Privacy Policy

1. PREAMBLE

This Privacy Policy reflects Quest Lab Games Korlátolt Felelősségű Társaság (registered office:
1123 Budapest, Alkotás utca 55-61, Hungary, site: 1027 Budapest, Bem József utca 1/B, registration
number: 01-09-430708, tax number: 32561528-2-43, statistical number: 32561528-6210-113-01,
represented by: Fórizs András Sándor managing director, hereinafter: “Quest Lab,” also “we,” “us”) in
processing the personal data of our users: how and why we collect and use your personal data, it also
covers your rights to such personal data processing. It covers data processing when you install and
play video games owned and distributed by Quest Lab (hereinafter: “Games”), both when you use
our desktop or mobile Games or use other gaming platforms, surf our websites, or otherwise use our
products and services, as well as when you are attending the events that we are organizing (“Service
or Services”).

We may periodically update this Privacy Policy by posting a new version on the questlab.games website. If we make any material changes, we will notify you as required under applicable law, including by
posting a notice in the Service prior to the change becoming effective. Your continued use of the
Service after the effective date will be subject to the new Privacy Policy.

Quest Lab intends to fully comply with the legal requirements regarding the processing of personal
data, particularly those contained in Regulation (EU) 2016/679 of the European Parliament and of the
Council (“GDPR”) and in Act CXII of 2011 on the Right to Informational Self-Determination and
Freedom of Information, and has therefore created the following Data Protection Notice.

2. WHO WE ARE

Your data is processed by Quest Lab, meaning the following legal entity:

  • Name: Quest Lab Games Korlátolt Felelősségű Társaság
  • Registered office: 1123 Budapest, Alkotás utca 55-61.
  • Registration number: 01-09-430708
  • Tax number: 32561528-2-43
  • Mailing address: 1123 Budapest, Alkotás utca 55-61.
  • E-mail: info@questlab.games

Quest Lab, as the data controller, recognizes this data processing information as binding on itself.
For certain personal data processing, our partners are also considered data controllers. For example,
when you access our Services through gaming consoles or platforms, or the Services are provided
together with other entities.

If you have questions about data protection, or if you have any requests for resolving issues with your
personal data, we encourage you to primarily contact us by email at info@questlab.games, so we can
reply to you more quickly. Alternatively, you may reach us on the following address: 1123 Budapest,
Alkotás utca 55-61., Hungary. Please also see Section 15 of this Privacy Policy for more contact
information.

3. DEFINITIONS

Data processing”: any operation or set of operations which is performed on personal data or on data
sets, whether or not by automated means, such as collection, recording, organisation, structuring,
storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination
or otherwise making available, alignment or combination, restriction, erasure or destruction;

Data processor”: any natural or legal person, public authority, agency or any other body which
processes personal data on behalf of the controller;

Third party”: any natural or legal person, public authority, agency or any other body other than the
data subject, the controller, the processor or persons who, under the direct control of the controller or
the processor, are authorised to process personal data;

Personal data”: any information relating to an identified or identifiable natural person (“data subject”);
an identifiable natural person is one who can be identified, directly or indirectly, in particular by
reference to an identifier such as a name, a number, location data, an online identifier or to one or
more factors specific to the physical, physiological, genetic, mental, economic, cultural or social
identity of that natural person.

Service or Services”: As defined in the Preamble.

IP address”: the IP address is a series of numbers that can be used to clearly identify the computers
and mobile devices of users accessing the Internet. IP addresses can even be used to geographically
locate the visitor using a given computer or mobile device. The address of the pages visited, as well as
the date and time data, are not suitable for identifying the data subject in themselves, but when
combined with other data (e.g. provided during registration), they are suitable for drawing conclusions
about the user.

4. LEGAL STATUS, DUTIES AND RESPONSIBILITIES

4.1. Legal Status, Duties and Responsibilities of the Data Protection Officer (DPO)

The controller shall ensure that the DPO is involved in all matters relating to the protection of
personal data in an appropriate and timely manner. It shall be ensured that the DPO has the
necessary resources to maintain his/her expert knowledge.

  • The DPO shall not take instructions from anyone in the performance of his/her tasks. The
    controller or processor shall not dismiss or penalise the DPO in relation to the performance of
    his/her tasks. The DPO shall be directly accountable to the highest management of the
    controller or processor.
  • Data subjects may contact the DPO on all matters relating to the processing of their personal
    data and the exercise of their rights.
  • The DPO shall be bound by an obligation of confidentiality or an obligation of confidentiality in
    the performance of his/her tasks.
  • The contact details of the DPO
    by mail: 1027 Budapest, Bem József utca 1/B
    Email: andras.forizs@questlab.games
    Phone: +36707789594
4.2. Data Protection Impact Assessment (DPIA)

The controller is responsible for carrying out a DPIA, which assesses the source, nature, specificity
and severity of the risk to the rights and freedoms of natural persons. The findings of the DPIA shall be
taken into account when determining which measures are appropriate to demonstrate that the
processing of personal data complies with the GDPR. If the DPIA indicates that the processing
operations involve a high risk which the controller cannot mitigate by appropriate measures, taking into
account the available technology and the costs of implementation, the National Authority for Data
Protection and Freedom of Information (NAIH) shall be consulted prior to the processing. If it becomes
necessary to conduct a DPIA in connection with high-risk data processing in the future, it will be
carried out using open source software (originally called “PIA software”) published by the French data
protection authority (Commission Nationale de l’Informatique et des Libertés) and recommended by
the NAIH.

5. BALANCE OF INTEREST TEST (BIT)

In the case of data processing based on legitimate interest (GDPR II. Section 6 (1) f)), the BIT is
carried out based on the position paper NAIH/2015/3731/2/V. Based on this, the BIT is a multi-step
process, during which the legitimate interest of the data controller must be identified, as well as the
data subject’s interest and fundamental right that constitute the counterpoint of the weighing, and
finally, based on the weighing, it must be determined whether the personal data can be processed.
Steps used in the BIT:

Step 1 – examining whether data processing is necessary or can be solved differently
Step 2 – defining the legitimate interest as precisely as possible
Step 3 – determining the purpose of data processing, what personal data is required and for
how long the data processing requires it
Step 4 – determining the aspects of the data subjects
Step 5 – carrying out the BIT

6. PRINCIPLES OF DATA MANAGEMENT

Quest Lab is committed to protecting the personal data of its users and partners and considers it of
utmost importance to respect the informational self-determination of its customers.
Quest Lab, as a data controller, is responsible for complying with the following:

  • Processing personal data lawfully and fairly, and in a manner that is transparent to the data
    subject (“lawfulness, fairness and transparency”);
  • Collecting personal data only for specified, explicit and legitimate purposes and not processing
    them in a manner that is incompatible with these purposes (“purpose limitation”);
  • Processing personal data is adequate and relevant in relation to the purposes of the data
    management and is limited to what is necessary (“data economy”);
  • Ensuring that personal data is accurate and, where necessary, up-to-date and taking all
    reasonable steps to erase or rectify personal data that is inaccurate in relation to the purposes
    of the data management without delay (“accuracy”);
  • Store personal data in a form that permits identification of data subjects only for the time
    necessary to achieve the purposes for which the personal data are processed (“limited
    storage”);
  • Process personal data in such a way that appropriate technical or organizational measures
    ensure appropriate security of personal data, including protection against unauthorized or
    unlawful processing, accidental loss, destruction or damage (“integrity and confidentiality”).

7. THE DATA WE COLLECT

The categories of personal data we collect depend on the Services you use, and the requirements of
applicable law.

7.1. Data You Provide to Us Directly

While using our Services, you are providing us with certain information, usually when you register and
manage your Quest Lab Account; use Quest Lab’s websites; play Quest Lab games or use other
Services, purchase goods and services provided by Quest Lab; participate in discussions on forums
and Quest lab social media; participate in our surveys; request and receive support or customer
service or communicate with us over a claim. Such data may include the following categories:

  • Your messages and other content you submit when you use the Service (such as chat logs
    and player support tickets).
7.2. Data We Collect Automatically

Your device may transmit some information while you interact with Quest Lab Services, including:

  • Data about your account and game progress, including in most cases an automatically
    created internal account ID
  • Your IP address and mobile device identifiers (such as your device or advertising ID)
  • Data about your device, such as device name and operating system, browser type and
    language, internet service provider, and mobile carrier
  • Data we collect with cookies and similar technologies (see more below)
  • Approximate location data (as derived from IP address)
  • Data about your use of the Service, such as gameplay data, purchases made and your
    interactions with other players inside the Service

7.3. Data We Receive from Third Parties

We may receive certain data from our partners, affiliates, and vendors that assist us in providing the
Services to our users. These data include the following:

  • Demographic data (such as to determine the coarse location of your IP address)
  • Data to fight fraud (such as refund abuse in games or click fraud in advertising)
  • Data from platforms that the games run on or data from payment service providers (such as
    payment verification data)
  • Data for advertising and analytics purposes (such as surveys), so we can provide you a better
    Service

8. FOR WHAT PURPOSES DO WE COLLECT YOUR DATA?

We use your data for a variety of business purposes, such as:

8.1. To Make the Service Work

To perform the contract, we process data necessary to

  • Create accounts and allow you to play our games and use our Service
  • Operate the Service
  • Verify and confirm payments
  • Provide and deliver products and services you request
  • Send you Service-related communications
8.2. To Make the Service More Suitable for Our Players

To provide a great Service to our players, we have a legitimate interest to collect and process
necessary data to

  • Update and develop player profiles
  • Develop and improve the Service and player experience
  • Manage our relationship with you
  • Provide social features as part of the Service
  • Customize your Service experience
  • Respond to your comments and questions and provide player support
  • Provide you offers in the Service as well as in other websites and services (including by email)
  • Send you related information, such as updates, security alerts, and support messages
8.3. To Show Personalized Advertisements

To show you personalized advertisements in the Service and elsewhere (including email) we have a
legitimate interest to process necessary data to

  • Track the content you access in connection with the Service and your online behavior
  • Deliver, target and improve our advertising and the Service

For information on how to opt-out from personalized advertisements, see section ‘Your Rights and
Options’ below.

8.4. To Keep the Service Safe and Fair

Ensuring a level playing field in the Service is a top priority for us. For more information on our
acceptable use policy please see our Terms of Service.

To keep the Service and its social features safe and fair, to fight fraud and ensure acceptable use
otherwise, we have a legitimate interest to process necessary data to

  • Analyse and monitor use of the Service and its social features
  • Take action against fraudulent or misbehaving players
8.5. To Analyse, Profile, and Segment

In all of the above cases and purposes, we may analyse, profile and segment all collected data.

8.6. With Your Consent

With your consent, we may process your data for additional purposes.

We may also collect and use your device identifiers to display and personalize in-game ads and serve
behaviourally targeted advertising as explained below. Where applicable, we may collect your
advertising identifier (IDFA, GAID), vendor identifier, IP address, device ID and other device identifiers
(country, os version, device model, client version) for these purposes. Under applicable privacy laws,
including the GDPR, we are required to ask your consent to do so.

This data is shared with your consent so that our ad partners can deliver the right ad and optimize the
ad content to make sure you don’t see the same ad multiple times. We share your device identifiers
with selected partners for such ad delivery and personalization.

You can manage your consent in the game settings and limit ad tracking in your device settings.
Please note that opt-outs are specific to each browser and device, and it may take a little bit of time
before your opt-out will take effect.

For mobile advertising in apps, you can reset your Advertising Identifier and depending on your
device, select to opt out of interest-based ads (Android) or turn on the Limit Ad Tracking setting (iOS).

The partners operate the ad network and mediation platform, as well as facilitate and participate in ad
inventory bidding. The partners may also use the device identifiers for fraud detection purposes based
on their legitimate interest. For more information, please check the partners’ privacy policies here:
questlab.games/partner-opt-out.

9. WHO CAN SEE YOUR DATA?

Apart from Quest Lab, your data can be accessed by others in the following situations:

9.1. Other Players and Users

Social features are a core component of our games. Other players and users may, for example, see
your profile data, in-game activities and read the messages you have posted.

9.2. Our Service Providers

Quest Lab has vendors who help us to provide the Service. These vendors process your data only at
and according to Quest Lab´s instructions to provide the Service, and perform tasks such as hosting,
player support, advertising, analytics and fraud prevention.

9.3. Other Companies and Public Authorities

To verify payments (with payment providers such as PayPal) and combat fraud and illegal activity, we
may process and disclose data with other companies and organizations and provide it to public
authorities in response to lawful requests. We may also disclose your data based on your consent, to
comply with the law or to protect the rights, property or safety of us, our players or others.

9.4. Advertising and Social Media Partners

The Service includes features from our partners, such as social media interaction tools, functionalities
through application programming interfaces (APIs) or software development kits (SDKs) and in-game
advertising. A list of these partners is available at questlab.games/partner-opt-out. These partners may
access your data and operate under their own privacy policies. We encourage you to check their
privacy policies to learn more about their data processing practices.

These partners may access data regarding your activities and your device (such as your IP address,
mobile identifiers, page(s) visited, location, time of day). We may also combine and share data we
have collected about you with third-party advertising partners. These advertising partners may use this
data (and similar data collected from other services) for purposes of delivering targeted
advertisements to you when you visit third-party services within their networks. These partners may
operate under their own privacy policies. This practice is commonly referred to as “interest-based advertising” or “online behavioural advertising.” If you prefer not to share your personal data with third-
party advertising partners, you may follow the instructions in “Your Rights and Options” below.

10. INTERNATIONAL DATA TRANSFERS

Our Service is global by nature and your data can therefore be transferred to anywhere in the world.
Because different countries may have different data protection laws than your own country, we take
steps to ensure adequate safeguards are in place to protect your data as explained in this Privacy
Policy. Adequate safeguards that we may use include standard contractual clauses approved by EU
Commission and other lawful safeguards.

11. OPT-OUT RIGHTS

11.1. Opt-out of Marketing Emails and Other Direct Marketing

Where allowed under applicable laws, Quest Lab may send you marketing communications based on
the existing customer relationship.

You may opt out of receiving promotional communications, such as marketing emails from us by
following the instructions in such communications, or by changing your in-game settings. The updated
settings may not be effective immediately. Note that you may continue to receive non-promotional
communications from us, such as communications regarding the Service or updates to our Terms of
Service or this Privacy Policy or transactional information e.g. relating to your purchases on the
Service.

11.2. Push Notifications

We may send you push notifications through our mobile applications. You may at any time opt-out
from receiving these types of communications by changing the settings on your mobile device.

11.3. Opt-out of Targeted Advertising

You can opt-out of interest-based advertising on mobile applications by checking the privacy settings
of your Android or iOS device and turning off “Allow Apps to Request to Track” or selecting “Limit Ad
Tracking” (Apple iOS) or “Opt-out of Interest Based Ads” (Android).

For more information, see also:
questlab.games/partner-opt-out.

12. COOKIES AND SIMILAR TECHNOLOGIES

Like most online services, we and our partners use cookies and similar technologies to provide and
personalize the Service, analyse use, target advertisements and prevent fraud. Cookies and similar
technologies allow us and our partners to store their preferences and track your activities within the
Service. Note that our partners may operate under their own privacy policies.

We and our partners collect and store information about users’ interactions with unaffiliated websites
and applications that use our technologies, including cookies and similar tracking technologies. This
allows us to infer the presence of a common user or household behind multiple devices or browsers,
for instance, and then link those browsers and devices into a device graph. We do so to

  • Detect and prevent fraud;
  • Improve the Service;
  • Allow users to use the Service on one device and pick up seamlessly where they left off on
    another device;
  • Analytics, personalization and attribution;
  • Limit the number of times a user is shown the same advertisement, across all known or inferred devices; and/or
  • Provide personalized advertising on each device that is inferred from the browsing patterns on all of the devices.

You can disable cookies in your browser settings, but some parts of the Service may then not function
properly. Here are links to some popular browsers where you can adjust your cookie and web data
settings:

For display advertising on the Web, you can also adjust your browser settings to limit certain tracking
by means of cookies, and by visiting the following sites:

On some of our websites, we use third party analytics and telemetry providers and certain marketing
providers for the above purposes. Where applicable, we ask for your consent on the site.

Please note that above 3rd parties are not necessarily being used at all sites, or on all market areas.
For further information (including how to opt out), please visit questlab.games/partner-opt-out.

13. HOW DO WE PROTECT YOUR DATA?

13.1. Security Safeguards

To help ensure a secure and safe player experience, we are continuously developing and
implementing administrative, technical and physical security measures to protect your data from
unauthorized access or against loss, misuse or alteration.

13.2. Data Retention

We retain your data for as long as your account is active or as needed to provide you the Service. We
may for example periodically de-identify unused game accounts, and we may regularly review and de-
identify unnecessary data.

Note that if you ask us to remove your personal data, we will retain your data as necessary for our
legitimate business interests, such as to comply with our legal obligations, resolve disputes, and
enforce our agreements.

14. CHILDREN’S DATA

We acknowledge the importance of protecting children’s data and confirm our special duty to act
accordingly. Thus, we take additional steps to verify the user’s age and limit access to our Services for
those who have not reached the appropriate age limit.

We do not intentionally collect, store or otherwise process any personal data of users under the age of
16 unless we are furnished with consent from their parent, guardian, or another holder of parental
responsibility.

If you are a parent, guardian, or another holder of parental responsibility, and you want to withdraw
your previously given consent, or you find out that your child has provided us with their personal data
without your consent, or you believe that we have unintentionally collected your child’s data and
processed such data in violation of applicable law, please send us a request for the removal of such
data. To proceed with such a request, we may ask you to provide us with conclusive evidence that:

  • The child has not yet reached 16 or the minimum age of consent in accordance with their
    applicable legislation, and
  • You are the holder of parental responsibility for such a child.

If it comes that we have unintentionally collected personal data of a child under 16 (or a child who has
not reached the age of consent in accordance with applicable law) without the consent of that child’s
holder of parental responsibility, we will take all reasonable steps to erase this information as soon as
possible, unless we are legally obliged to keep these data.

We strongly encourage parents, legal guardians, or other holders of parental responsibility to instruct
their children never to disclose their real names, addresses, phone numbers, financial information, or
any other sensitive data about themselves when using our services, in-game chats, on the websites
(forums, commentaries, etc.) and otherwise on the Internet.

15. DATA PROTECTION RIGHTS AND LEGAL REMEDIES

According to Articles 15-20 of the GDPR, you have the right to:

  • Access your personal data processed by Quest Lab;
  • Request rectification of your personal data;
  • Request erasure of your personal data;
  • Request restriction of processing of your personal data;
  • Object to the processing of your personal data;
  • Receive your personal data and transmit them to another data controller, if the legal prerequisites for this are met (right to data portability);
  • If the processing of your personal data is based on your consent, you may withdraw your
    consent at any time.

You can send your request to exercise the above rights to info@questlab.games.

13.1. Security Safeguards

You have the right to receive feedback from Quest Lab as to whether your personal data is being
processed and, if such processing is taking place, you have the right to access your personal data and
to be informed about the circumstances surrounding their processing.

15.2. Rectification

You have the right to request that Quest Lab correct inaccurate personal data without undue delay and
to request that incomplete personal data be completed.

15.3. Right to Erasure (“Right to Be Forgotten”)

You have the right to obtain from Quest Lab, upon request, the rectification of inaccurate personal data
without undue delay and the completion of incomplete personal data.
You have the right to obtain from Quest Lab, upon request, the erasure of personal data without undue
delay where one of the following grounds applies:

  • The personal data is no longer needed;
  • The consent on which the data processing is based is withdrawn and there is no other legal
    basis for the data processing;
  • The personal data has been unlawfully processed by Quest Lab;
  • The personal data must be erased by law.

We will not erase the data if the processing is necessary for one of the following reasons: (i) for the
exercise of the right to freedom of expression and information; (ii) for the performance of a legal
obligation to which the personal data are subject; (iii) or for the establishment, exercise or defence of
legal claims.

15.4. Right to Restriction of Data Processing

You have the right to obtain from Quest Lab, at your request, restriction of data processing where one
of the following applies:

  • You contest the accuracy of the personal data, in which case the restriction shall apply for a
    period enabling to verify the accuracy of the personal data;
  • The processing is unlawful and you oppose the erasure of the data and request the restriction
    of their use instead;
  • You have objected to the processing; in which case the restriction shall apply for a period of
    time until it is determined whether the legitimate grounds of the controller override those of the
    data subject
15.5. Right to Object

You have the right to object at any time, on grounds relating to your particular situation, to the
processing of your personal data based on the legitimate interests of Quest Lab. In such a case,
Quest Lab shall no longer process the personal data unless the controller demonstrates compelling
legitimate grounds for the processing which override your interests, rights and freedoms, or for the
establishment, exercise or defence of legal claims.

15.6. Right to Data Portability

You have the right to receive your personal data in a structured, commonly used and machine-
readable format, if it does not adversely affect the rights and freedoms of others. You also have the
right to have these data transmitted directly by Quest Lab to another data controller where the
processing is based on your consent or is necessary for the performance of a contract to which you
are a party, or in order to take steps at your request prior to entering into a contract; and the
processing is carried out by automated means, i.e. the personal data are processed in an IT system
and not on paper.

15.7. Legal Remedy

You can file a complaint with the Nemzeti Adatvédelmi és Információszabadság Hatóság:

  • Name: Nemzeti Adatvédelmi és Információszabadság Hatóság
  • Registered office: 1055 Budapest, Falk Miksa utca 9-11.
  • Mailing address: 1363 Budapest, Pf.: 9.
  • Telephone: +36 1 391 1400
  • Fax: +36 1 391 1410
  • Website: http://www.naih.hu
  • Email: ugyfelszolgalat@naih.hu

Quest Lab Games Korlátolt Felelősségű Társaság
Effective Date: 2025.04.07.