PRIVACY POLICY
1. INTRODUCTION
This Privacy Policy and Data Protection Notice (“Policy”) sets out the basis upon which Fallohide Africa Limited (“Fallohide”, “we”, “us” or “our”) collects, receives, records, organises, stores, uses, discloses, transfers, retains and otherwise processes Personal Data.
This Policy applies to Personal Data processed through or in connection with:
1.1 Fallohide Africa
Fallohide’s corporate websites, digital platforms, consultancy services, productions, events, training programmes, demonstrations, client engagements and related services.
1.2 Overpowered
Games, interactive entertainment products, multiplayer experiences and related content developed, published, distributed or operated under the Overpowered name.
1.3 FieldTrips
Educational, edutainment and experiential-learning products, including curriculum-aligned experiences, web-based activities, mobile applications, XR learning experiences, learner accounts, institutional programmes and related events offered under the FieldTrips name.
1.4 Digital Platforms
This Policy further applies to:
a. websites and subdomains operated by Fallohide;
b. mobile applications made available through mobile application stores or direct distribution;
c. Virtual Reality, Augmented Reality and Mixed Reality applications made available through XR devices, headsets, application stores or other platforms;
d. web-based games, applications and interactive experiences;
e. accounts, portals, dashboards and subscription services;
f. official social-media pages and accounts operated by Fallohide, Overpowered or FieldTrips;
g. customer-support, mailing-list, registration and payment systems; and
h. any other product or service that refers or links to this Policy.
The services described above are collectively referred to in this Policy as the “Services”.
Fallohide Africa Limited is incorporated in Kenya as a private limited company under Company Number PVT-3QUD7XZQ, with its registered office at Keystone Park, Riverside Drive, Westlands, Nairobi.
2. STATUS OF THIS POLICY
This Policy constitutes a privacy notice and is intended to inform Data Subjects about the nature and extent of Fallohide’s processing of Personal Data.
This Policy does not, by itself, constitute consent to any processing activity for which express consent is required by law. Where consent is required, Fallohide shall seek such consent separately and in an appropriate form.
By accessing or using the Services, a user acknowledges that they have been provided with an opportunity to read and understand this Policy.
3. DEFINITIONS
For purposes of this Policy:
3.1 “Data Controller”
Means the person or entity that determines the purposes and means of processing Personal Data.
3.2 “Data Processor”
Means the person or entity that processes Personal Data on behalf of a Data Controller.
3.3 “Data Subject”
Means an identified or identifiable natural person to whom Personal Data relates.
3.4 “Personal Data”
Means any information relating to an identified or identifiable natural person.
3.5 “Processing”
Includes collecting, recording, organising, structuring, storing, adapting, retrieving, consulting, using, disclosing, transmitting, disseminating, restricting, erasing or destroying Personal Data.
3.6 “Sensitive Personal Data”
Includes Personal Data relating to matters such as health, disability, race, ethnicity, biometric information, genetic information, family details, religious or philosophical beliefs, sexual orientation and such other categories as may be recognised under applicable law.
3.7 “Child”
Means a person under the age of eighteen years, unless a different age is prescribed by a mandatory law applicable to the particular Data Subject.
4. CAPACITY IN WHICH FALLOHIDE PROCESSES PERSONAL DATA
Fallohide may process Personal Data in different legal capacities depending on the circumstances.
4.1 Fallohide as Data Controller
Fallohide shall ordinarily act as a Data Controller where it determines:
a. what Personal Data is collected;
b. why the Personal Data is collected;
c. how the Personal Data is used;
d. how long the Personal Data is retained; and
e. with whom the Personal Data is shared.
This will generally apply to users who create accounts directly with Fallohide, purchase Services, subscribe to communications or interact directly with Fallohide’s platforms.
4.2 Fallohide as Data Processor
Where a school, university, employer, client, NGO, government institution or other organisation appoints Fallohide to provide Services to its authorised users, Fallohide may process Personal Data as a Data Processor acting on that organisation’s documented instructions.
In such circumstances, the appointing organisation may be the Data Controller and its privacy notice may apply in addition to this Policy.
4.3 Independent or Joint Responsibility
Fallohide and a partner organisation may, in certain circumstances, independently or jointly determine the purposes and means of processing. The respective responsibilities of the parties shall, where appropriate, be addressed in the applicable contract, data-processing agreement, programme notice or other written arrangement.
5. CATEGORIES OF PERSONAL DATA WE MAY COLLECT
The nature of Personal Data collected will depend upon the Service used, the user’s relationship with Fallohide and the features activated by the user.
Fallohide may collect and process the following categories of Personal Data.
5.1 Identity and Contact Information
This may include:
a. full name;
b. username, display name or assigned learner identifier;
c. email address;
d. telephone number;
e. postal or physical address;
f. country, county, city or region;
g. age, date of birth or age range;
h. parent or guardian details;
i. school, institution, employer or organisation;
j. job title, class, year group, department or learner category; and
k. preferred language and communication preferences.
5.2 Account and Authentication Information
This may include:
a. account number or internal user identifier;
b. username and password credentials;
c. authentication tokens;
d. account status;
e. subscription, licence or membership information;
f. account preferences and settings;
g. login records;
h. password-reset records;
i. linked parent, guardian, teacher or institutional accounts; and
j. access permissions and administrative roles.
Passwords shall be subject to appropriate technical safeguards. Users must not disclose their passwords or allow unauthorised persons to access their accounts.
5.3 Gameplay and Interaction Information
Where a person uses an Overpowered game or other interactive Service, Fallohide may collect:
a. games, levels, scenes or modes accessed;
b. game progress;
c. scores, achievements, rankings, badges and rewards;
d. gameplay choices and interactions;
e. player preferences and settings;
f. session duration and frequency;
g. saved-game information;
h. multiplayer or team participation;
i. in-game actions;
j. avatar or profile selections;
k. challenge and mission completion;
l. gameplay errors and interrupted sessions; and
m. information reasonably required to operate, balance, secure and improve the game.
Where multiplayer, social or spectator functions are enabled, other participants may be able to view a user’s display name, avatar, score, team, participation status or other information intentionally made visible within the experience.
5.4 Learning and Educational Information
In connection with FieldTrips and other education-related Services, Fallohide may collect:
a. learner identifiers;
b. school, institution, class or group;
c. learning modules accessed;
d. activities, quests or lessons completed;
e. assessment results;
f. scores, badges, certificates and achievements;
g. responses to exercises, quizzes and reflection questions;
h. participation and attendance information;
i. learning progress and completion status;
j. feedback from learners, teachers or facilitators;
k. learning objectives and curriculum categories;
l. accessibility or reasonable-accommodation requirements; and
m. educator or facilitator observations where relevant to the programme.
Where an account is administered by a school, parent, guardian, educator, employer or other organisation, authorised representatives may be able to access relevant learner progress, participation and reporting information.
5.5 Payment and Transaction Information
Where a user purchases, subscribes to or licenses a Service, Fallohide may collect:
a. billing name;
b. billing contact information;
c. billing address;
d. mobile-money telephone number;
e. payment method;
f. transaction reference;
g. payment amount and currency;
h. payment status;
i. subscription or licence details;
j. invoice and receipt information;
k. refund information; and
l. records required for taxation, accounting, audit and regulatory purposes.
Payments may be processed by banks, mobile-money operators, application stores, payment gateways or other third-party payment processors.
Fallohide may not receive or retain complete payment-card, bank-account or mobile-money credentials where such information is processed directly by the relevant payment provider.
5.6 Device and Technical Information
When a user accesses the Services, Fallohide or its authorised service providers may automatically collect:
a. Internet Protocol address;
b. device type and model;
c. operating system;
d. browser type and version;
e. mobile application or XR application version;
f. device identifiers;
g. application-store or platform identifiers;
h. language and time-zone settings;
i. network and connectivity information;
j. screen resolution and display information;
k. session dates and duration;
l. referring and exit pages;
m. security and authentication logs;
n. crash reports;
o. error logs;
p. diagnostic information; and
q. application and system-performance information.
5.7 Website and Application Usage Information
Fallohide may collect information relating to how a user interacts with its Services, including:
a. pages, screens or content accessed;
b. links, menus or buttons selected;
c. features used;
d. searches conducted;
e. duration and sequence of interactions;
f. account activity;
g. downloads;
h. referral information;
i. campaign attribution information; and
j. analytics and performance measurements.
5.8 Mobile Application Information
Where a user accesses a Fallohide, Overpowered or FieldTrips mobile application, Fallohide may process:
a. mobile-device identifiers;
b. push-notification tokens;
c. application-installation and update information;
d. mobile operating-system information;
e. application permissions;
f. mobile application usage;
g. crash and diagnostic information; and
h. limited approximate-location information derived from an Internet Protocol address.
Fallohide will request access to a device function, including the camera, microphone, storage or location services, only where such access is required for a feature and subject to the permissions made available by the user’s device.
5.9 XR, Spatial and Sensor-Derived Information
Virtual Reality, Augmented Reality and Mixed Reality applications may require the use of device sensors and headset functions.
Depending upon the experience and device, information processed may include:
a. headset position and orientation;
b. controller position and movement;
c. hand-tracking information;
d. body-movement information;
e. eye-tracking or gaze-direction information;
f. voice or microphone input;
g. camera or passthrough information;
h. room boundaries;
i. spatial anchors;
j. environmental-mapping information;
k. physical-space dimensions;
l. gesture and interaction information;
m. device safety-boundary information; and
n. other sensor information required to render or operate the experience.
Some sensor-derived information may be processed locally by the user’s headset, device or operating platform and may not be transmitted to or retained by Fallohide.
Where Fallohide intends to record, upload, retain or otherwise process raw camera, microphone, eye-tracking, spatial-mapping or biometric information, Fallohide shall provide an additional feature-specific notice and seek express consent or another lawful authorisation where required.
Fallohide shall not use biometric or sensor-derived information for the purpose of uniquely identifying a user unless that purpose has been expressly disclosed and lawfully authorised.
5.10 Communications and User-Submitted Content
Fallohide may process:
a. emails and direct messages;
b. customer-support enquiries;
c. survey and feedback responses;
d. photographs, audio, video and documents submitted by users;
e. reviews and testimonials;
f. competition and event entries;
g. messages submitted through games or learning activities;
h. reports of inappropriate conduct or technical problems; and
i. any other information voluntarily provided by the user.
Users must not upload Personal Data relating to another person unless they are lawfully authorised to do so.
5.11 Social-Media Information
Where a user follows, communicates with or otherwise interacts with an official Fallohide, Overpowered or FieldTrips social-media account, Fallohide may receive or process:
a. the user’s social-media name or handle;
b. profile photograph;
c. publicly available profile information;
d. comments, reactions and shares;
e. direct messages;
f. mentions and tags;
g. competition or campaign participation;
h. content submitted to Fallohide;
i. audience and engagement analytics; and
j. advertising or campaign-performance information.
Information posted publicly on a social-media platform may remain visible to other users and may be copied, shared, indexed or retained by third parties.
The relevant social-media provider separately processes Personal Data in accordance with its own privacy policy, terms and platform settings. Fallohide does not control all processing undertaken independently by such providers.
5.12 Information Received from Institutions and Other Third Parties
Fallohide may receive Personal Data from:
a. schools and educational institutions;
b. parents and guardians;
c. employers;
d. clients and project partners;
e. NGOs and development organisations;
f. government bodies;
g. application stores;
h. XR platform providers;
i. payment providers;
j. event organisers;
k. technical service providers; and
l. publicly available sources where lawful.
Any person or organisation providing Personal Data to Fallohide must possess the necessary authority and lawful basis to disclose that information.
5.13 Sensitive Personal Data
Fallohide does not seek to collect Sensitive Personal Data unless such collection is reasonably necessary for:
a. accessibility or reasonable accommodation;
b. learner or participant safety;
c. safeguarding;
d. an expressly agreed research or programme purpose;
e. compliance with a legal obligation; or
f. another legitimate and lawful purpose.
Sensitive Personal Data shall be processed subject to enhanced safeguards and only where a lawful condition for such processing applies.
6. PURPOSES FOR WHICH PERSONAL DATA MAY BE PROCESSED
Fallohide may process Personal Data for the following purposes:
a. providing, operating and maintaining the Services;
b. creating and administering user accounts;
c. authenticating users;
d. saving game and learning progress;
e. operating gameplay, multiplayer, educational and interactive functions;
f. administering subscriptions, licences and institutional access;
g. delivering purchased, commissioned or sponsored Services;
h. facilitating learning programmes, workshops, events and demonstrations;
i. providing reports to authorised schools, educators, parents, guardians, employers, clients or administrators;
j. processing payments, invoices, refunds and receipts;
k. providing customer and technical support;
l. responding to enquiries;
m. communicating account, service, safety and security notices;
n. personalising content and user settings;
o. maintaining platform safety and preventing abuse;
p. moderating user-submitted content where applicable;
q. detecting fraud, unauthorised access and security threats;
r. diagnosing technical errors and application crashes;
s. conducting analytics and measuring engagement;
t. evaluating learning and programme outcomes;
u. improving existing products and developing new products;
v. conducting research using aggregated, pseudonymised or anonymised information where reasonably practicable;
w. administering marketing communications and campaigns;
x. maintaining contractual, accounting, tax and audit records;
y. protecting Fallohide’s legal rights and intellectual property;
z. establishing, exercising or defending legal claims; and
aa. complying with lawful orders, regulatory obligations and applicable law.
7. LAWFUL BASIS FOR PROCESSING
Depending upon the circumstances, Fallohide may rely upon one or more of the following lawful bases:
7.1 Performance of a Contract
Processing may be necessary to provide a Service requested by the user or to perform a contract with a client, subscriber, institution or partner.
7.2 Consent
Fallohide may rely upon consent where a user has freely provided a specific, informed and unambiguous indication of agreement.
Where consent is relied upon, the Data Subject may withdraw that consent, subject to applicable law. Withdrawal shall not affect processing undertaken lawfully before the withdrawal.
7.3 Compliance with a Legal Obligation
Processing may be necessary to satisfy taxation, accounting, regulatory, safeguarding, law-enforcement or other legal requirements.
7.4 Legitimate Interests
Fallohide may process Personal Data where necessary for legitimate interests including:
a. operating and improving its Services;
b. maintaining security;
c. preventing fraud and misuse;
d. managing client and user relationships;
e. understanding platform performance;
f. protecting its legal rights; and
g. communicating with existing clients and partners.
Fallohide shall consider whether such interests are overridden by the rights and freedoms of the affected Data Subject, with particular care being taken where the Data Subject is a child.
7.5 Vital Interests
Processing may occur where reasonably necessary to protect the life, health or safety of a person.
7.6 Public Interest or Official Authority
Where Fallohide is engaged by a public authority or participates in a legally authorised programme, processing may, where applicable, be carried out in the public interest or in connection with an official function.
8. CHILDREN’S PERSONAL DATA
FieldTrips and certain Overpowered or Fallohide Services may be designed for, made available to or used by children.
Fallohide recognises that children require enhanced protection and shall process children’s Personal Data with due regard to the best interests of the child.
8.1 Parental or Guardian Authorisation
Where required by law, Fallohide shall obtain or require verifiable consent from a parent or legal guardian before processing a child’s Personal Data.
Where access is arranged through a school or other institution, that institution shall be responsible for confirming that:
a. it is authorised to provide the child’s Personal Data;
b. all required privacy notices have been issued;
c. all required permissions have been obtained; and
d. the proposed use of the Service is consistent with the child’s best interests.
Fallohide may request reasonable evidence of the identity and authority of a person providing consent on behalf of a child.
8.2 Data Minimisation for Children
Fallohide shall seek to collect only the minimum amount of information reasonably necessary to provide the relevant Service.
Where reasonably practicable, child users should use:
a. first names only;
b. initials;
c. institution-issued identifiers;
d. non-identifying usernames; or
e. avatars that do not disclose unnecessary Personal Data.
8.3 Marketing and Profiling of Children
Fallohide shall not knowingly:
a. sell a child’s Personal Data;
b. use a child’s Personal Data for behavioural advertising;
c. profile a child for direct-marketing purposes; or
d. send direct marketing to a child without the authorisation and safeguards required by law.
8.4 Images, Audio and Recorded Media
Fallohide shall not publish a recognisable child’s photograph, voice, video, testimonial or other recorded media for promotional, documentary or public-facing purposes without obtaining the permissions required by law and the applicable programme arrangements.
8.5 Parent and Guardian Requests
A parent or legal guardian may, subject to verification and applicable law:
a. request information about a child’s Personal Data;
b. request access;
c. request correction;
d. withdraw consent;
e. object to processing;
f. request restriction of processing; or
g. request deletion.
Kenyan data-protection law and ODPC education guidance emphasise clear notices, data minimisation, appropriate safeguards and the protection of children and learners. (Kenya Law)
9. COOKIES AND SIMILAR TECHNOLOGIES
Fallohide’s websites and web-based Services may use cookies, local storage, pixels, software-development kits and similar technologies.
These technologies may be used to:
a. authenticate users;
b. maintain user sessions;
c. remember preferences;
d. save progress;
e. maintain security;
f. prevent fraud;
g. measure Service usage;
h. identify errors;
i. improve performance; and
j. assess communications and campaigns.
Cookies may be classified as follows:
9.1 Strictly Necessary Cookies
Cookies required for security, authentication, payments, account management or core functionality.
9.2 Preference Cookies
Cookies used to remember language, accessibility, display and user-experience preferences.
9.3 Analytics and Performance Cookies
Cookies used to understand how the Services are used and to identify errors or performance issues.
9.4 Marketing Cookies
Cookies used to measure marketing campaigns or deliver communications, where such processing is permitted and any required consent has been obtained.
Users may manage cookies through Fallohide’s cookie-management interface, where available, or through their browser settings.
Disabling certain cookies may prevent parts of the Services from functioning correctly.
10. ANALYTICS, CRASH REPORTING AND PRODUCT IMPROVEMENT
Fallohide may use internal systems or authorised third-party service providers to measure performance and diagnose technical issues.
The information processed may include:
a. device and browser information;
b. application version;
c. session information;
d. features used;
e. interaction events;
f. error logs;
g. crash reports;
h. diagnostic data; and
i. approximate location derived from an Internet Protocol address.
Where reasonably practicable, Fallohide shall aggregate, pseudonymise or anonymise analytics information.
11. APPLICATION STORES, XR PLATFORMS AND DEVICE PROVIDERS
Mobile applications and XR applications may be distributed through third-party application stores, headset platforms or device ecosystems.
Those providers may independently collect and process information including:
a. platform-account details;
b. device identifiers;
c. purchases and subscriptions;
d. application installations;
e. system analytics;
f. headset or controller telemetry;
g. crash reports;
h. location information; and
i. account or social-platform activity.
Such processing is governed by the privacy policies and settings of the relevant provider.
Fallohide does not control Personal Data processed independently by an application store, headset manufacturer, mobile operating-system provider or XR-platform operator.
12. DISCLOSURE OF PERSONAL DATA
Fallohide may disclose Personal Data to the following categories of recipients where reasonably necessary and lawful.
12.1 Service Providers
Providers of:
a. hosting and cloud infrastructure;
b. application development and maintenance;
c. analytics and crash reporting;
d. customer support;
e. email and communications;
f. cybersecurity;
g. payment processing;
h. accounting and invoicing; and
i. data storage and back-up services.
12.2 Schools, Institutions and Client Organisations
Where the user accesses a Service through a school, employer, client, NGO, government body or other institution, Fallohide may share relevant account, participation, progress and reporting information with authorised representatives of that institution.
12.3 Platform and Distribution Providers
Fallohide may share information with application stores, mobile-platform providers, XR-platform providers and distribution partners as necessary to publish, licence, authenticate or support an application.
12.4 Professional Advisers
Fallohide may disclose information to lawyers, accountants, auditors, insurers and other professional advisers.
12.5 Production and Programme Partners
Information may be shared with production partners, facilitators, researchers, educators, contractors and programme partners where necessary to deliver an agreed Service and subject to appropriate confidentiality and data-protection obligations.
12.6 Public Authorities
Fallohide may disclose Personal Data to courts, regulators, law-enforcement agencies and other public authorities where required or permitted by law.
12.7 Corporate Transactions
Personal Data may be disclosed in connection with a proposed or completed investment, merger, restructuring, acquisition, sale of assets or transfer of a business, subject to appropriate confidentiality and legal safeguards.
13. NO SALE OF PERSONAL DATA
Fallohide does not sell Personal Data.
Fallohide shall not permit a third party to use Personal Data obtained through the Services for an unrelated independent purpose unless:
a. the Data Subject has been appropriately informed;
b. any required consent has been obtained; and
c. the processing is otherwise lawful.
Fallohide may share aggregated or anonymised information that does not reasonably identify an individual.
14. INTERNATIONAL TRANSFERS
Certain service providers, cloud platforms, social-media platforms, application stores or XR-platform providers may process Personal Data outside Kenya.
Where Personal Data is transferred outside Kenya, Fallohide shall take reasonable steps to ensure that:
a. the transfer is lawful;
b. the recipient is subject to appropriate data-protection obligations;
c. reasonable contractual, technical or organisational safeguards are implemented;
d. only the information necessary for the relevant purpose is transferred; and
e. additional safeguards are applied to children’s or Sensitive Personal Data where required.
International transfers may be undertaken on the basis of adequacy, contractual safeguards, consent or another transfer mechanism recognised under applicable law.
15. DATA RETENTION
Fallohide shall retain Personal Data only for as long as is reasonably necessary for the purpose for which it was collected.
Retention periods may be determined by reference to:
a. the duration of a user account;
b. the duration of a contract, subscription, licence or programme;
c. the need to maintain saved game or learning progress;
d. the instructions of the relevant institutional Data Controller;
e. safeguarding requirements;
f. the need to investigate misuse or security incidents;
g. taxation, accounting, audit and regulatory requirements;
h. statutory limitation periods;
i. actual or anticipated legal proceedings; and
j. the user’s request for deletion.
Upon expiry of the applicable retention period, Personal Data shall be deleted, anonymised or securely archived, subject to legal, contractual and technical requirements.
Personal Data retained within back-up systems may remain for a limited period until the relevant back-up is securely overwritten or deleted.
16. INFORMATION SECURITY
Fallohide shall implement reasonable and proportionate technical and organisational measures designed to protect Personal Data against:
a. accidental or unlawful destruction;
b. loss;
c. alteration;
d. unauthorised disclosure;
e. unauthorised access;
f. misuse; and
g. other unlawful processing.
Such measures may include:
a. access controls;
b. password and authentication controls;
c. encryption where appropriate;
d. secure hosting;
e. restricted administrative access;
f. system monitoring;
g. data back-ups;
h. software and security updates;
i. contractor and staff confidentiality obligations;
j. incident-response procedures; and
k. privacy-by-design and data-minimisation practices.
No electronic transmission or storage system can be guaranteed to be completely secure. Users are responsible for maintaining the confidentiality of their credentials and securing the devices through which they access the Services.
17. PERSONAL-DATA BREACHES
Where Fallohide becomes aware of a Personal Data breach, it shall investigate the incident and take reasonable steps to contain, remediate and mitigate its effects.
Where notification is required by applicable law, Fallohide shall notify the Office of the Data Protection Commissioner, the relevant Data Controller and affected Data Subjects within the applicable statutory period.
18. MARKETING COMMUNICATIONS
Fallohide may send communications concerning:
a. products and Services;
b. games and releases;
c. FieldTrips programmes;
d. events and demonstrations;
e. training opportunities;
f. surveys;
g. funding, partnership or collaboration opportunities; and
h. company news.
Such communications shall be sent where:
a. the recipient has requested them;
b. the recipient has consented;
c. the communication is permitted in the context of an existing client or partner relationship; or
d. another lawful basis applies.
Recipients may unsubscribe through the mechanism provided in the communication or by contacting Fallohide.
Withdrawal from marketing communications shall not prevent Fallohide from sending essential transactional, contractual, security, safeguarding or account-related communications.
19. USER-GENERATED AND PUBLIC CONTENT
Where a user submits content for publication, community participation, a competition, an event or a shared experience, such content may be visible to other users or the public.
Users must not submit:
a. unlawful content;
b. confidential information;
c. another person’s Personal Data without lawful authority;
d. content that infringes intellectual-property rights; or
e. content that exposes a child or vulnerable person to an unreasonable risk.
Fallohide may remove, restrict or moderate content where reasonably necessary to maintain safety, comply with law or enforce applicable terms.
Deletion by Fallohide may not remove copies already captured, shared, cached or retained by third parties.
20. AUTOMATED PROCESSING
Fallohide may use automated systems for ordinary operational purposes, including:
a. account authentication;
b. fraud and security detection;
c. content recommendations;
d. difficulty adjustment;
e. saved-progress management;
f. learner-progress calculation;
g. achievement allocation; and
h. content personalisation.
Fallohide shall not make a decision producing legal or similarly significant effects solely by automated means unless the processing is lawful and all required notices, safeguards and rights have been provided.
21. RIGHTS OF DATA SUBJECTS
Subject to applicable law and any lawful limitations, a Data Subject may have the right to:
a. be informed of the use to which their Personal Data is to be put;
b. access Personal Data held about them;
c. object to the processing of all or part of their Personal Data;
d. request correction of false, inaccurate, outdated or misleading information;
e. request deletion of false or misleading information;
f. request erasure where applicable;
g. request restriction of processing;
h. withdraw consent where processing is based upon consent;
i. request data portability where applicable;
j. object to direct marketing;
k. request information concerning qualifying automated decision-making; and
l. lodge a complaint with a competent data-protection authority.
These rights reflect the protections provided under Kenya’s Data Protection Act and accompanying Regulations. (Kenya Law)
22. EXERCISING A DATA-PROTECTION RIGHT
A request may be submitted to:
Privacy Contact
Fallohide Africa Limited
Keystone Park, Riverside Drive
Westlands, Nairobi, Kenya
Email: xr@fallohide.africa
The email subject line should state: “Privacy Request”.
A request should provide sufficient information to enable Fallohide to identify:
a. the Data Subject;
b. the relevant account, transaction or programme;
c. the nature of the request; and
d. the Personal Data concerned.
Fallohide may require reasonable proof of identity or authority before responding to a request.
Where a request is submitted on behalf of a child or another Data Subject, Fallohide may require proof of parental responsibility, guardianship or other lawful authority.
23. LIMITATIONS ON DATA-SUBJECT REQUESTS
A request may be limited, delayed or refused to the extent permitted by law, including where compliance would:
a. adversely affect the rights of another person;
b. disclose confidential or legally privileged information;
c. prejudice an investigation;
d. conflict with a legal obligation;
e. undermine safeguarding or security;
f. prevent the establishment, exercise or defence of a legal claim; or
g. require deletion of records that Fallohide is legally required to retain.
Where required, Fallohide shall provide an explanation for the limitation or refusal.
24. THIRD-PARTY LINKS AND SERVICES
The Services may contain links to or integrations with third-party websites, applications, stores, payment providers, social-media platforms or content.
Fallohide is not responsible for the independent privacy, security or content practices of such third parties.
Users should review the privacy policies and terms applicable to any third-party service before providing Personal Data or enabling an integration.
25. REQUIRED AND OPTIONAL INFORMATION
Certain Personal Data may be required in order to:
a. create an account;
b. verify a user;
c. process payment;
d. deliver a purchased Service;
e. save progress;
f. manage institutional access;
g. comply with safeguarding requirements; or
h. comply with law.
Where required information is not provided, Fallohide may be unable to provide all or part of the requested Service.
Where information is optional, the user may decline to provide it, although certain personalised or optional features may not be available.
26. CHANGES TO THIS POLICY
Fallohide may amend this Policy from time to time to reflect:
a. changes to its Services;
b. the introduction of new games, applications or experiences;
c. changes in technology;
d. changes to service providers;
e. operational developments; or
f. legal and regulatory requirements.
The revised Policy shall be published with an updated “Last Updated” date.
Where a change materially affects the manner in which Personal Data is processed, Fallohide may provide additional notice through the relevant website, application, account, email, institution or other appropriate communication channel.
27. COMPLAINTS
A person who believes that Fallohide has infringed their privacy or data-protection rights is encouraged to contact Fallohide first to allow the matter to be investigated and addressed.
A Data Subject may also lodge a complaint with the:
Office of the Data Protection Commissioner of Kenya
Complaints may be submitted through the official procedures prescribed by the Office of the Data Protection Commissioner. (Data Protection Commissioner)
28. GOVERNING DATA-PROTECTION FRAMEWORK
This Policy shall be interpreted primarily in accordance with the laws of Kenya, including the Data Protection Act, 2019 and applicable subsidiary legislation.
Where a Data Subject is entitled to mandatory additional protections under the laws of another jurisdiction, nothing in this Policy is intended to exclude those protections.
29. CONTACT INFORMATION
For questions concerning this Policy or Fallohide’s processing of Personal Data, please contact:
Fallohide Africa Limited
Keystone Park, Riverside Drive
Westlands, Nairobi, Kenya
Email: xr@fallohide.africa
Email subject: Privacy Enquiry