
Privacy Policy
Last Updated 27th July 2026
#1. Introduction
1.1 Shockbyte Pty Ltd (ABN 40 626 765 455, ACN 626 765 455) ("Shockbyte", "we", "us", "our") provides game server hosting and related products and services.
1.2 This Privacy Policy ("Policy") explains how we collect, use, disclose and protect personal information. It applies to:
- (a) our game server hosting services, including Shockbyte Plus and other add-on services;
- (b) Shockbyte for Game Studios; and
- (c) any other product or service we offer that links to this Policy,
together with our websites, billing systems, control panels and support channels (collectively, the "Services").
1.3 This Policy forms part of, and should be read together with, our Terms of Service and Acceptable Use Policy.
1.4 In this Policy, "personal information" means information about an identified individual, or an individual who is reasonably identifiable. Where the General Data Protection Regulation ("GDPR") or the UK GDPR applies, it has the meaning given to "personal data" in those laws. "Controller" and "processor" have the meanings given in the GDPR.
#2. Contact details
2.1 The entity responsible for your personal information is:
Shockbyte Pty Ltd Suite 339, Level 3, 697 Collins Street Docklands, Melbourne VIC 3008 Australia
2.2 Privacy enquiries, requests and complaints should be directed to our Privacy Officer at privacy@shockbyte.com, or by post to the address in clause 2.1.
#3. Our role in relation to your data
3.1 This clause applies where we host or operate a game server or similar environment for you, including under our game server hosting Services and Shockbyte for Game Studios. Where you are a business customer, a separate written data processing agreement may apply — see clause 4.4.
3.2 Account and relationship data. We are the controller of personal information relating to your account, billing, support requests and use of our websites. This Policy governs that information.
3.3 Data on your server. You determine the purpose of your server, who may access it and what occurs on it. For most purposes you are the controller of the data on your server and we act as your processor, holding and operating that data on your behalf and on your instructions.
3.4 Your responsibilities. Where individuals access or participate in a server you operate, you are responsible for their personal information. In particular, you must:
- (a) have a lawful basis for collecting and using their personal information;
- (b) provide them with any privacy notice required by applicable law;
- (c) respond to any request they make to exercise their privacy rights;
- (d) comply with any applicable game publisher requirements, including the Minecraft Usage Guidelines, which require server operators to address end-user privacy;
- (e) where your server is directed to, or likely to be accessed by, children, comply with the laws that apply to children's personal information; and
- (f) manage the access you grant to sub-users, and remove it when it is no longer needed.
3.5 Sensitive information. You must not use the Services to collect or store special categories of personal information — including health information, biometric information, government identifiers, or financial account details — unless we have agreed to it in writing. If such information is provided to us in breach of this clause, we may delete it, and we are not responsible for it.
3.6 Where we act as controller of server data. We also process data on your server for our own purposes, and we are the controller in respect of that processing. Those purposes are limited to:
- (a) providing, operating and supporting the Services, including investigating faults and diagnosing issues you report to us, which may involve AI-assisted tools;
- (b) understanding how our Services are used — including trends across games and server types — and improving our platform and products, using aggregated and anonymised insights;
- (c) detecting, preventing and responding to abuse, fraud and security threats affecting our infrastructure, our personnel or our other customers;
- (d) complying with applicable law and responding to valid legal process; and
- (e) establishing, exercising or defending legal claims, including responding to disputes and chargebacks.
3.7 We do not use data from your server to train artificial intelligence models, and we do not permit our service providers to do so. We do not sell that data. We do not access it except for the purposes in clause 3.6 and as described in clause 8.
3.8 Anonymised data. Where we refer to anonymised or aggregated data, we mean data that can no longer be attributed to you, your server or any individual, and which we do not attempt to re-identify. Anonymised data is not personal information and is not subject to this Policy.
3.9 Analytics and monitoring features. The Services include features that analyse activity on your server, such as player activity reports generated from server logs. Some of these operate by default as part of the Services; others you can enable, configure, or ask us to set up for you. The resulting reports are made available to you. We act as your processor in respect of that processing, except where we use the information for one of the purposes set out in clause 3.6.
#4. Who this Policy applies to
4.1 This Policy applies to:
| Category | Our role |
|---|---|
| Account holders who purchase Services from us | Controller |
| Sub-users granted access to a control panel by an account holder | Controller of their account credentials; the account holder controls their permissions |
| Individuals who connect to a server we host for a customer | The customer is the controller. We act as their processor, except where we process the information for one of the purposes in clause 3.6, where we are the controller |
| Visitors to our websites | Controller |
| People who contact us, including enquiries, complaints and reports of abuse | Controller |
| People who receive our marketing but are not customers | Controller |
| People sent a gift card by someone else | Controller |
| Affiliates and partners | Controller |
#Business and studio customers
4.2 Where you engage with us as a business, including through Shockbyte for Game Studios, we collect personal information about your personnel — name, business contact details and role — in order to establish and administer our relationship with you, provide the Services, and comply with our legal obligations. We are the controller of that information, and clauses 5 to 22 apply to it.
4.3 Where we host or operate infrastructure for a business customer, that customer is the controller of personal information relating to its own users, players and customers, and we act as its processor in accordance with clause 3.
4.4 Business customers contract with us under a Master Services Agreement which includes a Data Processing Addendum governing our handling of personal information on their behalf. Where that Addendum is inconsistent with this Policy in relation to that customer, the Addendum prevails in respect of the processing of personal data.
4.5 Certain provisions of this Policy are directed at consumers and do not apply to business customers. In particular, clause 17 (children and young people) is directed at individuals who purchase the Services for personal use. Clause 17.3 continues to apply to any individual who connects to a server we host.
4.6 The rights described in clause 14 are available to personnel of business customers on the same basis as to any other individual.
#5. Personal information we collect
5.1 Account and identity information. Name; email address; password (stored only in salted hashed form); country, state and city; account and control panel preferences; multi-factor authentication settings.
5.2 Billing information. Billing address; currency; Services purchased; invoices, payments, refunds and chargebacks; promotional codes; a payment card token and the last four digits of the card. We do not receive or store complete payment card numbers. Card details are transmitted directly to our payment processors.
5.3 Support information. The content of support requests and attachments; correspondence with our personnel; the status and history of your requests.
5.4 You should not include sensitive information in support requests. This includes health information, government identifiers, and information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or sexual orientation. We do not require this information and ask that you do not provide it.
Where you provide it anyway, we remove it from our records where we identify it.
5.5 Technical and usage information. IP address; browser and device information; pages accessed and time spent; referring URL; control panel activity and login history; connection and error logs; server performance metrics.
5.6 Session recording. We use analytics tools that record interactions with our websites, including mouse movement, clicks and scrolling, for the purpose of identifying usability issues.
5.7 Affiliate and partner information. Payout details, including PayPal or bank account details; referral links and attributed purchases; commission balances and withdrawals; tax information where required by law.
5.8 Identity verification. In limited cases — for example where an order or account is flagged for possible fraud — we may ask you to verify your identity by providing a copy of a government-issued identity document. We ask for this only where we consider it necessary to protect our Services, our customers or ourselves against fraud or abuse. We use it only to verify your identity, and we delete it immediately once your identity is confirmed.
5.9 We do not ask for or record your date of birth or age.
#6. Personal information we collect from other sources
6.1 We collect certain personal information from sources other than you:
| Category of information | Source |
|---|---|
| Name, email address and control panel access | An account holder who grants you sub-user access |
| Payment confirmation, fraud and chargeback signals | Our payment processors |
| Reports concerning activity on a hosted server | Other customers, players, or third parties reporting abuse |
| IP reputation data and attack signatures | Network security and DDoS mitigation providers |
| Referral attribution data | Our affiliate system |
| Reviews you publish concerning us | Our review platform provider |
| Your name and email address, where someone sends you a gift card | The person who purchased the gift card |
6.2 Where you have been granted sub-user access by an account holder, that account holder has provided your details to us. You have the rights set out in clause 14 in respect of that information.
#7. Purposes and legal bases
7.1 We use personal information for the purposes set out below. Where the GDPR or UK GDPR applies, the corresponding legal basis is identified.
| Purpose | Legal basis |
|---|---|
| Creating and administering your account; provisioning the Services; processing payments, renewals and cancellations; issuing and redeeming gift cards; administering our affiliate programme; sending service communications; and responding to support requests | Performance of a contract (Art 6(1)(b)) |
| Fraud prevention, identity verification and network security; enforcing our Acceptable Use Policy; debt recovery and legal claims; analytics and improving our platform; marketing to existing customers; legal and record-keeping obligations; and business transactions | Legitimate interests (Art 6(1)(f)) — the specific interests are set out in clause 7.2 |
| Marketing to individuals who are not customers | Consent (Art 6(1)(a)) |
| Cookies and similar technologies that are not strictly necessary | Consent, as described in clause 18 |
7.2 The legitimate interests referred to in clause 7.1 are:
- protecting our network, our customers and our personnel from fraud, attack and misuse of the Services — including preventing account creation using stolen payment credentials, verifying identity where an order has been flagged, mitigating denial-of-service attacks, and identifying servers used to distribute malware or prohibited content;
- understanding how our Services are used and improving them;
- promoting our own services to people who already buy from us;
- recovering amounts owed to us, and establishing or defending legal claims;
- meeting our record-keeping obligations and responding to lawful requests from authorities; and
- evaluating and completing a sale, merger or restructure of our business.
7.3 Where we use personal information for a purpose not described in this Policy, we will do so only where permitted by law and, where the law requires, will notify you or obtain your consent.
#8. Access to your server by our personnel
8.1 Our support and engineering personnel are able to access your server files, console and backups. They will do so only where it is necessary to:
- (a) provide assistance you have requested;
- (b) investigate a fault affecting your server or our platform;
- (c) carry out maintenance, migrations, upgrades or other operational work on our infrastructure;
- (d) investigate a report of abuse or prohibited content; or
- (e) comply with valid legal process.
8.2 Access under clause 8.1 is limited to personnel who require it, is limited to the purpose for which it is granted, and is logged.
8.3 Backups. We operate two separate kinds of backup.
- (a) Backups you create. Your control panel lets you create and schedule your own backups. You control when these are taken and can delete them at any time. Each server has a limited number of backup slots; when they are full, the oldest backup is replaced.
- (b) Our disaster recovery snapshots. We take daily snapshots of our infrastructure for business continuity purposes. These exist for our own recovery, are not a customer backup service, and can only be restored by our personnel.
Deleting data from your live server does not immediately remove it from existing backups. It is removed as those backups are replaced or expire.
#9. Automated decision-making
9.1 We use automated processes to make, or to support, decisions about:
- (a) whether to accept an order or payment, or to issue a refund. An order or request may be flagged for review or declined, based on payment history, account activity, device information and behavioural indicators.
- (b) whether to restrict, suspend or take other action on an account or service. A server may be suspended, throttled or restricted where our systems detect activity contravening our Acceptable Use Policy.
- (c) whether to approve or withhold an affiliate payment. A commission may be withheld, reversed or delayed where our systems identify indicators of referral fraud.
9.2 Where a decision described in clause 9.1 significantly affects you, you may:
- (a) request that the decision be reviewed by a member of our personnel;
- (b) request an explanation of the reasons for the decision; and
- (c) provide information you consider relevant, which we will take into account.
Requests should be sent to support@shockbyte.com.
9.3 We do not use sensitive information as an input to automated decision-making.
#10. Retention
10.1 We retain personal information for as long as necessary to provide the Services, or for other legitimate business purposes such as resolving disputes, preventing fraud and abuse, maintaining the security of our network, and complying with our legal obligations. How long we retain it depends on the nature and sensitivity of the information, the potential risk of harm from unauthorised use or disclosure, the purpose for which we hold it, and any legal requirements that apply. When we no longer have a business or legal reason to hold it, we take reasonable steps to destroy it or to permanently de-identify it.
10.2 Some information is subject to a minimum retention period set by law. In particular, we are required to keep financial records for at least 7 years after the transaction they relate to.
10.3 Where you exercise a right to erasure, we delete your personal information within the period required by applicable law, except where we are required or permitted by law to retain it.
#11. Disclosure of personal information
11.1 We do not sell personal information for money. We do share personal information with advertising partners, as described in clause 18.5, which some privacy laws — including in California — treat as "selling" or "sharing". You can opt out at any time; see clause 18.5.
11.2 We disclose personal information to the categories of recipient set out below:
| Category of recipient | Purpose |
|---|---|
| Payment processors, including Stripe and PayPal | Taking payment, processing refunds and chargebacks, screening for payment fraud, and paying affiliates |
| Datacentre, hosting and network providers | Running the servers, infrastructure and network the Services operate on |
| Backup and storage providers | Storing backups and disaster recovery snapshots |
| Network security and content delivery providers, including Cloudflare | Protecting our network, mitigating attacks, and delivering our websites |
| Analytics and product measurement providers | Understanding how our websites and Services are used, including session recording and testing |
| Advertising partners | Measuring our advertising and showing you relevant advertising |
| Email providers | Sending service messages and marketing communications, and corresponding with you |
| Artificial intelligence providers, including Google, Anthropic and OpenAI | Assisting us in operating and supporting the Services, including diagnosing issues, analysing information, automating tasks, carrying out actions on services, and improving our products |
| Consent management providers | Recording and applying your cookie preferences |
| Website content and review platforms | Managing our website content and collecting customer reviews |
| Our group companies | Providing, operating and supporting the Services |
11.3 The countries these providers operate in are set out in clause 12. Our providers may in turn engage their own providers, who may be located in other countries. Where we use locally hosted artificial intelligence models, no personal information is shared with a third party.
11.4 We also disclose personal information where required or authorised by law, as described in clause 15, and in connection with a corporate transaction such as a merger, acquisition or sale of assets, in which case the recipient will be bound to handle the information consistently with this Policy.
11.5 Except as described in this Policy, we do not disclose personal information to third parties.
#12. International transfers
12.1 We are an Australian company with infrastructure and service providers in a number of countries. Personal information may be stored in, or accessed from, the following places:
- (a) Your game server runs in the region you select when you order it. The regions currently available, and the countries in which they are located, are listed at shockbyte.com/hardware.
- (b) Our own systems, including our account, billing, support and backup systems, are hosted primarily in the United States, with some information held in Australia and Europe.
- (c) Our service providers operate in Australia, Austria, Denmark, Germany, India, Ireland, the Netherlands, the United Kingdom and the United States. Some, including our network security and email providers, operate globally.
12.2 Where you change the region in which your server operates, your server data is transferred to that region.
12.3 Where we transfer personal information from the European Economic Area or the United Kingdom to a country that has not been the subject of an adequacy decision, we rely on Standard Contractual Clauses approved by the European Commission, or the International Data Transfer Agreement or Addendum issued by the UK Information Commissioner, as applicable. Where a recipient is certified under the EU-US Data Privacy Framework we may rely on that certification, with Standard Contractual Clauses in place as an alternative safeguard. Copies of the relevant safeguards are available on request.
12.4 For customers in Australia, we take such steps as are reasonable in the circumstances to ensure that overseas recipients do not breach the Australian Privacy Principles, as required by Australian Privacy Principle 8.
#13. Marketing communications
13.1 Service communications. Communications relating to provisioning, billing, renewals, service availability, security and changes to our terms form part of the Services. You cannot opt out of these while you hold an account.
13.2 Marketing communications. We send marketing communications about our products, services and offers to existing customers unless they opt out. Every marketing communication contains an unsubscribe facility, and we act on unsubscribe requests promptly.
13.3 We send marketing communications to individuals who are not customers only where they have consented.
#14. Your rights
14.1 Subject to applicable law, you may request that we:
- (a) provide access to the personal information we hold about you;
- (b) correct personal information that is inaccurate, out of date or incomplete;
- (c) delete personal information;
- (d) provide personal information in a portable format;
- (e) restrict how we use personal information while a dispute is resolved;
- (f) cease using personal information for a particular purpose; or
- (g) give effect to the withdrawal of a consent previously given.
14.2 Direct marketing. Where you object to the use of your personal information for direct marketing, we will cease that use. This right is not subject to any balancing of interests.
14.3 How to make a request. Requests should be sent to privacy@shockbyte.com. We respond within 30 days. Where a request is complex or we have received a number of requests from you, we may extend that period by up to two months and will notify you of the extension and the reasons for it within the first 30 days. We do not charge a fee, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act.
14.4 We may require verification of your identity before acting on a request. We will not require identity verification as a condition of giving effect to an opt-out of marketing or of the sale or sharing of personal information.
14.5 Rights vary by jurisdiction and by the basis on which we hold the information. Additional rights are set out in the annexes.
#15. Legal and regulatory disclosure
We disclose personal information to law enforcement, regulators and government agencies where we are required or authorised to do so by law, by a court or tribunal order, or where we reasonably believe disclosure is necessary to lessen or prevent a serious threat to the life, health or safety of any individual.
#16. Security
16.1 We maintain administrative, technical and physical safeguards designed to protect personal information against unauthorised access, use, disclosure, alteration and loss.
16.2 No method of transmission or storage is completely secure. While we take reasonable steps to protect personal information, we cannot guarantee absolute security.
16.3 You are responsible for maintaining the confidentiality of your account credentials and for enabling the security features we make available, including multi-factor authentication.
16.4 Data breaches. Where a data breach occurs that is likely to result in serious harm, or in a risk to the rights and freedoms of individuals, we will assess it promptly and notify affected individuals and the relevant regulators as required by law. Where the GDPR or UK GDPR applies, we notify the relevant supervisory authority within 72 hours of becoming aware of a notifiable breach. In Australia we comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).
#17. Children and young people
17.1 The Services are not directed to children. You must be at least 13 years of age to hold a Shockbyte account. If you are under 18, you must have the permission of a parent or guardian.
17.2 We do not request or collect date of birth or age. Instead, we apply the following protections to all users of the Services:
- (a) we do not use deceptive design or pressure techniques in our purchase or upgrade flows;
- (b) we explain our privacy practices in plain language; and
- (c) we do not knowingly direct behavioural advertising to any individual we believe to be under 18 years of age.
17.3 Individuals who connect to servers we host may include children. We do not have a direct relationship with those individuals. The customer operating the relevant server is responsible for their personal information, as set out in clause 3.4.
17.4 If you are a parent or guardian and believe we hold personal information concerning your child, contact privacy@shockbyte.com. We will investigate and take appropriate action, which may include deleting the information.
#18. Cookies and similar technologies
18.1 We use cookies and similar technologies, including local storage, tracking pixels and software development kits. The categories we use are set out below.
18.2 Strictly necessary — no consent required. These are needed to provide the Services and cannot be turned off. They keep you signed in, secure your account and protect against fraudulent sign-ups, balance network load, preserve your cart during checkout, and record your cookie preferences.
18.3 All other categories — consent required. These operate only where you agree, and you can change your mind at any time using the cookie preferences link on our websites.
| Category | What it does |
|---|---|
| Analytics | Measures how our websites and Services are used, so we can improve them |
| Session recording | Records mouse movement, clicks and scrolling, so we can find usability problems |
| Testing | Compares different versions of our pages |
| Advertising | Measures our advertising and shows you relevant advertising |
| Referral tracking | Attributes a purchase to the affiliate who referred you, for up to 3 months |
The specific technologies in each category, and who provides them, are listed in our cookie preferences tool.
18.4 We do not require you to accept optional cookies in order to use our websites.
18.5 Advertising. We share limited personal information with advertising partners, including Google, Meta and Reddit, so that we can measure the effectiveness of our advertising and show you advertising relevant to you. This takes place only where you have consented. You can withdraw consent at any time using the cookie preferences link on our websites, and we recognise and honour the Global Privacy Control. See Annex D for how this is treated under United States state privacy laws.
#19. Third-party services
19.1 Our websites and the Services may contain links to, or integrations with, websites and services operated by third parties, including game publishers, plugin repositories, payment providers and community platforms. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review their privacy policies.
19.2 Where you install or enable third-party software, plugins or modifications on your server, that software may collect personal information. We do not control that software and are not responsible for it. You are responsible for the software you install and for any personal information it collects.
#20. Complaints
20.1 If you have a concern about how we handle personal information, contact privacy@shockbyte.com. We will respond as soon as reasonably practicable.
20.2 If you are not satisfied with our response, you may complain to the privacy regulator in your jurisdiction. Details are set out in the annexes.
#21. Changes to this Policy
21.1 We may amend this Policy from time to time.
21.2 Amendments take effect when published on this page. Where an amendment is material, we will also take reasonable steps to notify you, such as by email or through your account.
#22. General
22.1 Severability. If any provision of this Policy is held to be invalid or unenforceable, that provision is severed and the remainder continues in effect.
22.2 Language. This Policy is published in English. Where we provide a translation and there is an inconsistency, the English version prevails, except where applicable law provides otherwise.
22.3 Governing law. This Policy is governed by the laws of Victoria, Australia. Nothing in this clause limits any right you have under the privacy or consumer laws of your own jurisdiction, and nothing in this Policy excludes, restricts or modifies any guarantee, right or remedy conferred by the Australian Consumer Law or any other law that cannot lawfully be excluded.
Annexes
#Annex A — Australia
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Access and correction. Requests under Australian Privacy Principles 12 and 13 should be sent to privacy@shockbyte.com. We respond within 30 days and do not charge a fee. Where we refuse access or correction we will provide written reasons and information about how to complain.
Complaints. If you are not satisfied with our response to a complaint, you may complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, GPO Box 5218, Sydney NSW 2001.
#Annex B — European Economic Area
Your rights under Articles 15 to 22 of the GDPR are set out in clause 14. The legal bases on which we rely are set out in clause 7.
Our presence in the European Union. Some of our personnel are employed through Shockbyte B.V., a company in the Shockbyte group established in the Netherlands. Shockbyte Pty Ltd remains the entity responsible for your personal information and the entity you contract with, as set out in clause 2.1. Privacy enquiries may be directed to privacy@shockbyte.com.
Complaints. You may lodge a complaint with the supervisory authority in your Member State of residence, place of work, or the place of the alleged infringement. A list is published at edpb.europa.eu. You may also bring proceedings in the courts of your Member State.
#Annex C — United Kingdom
Your rights under the UK GDPR are set out in clause 14, as modified by the Data (Use and Access) Act 2025.
Right to complain to us. Under section 164A of the Data Protection Act 2018 you have a right to complain to us directly about our processing of your personal data. Complaints may be sent to privacy@shockbyte.com. We will acknowledge your complaint within 30 days and inform you of the outcome.
Information Commissioner's Office. If you remain dissatisfied you may complain to the ICO: ico.org.uk, 0303 123 1113.
Our presence in the United Kingdom. Some of our personnel are employed through Shockbyte Limited, a company in the Shockbyte group established in the United Kingdom. Shockbyte Pty Ltd remains the entity responsible for your personal information and the entity you contract with, as set out in clause 2.1. Privacy enquiries may be directed to privacy@shockbyte.com.
#Annex D — United States
Categories of personal information collected. Identifiers; commercial information; internet and other electronic network activity information; approximate geolocation derived from IP address; and, classified as sensitive personal information under the California Consumer Privacy Act, account log-in credentials and — in the limited circumstances described in clause 5.8 — government identification numbers.
Sensitive personal information. We collect account credentials, and in rare cases a government identification number in order to verify identity. We use these only to perform the Services reasonably expected by you, to maintain the security and integrity of accounts, to detect and resist fraudulent or illegal activity, and to ensure the safety of individuals. We do not use or disclose sensitive personal information for the purpose of inferring characteristics about you. Accordingly, the right to limit the use of sensitive personal information does not apply.
Sale and sharing. We share identifiers, internet and other electronic network activity information, and commercial information with advertising networks and analytics providers, including Google, Meta and Reddit, for cross-context behavioural advertising. We do not sell personal information in exchange for monetary consideration. We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.
You may opt out using the cookie preferences link on our websites, or by enabling the Global Privacy Control in your browser, which we recognise and honour. We do not require you to verify your identity in order to act on an opt-out.
Your rights. Residents of California and other states with comprehensive privacy laws may request to know, delete and correct personal information, opt out of its sale or sharing, and are protected against discrimination for exercising those rights. Requests may be sent to privacy@shockbyte.com.
Appeals. Residents of Virginia, Colorado, Connecticut and other states providing a right of appeal may appeal a refused request by writing to privacy@shockbyte.com. We will respond in writing within 45 days.
Retention. How long we keep personal information, and the criteria we apply, are set out in clause 10.
#Annex E — Other regions
Canada. We comply with the Personal Information Protection and Electronic Documents Act. Personal information may be processed outside Canada and may be accessible to law enforcement and national security authorities of those countries. Residents of Quebec also have rights of portability and to be informed of decisions based exclusively on automated processing. Complaints: Office of the Privacy Commissioner of Canada at priv.gc.ca, or in Quebec the Commission d'accès à l'information at cai.gouv.qc.ca.
Brazil. We comply with the Lei Geral de Proteção de Dados. We respond to requests for confirmation of processing and access immediately in simplified form, or within 15 days by way of a complete declaration. Complaints: Autoridade Nacional de Proteção de Dados at gov.br/anpd.
Singapore. We comply with the Personal Data Protection Act 2012. Our Data Protection Officer can be contacted at privacy@shockbyte.com. Complaints: Personal Data Protection Commission at pdpc.gov.sg.
New Zealand. We comply with the Privacy Act 2020. Complaints: Office of the Privacy Commissioner at privacy.org.nz.