Personal Data Processing Policy

1. Data controller

2. Legal framework

This policy is issued in compliance with Article 15 of the Political Constitution, Law 1581 of 2012, Decree 1377 of 2013 and the instructions of the Superintendence of Industry and Commerce (SIC), the data protection authority in Colombia.

3. Personal data we collect

Registration data: name, email address, mobile number, date of birth, gender, professional level, profile photo and social network account data if the User chooses to register that way.

Profile data (optional): interests, personal description, Instagram link and other preferences the User chooses to add.

Location data: the device's geographic location, when the User grants the corresponding permission. Used to show nearby events and, in aggregated and anonymous form, to show attendee concentration zones.

Usage and interaction data: events attended or confirmed, matches, messages sent through the App's chats, games played, and technical logs (device, operating system, identifiers, date and time of access).

Multimedia content: photos and videos the User uploads to event albums or recaps.

4. Purposes of processing

Data is processed for the following purposes:

5. Sensitive data and minors

5.1. GamGam does not request sensitive data (health, ethnic origin, religious or political beliefs, biometric data). If the User chooses to include information of this nature in their profile or messages, they do so freely and voluntarily. The User is not required to authorize the processing of sensitive data, and their refusal does not prevent use of the App.

5.2. The App is not directed to persons under 18 years of age, and GamGam does not intentionally collect their data. If a minor's account is detected, it will be deleted together with their data.

6. Authorization

The processing of data requires the prior, express and informed authorization of the data subject, obtained at the time of registration through acceptance of this policy (acceptance checkbox). Location and camera/gallery permissions are requested separately through the device's operating system, and the User may revoke them at any time from settings.

7. Rights of data subjects

Pursuant to Article 8 of Law 1581 of 2012, the data subject has the right to:

8. Procedure to exercise rights (inquiries and complaints)

8.1. Channel: the data subject may exercise their rights by writing to support@gamgam.app or from the Profile > Settings > Privacy section of the App. To delete your account and data —including from the web and without installing the App— see the Delete account page.

8.2. Inquiries: will be handled within a maximum term of ten (10) business days from receipt. If it is not possible to handle it within that term, the interested party will be informed before its expiration, indicating the reasons and the response date, which may not exceed the following five (5) business days.

8.3. Complaints: will be handled within a maximum term of fifteen (15) business days. If the complaint is incomplete, the interested party will be requested within the following five (5) days to complete it; after two (2) months without a response, it will be deemed abandoned.

9. Data sharing

GamGam may share personal data with:

GamGam does not sell personal data to third parties.

10. Information security

GamGam adopts reasonable technical, human and administrative measures to protect data: encryption in transit, access control, and incident response protocols. In the event of a security incident affecting personal data, GamGam will report it to the SIC and to the data subjects in accordance with applicable regulations.

11. Data validity and retention

Data will be retained while the account is active and for the time necessary to fulfill the described purposes or legal obligations. When the User deletes their account, their data will be deleted or anonymized within a maximum of 90 days, except for data that must be retained by legal obligation.

12. National Database Registry

In accordance with Decree 090 of 2018, the obligation to register databases in the National Database Registry administered by the Superintendence of Industry and Commerce applies only to companies and non-profit entities with total assets exceeding 100,000 UVT and to public legal entities. As of this date, Daokio does not exceed said asset threshold and is therefore not obligated to register.

The foregoing does not exempt Daokio from complying with the other duties that Law 1581 of 2012 imposes on Data Controllers, which are set out in this policy. Should the aforementioned asset threshold be exceeded in the future, Daokio will register its databases in the RNBD within the terms established by the applicable regulations.

13. Modifications to this policy

Any substantial change will be communicated to users through the App before it takes effect.