Privacy
Privacy policy
Thirty-two clauses. Each opens with the rule it rests on, then sets out what follows from it. Clause 3 is the short answer to what is held right now; clauses 4 to 22 are the standing limits binding any puzzle title published under this company name.
Issue 2.0In force from 12 August 2026Privacy Act 1988 (Cth)
1The entity, and what this policy reaches
Rule. A privacy policy is worth reading only if it names the company answerable under it and marks the edge of what it covers.
1.1 AXIOM INTERACTIVE PTY LTD holds ACN 700 712 465 and ABN 77 700 712 465. Its form is that of a proprietary company whose liability is limited by shares, and its registration sits in New South Wales, Australia. It designs logic puzzles for mobile devices. Throughout what follows, the studio, we and us refer to that company alone.
1.2 This policy reaches three things: the website at axiominteractive.link, email sent to the address in clause 32.1, and any puzzle title published under the company name on any application store.
1.3 It does not reach Apple or Google, each of which collects information from you on its own account and under its own policy when you use a store or a device. Clause 15.4 explains why that distinction matters to what we can promise.
1.4 Nor does it reach an advertising network acting for itself, a case clause 12 takes separately, or any site you land on by following a link out of ours.
1.5 Personal information takes its meaning from section 6(1) of the Privacy Act 1988 (Cth). That definition reaches opinions as well as facts, about a person named outright or one who can be worked out from what is held, and it bites whether or not the content turns out to be accurate and whether or not anyone ever wrote it down.
2The statute this document answers to
Rule. A policy should name the law it is written against, so that a reader can check the policy against the law rather than against our tone.
2.1 The governing statute is the Privacy Act 1988 (Cth). The operative obligations sit in the thirteen Australian Privacy Principles in Schedule 1 to that Act, abbreviated in this document as APP 1 through APP 13.
2.2 APP 1 requires an entity to handle personal information openly and transparently, to keep practices and systems that deliver compliance, and to publish a current policy that costs nothing to read. This page is the discharge of that obligation.
2.3 APP 1.4 lists what such a policy must state: the kinds of information collected and held, how and why they are collected, held, used and disclosed, how an individual obtains access and correction, how to complain and what happens next, and whether information goes to recipients overseas and to which countries. Each of those has its own numbered clause below rather than a sentence hidden in a paragraph, because a policy that technically contains an answer while making it unfindable has not been clearly expressed.
2.4 Australian Consumer Law obligations about misleading conduct apply to this page as they apply to any other statement we publish. A privacy policy that overstated our restraint would be a contravention as well as a lie.
3Everything held at today's date
Rule. The current holding is a small, checkable fact, and it should be stated before anything hypothetical.
3.1 The studio holds no player data. There is no account, no save file on any server of ours, and no gameplay record of any kind in our possession.
3.2 The complete set of personal information held by the studio today is correspondence: the messages people send to the studio address, whatever those messages contain, the sending address, and the dates involved.
3.3 The website collects nothing. It writes nothing to your device, runs no measurement script, and operates no form. The cookie notice records that in detail and explains how to disprove it from your own browser.
3.4 Our hosting provider generates request logs, as any host does, containing IP addresses and requested paths. They are not mined for analytics, not turned into profiles, and not exported anywhere. They are consulted only where a security incident is suspected, and the provider deletes them on its own schedule.
What clauses 4 to 22 do. They fix in public the limits that bind any title published under the company name, from the first install rather than from the first complaint. Writing them here puts them where a reader can argue with them and where a departure from one is visible as a departure. The rights in clauses 23 to 25 and 29 are not aspirational, and apply today to the correspondence described in clause 3.2.
4What a published title collects
Rule. The list should be published in a form the build can be checked against.
4.1 Progress held on your device. Which boards you finished, your position in the sequence, and your display preferences. This lives in the private storage the operating system gives an application. It is not sent to us and forms no part of anything we hold.
4.2 Purchase records. The business model is advertising between puzzles with a single purchase that removes it. Where you make that purchase, the store operator processes the payment and tells us that an entitlement exists. We receive a transaction identifier and the fact of the purchase. We do not receive your card number, your bank details, or your billing address, and there is no arrangement under which we could.
4.3 Crash and defect reports. A crash may generate a report. Such a report carries the model of the handset, which release of the operating system it runs, and where the program was when it stopped. Where such a report is turned on, clause 7.2 requires it to be disclosed in the store listing and in this policy before the build ships, and clause 22 requires the same disclosure on Google Play.
4.4 Correspondence. As described in clause 3.2, unchanged by the existence of a title.
4.5 Advertising identifiers. Handled entirely by clause 12, which is where the difficult part of this document is.
4.6 An account is not required to play. Where a title offers one, in order to carry progress between devices, it is optional, the email address is the only identifier requested, and clause 31.2 governs how this policy is updated to say so.
5Collection the six axioms rule out
Rule. A design rule that forbids a mechanic also forbids the data that mechanic would need, and the second consequence is worth stating explicitly.
5.1 Axiom 5 forbids a hint you did not ask for. A hint offered because you have been still for a while requires the program to time how long you have been still. Nothing in a title of ours measures idle time, stores it, or transmits it, because there is no feature left that would read it.
5.2 Axiom 6 forbids progress that decays and streaks that expire. Both need the program to record when you last played and to compare that against the clock. Progression state in our builds carries no timestamps for that purpose, so the record does not exist to be collected, analysed or sold.
5.3 Axiom 4 makes undo unlimited and free. A paid or rationed undo needs a per-player counter reported somewhere it can be monetised. There is no counter.
5.4 Axioms 1 and 2 are enforced before a board reaches you, by a solver running against the generated puzzle during the build. That check runs on our machines against boards, not against people, and produces no personal information at all.
5.5 The studio does not collect gameplay telemetry. Should that ever change, for a purpose such as tuning difficulty, clause 7.2 requires the collection to be described here and in the store listing before the build that performs it is released, and clause 31.2 requires the version number of this document to move.
5.6 Clause 5 is offered as an explanation of why the collection lists in clause 4 are short. It is not a substitute for those lists, and where clause 5 and clause 4 appear to conflict, clause 4 states what is collected.
6Necessity, and the limit on asking (APP 3)
Rule. Information not needed for a function of the business must not be requested, however useful it might one day prove.
6.1 APP 3 makes necessity the gate. An organisation may take personal information where doing so is reasonably necessary to some function or activity it genuinely carries on, and where that test fails it may not take the information at all. The functions of this company are designing puzzle games, publishing them, and answering correspondence about them.
6.2 Collection is by lawful and fair means, and directly from you wherever that is practicable. The only routine exception is clause 4.2, where the store operator is the source of the purchase record because it, and not we, processed your payment.
6.3 We do not buy personal information, do not obtain it from data brokers, and do not enrich what we hold from outside sources.
6.4 Where a purpose could be served without personal information, APP 3 requires us to serve it that way, and the outcome of applying that test is the list in clause 4 rather than a longer one.
7Notice at the moment of collection (APP 5)
Rule. Notice given after collection is not notice; it is an apology.
7.1 APP 5 fixes a moment, being the point of collection, anything earlier, or the earliest practicable point after it. By that moment you are entitled to know who took the information and how they can be reached, what it was taken for, who else stands to see it, that this document deals with access, correction and complaints, and whether the information is headed out of the country.
7.2 The studio's practice is stricter than APP 5 requires in one respect: a category of collection is published here, and in the store listing where a title is involved, before the build performing it is released. This is the commitment relied on by clauses 4.3, 5.5, 12.4 and 20.3.
7.3 The matters listed in clause 7.1 are covered as follows: the collector by clause 1.1, the contact point by clause 32.1, the purposes by clauses 4 and 11, the recipients by clause 14, access and correction by clauses 24 and 25, complaints by clause 29, and overseas disclosure by clause 15.
8Dealing with us without a name (APP 2)
Rule. Where a transaction does not need to know who you are, it must not insist on finding out.
8.1 APP 2 lets you keep your name to yourself, or offer one that is not yours, in your dealings with an organisation. Only two things defeat that entitlement: a statute demanding that you be identified, and genuine impracticability. A preference on our side for knowing who we are talking to is neither.
8.2 The website can be read without identifying yourself. There is no login, no wall and no form.
8.3 Correspondence may be sent from a pseudonymous address. An argument about an axiom, a defect report, and a security report are all assessable without knowing your legal name, and we will not ask for it.
8.4 Identification becomes practically necessary in one situation only: a request under clause 24 or clause 25 about information keyed to a particular address or account. Handing someone else's correspondence to the wrong person is the harm APP 2 is not asking us to risk, and clause 24.4 sets out the smallest check that resolves it.
9Information arriving unrequested (APP 4)
Rule. Information we did not ask for does not become ours merely because it arrived.
9.1 APP 4 applies where an organisation receives personal information it did not solicit. It must decide whether it could lawfully have collected the information under APP 3, and if not, destroy or de-identify it where lawful and reasonable to do so.
9.2 In practice this arises when a message contains far more than the matter required, for example a full medical history attached to a note about a puzzle.
9.3 Where the surplus can be separated from the message, it is deleted and the deletion is noted in the thread. Where it cannot be separated without destroying a record we are required to keep, the message is retained under clause 19 and used only for the matter it was sent about.
10Sensitive information
Rule. The categories the Act treats as sensitive have no function in a puzzle game, so none is requested.
10.1 Sensitive information under section 6(1) of the Privacy Act includes health information and information about racial or ethnic origin, political opinions, religious beliefs, sexual orientation and criminal record. APP 3.3 generally requires consent before it may be collected.
10.2 The studio does not request sensitive information, has no field in which to record it, and no feature that would use it.
10.3 If you volunteer sensitive information in a message, clause 9 governs what happens to it.
11Use and disclosure (APP 6)
Rule. Information collected for one purpose is used for that purpose, and a second purpose needs its own justification.
11.1 APP 6 lets information do the job it was gathered to do. Putting it to some further job needs one of three warrants: your consent, or an expectation you would reasonably have held together with a real connection between the further job and the original one, or an exception the Act itself spells out.
11.2 The primary purposes are: answering your message, honouring a purchase, diagnosing a defect, meeting an obligation imposed by law, and dealing with a complaint or a legal claim.
11.3 The studio does not sell personal information. There is no arrangement, present or contemplated, under which correspondence or purchase records are transferred to another party for that party's own commercial use.
11.4 A defect report may be quoted internally and in a public changelog. Where it is quoted publicly, identifying details are removed unless you have asked to be credited under clause 9.2 of the terms of use.
11.5 Disclosure is made where the law compels it, including under a warrant, a subpoena, a notice to produce, or a request from an enforcement body acting under a power the Act recognises. We satisfy ourselves that the instrument is valid and disclose no more than it requires. Where we are permitted to tell you, we do.
12Advertising between puzzles
Rule. The part of the model that is hardest to reconcile with the rest of this document is the part that must be described most precisely.
12.1 The model is an advertisement between puzzles, with one purchase that removes advertising permanently. The axioms forbid paid undo, paid hints, lives, energy, loot boxes and expiring streaks, so this is what remains, and it is the whole of the model.
12.2 An advertisement inside a mobile application is served by an advertising network, not by us. What such a network customarily takes is the advertising identifier held by the handset, an approximate location inferred from the network address, the handset model, which release of the operating system is installed, and the bare fact that an advertisement was asked for and displayed. It writes identifiers into device storage on its own account.
12.3 That collection is the network's, made for the network's purposes. What we can tell you is what we asked it to do and what its own policy says. What we cannot do is inspect its systems, and claiming otherwise would be worthless.
12.4 No advertising network is integrated, and none is named here, because naming one before the choice is made would be a guess. This clause is replaced with the network's identity, a link to its policy, what it receives, the retention it applies, and what the purchase in clause 12.1 actually switches off. Clause 7.2 requires that replacement to be published with the build carrying advertising rather than after it.
12.5 The studio's position, recorded now while it costs something to record, is that advertising will be requested in the mode that does not use a profile built from your behaviour, and that a title will not condition access to content on watching one. Axiom 4 already forbids the usual arrangement, in which an advertisement is the price of continuing.
12.6 Clause 21 sets out what Apple's App Tracking Transparency framework requires before any of this may involve tracking on an Apple device, and clause 21.3 states what the studio asks for.
13Marketing, and the Spam Act (APP 7)
Rule. Writing to us is not a subscription, and nothing here converts one into the other.
13.1 APP 7 restricts the use of personal information for direct marketing. The Spam Act 2003 (Cth) separately requires consent, accurate sender identification and a working unsubscribe facility for commercial electronic messages.
13.2 The studio operates no mailing list. Sending a message to the address in clause 32.1 adds you to nothing, and produces a reply about the matter you raised and nothing else.
13.3 Were such a list ever to exist, getting onto it would take a deliberate act on your part. Every message would carry the sender identified in clause 1.1, and leaving would cost one step and bite immediately.
13.4 You may tell us at any time not to use your information for marketing, and the request takes effect on receipt. Under clause 13.2 there is presently nothing for such a request to stop.
14Categories of recipient
Rule. Naming categories of recipient is only useful if the categories are narrow enough to exclude something.
14.1 Email and hosting providers. The provider carrying the studio mailbox necessarily holds correspondence. The provider serving these pages handles requests for them. Both act on our instructions.
14.2 Application store operators. Apple and Google, in respect of a published title, for distribution, payment and entitlement. Each also collects from you directly under clause 1.3.
14.3 An advertising network, once one exists, on the terms in clause 12.
14.4 Professional advisers, being an accountant or a lawyer, where a matter genuinely requires it, each bound by professional obligations of confidence.
14.5 A regulator, court or enforcement body, on the basis set out in clause 11.5.
14.6 There is no category outside clauses 14.1 to 14.5. No measurement vendor sits behind these pages. Neither does a marketing suite, a profile warehouse, an exchange buying inventory on our behalf, or a broker of any description.
15Disclosure to overseas recipients (APP 8)
Rule. Sending information abroad does not send the obligation abroad with it.
15.1 APP 8.1 puts a condition on sending anything abroad. Before the transfer, the sender has to take reasonable steps to satisfy itself that whoever receives the information will treat it consistently with the Australian Privacy Principles. Those steps belong ahead of the transfer, not behind a problem.
15.2 Section 16C of the Privacy Act reinforces that: where an overseas recipient handles the information in a way that would breach the Australian Privacy Principles, the disclosing organisation is taken to have breached them itself. The obligation is therefore not delegable, and clause 15.2 is why the studio treats the choice of provider as a privacy decision rather than a procurement one.
15.3 Correspondence is likely to be stored or processed on infrastructure located in Australia, the United States of America, or a member state of the European Union, depending on where the mail and hosting providers operate their facilities. Where the studio can select an Australian region for a service, it does.
15.4 Where a title is distributed by Apple or Google, those companies operate globally and handle information under their own arrangements. That handling is their collection, not a disclosure by us, and clause 1.3 marks the boundary.
15.5 The reasonable steps taken are: choosing providers that publish binding commitments about handling personal information, preferring Australian storage where it is offered, keeping the volume disclosed to the minimum the service requires, and declining services that will not say where information is held.
15.6 Before any overseas recipient outside clauses 15.3 and 15.4 receives personal information, this clause will name the country, and clause 31.2 applies to that change.
16Government related identifiers (APP 9)
Rule. An identifier issued by government belongs to the relationship between you and government.
16.1 A number an agency issued to you may not be taken over by a private company and pressed into service as that company's own handle for you. APP 9 forbids the adoption outright and puts tight limits on using or passing on such a number even where nobody adopted it.
16.2 Nothing issued by an agency is collected here. The tax file number is not, nor the Medicare card, nor the driver licence, nor the passport, nor anything else of that character. No step in any process this document describes asks for one.
16.3 No verification step in any process described in this document, including the identity check in clause 24.4, requires a government issued document.
17Quality of what we hold (APP 10)
Rule. A record that is wrong is a liability to the person it describes before it is an inconvenience to us.
17.1 APP 10 sets two bars rather than one. What comes in has to be right, current and whole. What then goes out, whether used internally or handed to somebody else, has to clear that same bar and additionally has to bear on the purpose it is being put to. The second bar is the higher of the two, and it is the one that governs when a record leaves our hands.
17.2 Because almost everything held is correspondence, accuracy mostly means keeping a thread intact and not summarising a message into something it did not say.
17.3 Where you tell us a record is wrong, clause 25 applies and the correction is made rather than argued about, unless we genuinely disagree, in which case clause 25.4 governs.
18Security, and destruction (APP 11)
Rule. The most reliable protection is not holding the information, and the measures matter for whatever survives that test.
18.1 APP 11.1 imposes a duty of reasonable steps against six fates: misuse, interference, loss, and access, alteration or disclosure by anyone lacking authority for it. APP 11.2 then imposes an ending. Once a record serves no purpose the Act allows and no statute compels anyone to keep it, the record must be destroyed or stripped of the identity attached to it.
18.2 The measures actually in place: multi-factor authentication on the mail account and the domain registrar; access limited to the people running the company; encryption in transit for the website through HTTPS and for mail in the usual way; a response header policy that prevents third-party scripts from executing on these pages; and no database of players, which follows from clause 3.1.
18.3 No set of measures makes a breach impossible. Clause 28 sets out what happens when one occurs, which is the more useful commitment.
18.4 Destruction under APP 11.2 is performed on the schedule in clause 19, and is not deferred on the basis that storage is inexpensive.
19Retention periods
Rule. A retention period stated as "as long as necessary" is not a period, and gives the reader nothing to hold us to.
19.1 The periods below run from the date shown in the third column, and destruction follows within thirty days of the period ending.
| Record | Kept for | Counted from | Why that period |
|---|---|---|---|
| General correspondence | 24 months | Last message in the thread | Long enough to recognise a returning correspondent, short enough that an inbox does not become an archive |
| Defect and axiom reports | While the affected title is supported, then 24 months | End of support | A report is evidence about a build, and stops being useful when the build does |
| Privacy requests under clauses 23 to 25 | 7 years | Closure of the request | Proof that a request was answered, for the period a complaint may still be examined |
| Privacy complaints and their outcomes | 7 years | Closure of the complaint | The OAIC may examine a matter well after we consider it finished |
| Security reports and incident records | 7 years | Closure of the incident | Records required by clause 28.5 for the notification scheme |
| Purchase and financial records | 7 years | End of the transaction | Section 286 of the Corporations Act 2001 (Cth) |
| Account and save data, if accounts ever exist | Until deletion is requested | Request under clause 23 | Deleted within 30 days, per clause 23.3 |
| Hosting request logs | The provider's own period | The request | Held by the provider under clause 3.4, not exported to us |
19.2 A record subject to a legal hold, because it is relevant to a claim, an investigation or a proceeding on foot, is retained until the hold is lifted, and then destroyed under clause 19.1.
19.3 Where a record cannot lawfully be destroyed but is no longer needed, it is de-identified so that it no longer relates to an identifiable person, which is the alternative APP 11.2 permits.
20Device permissions a title would request
Rule. A permission prompt is a request for something you own, and the number of prompts should be as close to zero as the product allows.
20.1 A logic puzzle needs a screen and a touch input. It does not need your contacts, your camera, your microphone, your photo library, your precise location, your calendar, or the list of other applications installed on the device.
20.2 The permission set is empty, with one conditional exception: a notification permission, requested only where a title offers something worth notifying you about, refusable without any loss of content, and never used to bring you back to a game you had put down.
20.3 If a build ever requires a permission not listed in clause 20.2, clause 7.2 requires the requirement and its reason to be published here first.
21App Tracking Transparency on Apple devices
Rule. Where a platform gives you a switch, our job is to explain honestly what the switch does, not to argue you out of using it.
21.1 Apple's App Tracking Transparency framework requires an application to obtain your permission through a system prompt before it may access the identifier for advertisers, or otherwise link information about you with data from other companies' applications and websites for advertising or measurement purposes.
21.2 No App Tracking Transparency prompt has been shown by us to date. Clause 21 states the position that will apply when a title ships.
21.3 The studio's position is that a title carrying its name ships without tracking as App Tracking Transparency defines it, and therefore without the prompt. Advertising under clause 12.5 is requested in the mode that does not require the identifier for advertisers.
21.4 If that intention is abandoned, the prompt will be shown before any tracking begins, refusing it will cost you no content and no feature, and this clause will be rewritten to say what changed and why. It will not be shown twice after a refusal, and it will not be preceded by a screen designed to talk you into it.
21.5 The privacy labels shown on the App Store listing for any title will match clauses 4, 12 and 20. Where a label and this policy disagree, one of the two is wrong, and clause 32.1 is the address for telling us so.
22The Data Safety declaration on Google Play
Rule. A declaration made to a store is a statement to the public, and it must be capable of being read alongside this document without contradiction.
22.1 Google Play requires a Data Safety section stating what an application collects and shares, whether the transfer is encrypted, whether collection is optional, and whether a user can request deletion.
22.2 On the basis of clauses 4, 5 and 20, the declaration for a title shipping without advertising would record no data collected and no data shared, with device storage of progress under clause 4.1 remaining on the device and outside the definition of collection.
22.3 A title shipping with advertising must declare what the network in clause 12.4 collects and shares, including the advertising identifier and approximate location, and the declaration will name it before release.
22.4 Purchase records under clause 4.2 are declared as financial information collected for app functionality, transmitted over an encrypted connection.
22.5 The declaration will state that deletion may be requested, with clause 23 as the route, and Google Play's own account deletion requirements will be met through that clause.
23Erasure, and how to delete your account
Rule. Deletion should take one message and no negotiation.
23.1 To have what we hold erased, write to the address in clause 32.1 with the subject line Delete my data. No form, no telephone call and no reason are required.
23.2 Today, under clause 3.2, that means correspondence. The thread you name, and any other thread from the same address, is destroyed.
23.3 Where accounts exist, the same message will delete your account and the data attached to it, and the deletion is completed within thirty days. Progress held on your device under clause 4.1 is removed by uninstalling the application, which we cannot do for you.
23.4 Two things survive a deletion request, and both are stated here rather than discovered later. Records that section 286 of the Corporations Act 2001 (Cth) requires to be kept, being purchase and financial records, are retained for the period in clause 19. The record of the deletion request itself is retained under clause 19, because a company that deletes the evidence that it honoured a deletion request cannot prove that it did.
23.5 Confirmation is sent when the deletion is done, and it states what was destroyed and what was retained under clause 23.4.
23.6 Deletion is free. There is no charge for a first request, a second, or a later one.
24Access to what we hold (APP 12)
Rule. Access and correction are the rights that let you check every other statement in this document, so they are answered without friction.
24.1 APP 12 entitles you, on request, to access the personal information an organisation holds about you.
24.2 Write to the address in clause 32.1 with the subject line Privacy request. A response is provided within thirty days, and that period includes any verification under clause 24.4 rather than beginning after it.
24.3 Information is supplied in a readable electronic form. Given clause 3.2, this is ordinarily a copy of the correspondence itself.
24.4 Verification is the smallest step that resolves the question, which for correspondence means replying from the address the messages were sent from. Where that is impossible, we will agree another method with you and will not demand a government issued document, consistently with clause 16.3.
24.5 Asking costs nothing and receiving what you asked for costs nothing. APP 12.8 permits a charge that is not excessive; the studio does not levy one.
24.6 Refusal is available on the grounds APP 12.3 lists and on no others. The two that could conceivably arise here are a disproportionate intrusion into somebody else's privacy, and a request made to harass rather than to find anything out. Any refusal arrives in writing, identifies which ground it rests on, works through the reasoning, and points you at the escalation described in clause 29.
25Correction of what we hold (APP 13)
Rule. Correcting a record costs less than defending an inaccurate one.
25.1 APP 13 compels correction where what is held has gone wrong, gone stale, stops short, misses the point or tends to mislead. The duty bites both when you ask for it and when we notice the defect ourselves.
25.2 Write to the address in clause 32.1 with the subject line Privacy request, stating what is wrong and what it should say instead. A response is provided within thirty days.
25.3 Where information we corrected has already been disclosed to a recipient in clause 14, you can require that recipient to be told, and they will be told unless doing so would be unlawful or cannot practically be managed.
25.4 Should we decline, APP 13.4 lets you insist that your own account be fastened to the record, positioned so that whoever reads the record afterwards cannot miss it. That statement is attached at no charge, and the refusal is written and explains its ground.
26Children and young people
Rule. Logic puzzles attract children, so the clause about children has to be written as though children are the ordinary case rather than an edge case.
26.1 Puzzle games are played by people of every age, and a studio that pretended otherwise would be arranging not to notice. The design position taken here is therefore that a title should be safe for a child to play without any privacy decision having been made on the child's behalf.
26.2 Australian privacy law does not fix an age of capacity for privacy purposes. The OAIC's guidance is that an individual under 18 may give consent where they have the capacity to understand what is being asked, assessed case by case, and that an entity unable to make that assessment may presume capacity from the age of 15. The studio adopts that guidance and applies it to any request under clauses 23, 24 and 25.
26.3 A request from a young person is answered on its merits, and is not refused for the reason that it came from a young person. Where capacity is genuinely doubtful and the request would delete or disclose something significant, we will say what we need in order to proceed and will not simply stop replying.
26.4 A parent, guardian or carer may make a request on behalf of a child. We ask only for enough to establish the relationship and the child's connection to the record, and clause 24.4 applies to the extent it can.
26.5 The structural protection is more valuable than the procedural one. Under clause 4.1 progress stays on the device; under clause 4.6 no account is needed to play; under clause 5 there is no idle timing, no streak and no decay; under clause 20.2 the permission set is empty. A child playing a title of ours is therefore not creating a profile with us, because there is nothing collected from which to build one.
26.6 The mechanics the axioms forbid are, in large part, the mechanics that work on children specifically: the expiring streak, the resource that refills on a timer, the paid continue at the moment of frustration, and the randomised paid reward. Axioms 3, 4 and 6 remove all four, and clause 12.5 records that access to content will not be conditioned on watching an advertisement.
26.7 Where a title is rated for children on a store, the additional obligations that rating carries are met, including the restrictions such programs place on advertising and on the collection of data from child users. Any title in that category is declared under clause 22 accordingly, and clause 12.4 is settled for it on the footing clause 7.2 requires.
26.8 We do not knowingly hold personal information about a child beyond correspondence. If a message tells us that we hold something about a child that should not be held, it is deleted under clause 23 without waiting for the thirty day period in clause 23.3 to run.
27Decisions taken by a program
Rule. A program that decides something about a person should be disclosed even when the decision seems harmless.
27.1 No decision producing a legal or similarly significant effect on any individual is taken by automated means, and no profiling is performed.
27.2 The one automated process the studio runs is the solver described in clause 5.4, which decides whether a generated puzzle is acceptable. It evaluates boards. It has no input describing a person and produces no output about one.
27.3 Should automated decision-making about individuals ever be introduced, clause 7.2 requires it to be described here first, together with how a human review may be requested.
28The Notifiable Data Breaches scheme
Rule. The commitment that matters is not that a breach will never happen; it is what is done in the days after one does.
28.1 Part IIIC of the Privacy Act 1988 (Cth) establishes the Notifiable Data Breaches scheme. A breach becomes an eligible one when three limbs hold at once. The first is that personal information was reached or handed out without authority, or went missing. The second is that the objective observer the Act posits would judge serious harm to somebody the information describes to be a likely consequence. The third is that nothing still open to us would head that harm off. Knock out any limb and the duty to notify does not arise; leave all three standing and it does.
28.2 Suspicion alone engages section 26WH: an assessment has to get moving quickly and to finish inside thirty days at the very outside. The studio treats thirty days as the outer limit rather than the target, and the first day is spent stopping the loss rather than characterising it.
28.3 If the assessment lands on yes, two duties follow without delay. A statement goes to the Australian Information Commissioner, and everyone facing a real prospect of serious harm is told directly. The statement identifies the company, describes the breach, states the kinds of information involved, and sets out what those individuals should do in response.
28.4 Any notice reaching you will be in plain words. It will cover the event, its date, the categories of information caught up in it, the steps already taken at our end, the steps worth taking at yours, and the address to reply to. It will not be written to minimise the event, and it will not be timed to arrive when it is least likely to be read.
28.5 A record of every suspected breach is kept under clause 19, including those assessed as not eligible, together with the reasoning. A decision not to notify is a decision that should be reviewable afterwards.
28.6 Where a breach occurs at a provider in clause 14 rather than at the studio, our obligations under clause 28 are unchanged, which follows from clause 15.2.
28.7 If you believe personal information held by us has been exposed, write with the subject line Security to the address in clause 32.1. A reply is sent the same or the next business day.
29Complaints, and the route past us
Rule. The regulator's details belong in the same clause as our own, at the same size, without a paragraph asking you to reconsider.
29.1 To complain about how the studio has handled personal information, write to the address in clause 32.1 with the subject line Privacy complaint. Set out the conduct you object to and the remedy you are asking for.
29.2 Receipt is confirmed within five business days and the complaint is answered in writing within thirty. The answer states what we found, what we accept, what we do not accept and why, and what has been changed as a result.
29.3 You are not obliged to complain to us first, and clause 29.1 does not condition anything. You may go directly to the regulator at any point.
Office of the Australian Information Commissioner
GPO Box 5218, Sydney NSW 2001
Telephone 1300 363 992
oaic.gov.au
29.4 The Commissioner may investigate an act or practice that may interfere with the privacy of an individual, may accept a complaint under section 36, and may make a determination under section 52, including a declaration that compensation be paid. In practice the office usually asks whether the organisation has had an opportunity to respond, which is what clause 29.2 is designed to give it a record of.
29.5 Complaining costs you nothing. Making a complaint against us will not affect how any request of yours under clauses 23 to 25 is handled, and we will not treat it as a reason to answer more slowly.
30Readers outside Australia
Rule. Claiming compliance with every regime in the world is a claim nobody can audit, so it is not made here.
30.1 This policy is written to Australian law. The studio is an Australian company. It makes no claim that what it does would satisfy the European regulation, the equivalent British rules, or any other scheme belonging to somebody else's jurisdiction.
30.2 The substantive rights in this document are not restricted by where you live. Clauses 23, 24, 25 and 29 are answered on the same terms and in the same periods for a correspondent anywhere.
30.3 Where a mandatory law of your own country confers a right on you that Australian law does not, we will consider a request made under it on its merits, and will tell you plainly if we conclude that we are not subject to it.
30.4 Information about you may be held outside your country in the places listed in clause 15.3.
31Amendment of this policy
Rule. The dangerous amendment is the one made quietly, so the ability to make one is given up in writing.
31.1 Whichever issue bears the number and commencement date printed at the head of this page is the one that operates.
31.2 An amendment that widens collection, adds a recipient, adds a country under clause 15, or lengthens a retention period in clause 19 is published before the change it describes takes effect. This is the same commitment as clause 7.2, restated here because it is the clause a reader checks when they suspect something has moved.
31.3 The superseded issue is retained and supplied on request to the address in clause 32.1.
31.4 An amendment that repairs a typographical error or clarifies wording without altering effect increments the version number and does nothing else.
32Where to write
Rule. One address, with the response time for each kind of matter written next to it.
32.1 Every matter in this document reaches [email protected]. The subject lines below route the message; a message with the wrong subject line is still answered.
| Matter | Subject line | Clause | Period |
|---|---|---|---|
| Access to your personal information | Privacy request | 24 | 30 days |
| Correction of your personal information | Privacy request | 25 | 30 days |
| Erasure, or to delete your account | Delete my data | 23 | 30 days |
| Complaint about our handling of information | Privacy complaint | 29 | Confirmed in 5 business days, answered in 30 |
| Suspected exposure of personal information | Security | 28.7 | Same or next business day |
| A question about a clause of this policy | Privacy | Any | 5 business days |
32.2 Messages under this policy are answered by the people running the company, and clause 32.1 is the address at which they arrive.
32.3 No postal address appears here. Formal service belongs at whatever registered office the Australian Securities & Investments Commission (ASIC) currently records against ACN 700 712 465, that being the sole location where serving a document accomplishes anything at law.
The entity answerable under this policy. AXIOM INTERACTIVE PTY LTD, ACN 700 712 465, ABN 77 700 712 465, New South Wales, Australia. Related documents: the cookie notice for device storage and outside hosts, and the terms of use for the conditions on which this site is published.