PRIVACY POLICY
SimFly Pte. Ltd. – Last updated: 29 May 2025
Your privacy matters to us. This Privacy Policy explains how SimFly Pte. Ltd. (“SimFly”, “we”, “our”) collects, uses, stores, shares and protects information when you visit simfly.io and related sites, install or use the SimFly client, participate in our marketplace, or otherwise interact with any SimFly Service (collectively, the “Services”). By accessing or using the Services you consent to the practices described below.
1 SCOPE AND RELATIONSHIP TO OTHER POLICIES
This Policy applies to all natural persons who browse, register, or transact on the Services, anywhere in the world. It complements, and should be read together with, the Terms and Conditions, Cookie Policy, and any in‑product notices. Wherever local law imposes stricter requirements than those set out here, we comply with the stricter standard.
2 DEFINITIONS
“Personal Data” means any information that identifies, relates to, or could reasonably be linked with an individual.
“Processing” means any operation performed on Personal Data, such as collection, storage, use, disclosure, or erasure.
“Data Subject” means the individual to whom Personal Data relates.
“Gameplay Data” means telemetry, logs, mission statistics and other information generated by your use of the Services that do not, standing alone, directly identify you.
3 WHAT WE COLLECT
• Identity Data – name, date of birth, government‑issued ID details (for KYC), nationality.
• Contact Data – email address, postal address, telephone number, Discord handle or similar.
• Account Data – username, password hash, authentication tokens, account preferences.
• Financial Data – billing address, payment‑card details (tokenised), PayPal address, payout bank information, tax identifiers where required.
• Gameplay Data – flight telemetry, mission participation, asset ownership, marketplace activity, in‑game chat and support tickets.
• Technical Data – IP address, device identifiers, operating‑system version, browser type, crash reports, cookies and similar trackers.
• Marketing Data – your communication preferences and responses to surveys or promotions.
We do not knowingly collect data from children under thirteen (13). If we discover that we have inadvertently processed such data without verifiable parental consent, we will delete it promptly.
4 HOW WE COLLECT DATA
Most Personal Data is provided directly by you when you create an account, complete a transaction, participate in an event, contact support, or adjust settings. Gameplay Data and Technical Data are generated automatically by the SimFly Client or collected by cookies and server logs. Financial Data may be provided by our payment processors and banks.
5 PURPOSES AND LEGAL BASES OF PROCESSING
We process Personal Data for the following purposes and, where required by the EU GDPR, on these legal bases:
• Account creation and contract performance – Article 6(1)(b).
• Delivery of core gameplay functions – contract performance.
• Transaction settlement, payouts, and fraud prevention – legal obligation Art. 6(1)(c) and legitimate interests Art. 6(1)(f).
• KYC/AML compliance for fiat withdrawals – legal obligation.
• Personalisation, analytics, and service improvement – legitimate interests.
• Marketing communications with opt‑in consent – Art. 6(1)(a).
• Handling support requests or disputes – contract performance and legitimate interests.
• Enforcing our Terms and protecting the platform – legitimate interests.
6 DISCLOSURE TO THIRD PARTIES
We share data only when necessary:
• Payment processors, payout partners, and banks to complete transactions.
• Cloud‑hosting providers and analytics vendors that operate under confidentiality agreements.
• Fraud‑monitoring, identity‑verification, and AML screening service providers.
• Professional advisers (lawyers, auditors) and governmental authorities where required by law or to defend legal rights.
We do not sell or rent your Personal Data.
7 INTERNATIONAL TRANSFERS
SimFly is headquartered in Singapore and uses servers located in multiple jurisdictions. Where data is transferred outside your country, we rely on approved transfer mechanisms such as contractual clauses adopted by the European Commission or other legally recognised safeguards.
8 RETENTION
We keep Personal Data only as long as necessary to fulfil the purpose for which it was collected, including satisfying legal, accounting, or reporting obligations. Gameplay Data linked to your account is retained for the life of the account and may be anonymized upon deletion. Backup records may persist for up to sixty (60) months before secure destruction.
9 SECURITY
We implement technical and organizational measures appropriate to the risk, including encryption in transit, firewalls, role‑based access controls, and periodic security audits. No online service is 100 % secure; you are responsible for keeping your password confidential.
10 AUTOMATED DECISIONS AND PROFILING
SimFly uses automated systems to calculate rewards, detect fraud, balance the in‑game economy, and personalise offers. These processes do not produce legal effects nor significantly affect individuals beyond normal expectations of a game economy.
11 MEDIA & COMMUNITY CONTENT
From time to time we create public content such as livestreams, tutorial videos, or promotional material that showcases gameplay or community activity. This may include displaying usernames, call‑signs, flight paths, logbook entries, asset statistics, screenshots, or video captures of in‑game actions. We rely on our legitimate interests to foster community engagement and promote the Services (GDPR Art. 6(1)(f)). Where such content is published on platforms like YouTube, social media, or our own websites, it is visible worldwide. If you prefer that your account not be featured, you may opt out by emailing info+privacy@simfly.io with your username; we will use reasonable efforts to exclude your data from future recordings.
12 YOUR RIGHTS
Depending on your jurisdiction, you may have the right to: access, rectify, erase, restrict, or port your Personal Data; object to certain processing; withdraw consent; and lodge a complaint with a supervisory authority. To exercise any of these rights, contact our Data Protection Officer (“DPO”) at the address in Section 14.
13 COOKIES AND SIMILAR TECHNOLOGIES
Our use of cookies is explained in the separate Cookie Policy. You can control cookies via your browser settings; however, disabling them may impair functionality.
14 DATA BREACH NOTIFICATION
In the event of a breach likely to result in risk to personal rights and freedoms, we will notify affected Users and, where applicable, relevant authorities without undue delay in accordance with applicable law.
15 CONTACT DETAILS
Data Protection Officer – SimFly Pte. Ltd.
Email: info+dpo@simfly.io
Postal: see corporate contact page.
16 CHANGES TO THIS POLICY
We may update this Policy from time to time. The “Last updated” date will change when revisions are posted. Material changes will be communicated via email or in‑platform notice. Continued use of the Services after the effective date constitutes acceptance of the revised Policy.
17 GOVERNING LAW AND COMPLAINTS
This Policy is governed by the laws of the Republic of Singapore. We encourage you to contact us first if you believe your privacy rights have been infringed; you also have the right to complain to your local data‑protection authority.
© 2025 SimFly Pte. Ltd. All rights reserved.