information;
- Technical Data: IP address, device data, geolocation (to ensure you aren't playing from a restricted state/country);
- Gameplay Data: Information on your game preferences, gameplay history;
- Other additional details you give us while contacting with us and while playing games.
2. How we use your data
We process your information for the following purposes and legal grounds:
1) Purpose: Account registration & service delivery
Legal Basis: Contractual necessity
2) Purpose: Compliance with legal obligations
Legal basis: Legal obligation
3) Purpose: Security monitoring
Legal Basis: Legal obligation and legitimate interest
4) Site Analytics: Analytics and UX improvement
Legal Basis: Legitimate interest
3. Sources of data
Personal data is gathered:
- directly when you create an account, make use of our services, or communicate with us (for example, through chat or customer service);
- automatically when you access the site;
- from other parties, including partners who help us execute our services, regulatory organizations,etc.
4. How we handle your data
We may share your personal data with the following entities to fulfill service, legal, or business obligations:
- Game providers, for game facilitation (e.g., username, IP);
- Payment processors, to execute your financial transactions securely;
- Regulators and authorities, where disclosure is legally required;
- Verification platforms, including age verification tools;
- Professional advisors, such as legal consultants;
- Communication tools, to manage customer support (live chat, email);
All third-party recipients are bound by data protection agreements and may process your data only under our direction.
5. Data transfers
In some instances, we may transfer your personal data to countries outside the European Economic Area (EEA). When we do so, we ensure:
- The destination country offers an adequate level of data protection, as determined by the European Commission; or
- We implement Standard Contractual Clauses (SCCs).
6. Data retention
We retain your personal information only for as long as is necessary to fulfill the purposes for which it was collected.
7. Your data protection rights
You have the right to:
- Access your personal data;
- Rectify inaccurate or incomplete data;
- Request erasure, subject to legal exceptions;
- Restrict processing or object to certain data uses;
- Withdraw consent at any time;
- Port your data to another service provider;
- Lodge complaints with a supervisory authority.
To exercise any of these rights, contact our Support team at [support email].
8. Automated decision-making
We do not rely solely on automated decision-making processes, including profiling, to make decisions that could significantly affect you.
While we may use automated tools to assist with certain functions - all such processes involve human oversight and intervention.
9. Security measures
- Physical Security Controls:
Access to facilities, offices, and data center environments where personal data is processed is tightly controlled to prevent unauthorized entry. Our systems are hosted in secure data centers that comply with established physical and information security standards. Only authorized staff members are permitted to enter areas where personal data is stored or managed. - System Access Controls:
Systems used for processing personal data are secured through strong authentication measures and password requirements. Every authorized user is assigned an individual account or identifier, allowing access to be monitored and traced when necessary. - Data Access Controls:
Access to data and software is limited according to operational necessity, ensuring that only individuals with a legitimate business need can view or use personal information. Unauthorized installation or use of software and hardware is restricted, and defined processes are in place to ensure that obsolete data is permanently and securely erased. - Organizational Measures:
To reduce the risk of accidental mixing of personal data, we apply a combination of technical safeguards and internal procedures.