SKIN LAND PRIVACY AND DATA PROTECTION POLICY
29/08/2022

1. Introduction

This Privacy Policy is intended for users’ enlightenment and describes how we process users’ data and what rights users have as data subject.

We at Skin Land are dedicated to safeguarding and preserving Your personal data and privacy when visiting Our Website, utilising Our services, products or communicating electronically with Us.

For the purposes of the data protection laws that apply to Us, including the GDPR which is the European General Data Protection Regulation and LPPNP, which is the “Law providing for the protection of natural persons with regard to the processing of personal data and for the free movement of such data”, We act as the Data Controller for the personal data that We collect and process to enable You to make use of Our Services.

The purpose of this Privacy Policy is to transparently provide You with an explanation of the legal basis for Us collecting and processing Your personal data, the categories of personal data that We may collect about you, what happens to the personal data that We may collect, where We process Your personal data, how long We are required to retain Your personal data, who We may share Your personal data with and to also explain Your rights as a data subject.

We update this Privacy Policy from time to time and will post all updates to Our Website as and when issued. Please do review this policy regularly on Our Website for any changes.

2. Definitions

In this Privacy Policy the following terms shall have the following meanings:

“Cookies” mean small text files placed on Your computer or device by Our Website when You visit certain parts of Our Website.

“Consent” of Personal data procession shall mean any freely given, specific, informed and unambiguous indication of the Data Subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

“GDPR” means the General Data Protection Regulation (EU) 2016/679, of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC, as amended, replaced or superseded and in force from time to time and as transposed into member-state legislation.

“LPPNP” means the “Law providing for the protection of natural persons with regard to the processing of personal data and for the free movement of such data” №125(I) of 2018, which aims to govern the collection, use and disclosure of personal data by Cyprus organizations.

“Privacy Policy” means this Privacy Policy updated from time to time and made public on Our Websites.

“Personal Data” in accordance with GDPR means any information which relates to an identified or identifiable natural person. An identifiable person is one who can be identified directly or indirectly in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

“Personal Data” in accordance with LPPNP means any information concerning an identified or identifiable natural person ("data subject"). The identifiable natural person is one whose identity can be ascertained, directly or indirectly, in particular through reference to an identifier, such as a name, to an ID number, to data location, online identifier, or one or more factors that attribute to the physical, physiological, genetic, psychological, economic, cultural or social identity of the natural person in question.

“Personal data procession” or “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

“Third party” means a natural or legal person, public authority, agency or body other than the Data Subject, Controller, processor and persons who, under the direct authority of the Controller or processor, are authorized to process personal data.

“Services” mean all Our services delivered through our Website.

“You” (“your”) refers to You when You are visiting Our Websites, utilising Our services, products or communicating electronically with us.

“We” (“us” or “our”) refers to Skin Land.

All terms not otherwise defined in this Privacy Policy shall have the meanings ascribed to them in the Terms of Use.

3. Your data protection rights

Under the GDPR you, as a data subject, have certain rights over the Personal Data that We hold and process.

At Skin Land, We are committed to make it easy for You to exercise these rights in the most transparent manner possible. You can exercise any of Your rights in relation to the data that Skin Land holds about you, by contacting Our data protection officer through the email address provided at the end of this section.

The following are the specific rights You have over Your Personal Data We hold and process, namely:

1) The right to be informed about Our collection and processing of Your Personal Data including without limitation the legal basis for the collection and processing, the categories of data, the methods of data use, the envisaged period for which the Personal Data will be retained. This Privacy Policy should tell You everything You need to know, but You can always contact Us to find out more or to ask any questions.

2) The right to access Your Personal Data We collect about You, commonly referred to as “Subject Access Requests”, which provides You, as the data subject, the right to obtain a copy of Your personal data that We are processing for You Pursuant to GDPR We are required to respond without undue delay to all Subject Access Requests in practice this means We have to respond within 1 month of receipt of the Subject Access Request.

Ordinarily Subject Access Requests are free of charge. However, if you reside in Cyprus, a reasonable fee may apply.

We may extend the time period for responding to a Subject Access Request by a further two months and may charge a reasonable fee if We deem the request to be manifestly unfounded or excessive, however, We are required to advise You of Our intention to do this within 1 month of Your subject access request.

The provisions of this Article shall apply to the extent that they do not affect the right to freedom of expression and information and the press confidentiality.

3) The right to have Your Personal Data rectified if any of Your Personal Data that We collect and process is in any way inaccurate or incomplete.

4) The right of erasure (otherwise known as “the right to be forgotten”), i.e. the right to ask Us to delete or otherwise dispose of any of Your Personal Data that We process. Please note that this is not an absolute right and We may not be able to comply with Your request as We may be legally obliged to continue to retain Your Personal Data for a specific period

5) The right to restrict (i.e. prevent) the processing of Your Personal Data by Us if one of the following conditions applies:

- The accuracy of the Personal Data is disputed by You for a period allowing us to verify the accuracy of the Personal Data.

- The processing is illegal and You oppose the deletion of Personal Data and instead request the restriction of their use.

- We no longer need Personal Data for the purposes of the processing, but it is required by You to establish, enforce or defend legal claims.

- You object to the processing pending the verification of whether our legitimate grounds prevail over your Personal Data.

6) The right to object to Us processing Your personal data for a particular purpose or purposes. Please note that the right to object only applies in certain circumstances and will depend on the purposes or legal basis for the processing.

We will no longer process Personal Data in the event of an objection unless we can demonstrate compelling legal grounds for processing that outweigh your interests, rights, and freedoms, or to establish, exercise, or defend legal claims.

If we process Personal Data for direct marketing purposes, You have the right at any time to object to the processing of Personal Data concerning You for such marketing. If you object to processing by us for direct marketing purposes, we will no longer process Personal Data for these purposes.

In addition, you have the right to object to the processing of Personal Data concerning You by us for scientific or historical research or for statistical purposes, unless the processing is necessary to fulfil the task performed for reasons of public interest.

7) The right to data portability. This only applies where You have provided Personal Data to Us directly, the legal basis for Us processing Your Personal Data is i) consent or ii) for the performance of a contract and We are processing Your data using automated means. In such instances You have the right to receive Your Personal Data (or request that We transfer it to another Controller) in a structured, commonly used and machine readable format.

8) Rights relating to automated decision-making and profiling. We do not use Your personal data in this way.

9) Right to withdraw consent to data processing. You have the right to revoke your consent to the processing of your Personal Data at any time.

If You wish to exercise any of the aforementioned rights, please contact Us. We request that in the first instance You contact Our data protection officer at any time via [email protected]

We shall promptly consider Your request and respond to You in accordance with the requirements of LPPNP and GDPR accordingly.

Complaints to the Commissioner of Personal Data Protection should be made by using the instructions provided in the Commissioner of Personal Data Protection

4. Consent

The Personal data can be processed only after receiving freely given, specific, informed, unambiguous and clear “Consent” of Personal Data procession from You.

By using Services on the Website, You are joining the Privacy Policy by clicking the “I Accept” button in the appropriate section of the Website means full and unambiguous acceptance of the provisions of the Privacy Policy. By accepting the Privacy Policy, You agree with the collection, storage, processing, use, and disclosure of your personal data by Skin Land strictly within the Privacy Policy.

Your consent to the processing of Personal Data is valid indefinitely from the moment of acceptance of terms of this Policy in full.

If You don't wish to provide your Personal Data on the premise set out in this Privacy Policy, you should not enter the relevant information on the Website or provide your Personal Data to us otherwise. In any case, if you deny dispensing your Personal Data, you might not be utilizing all of our Services.

This Policy applies only to the Website and Services. We do not control and are not responsible for third party websites to which You can click on the links available on the Website. On such sites, website owner may collect or request other personal information, and other actions may be performed.

5. Use of Cookies

To enhance the quality of Our services, We use technologies, such as Cookies. Cookies do not typically contain any information that personally identifies users, but Personal Data that We store about users may be linked to the information stored in and obtained from Cookies.

We use Cookies to learn about users’ traffic patterns and Website usage to help Us develop the design and layout of the Website in order to enhance users’ experience browsing Our Website.

We use the following types of cookies:

· Strictly necessary cookies – these are cookies that are required for the operation of Our websites.

Through cookies, Personal Data is being processed for the purposes as described in Section 4 (“Purposes”) in the following way:

Ø Cookies are to be deleted when user closes the browser (session cookies).

Ø Cookies remain stored on end user device even after the browser was closed (permanent cookies).

If You want to delete any cookies already stored on Your personal device or stop the cookies, You can do so by deleting Your existing cookies and/or altering Your browser's privacy settings. However, if, as mentioned above, due to Your personal device settings or browser settings, We are not able to use other technical solutions to store respective information, restriction/deletion of cookies may lead to your inability to access the content of Our Website.

In order to restrict it to certain cookies, users can use browser settings. *

*Details can be found in browser helpdesk (usually accessible via the F1 key on keyboard).

6. Personal Data we collect about You

6.1         Legal basis for collecting and processing personal data

Skin Land processes Your Personal Data based on the following:–

Ø the performance of Our contract with You (i.e. the provision of Our Services to You);

Ø our legitimate business interests (i.e. for fraud prevention, maintaining the security of Our network and Services, seeking to improve the Services that We provide and Your interaction with us). Whenever We rely upon on this lawful basis We assess Our business interests to make sure that they do not override Your rights. Furthermore, in some cases You have the right to object to this processing;

Ø with Your consent for direct marketing purposes so that We may keep You fully up to date with other products and services that We supply and think may be of interest to you. Where We rely upon consent, We will need Your explicit consent, which may be removed at any time.

6.2        Categories of the Personal Data we collect

A summary of the Personal Data that We process - includes information such as your name, age, address, telephone number, date of birth, e-mail address, IP address or user behaviour. Information that cannot (or only with a disproportionate effort) be referred to your person, e.g. by anonymizing the information, is not Personal Data. The processing of Personal Data (e.g. the collection, retrieval, use, storage or transmission) always requires a legal basis or your consent.

We will use your Personal Data for our legitimate interests to respond to your enquiries, to send information to you, to fulfil any contractual obligation to you, for research purposes, to send marketing information to you regarding our goods, services and related opportunities, and other reasonable uses by virtue of your affirmative consent.

We may refuse You access to our Service and Website should we, in good faith, have doubts as to validity or authenticity of any Personal Data You provide.

7. Protecting Your Personal Data and data retention

We use, store and process Your Personal Data on Skin Land.

By filling a “consent application“ You agree to this conditions of collection, processing, transfer and storing Your Personal Data. When We process Your Personal Data for one of the legal bases specified in this Privacy Policy, We will take all steps reasonably necessary to ensure that Your Personal Data is treated securely and in accordance with this Policy.

We protect Your Personal Data under internationally acknowledged standards, using physical, technical, and administrative security measures to reduce the risks of loss, misuse, unauthorized access, disclosure, and alteration. Some of the safeguards We use are firewalls and data encryption, physical access controls to Our data centres, and information access authorization controls. Skin Land also authorizes access to Personal Data only for those employees or contractors who require it to fulfil their job or service responsibilities. Our staff is trained on procedures for the management of Personal Data, including limitations on the release of data. Access to Personal Data is limited to those members of Our staff and contractors whose work requires such access. We conduct periodic reviews to ensure that proper information management policies and procedures are understood and followed. All of Our physical, electronic, and procedural safeguards are designed to comply with applicable laws and regulations.

7.1. How We protect Your data

When You provide Your Personal Data through Our Website, this information is transmitted across the internet securely using industry standard encryption. Your Personal Data will be held encrypted on secure servers.

Where any Third parties process Your Personal Data on Our behalf, We require that they have appropriate technical and organizational measures in place to protect this Personal Data and We will also ensure that a GDPR compliant Data Processing Agreement is in place between Skin Land and the third party so that both parties understand their responsibilities and liabilities pursuant to GDPR.

7.2. How You can protect Your Personal Data

When You create Your Steam account, choose a strong password that is unique to this account. Do not share Your password with other people. Using the same password across Your different accounts will increase the risk of Your data being compromised if Your password is accidentally or unlawfully accessed by unauthorized persons. If You suspect that someone else has got access to Your password, make sure that You change it immediately.

As We use Your Steam account in order to provide You with our Services, make sure You have been following up the rules of choosing and storing your password.

7.3. Data retention

We store and process Personal Data for as long as it is necessary to achieve the purpose for which it was collected, or to comply with legal requirements and regulations.

Your Personal Data will be retained for as long as necessary to satisfy the purposes We received it for, this includes regulatory and business purposes.

In determining the necessary Personal Data retention period, the following factors are considered:

· The amount of Personal Data as We aim to minimize this amount to the extent possible for each specific purpose specified in Section 5.1 of this Privacy Policy.

· The nature of the Personal Data depending on the exact purpose which this specific Personal Data serves as detailed in Section 5.1 of this Privacy Policy.

· The sensitivity of the Personal Data by its nature and substance.

· The potential risk of harm from unauthorized use or disclosure of Your Personal Data and We continue to run risk assessments and risk mitigation activities to minimize this potential risk including engagement of a Third party specialized data management and data protection providers.

· The purposes for which We process Your Personal Data and whether We can achieve those purposes through other means, and the applicable legal requirements.

· We keep records on the ways We have used or disclosed Your Personal Data for at least 12 months in order to enable Us to provide You with access to Your Personal Data

8. Who do We share Your Personal Data with?

We do not share Your Personal Data to Third parties, except cases that are mentioned in this Privacy Policy.

8.1.         With Your consent

We may share information with companies, organizations or individuals outside of us when We have Your explicit consent.

8.2.         To comply with the law

We may share information in response to a request for information if We believe disclosure is in accordance with, or required by, any applicable law, regulation, legal process or governmental request, including, but not limited to, meeting national security or law enforcement requirements. To the extent the law allows it, We will attempt to provide You with prior notice before disclosing Your information in response to such a request.

8.3.         In an emergency

We may share information if We believe that it's necessary to protect the vital interests of the data subject (i.e. to prevent imminent serious physical harm or death to a person.)

8.4. To enforce Our policies and rights

We may share information if We believe Your actions are inconsistent with Our user agreements, rules, or other policies, or to protect the rights, property, and safety of ourselves and others.

8.5. With Our partners

We may share information with vendors, consultants, and other service providers (but not with advertisers and ad partners) who need access to such information to carry out processing activities for us. The partner’s use of Personal Data will be subject to appropriate confidentiality and security measures.

We engage service providers to perform functions and provide processing services to us. We may share Your private Personal Data with such service providers subject to obligations consistent with this Privacy Policy and any other appropriate confidentiality and security measures, and on the condition that the third parties use Your private Personal Data only on Our behalf and pursuant to Our instructions.

Where any third parties process Your Personal Data on Our behalf, We require that they have appropriate technical and organizational measures in place to protect this Personal Data and We will also ensure that a GDPR compliant Data Processing Agreement is in place between us and the third party so that both parties understand their responsibilities and liabilities pursuant to GDPR.

8.7        International transfers of Personal Data

In cases when we transfer Your Personal Data internationally, We ensure our compliance with all requirements set out in GDPR and LPPNP regarding the international transfer of Personal Data.

8.8        Other information

Other information, that does not personally identify You as an individual is collected by Skin Land (such as, by way of example, patterns of use) and is exclusively owned by Skin Land. We can use this information in such manner that Skin Land, in its sole discretion, deems appropriate.

We may share specific aggregated, non-personal information with third parties, such as the number of users who have registered with us, the volume and pattern of traffic to and within the site, etc. That information will not identify you, the individual, in any way.

We shall not use Your email or other contact information for sending of commercial proposal, other marketing needs, without Your prior consent.

In the light of the above, when You send Us messages, We can keep them for administering of Your inquiries, for improving of Our services. We shall not transfer information from such messages to third parties.

9. Third parties

We may also share users’ Personal Data with our third party providers that provide customer support services in connection with content and Services distributed via Websites. User’s Personal Data will be used in accordance with this Privacy Policy and only as far as this is necessary for performing customer support services. We may also share certain information (including user’s IP address and the identification details with our third party network providers that provide content delivery network services. Our content delivery network providers enable the delivery of digital content users have requested, e.g. when using Website, by using a system of distributed servers that deliver the content to users, based on users’ geographic location.

We do not share user’s Personal Data with any third party except for the reason described above or unless this is required by the law.

10. Contact Us

We welcome any queries, comments or requests You may have regarding this Privacy Policy. If You wish to make a subject access request

Please do not hesitate to contact Us at

E-mail: [email protected]

10. Changes to this Privacy Policy

Any changes that We make to Our Privacy Policy in the future will be posted on Our Website. Where appropriate, We will notify You of the changes when You next visit Our Website.

This Privacy Policy was last updated on 29th August 2022.