PRIVACY POLICY

HYUNDAI GAMING EXPERIENCE

Last update: 02/04/2026

This Privacy Policy is provided in accordance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 (as amended by Legislative Decree 101/2018).

Data Controller: Smash Labs Srl, Via Giovanni Battista Tiepolo 13A, 00196 Rome (RM), Italy, acts as independent Data Controller for the processing activities related to the operation and technical management of the Hyundai Gaming Experience.

Data Protection Contact: info@smashlabs.io


1. Types of Data Processed and Purposes

Smash Labs Srl processes only technical and usage data strictly necessary for the service, in compliance with the principles of data minimisation (Art. 5(1)(c)) and purpose limitation (Art. 5(1)(b)).

  1. Data NOT processed: We do not collect or have access to names, email addresses, telephone numbers, payment details, or exact GPS location.
  2. Device ID: We process the Device ID exclusively for analytics purposes. The Device ID is protected using strong, industry-leading one-way hashing techniques, significantly reducing the risk of re-identification.
  3. Analytics Data: We collect aggregated and pseudonymous analytics data including: session counts, average session duration, most used features, user flow patterns and UI clicks. This data is processed through our internal analytics system and is used solely to improve the gaming experience and monitor service health.

2. Legal Basis for Processing (Art. 6 GDPR)

The processing of data is based on the following legal grounds:

  1. Legitimate interest (Art. 6(1)(f)): Device ID (hashed) for analytics and fraud prevention; aggregated analytics data for service improvement and performance monitoring; IP address (truncated) and session tokens necessary for the provision of the controller synchronisation functionality; IP address and HTTP metadata for network security and DDoS protection. A Legitimate Interest Assessment has been conducted confirming that all processing is proportionate and relies exclusively on pseudonymous or aggregated data.
  2. Legal obligation (Art. 6(1)(c)): Recording of Privacy Policy acceptance.

3. Third Parties (Sub-processors)

We use the following technical partners to provide our online services:

  1. Photon (Exit Games GmbH) – Germany (EU): Manages the IP address (truncated at source) and session tokens for controller synchronisation via smartphone. Processing is limited to the duration of the P2P session.
  2. ServerPlan Srl – Italy (EU): Provides cloud hosting and database infrastructure for the secure storage of pseudonymous data.
  3. Cloudflare, Inc. – USA / Global: Provides DDoS protection, CDN and network services. Data may transit through edge servers outside the EEA, safeguarded by Standard Contractual Clauses (Art. 46(2)(c) GDPR) and Cloudflare’s certification under the EU-U.S. Data Privacy Framework.

 

The gaming experience uses an internal authentication and access system developed by Smash Labs. No third-party platform services are used for user access or identity management.

4. Internal Analytics System

Smash Labs operates a proprietary internal analytics system. No third-party analytics providers (such as Google Analytics or Firebase) are used. The system collects pseudonymous usage data (session metrics, feature interaction counts, navigation patterns), processes it entirely on our own infrastructure hosted by ServerPlan within the EU, and stores only aggregated and pseudonymous data. No personally identifiable information is collected or stored. Analytics data is used exclusively to improve user experience, identify technical issues, and optimise performance.

5. Data Retention

In compliance with the storage limitation principle (Art. 5(1)(e) GDPR), data is retained only as long as necessary:

  1. Gameplay and ULID Data: Retained for the duration of the service agreement. Upon termination, or upon user deletion request, data is permanently anonymised or deleted within 30 days.
  2. Session Logs (Photon): Automatically deleted at the end of each gaming session.
  3. Analytics Data: Aggregated analytics data is retained for the duration of the service agreement.
  4. Network Traffic Logs (Cloudflare): Stored for up to 7 days solely for performance routing and security.

6. Data Security (Art. 32 GDPR)

Smash Labs implements appropriate technical and organisational security measures, including: strong one-way hashing of Device ID using industry-leading algorithms; TLS 1.2+ encryption for all data in transit; pseudonymisation through ULID identifiers not linkable to real identities; IP address truncation at source for Photon connections; DDoS protection and WAF via Cloudflare; access control policies restricting data to authorised personnel only.

7. User Rights (Art. 15–21 GDPR)

In accordance with the GDPR, users have the following rights:

  1. Right of Access (Art. 15): Confirmation of whether your data is being processed and access to such data.
  2. Right to Rectification (Art. 16): Correction of inaccurate personal data.
  3. Right to Erasure (Art. 17): Deletion of your personal data (“right to be forgotten”).
  4. Right to Restriction (Art. 18): Restriction of processing under certain conditions.
  5. Right to Object (Art. 21): Objection to processing based on legitimate interest.

 

7.1 Information Asymmetry

Important: Smash Labs does not collect or store any directly identifying personal data. All data is pseudonymous (ULID-based) or processed through strong one-way hashing (Device ID). Due to the absence of directly identifying data:

  • Smash Labs is generally unable to associate external requests (such as emails) with specific datasets, as no data exists capable of linking a real identity to the pseudonymous records in our systems;
  • The exercise of the rights of access, rectification, and restriction via external channels is therefore subject to the same technical limitation;
  • The right to data portability (Art. 20) does not apply, as no directly identifying data is stored and the processing is based on legitimate interest;
  • The right to erasure is most effectively exercised through the in-app mechanism described below, which is the only channel capable of correctly identifying the data associated with a specific application instance.

 

7.2 Deletion Procedure (In-App)

Users can delete all their data independently via “Main Menu” → “Settings” → “Info” → “Delete Account”. This permanently deletes all pseudonymous data (ULID, gameplay metrics, analytics, UI logs) associated with the application instance. This operation is irreversible.

 

7.3 Data Protection Contact

For general enquiries regarding data protection: info@smashlabs.io. Please note that, due to the technical limitations described above, it may not be possible to process individual data access or deletion requests received via email.

7.4 Right to Lodge a Complaint

You may lodge a complaint with the Garante per la protezione dei dati personali (www.garanteprivacy.it).

8. Additional Provisions

Automated Decision-Making (Art. 22): Smash Labs does not carry out any automated decision-making or profiling. Analytics data is processed in aggregated form only and is never used to evaluate or categorise individual users.

Minors (Art. 8): Smash Labs does not knowingly collect personal data from children under 16. No directly identifying data is collected and all processing relies on pseudonymous identifiers.

Changes to This Policy: Smash Labs may update this Privacy Policy to reflect changes in legislation or processing activities. Material changes will be communicated through the gaming application.

For any questions: info@smashlabs.io