Privacy Policy

Larian Studios Merch Store
Privacy Policy
Last updated: 10 June 2020

Thanks for visiting the Larian Studios Merch Store, the marketplace to shop for official merchandise related to our video games. As you can imagine, running an online store means will be gathering personal data from our customers to fulfill their orders. In this document, we will inform you about how that process looks like, and what your rights are in regard to the data you provide us with.

Should any questions or comments you can reach out to us via merch-support@larian.com.

1. WHO WE ARE

Based on your location Larian Studios (hereinafter also "we" or “us”) is to be understood as

For EU: (meaning the 27 member states of the European Union and the UK): 17a New Bride Street Dublin 8, Ireland Company n° 556210

For US: and Canada Larian Studios Games ltd: Larian Studios US Inc. %Frederik U Fierst 64 Gothic St., STE 4 Northhampton, MA 01060 Company n° 84-3068623

2. SCOPE

This Policy governs personal data and non-personal data, which we collect from you when you use the Larian Studios Merch Store services. In short, all data, which, on its own or in combination with other data, can be used to identify you, will be considered “personal data”.

Please note that this document is strictly limited to the operation of the Merch Store. If you want to know more on how we treat personal data in general, you can read this in our more general privacy policy here. If for example you would sign up for the Larian Gazette while visiting the store, you can find more on that topic in the general privacy policy.

On the other hand, if you want to know more on how the store itself works, as well as on your rights as a customer of the store, you will find most information in our Terms of Sale, here

3. PROTECTING CHILDREN

We try and be especially careful in protecting personal data obtained from children. We do not and will not knowingly collect personal data from any child under 16. If for any reason, we would become aware of having collected or start collecting personal information of children between the ages of 13 and 16 we seek for their parent or guardian's consent.

If you are a parent or guardian and are concerned about the transfer of your child's personal information, please contact privacy@larian.com.

4. INFORMATION WE COLLECT

4.1 When you use Store services, we may collect the following data if relevant.
In the context of order handling and customer accounts, we will process your basic personal data such as:
a. your name and surname;
b. email address;
c. residence address,
d. shipping address and/or billing address;
e. phone number (optional);
f. IP address;
g. country, where you place your order;
h. order and payment history (including identifiers, order values and ordered items);
i. data resulting from your use of Store functionalities and optional data which you may provide in account settings (favorite items list, account settings, product reviews and ratings, day and month of your birthday);
j. additionally — if you place your order as part of your business activity — invoicing address, business name, VAT/company number.

Moreover, depending on the payment method you choose, we will process the following payment-related data:
a. debit/credit card data — card number, name and surname of the card holder, validity date;
b. bank account number, name and surname of the account holder;
c. e-mail address linked to PayPal account.

4.2 We may also collect some non-personal data about our users (statistical information on the use of our services, information on devices used to connect to them) in order to better understand how our games and services are used and to improve them based on this knowledge.

4.3 In order for you to use our services, we need to process the data described above — provision of the data is voluntary, but without it, you will not be able to use our services.

5. HOW IS YOUR INFORMATION USED

5.1 We will use the available data the following purposes:
a. providing access to store services, including account registration and personalization, order history and status, favorite items list, product review and comments functionalities;
b. sale and delivery of goods and payment handling;
c. providing technical support and customer service, as well as providing information about changes regarding goods and services of the store;
d. preventing payment fraud in the use of store services;
e. monitoring operations of store services and introducing improvements based on submitted remarks and suggestions;
f. in applicable cases - for the purposes of asserting claims and legal defense, including litigation, arbitration or mediation;
g. fulfilling the obligations resulting from provisions of law, including tax and accounting law;
h. documenting personal data processing, i.e. for accountability purposes as required by the General Data Protection Regulation (GDPR);
i. providing you with marketing information (including personalized and targeted marketing emails), which we feel may interest you. For example, we may send you newsletters or emails about our services (of course, this is optional and we will ask you for permission first).

5.2 Whenever we personalize or target our marketing communications, offers and advertisements, we may profile your personal data, which means that we may use the data we collect to adjust the communication addressed to you to meet your needs. In such cases, we do not use your personal data for profiling, which would constitute automated decision-making that could affect your legal situation (for example, we will not deny you access to our services based on your activity in the Store).

If you decide that you no longer wish to receive personalized offers, product recommendations from us, or any advertising news at all, you can withdraw your consent at any time.

6. WHY DO WE USE YOUR DATA (LEGAL BASIS FOR DATA PROCESSING)

6.1 We process your personal data to perform the agreement between us, which includes enabling you to use our store. This happens in the case of purposes (a)-(c) of Section 5.1. above (if you contact us as a registered customer).

Also, we process information about you for the purpose of and in scope necessary to pursue our legitimate interests (ensuring security of payment processing and IT systems of the Store, communication with unregistered users), within the purposes indicated in points (d)-(f) of Section 5.1. Moreover, we process your personal data to fulfill our legal obligations. This refers to the purposes indicated in points (g)-(h) of Section 5.1.

In other cases, your personal data is processed based on your consent (this primarily includes processing your data for marketing purposes, in particular providing you with our newsletter). You can withdraw your consent at any time; however, withdrawal of consent will not affect the lawfulness of prior processing.

6.2 Non-personal data.
We may process some aggregated and general non-personal data on user behavior (e.g. sales per region, number of reported technical issues) with third party partners who work with us to provide store services to you (for example, producers of our gadgets or payment providers) in order to support, improve or amend store services. We may also share non-personal data with data analysis services to help us run store services. As mentioned above, everything is anonymized, so you cannot be identified.

7. HOW DO WE HANDLE YOUR PERSONAL INFORMATION

7.1 Where do we store it? - The data we collect from you is stored on our secure servers in Europe or — only if necessary — by those of our Trusted Partners as described below. We implement appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction or damage. We will take all reasonably necessary steps to ensure that your data is treated securely and in accordance with our privacy policies.

7.2 ²How long will we store your data? - We will retain your personal data only for as long as needed in order to fulfill the purposes outlined in this Privacy Policy. In certain special cases, a longer retention period might be required by law, such as for tax reasons, accounting purposes or other legal requirements and obligations. When we no longer require your personal information in order to provide our store-related services to you, we will either delete it or anonymize it. In particular:
a. we will keep data that is associated with the services you use for the duration of the agreement to access the services (ex. Store Terms of Use). Following account closure, the limited data that we collect about you will still be retained for an additional few year for tax, legal or accounting purposes;
b. if you contact us and do not use our services, we will retain correspondence with you as long as necessary to assist you, followed by a period necessary for legal or accountability purposes;
c. for marketing purposes, we will store data as long as we have valid consent, and in case of its withdrawal, we will remove it without undue delay and no later than within 30 days from the moment we receive your request to cease data processing.

8. DATA SHARING

Please remember that any communications you have via the Merch Store services (e.g. reviews or comments published on product pages in the Store) may reveal details about you. Also, any data you post publicly will be publicly available for store users and others. We are not responsible for your use of any private personal data which you choose to make public through store features, or the activities of other users or other third parties to whom you give or make available your data.

9. THIRD PARTY INFORMATION COLLECTION AND EXTERNAL SERVICES

From time to time, we may post links on the store of third parties that we think might be interesting to our store visitors, but please consider we have no influence on the content or design of those pages. When you decide to follow those links, your visit to such website will not be covered by this privacy policy. You should contact the relevant provider for information about their applicable data privacy statement or policy.

10. OUR TRUSTED PARTNERS AND OTHER CASES OF DATA SHARING

10.1 We may share your data with the following Trusted Partners, who were engaged by us to help deliver our services and functionalities to you. Please rest assured that we always provide our partners with the minimum data necessary for them to achieve the purpose of their cooperation with us. They may have access to limited data about you and process it on our behalf for the purposes set out below:
a. Larian Studios affiliated companies, who supports us in our activities, record keeping and correspondence handling, legal and technical support, and customer service, as well as provides us with internal management and data-sharing tools;
b. Reborn S.C. — technical operator of our Store;
c. payment providers;
d. partners providing assembly and shipping services;
e. our partners who provides us with tax and accounting services; f. our professional advisors who assist us with legal, tax, audit or accounting matters;
g. our partners who help us in data analysis by providing us with analytical tools;
h. our partners who help us manage our newsletters and email communications by providing us with email marketing tools.

10.2 When required by law, we may also share your data with the police or other government authorities (including your IP address and details of suspected unlawful or fraudulent activity such as unauthorized use of payment methods and security risk scores - so if, e.g. it seems for us your card was stolen, we can inform the police about it).

10.3 Your data may be processed, stored and transferred to countries outside your country of residence and beyond the European Economic Area (EEA), such as the United States. Privacy laws in these countries may not offer the same level of protection as in your country or in the EEA. But whenever we share your personal data outside the EEA, we will ensure the adequate protection of your personal data and apply lawful measures of data transfer, such as EU standard contractual clauses or the Privacy Shield Framework.

10.4 Please be aware that we are subject to various laws and may be required to release personal data to comply with law enforcement and other legal requirements.

11. YOUR RIGHTS

You may exercise the following rights:

a. Right of Access - You have the right to obtain access to your personal information, as well as to be informed about the purpose of the processing by Larian Studios.
b. Right to Rectification, Erasure, or Restriction - You can request Larian Studios to rectify your personal information or have it erased. You can also request the processing of your personal data to be restricted. When you choose not to share data, or when you request that we erase your personal information, we may be prevented from providing you with several services, products and access to a Larian Studios website.
c. Right to Object - You have the right to object to the processing of your personal information when you have legitimate reasons to do so. You also have the right to object to the use of your personal information for purposes of direct marketing. In such case specific reasoning will not be requested.
d. Right to Data Portability - You have the right to obtain your personal information which is processed by Larian Studios in a structured, commonly used and machine-readable format and/or to transfer this data to another data controller.
e. Right to Withdraw Consent - When the processing is based on prior consent you have the right to withdraw this consent. If you signed up to the Larian Gazette, there will always be an appropriate link in the footer of the newsletter to unsubscribe. You can also always simply ask us by sending us a request to: privacy@larian.com.
f. Automated Decisions and Profiling - The processing of your personal data does not include profiling, nor shall you be subjected to automated decisions.
g. Right to File a Complaint - If you have any complaints about the way Larian Studios collect, use and/or processes your personal data, you have the right to file a complaint with the Irish Data Protection Authority or Supervisory authority, which is the Lead Supervisory Authority of Larian Studios:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28
Ireland
https://forms.dataprotection.ie/contact
However, you are always free to contact your own EU-vested authority.

11.3 You can exercise these rights on your own (for example, by correcting your data in account settings) or by contacting us at privacy@larian.com.

11.4 In case of any concerns or questions about your privacy, please do contact us and we will do our best to assist you.

12. CHANGES TO THIS PRIVACY POLICY

We may change this Privacy Policy if we deem it necessary, such as for legal reasons or to reflect changes in our services. If we do so, we will make the altered Privacy Policy available online, update the “Last Updated” date and notify you about the changes.

We use cookies

This website uses cookies to ensure you get the best experience from our website. Some cookies are essential to the functioning of the site and cannot be turned off. We also use analytics cookies to count visits and traffic sources; these are disabled by default. You can accept them by clicking on the 'Analytics' checkbox. Learn more about our privacy policy.