Privacy Policy
This Privacy Policy describes how your personal information is collected, used, and shared when you visit www.crytek.com or make a purchase from shop.crytek.com – (the "Site").
WHO WE ARE
The controller of this Site in terms of the General Data Protection Regulation ("GDPR") is:
- Crytek GmbH, Hugo-Junkers-Strasse 3, 60386 Frankfurt am Main, Germany, info@crytek.com
PERSONAL INFORMATION WE COLLECT
In terms of Art. 4 No. 1 GDPR Personal data includes any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Crytek collects data as follows when a user visit its Site we collect the following data which can be assessed at being personal data:
Device Information:
- Information about the web browser you're using
- IP address
- Time zone
- Information on cookies/apps that are in use by your browser.
- Information on web products or pages that you view.
- Information regarding redirects/which website or search terms referred you to the Site.
Activity information, including online time, clickpaths, and how you interact with the Site. We refer to this information collectively as “Device information”.
We collect Device Information using the following technologies:
- “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable cookies, visit Cookie Policy page.
- “Log files” track actions occurring on the Site, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
- “Web beacons”, “tags”, and “pixels” are electronic files used to record information about how you browse the Site.
Certain Device Information are necessary to access our Site. We also use the Device Information that we collect to help us screen for potential risk and fraud (in particular, your IP address), and more generally to improve and optimize our Site (for example, by generating analytics about how our customers browse and interact with the Site, and to assess the success of our marketing and advertising/retargeting campaigns). We regard those interests as legitimate interest under Art. 6 (1) lit. f GDPR since it is in our and the interest of the visitors of our Site that this Site is safe.
When a user signs up for our newsletter:
- Email address
When you subscribe to our Crytek newsletter you give your consent to receive our newsletter with information to Crytek, our products and services and that your email address will be stored for this purpose. After submitting your email address you will receive a confirmation email with a link which has to be clicked in order to confirm your subscription. Only after such confirmation by you you will receive our newsletter. We will send out our newsletter from time to time if useful to provide you interesting news concerning Crytek, our products and services. Your email address will only be used for this purpose. You are entitled to withdraw your consent at any time without any reason by clicking at a respective “unsubscribe" link included in each newsletter. We use MailChimp to send our newsletter when you sign up for a newsletter subscription. You can review MailChimp's privacy policy at mailchimp.com/legal/privacy. MailChimp is certified under the EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield.
The legal basis for the use of personal data with regard to send you newsletter(s) is Art. 6 (1) lit (a) GDPR as you have given us your consent.
Purchases in our shop:
When a user chooses to sign up and log in to the shop.crytek.com/crytek.com:
- First name
- Last name
- Google reCaptcha (registration, resend activation, login, password reset, contact form)
Order information
- Email address
- Full name
- Payment information – all payment information is collected and processed by the following third-party vendors – PayPal and Stripe.
- Billing address
- Shipping address
We refer to this information collectively as "Order Information". Order information is gathered when you make, or attempt to make a purchase through the Site.
How we use Order information
Crytek will not transmit your personal data to third parties unless it is necessary according to the law or in order to fulfill your contract. In case of a purchase we provide payment services to our users we use third party service providers and this might include the transmission of personal data
The Order information gathered from you is gathered as it is necessary to fulfill our contract(s) with you (including processing your payment information, arranging for shipping, and providing you with invoices and/or order confirmations). The legal basis is the fulfillment of the contractual obligations (Art. 6 (1) lit. b GDPR).
If you order a product/service your email address may also be used in order to contact you in the case of future deals/sales, in the form of emails/newsletters, and is a legitimate interest under Art. 6 (1) lit. f GDPR. You are entitled to object against the usage of your data for advertisement purposes at any time by sending an email to shop@crytek.com.
Order information such as your billing address, shipping address and payment information may be used to screen our orders for the potential risk of fraud, as a legitimate interest under Art. 6 (1) lit. f GDPR.
When we talk about "Personal Information" in this Privacy Policy, we are talking both about Device Information and Order Information.
CRYTEK does not collect/keep private payment information such as credit card details. These data are being requested in an inline frame from stripe domain, meaning Crytek has no access to this data.
Job Application
If you apply for a job at Crytek some personal data is necessary to assess whether your qualification matches the job profile. The processing of the respective data is legally based on Art. 6 (1) (b) GDPR as a necessary step to potentially conclude an employment agreement. If you agree to a longer retention period the legal basis is Art. 6 (1) (a) GDPR. Further, data processing activities (e.g. personality tests) are based on your consent (Art. 6 (1) (a) GDPR.
Certain personal data is necessary for the specific application process. Generally we will need your:
- Full name
- Contact details
- Qualifications, certificates, testimony and job experience
- In some cases personality test or IQ-test
The access to your personal data is restricted to certain people inside Crytek on a "need-to-know" – basis. This will be members of the HR department, team leads/directors and – sometimes – subject matter experts which are stakeholders of the job.
Within our application process we use software of the service provider based in the USA: Lever, Inc., 155 5th Street, 6th Floor, San Francisco, CA 94103. With regard to us Lever serves as a data processor in terms of the GDPR. Any transfer of personal data is safeguarded by a data processing agreement including Standard Contractual Clauses as provided by the European Union.
We will store your personal data during the application process and a period of six months after the end of the application process.
Based on your explicit consent we will store your personal data for a period up to three years in order to review your qualifications for future job opportunities.
SHARING YOUR PERSONAL INFORMATION / Web Analytics
Google Analytics
If you have given your consent, this website uses Google Analytics, a web analysis service of Google LLC. The responsible service provider in the EU is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Scope of processing
Google Analytics uses cookies that enable an analysis of your use of our website. The information collected by the cookies about your use of this website is usually transferred to a Google server in the USA and stored.
We use the function 'anonymizeIP' (so-called IP-Masking): Due to the activation of IP-anonymization on this website, your IP-address will be shortened by Google within member states of the European Union or in other signatory states of the Agreement on the European Economic Area. Only in exceptional cases the full IP address will be transferred to a Google server in the USA and shortened there. The IP address transmitted by your browser within the framework of Google Analytics is not merged with other data from Google.
During your website visit the following data will be collected:
- the pages you call up, your "click behaviour"
- Achievement of "website goals" (conversions, e.g. newsletter registrations, downloads, purchases)
- Your user behavior (for example clicks, dwell time, bounce rates)
- Your approximate location (region)
- Your IP address (in abbreviated form)
- technical information about your browser and the end devices you use (e.g. language settings, screen resolution)
- Your internet provider
- the referrer URL (via which website/advertising medium you came to this website)
Purposes of processing
On behalf of the operator of this website, Google will use this information to evaluate your pseudonymous use of the website and to compile reports on website activity. The reports provided by Google Analytics serve to analyse the performance of our website and the success of our marketing campaigns.
Recipient
The data recipient is
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
as data processor. For this purpose we have concluded a contract with Google. Google LLC, headquartered in California, USA, and, if applicable, US authorities can access the data stored at Google.
Transfer to third countries
A transfer of data to the USA cannot be excluded.
Duration of storage
The data sent by us and linked to cookies is automatically deleted after 14 months. Data is automatically deleted once a month as soon as the storage period is reached.
You can also prevent the collection of data generated by the cookie and related to your use of the WebSite (including your IP address) to Google and the processing of this data by Google by
- not giving your consent to the setting of the cookie or
- downloading and installing the browser add-on to disable Google Analytics https://tools.google.com/dlpage/gaoptout?hl=en
By setting your browser software accordingsly you can also prevent the storage of cookies. If your browser is set to refuse all cookies, the functionality of this and other websites may be limited.
Legal basis and right of withdrawal
Your consent is the legal basis for this data processing, Art.6 para.1 S.1 lit.a GDPR. You can revoke your consent at any time with effect for the future by changing your selection in the cookie settings Customize privacy preferences.
For more information about Google Analytics terms of use and Google's privacy policy, please visit https://marketingplatform.google.com/about/analytics/terms/gb/ and https://policies.google.com/?hl=en.
How long is your Personal Data stored?
We will store your data as long as your Crytek user account exists. In addition there might be minimum retention periods stipulated by applicable law which Crytek has to comply to.
When you subscribe to our Newsletters, we (actually Mailchimp) store your email address until you unsubscribe.
For providing technical customer support
Additional Hardware and software information helps us to recreate the technical issues reported by the user to provide you in depth technical support e.g. in the case of a crash or error and respond to inquiries.
For processing business inquiries and feedback
Users can enter information such as Name, Email, Phone in the contact form. Such information is used to process the respective inquiry and to get in contact with you. The legal basis hereto is Art. 6 (1) lit. a GDPR since you consent to such processing by submitting you request/message.
Behavioral Advertising
You can opt out of targeted advertising by using the links below and in your cookie preferences:
- Google: https://www.google.com/settings/ads/anonymous
- Bing: https://advertise.bingads.microsoft.com/en-us/resources/policies/personalized-ads
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance's opt-out portal at: http://optout.aboutads.info/.
DO NOT TRACK
Please note that we do not alter our Site's data collection and use practices when we see a Do Not Track signal from your browser.
YOUR RIGHTS
At any time you have the right to:
- Request a copy of the data we have stored for your person, for the receiver or category of receivers of your transmitted personal for the purpose of storing.
- Request that your data be deleted or corrected, in the case that you have changed your mind or the data is incorrect (as far as possible according to applicable law).
- Object to the further processing or demand a restriction concerning the processing of your personal data
- Request to port your personal data.
- Lodge a complaint with a supervisory authority.
To contact us about any of the foregoing things, please send us an email to privacy@crytek.com. In case of a confidential request, please email our Data Protection Officer directly: dpo@crytek.com.
PLEASE NOTE: If you object, restrict, or otherwise refuse the processing of your personal data mentioned above and/or ask us for a deletion, you might not be able to continue to use our services.
You have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted or transmit the data to another controller. If you would like to exercise these rights, please contact us through the contact information below.
As a European resident, you also have the right to complain to the competent data protection authorities.
Additionally, if you are a European resident we note that we are processing your information in order to fulfill contracts we might have with you (for example if you make an order through the Site), or otherwise to pursue our legitimate business interests listed above. Additionally, please note that your information will be transferred outside of Europe, including to Canada and the United States.
HOW DO WE PROTECT YOUR DATA
All user data is stored on secure servers protected by firewalls and antivirus software.
We have implemented technical and organizational measures intended to protect the security and confidentiality of your Data against any accidental loss and any unauthorized access, use, modification or disclosure.
WHERE DO WE STORE PERSONAL DATA
Our services are hosted by our hosting provider (LeaseWeb Deutschland GmbH, Kleyerstraße 75-87, 60326 Frankfurt am Main- https://www.leaseweb.com/legal. Any service providers that come in contact with your personal data are required to comply with the same relevant data protection regulations. Upon request we may provide copies of relevant contract unless it is prohibited by contractual obligations and/or applicable law.
DATA RETENTION
When you place an order through the Site, we will maintain your Order Information for our records as long as this data is necessary to fulfill the purpose for which it was collected and/or as long as we are obliged by law.
CHANGES
We may update this privacy policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons.
MINORS
The Site is not intended for individuals under the age of 18.
CONTACT US
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by email at privacy@crytek.com or by mail using the details provided below:
Data Protection Officer
Crytek GmbH, Hugo-Junkers-Strasse 3, 60386 Frankfurt am Main, Germany