Personal Data (Privacy) Ordinance, Cap. 486
Privacy Policy Statement
How GARMA TECHNOLOGY LIMITED collects, holds, processes and uses personal data, on this website and in the mobile applications we publish.
Effective 7 August 2026. Version in force since that date.
1. Who the data user is
GARMA TECHNOLOGY LIMITED is a limited company incorporated in the Hong Kong Special Administrative Region. In this statement it is called GARMA, or we.
Under section 2 of the Personal Data (Privacy) Ordinance, Cap. 486 (the Ordinance), a person who controls the collection, holding, processing or use of personal data is a data user. GARMA controls those decisions in and from Hong Kong, so GARMA is the data user for the data described here. The Ordinance attaches to control exercised in or from Hong Kong rather than to where the individual is, so this statement applies to players outside Hong Kong as well as inside it.
This document is the Privacy Policy Statement required by Data Protection Principle 5. It is not the same as the collection notice required by DPP1(3), which is given at the point of collection. Both exist, and both are described below.
Registered details. Legal name: GARMA TECHNOLOGY LIMITED. Jurisdiction: Hong Kong SAR. D-U-N-S: 989111537. Companies Registry number: [TO CONFIRM: Hong Kong Companies Registry number]. Business Registration number: [TO CONFIRM: Business Registration number]. Registered office: [TO CONFIRM: registered office address in Hong Kong].
2. What this statement covers
It covers two things, and it says which is which throughout, because they collect very different amounts of data: this website, thegarma.com, and the mobile applications GARMA publishes on the Apple App Store and Google Play, called the apps or a title.
It does not cover a third party service you reach from our apps or this site, including the stores, a payment provider, or a social platform you link an account to. Those are separate data users with their own statements.
Where a title collects something not described here, it carries its own collection notice at first run and its own store disclosure, and that more specific document governs for that title. No title notice will reduce the commitments made here.
3. The words this statement uses
The Ordinance has its own vocabulary and this statement uses it, because that is the only way the commitments below can be checked against the statute.
- Personal data: data about a living individual whose identity it is practicable to ascertain from it, in a form in which access or processing is practicable.
- Data user: the party controlling the collection, holding, processing or use of the data. That is GARMA. Data subject: the individual the data is about. That is you. Data processor: a party processing data on our behalf, not for its own purposes, such as our hosting, analytics and support suppliers.
- Prescribed consent: an express indication of willingness, given voluntarily and not since withdrawn. Silence is not consent. A pre-ticked box is not consent. Consent bundled into acceptance of the Terms is not consent.
- Practicable steps: reasonably practicable in the circumstances, judged against the sensitivity of the data and the harm a compromise would cause. Relevant person: for a minor, someone with parental responsibility.
Hong Kong law does not use the terms controller, lawful basis, legitimate interests or data protection impact assessment, and neither does this statement. Hong Kong has no statutory category of sensitive personal data, no mandatory data protection officer, no registration with the regulator and no data localisation requirement.
4. What the website collects
This is a static corporate site with no accounts, login, forms or comment system, no advertising network and no cross site tracking. Collection is limited to what the hosting infrastructure must record to serve a page:
- Request logs held by our hosting provider: the originating IP address, the timestamp, the page requested, the HTTP status returned, the user agent string, and the referring page if the browser sent one.
- Country level location, derived by the provider from the IP address for routing and abuse prevention. We derive nothing finer from this site.
An IP address is treated as personal data wherever it is practicable to link it to an identifiable individual, not dismissed as technical data.
This site sets no cookies of any kind, and embeds no social widget and no third party pixel. It does load two typeface families from Google Fonts, so your browser requests files from fonts.googleapis.com and fonts.gstatic.com, and those hosts see your IP address and user agent in the ordinary course of serving a font. Google is a separate data user in respect of that request.
5. What the apps collect
An app collects more than a website. The categories below are the complete set a GARMA title may collect; a given title collects a subset, and its store listing and first run notice say which.
Account and profile data
Where a title offers an account: an identifier we generate, a display name you choose, and, if you sign in through a third party or store account service, the identifier it returns. We do not ask for a legal name, an Identity Card number, a passport number or a residential address. Collecting those for a mobile game would be excessive under DPP1. Guest play is tied to a device scoped identifier, and no profile data is collected until you create an account.
Gameplay and progression data
Progress, level state, inventory, currency balances, settings and preferences, tied to the account or guest identifier. This is what lets the game resume where you left it and makes a lost progress ticket answerable.
Device and technical data
Device model, operating system version, language and region, screen resolution, memory class, network type, app version and build, and a resettable installation identifier. Crash reports and performance traces sit here and may include a stack trace and the app state at the moment of failure.
Advertising and attribution identifiers
Where a title carries advertising or uses install attribution: the Identifier for Advertisers on iOS, only if you allowed it through the App Tracking Transparency prompt, and the Advertising ID on Android. Both are resettable in the operating system settings.
Purchase data
In app purchases are billed by Apple or Google, not by us. We receive a transaction receipt, the product identifier, the timestamp and a validation result. We never receive and never store your card number, expiry date, security code or bank details. Those go to the store operator and its payment processor.
Support correspondence
What you send: the message, any attachment, the account identifier quoted or matched, and the thread. If you write from an email address we hold it for the life of the ticket and its retention period.
User generated content, where a title has it
Where a title includes chat, guild communication or player profiles, the content and its account identifier are held for moderation, safety and dispute handling. Section 64 makes it a criminal offence to disclose another person's personal data without consent, with intent or recklessness as to causing specified harm, so a moderation and takedown route in such a title is a legal necessity, not an optional feature.
6. Device permissions
This is the complete set of device permissions a GARMA title may request, and it is a ceiling rather than a wish list: a title requests only what its shipped features need. Asking for a permission the game does not use is the classic excessive collection failure under DPP1, and one the Privacy Commissioner has pursued against app developers.
| Permission | Why it would be requested | Required | If you decline | Revoke on iOS | Revoke on Android |
|---|---|---|---|---|---|
| Notifications | Event reminders, timer completion, security messages. | Optional | The title works in full. You receive no push messages. | Settings, Notifications, the app. | Settings, Apps, the app, Notifications. |
| Photo library, read | Only for a custom avatar, or an image attached to a support ticket. | Optional | Built in avatars remain, and tickets still send. | Settings, Privacy and Security, Photos. | Settings, Apps, the app, Permissions, Photos and videos. |
| Camera | Only for a capture feature such as a code scanner. | Optional | That one feature is unavailable. | Settings, Privacy and Security, Camera. | Settings, Apps, the app, Permissions, Camera. |
| Microphone | Only where a title offers voice chat. | Optional | Voice chat is unavailable. Text still works. | Settings, Privacy and Security, Microphone. | Settings, Apps, the app, Permissions, Microphone. |
| Precise location | Not requested. No title has a feature needing it. | Never requested | Not applicable. | Not applicable. | Not applicable. |
| Contacts | Not requested. Friend systems use in game codes, not your address book. | Never requested | Not applicable. | Not applicable. | Not applicable. |
| App Tracking Transparency (iOS) | Using the Identifier for Advertisers to measure advertising across other companies' apps and sites. | Optional | Advertising still appears but is not personalised across apps, and the identifier is not read. | Settings, Privacy and Security, Tracking. | Not applicable, an iOS framework. |
| Advertising ID (Android) | Attributing an install to its campaign, and frequency capping. | Optional | Advertising is not personalised and attribution falls back to aggregate reporting. | Not applicable, an Android identifier. | Settings, Google, Ads, reset the advertising ID. |
| Files and media storage | Caching downloadable content on older Android versions that require it. | Sometimes required | On those versions the title cannot fetch content packs and will not run. | Not applicable. | Settings, Apps, the app, Permissions, Files and media. |
Any optional permission can be withdrawn at any time by the routes above, taking effect immediately at the operating system level. Withdrawal does not delete data already collected, which is what section 20 is for.
7. Purposes of collection
DPP1 requires collection for a lawful purpose directly related to a function or activity of the data user, and requires it to be necessary and not excessive for that purpose. These are our purposes, and we do not collect for one that is not on this list.
- Operating the game. Maintaining your account, saving and restoring progress, matchmaking or leaderboards where a title has them, and delivering the content the title is made of.
- Keeping the service stable. Crash reporting, performance measurement, capacity planning and diagnosing faults reported by players.
- Safety, fraud and abuse prevention. Detecting cheating, moderating user generated content, investigating chargebacks, and enforcing the Terms of Service.
- Completing purchases. Validating a receipt so the item you paid for reaches the right account, and handling refunds and disputes with the store operator.
- Supporting you. Answering tickets, restoring lost progress, and handling data access and correction requests.
- Understanding how a title is played. Aggregate analytics used to balance difficulty, find where players get stuck, and decide what to build next.
- Direct marketing, only with your separate consent. Governed entirely by section 13.
- Meeting legal and store obligations. Responding to lawful requests from competent authorities, keeping records the law requires, and satisfying the declarations Apple and Google require.
DPP3 prohibits use for a new purpose without prescribed consent, a new purpose being anything other than the one it was collected for or a directly related one. Sharing your data with an advertising network to build an audience segment is a new purpose and we will not do it without asking. Passing a receipt to a payment provider to complete a purchase you started is directly related and needs no separate consent.
8. Classes of transferees
DPP1(3) requires us to tell you the classes of persons your data may be transferred to. They are:
- Cloud hosting and content delivery providers running the servers and network we depend on.
- Analytics and crash reporting providers receiving event and diagnostic data on our instruction.
- Install attribution and, where a title carries advertising, advertising technology providers.
- Customer support platform providers holding the ticket queue.
- The app store operators, Apple and Google, for billing, receipt validation, refunds and store policy compliance.
- Professional advisers, legal and accounting, where a matter genuinely requires it.
- Competent authorities, courts and regulators, where we are required or permitted by law to disclose.
- A purchaser or successor entity on a sale, merger or reorganisation, under a statement no less protective than this one.
We do not sell personal data, and we do not provide it to any third party for that party's own direct marketing. Division 2 of Part VIA makes such provision an offence unless a written consent regime is satisfied, and doing it for gain carries a maximum fine of one million Hong Kong dollars and five years' imprisonment.
9. The six Data Protection Principles
Schedule 1 to the Ordinance sets out six Data Protection Principles. Contravening one is not itself a criminal offence, but it exposes a data user to an enforcement notice from the Privacy Commissioner, and contravening an enforcement notice is an offence. Here is how each applies to what we do.
DPP1, purpose and manner of collection
We collect for the purposes in section 7, only so far as is necessary and not excessive. That is why the table in section 6 records two permissions we never ask for at all. A collection notice is presented at first run or account creation, in plain language and on screen, not buried in a settings menu. It states whether supply is obligatory or voluntary and what follows if you do not supply, the purpose of use, the classes of transferees, and your right to request access and correction with the job title and address to send it to.
DPP2, accuracy and retention
We take practicable steps to keep data accurate for its purpose. Where you can correct something yourself, such as a display name, the app gives you that control; where you cannot, section 12 applies. We do not keep data longer than necessary, and section 26 separately requires erasure of data no longer required. The schedule is in section 10. DPP2(3) requires contractual means to stop a processor keeping data too long, and our agreements carry that term.
DPP3, use
Data is used only for the purpose it was collected for, or a directly related one. A genuinely new purpose needs prescribed consent first. Where a data subject is a minor who cannot understand the request, a relevant person may consent on the minor's behalf.
DPP4, security
Set out in section 11. DPP4(2) again requires contractual means where a processor is engaged, and our agreements carry a written data processing schedule.
DPP5, openness
This document discharges DPP5: published at a stable public address, linked from every page and from inside the apps, stating the kinds of data held and the main purposes, and not gated behind an account.
DPP6, access and correction
You may ascertain whether we hold data about you, be supplied with a copy, be given written reasons for a refusal, object to it, and request correction of inaccurate data. Sections 18 to 25 give DPP6 its machinery, and section 12 sets out how to use it.
10. How long data is kept
A retention schedule that is published but not operated is worth nothing. These are periods we hold ourselves to.
| Category | Retention period | Why |
|---|---|---|
| Active account and progression data | While the account is active. | It is the account. Deleting it deletes your progress. |
| Account data after a deletion request | Erased or irreversibly anonymised within 30 days of verification. | Covers reversal of an accidental deletion and completion across backups. |
| Dormant accounts | Reviewed after 24 months without a sign in, then erased or anonymised. | Section 26 requires erasure of data no longer required. |
| Guest sessions with no account | 90 days after the last session. | Long enough to survive a device change. |
| Crash reports and performance traces | 180 days. | Covers a release cycle, so a regression is traceable. |
| Support tickets and correspondence | 24 months from closure. | Repeat contacts need the history. |
| Chat and user generated content | 90 days, extended only while a moderation or safety case is open. | Moderation, dispute handling and section 64 obligations. |
| Purchase and receipt records | 7 years. | Accounting and tax record keeping. |
| Website request logs | Up to 30 days. | Abuse prevention and fault diagnosis. |
| Direct marketing consent records | While the consent stands, plus 7 years after withdrawal. | Part VIA is criminally enforced. We keep the evidence of consent. |
| Refusal log for access requests | As required by section 27. | Statutory requirement. |
Backups run on their own cycle. Data erased from live systems may persist in an encrypted backup until that backup rotates out, which takes no more than 90 days, and during that period it is used for nothing but disaster recovery.
11. Security
DPP4 requires practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss or use, having regard to the kind of data, the harm a compromise would cause, where it is stored, the measures on the equipment and in transmission, and the integrity and competence of the people with access. In practice:
- Transport encryption on every connection between an app or browser and our services, and onward to our processors.
- Encryption at rest for account credentials, session tokens and purchase receipts.
- No personal data written unencrypted to shared device storage. The Commissioner's Privacy by Design and Best Practice Guide on Mobile App Development warns about this specifically.
- Least privilege access to any live operations console, granted by role, reviewed periodically, revoked the day involvement ends.
- Multi factor authentication on every administrative account.
- A written data processing schedule in every supplier and software development kit agreement, covering security, retention and subprocessing, as DPP4(2) and DPP2(3) require.
- Logging of administrative access to player data, so an internal enquiry can establish who saw what and when.
No system is perfectly secure and we do not claim otherwise. What we commit to is the standard the Ordinance sets: practicable steps proportionate to the data and the harm a compromise would cause.
12. Access and correction requests
This is the part of the Ordinance you are most likely to need, so it is set out in full.
Data access request
Section 18 lets you ask whether we hold personal data about you and, if so, be supplied with a copy. Section 19(1) requires compliance within 40 days. If we cannot, section 19(2) requires us to tell you in writing inside those 40 days that we cannot and why, then comply as soon as practicable afterwards.
Section 20 sets out the grounds on which we must or may refuse, for example insufficient information to locate the data, or an applicable exemption. If we refuse, section 21 requires written reasons and section 27 requires a refusal log.
The prescribed form
The Commissioner publishes a standard Data Access Request Form, Form OPS003, downloadable from pcpd.org.hk. We accept it, and it is the easiest way to be sure a request contains what we need. It is not compulsory: a clear written request identifying you and the data you want is processed either way, and non use of the form is not a ground for refusal.
Fees
Section 28(3) permits a non excessive fee for complying with an access request, and section 28(5) allows compliance to be deferred until it is paid. Following the Commissioner's guidance note on the proper handling of data access requests and the charging of a fee, any fee is limited to costs directly related to and necessary for compliance: the labour and materials of locating, retrieving, reproducing and sending the data. We will not charge for designing our retrieval systems, for legal advice on whether to comply, or any profit element. If a fee applies we will say so inside the 40 day window.
Data correction request
Sections 22 to 25 let you request correction of data you believe is inaccurate. Where we are satisfied it is, section 23 requires us to correct it and supply a copy of the corrected data within 40 days. Section 28(4) prohibits any fee for a correction request. Correction is always free; access may carry a non excessive fee. Two different rules, applied as written.
How to send a request
Address a data access or data correction request to the Privacy Compliance Officer, GARMA TECHNOLOGY LIMITED, at the registered office: [TO CONFIRM: registered office address in Hong Kong]. Requests may also be sent to [TO CONFIRM: privacy contact email address].
DPP1(3) requires a data user to give a working channel for access and correction requests. The postal route becomes complete the moment the registered office address is published here, and the email route when a real address replaces the marker. We have deliberately not printed an address that does not exist, because publishing a channel that does not work would itself fail the same Principle.
So that nobody else can request your data, we ask you to verify the account is yours before we release anything. For an in game account that normally means proving control of the sign in method or supplying a purchase receipt.
13. Direct marketing
Part VIA, sections 35A to 35M, governs direct marketing and is the strictest part of Hong Kong privacy law. Breaching it is a criminal offence rather than something remedied by an enforcement notice.
Direct marketing under section 35A means offering or advertising goods, facilities or services, or soliciting donations, by sending information addressed to specific persons by name or by telephoning them. A banner shown to everybody inside a game is not direct marketing. A push notification or email aimed at you as an identified player, promoting a bundle or a new title, is.
Before we use your data for marketing
Before using your personal data in direct marketing for the first time, we will tell you, in a way that is easily readable and understandable:
- That we intend to use your personal data in direct marketing.
- That we may not do so unless we have received your consent.
- The kinds of personal data that would be used.
- The classes of marketing subjects, meaning the kinds of goods, facilities or services it would promote.
We then ask for consent, which must be an express indication that you do not object, in writing where the notification was in writing. Silence, inactivity and a pre-ticked box are not consent. Consent bundled into I agree to the Terms of Service and Privacy Policy is not consent, and we do not build sign up flows that way. Marketing consent is a separate, unticked, opt in step, and we log the timestamp and the exact notification text shown. On first use we also tell you that you may require us to stop, free of charge, and give you the channel.
Stopping it
You can require us to stop at any time and we will comply without charge. There is a permanent opt out in the app settings of any title that carries marketing, an unsubscribe link in every marketing email, and the postal route in section 12.
Providing data to others for their marketing
We do not provide your personal data to any third party for that party's own direct marketing. Division 2 would require written consent and a notification stating whether the provision is for gain, the kinds of data, and the classes of transferees and marketing subjects. Rather than operate that regime, we do not do it.
The penalties, stated plainly
Contravening the notification, consent or opt out requirements for a data user's own use carries a maximum fine of five hundred thousand Hong Kong dollars and three years' imprisonment. Doing so when providing data to a third party for direct marketing for gain carries a maximum of one million Hong Kong dollars and five years. These are prosecuted in the criminal courts, convictions have been secured in Hong Kong and custodial sentences imposed. The penalties are here because they are why the mechanics above are not negotiable.
14. Marketing messages and the UEMO
The Unsolicited Electronic Messages Ordinance, Cap. 593, is a separate statute enforced by the Communications Authority, with the Office of the Communications Authority doing the operational work, not by the Privacy Commissioner. It governs commercial electronic messages with a Hong Kong link: email, SMS and MMS, fax, pre-recorded telephone messages, and other messages sent to an electronic address.
The two regimes stack rather than substitute. Part VIA governs whether we may use your data for marketing at all; the UEMO governs the form and mechanics of the message. A marketing email needs both.
Every commercial electronic message we send carries accurate, current sender information identifying us and how to contact us, valid at least 30 days after sending; a clear and conspicuous unsubscribe statement saying you may unsubscribe and by what means; a functional, free unsubscribe facility valid at least 30 days; and a subject heading and sender information that are not misleading. We honour an unsubscribe request within 10 working days and in practice act as soon as it reaches us. We do not send to numbers on the do-not-call registers without consent, and we do not use address harvesting software or harvested lists.
15. Processing outside Hong Kong
Your personal data may be transferred to, stored in and processed outside Hong Kong. Cloud hosting, content delivery, analytics, crash reporting, attribution and support services commonly run outside the territory, and a game with players in several regions is served from several regions.
Section 33 of the Ordinance, which would restrict cross-border transfers, has never been brought into force. It has sat on the statute book since 1996, no commencement date has ever been appointed, and no timetable has been announced. There is consequently no Hong Kong adequacy list, no legally required Hong Kong equivalent of standard contractual clauses, and no transfer impact assessment obligation. We do not claim to rely on a section 33 condition, we do not claim the benefit of an adequacy decision, and we do not reproduce European transfer language that has no application here.
What exists instead is guidance. On 12 May 2022 the Commissioner published Guidance on Recommended Model Contractual Clauses for Cross-border Transfer of Personal Data, with two sets of clauses, one for data user to data user transfers and one for data user to data processor transfers, alongside earlier 2014 guidance. Both are recommendations, not legal requirements, framed by the Commissioner as good governance and as preparation in case section 33 is ever commenced.
What binds us wherever a processor sits is DPP4(2), requiring contractual means to secure the data, DPP2(3), requiring the same to limit retention, and DPP1 and DPP3, which govern what it may be used for at all. So the accurate position is: data may be transferred to and processed outside Hong Kong, and we impose contractual obligations on those processors covering security, retention, subprocessing and permitted purpose.
16. Children and our age position
Hong Kong law is silent on the point most people expect it to answer. The Ordinance does not define a child or a minor, sets no age of digital consent, and imposes no parental verification obligation. There is no Hong Kong rule fixing a threshold at 13 or at 16.
What it does say is that a minor's personal data is personal data like anyone else's, so all six Principles apply in full. Where a minor cannot understand a data access request or give prescribed consent, the relevant person may act on the minor's behalf. That is the statutory hook for parental consent, and it is capability based rather than age based. DPP1's fairness limb also bites harder where the data subject is a child, because a notice a child cannot understand is not a fair means of collection.
The Commissioner's guidance on children's privacy, on collection through the internet, and the Privacy by Design and Best Practice Guide on Mobile App Development recommend age appropriate approaches for services popular with under 18s, minimum necessary collection, notices in language a young user can follow, consent from a person with parental responsibility where applicable, and caution about profiling young users. We follow it.
Our position
A publisher still has to state an age position, because the stores impose their own regimes as conditions of distribution and other jurisdictions apply their own rules. Ours is this:
- Unless a title's store listing says otherwise, our services are not directed to children under 13 and we do not knowingly collect their personal data.
- The age rating declared to Apple and the target audience and content declaration made to Google Play will match that position, title by title.
- If we learn we hold personal data of a child under 13 collected without a person with parental responsibility involved, we delete it. A parent or guardian who believes this has happened can write to the Privacy Compliance Officer using section 12, and we act on notice.
- Where a title is knowingly directed at a younger audience, it runs without behavioural advertising and without cross-app tracking, and its store listing says so.
17. Cookies, SDKs and identifiers
Hong Kong has no separate cookie or electronic communications privacy regime and no equivalent of the European ePrivacy rules, so there is no statutory prior consent requirement for non-essential cookies and no legal requirement for a consent banner here. We are not going to overstate the law by showing you a blocking cookie wall.
What does apply is the Ordinance. Where a cookie, a software development kit identifier, an advertising identifier or a device fingerprint is personal data because a living individual can practicably be identified from it, the Ordinance applies in the ordinary way. DPP1 requires you to be told, on or before collection, of the purpose of use and the classes of transferees. DPP3 restricts use for any new purpose without prescribed consent. And if tracking data is used for direct marketing, Part VIA applies in full, with criminal penalties behind it.
This website sets no cookies. There is nothing here to consent to or to refuse. In the apps, the identifiers in section 5 serve the purposes in section 7. Where an identifier would be used for cross-app tracking, the App Tracking Transparency prompt on iOS and the advertising identifier controls on Android govern that use. Resetting the platform advertising identifier in your operating system settings severs the link between past and future activity.
If you are in the European Economic Area, the United Kingdom or California, those jurisdictions apply their own rules on their own terms, and a title distributed there presents whatever consent mechanism they require. That is separate from Hong Kong law, and this statement does not conflate the two.
18. Apple App Store specifics
Apple's requirements are contractual conditions of distribution and apply regardless of Hong Kong law.
App Tracking Transparency
Tracking, in Apple's definition, means linking data from our app with data from other companies' apps, websites or offline properties for targeted advertising or measurement, or sharing it with a data broker. Where a title would do that, it presents the App Tracking Transparency prompt and does not access the Identifier for Advertisers unless you allow it. Decline and advertising still appears where a title carries it, but it is not personalised across apps and the identifier is not read. Change the decision in Settings, Privacy and Security, Tracking. We do not use fingerprinting or any other technique to reconstruct a tracking identifier after a declined prompt.
App Privacy labels
The App Privacy label on each title's product page declares the data types it collects, whether they are linked to your identity, and whether they are used for tracking. Those declarations are maintained against actual behaviour and drawn from section 5. If a label and this statement appear to disagree, tell us using section 23 and we will correct whichever is wrong.
Purchases, refunds and the Kids Category
In app purchases are billed by Apple under your Apple Account, and refunds are requested from Apple through reportaproblem.apple.com. Where a title is submitted to the Kids Category it is built to Apple's App Review Guidelines for that category, which restrict third party analytics and behavioural advertising and require a privacy policy. Any such title's listing says so.
19. Google Play specifics
Data safety
Each title's Data safety section declares what it collects and shares, the purposes, whether data is encrypted in transit, and whether you can request deletion. Those declarations are maintained against the software development kits the title actually ships with, including ones embedded by third party libraries, and are drawn from sections 5 and 7, so the two read consistently.
Advertising ID and the Families policy
Where a title uses the Android Advertising ID it is declared in the Play Console as policy requires and used only for the purposes in section 7. Deleting or resetting it in Settings, Google, Ads takes effect immediately. A title declared as targeting children or a mixed audience under the Target Audience and Content policy complies with the Families policy, including restrictions on advertising and on permitted software development kits, and its listing says so.
Purchases and refunds
In app purchases are billed by Google under your Google Account and refunds are requested from Google Play. As with Apple, we receive the receipt and the validation result and never your payment instrument.
20. Account and data deletion
Both stores require a route to delete your account and the data attached to it. There are two, and either is sufficient.
- In the app. Settings, Account, Delete account. The app asks you to confirm, because deletion cannot be reversed once the grace period runs out.
- By writing to us. Send a deletion request to the Privacy Compliance Officer, GARMA TECHNOLOGY LIMITED, at [TO CONFIRM: registered office address in Hong Kong], or to [TO CONFIRM: account deletion request email address]. Name the title and the account, and we verify it is yours before acting.
What we commit to
- We acknowledge a deletion request within 7 days of receiving it.
- We complete the deletion within 30 days of verifying it, by erasing the data or irreversibly anonymising it.
- Encrypted backups holding the data rotate out within a further 90 days, during which it is used for nothing except disaster recovery.
- We confirm to you in writing when the deletion is complete.
What survives deletion, and why
Four things survive, and only where the law requires it or a record genuinely has to: purchase and receipt records, for the 7 year accounting and tax period, kept as transactions rather than a player profile; direct marketing consent and opt out records, so we can prove we stopped when told to and so a suppression list actually suppresses; records tied to an open safety, fraud or moderation case, until it closes; and aggregated or anonymised statistics from which you can no longer be identified, which are not personal data and fall outside the Ordinance.
Deleting your account does not cancel a subscription. Subscriptions are billed by the store and must be cancelled there. See section 6 of the Terms of Service.
21. Security incidents
Hong Kong has no mandatory personal data breach notification duty. Notification is voluntary, made on the Commissioner's Data Breach Notification Form, and the Guidance on Data Breach Handling and Data Breach Notifications recommends notifying the Commissioner and the affected data subjects where there is a real risk of harm.
Reform has been discussed repeatedly, and proposals for mandatory notification and administrative fines have had broad support in the Legislative Council, but as at the effective date of this statement those amendments have not been enacted. We will not promise a statutory notification clock that does not exist in Hong Kong law.
What we commit to instead: if an incident affecting your personal data occurs and there is a real risk of harm to you, we will notify you and notify the Commissioner using the voluntary form. We will tell you what happened, what data was involved, what we have done and what you should do, as soon as we can establish the facts, because a notification sent before the facts are known helps nobody.
22. Changes to this statement
We update this statement when what we do changes, when the law changes, or when a store requirement changes. The effective date at the top of the page always reflects the version in force.
Where a change is material, meaning it affects what we collect, what we use it for, who we transfer it to, or how long we keep it, we give notice inside the apps before it takes effect. Where the change requires prescribed consent under DPP3 we ask for that consent rather than infer it from your continued play.
23. Complaints
To us first
If you think we have handled your personal data wrongly, write to the Privacy Compliance Officer, GARMA TECHNOLOGY LIMITED, at [TO CONFIRM: registered office address in Hong Kong], or to [TO CONFIRM: privacy contact email address]. Say what happened and what you would like us to do.
To the Privacy Commissioner
You can complain to the regulator at any time, and you do not have to come to us first.
Office of the Privacy Commissioner for Personal Data, Hong Kong
Unit 1303, 13/F, Dah Sing Financial Centre, 248 Queen's Road East, Wanchai, Hong Kong
Hotline: 2827 2827. Fax: 2877 7026
Complaints: complaints@pcpd.org.hk
Website: www.pcpd.org.hk
Hotline hours: Monday to Friday, 8:45am to 12:45pm and 1:50pm to 5:40pm
A complaint can be made on the online form at pcpd.org.hk, by email, by post to the Wanchai address, or by telephone. Complaints should ordinarily be in writing and made within two years of becoming aware of the act complained of. The Commissioner may investigate under section 38.
What the Commissioner can and cannot do
This is the point most often got wrong. The Privacy Commissioner has no administrative fining power. The office cannot issue a percentage of turnover penalty and cannot fine a company directly at all. Where a contravention is found it serves an enforcement notice under section 50 directing the data user to take remedial steps by a deadline. Money penalties arrive only through the criminal courts. Failing to comply with an enforcement notice is an offence carrying, on first conviction, a fine up to fifty thousand Hong Kong dollars and up to two years' imprisonment, plus a daily fine of one thousand Hong Kong dollars for a continuing contravention, and higher amounts on a subsequent conviction. Since 2012, repeating the same contravening act after an enforcement notice has been complied with is itself an offence, without a fresh notice.
Separately, section 66 gives you a civil right to compensation for damage suffered as a result of a contravention, including injury to feelings. That right is yours to exercise in the courts, and nothing in this statement limits it.