Rocket Horse Limited, trading as Kwizzbit (“Kwizzbit”, “we”, “us”) are committed to protecting the privacy and security of those whose personal data we process. We acknowledge the need to protect personal data that is collected by or disclosed to us and to manage it in accordance with the Data Protection Act 2018 and EU General Data Protection Regulation 2016/679 (GDPR).
The purpose of this notice is to inform you how we collect and use (process) your personal data during and after your relationship with us, in accordance with applicable Data Protection Laws.
Kwizzbitt (www.kwizzbit.com and www.kwbit.com) is a unique interactive quiz and audience participation platform played and operated using a smart phone or Internet enabled device in real time. Designed and developed by a team of quiz and gamification enthusiasts with a proven track record of delivering entertainment solutions to market, KwizzBit allows both the player and the host to engage seamlessly in interactive entertainment. We are what is referred to in law as the data controller of your personal data. As the data controller we have a number of legal obligations to ensure that we only use your data in a fair, transparent and secure manner. There are also some circumstances in which we may operate as a data processor, for example when sending out marketing on behalf of a host. If you have any questions regarding this privacy notice, our use of your data or wish to exercise any of your legal rights under data protection law, you can contact us by email firstname.lastname@example.org
How we obtain your data
In most cases the personal data that we process will be provided by you when you register to use Kwizzbit as either a host or player and engage in any correspondence with us. If a host sends you an invitation using Kwizzbit we will be the data processor of this information. We may also ask you to provide information regarding your satisfaction of the service we have provided to you. Please help us to keep your information up to date by informing us of any changes to your contact details.
What personal data do we capture?
We will only ever ask for the minimum personal data required to allow you to use Kwizzbit. Not all data fields are compulsory, but may be used to offer you alternative ways to securely log-in in to your Kwizzbit account. To use Kwizbit we may capture some or all of the following data:
- Your player (quiz) user name
- Your first and surname
- Mobile phone number
- Email address
- If you are registering a corporate account, the name of the company
- Your use of our website which may include your IP address
- Customer satisfaction correspondence
- Marketing preferences
We use a third party card processer (Stripe – www.stripe.com) for taking payments. We have no access to your card details and the entire payment process is controlled by Stripe. Stripe are the data controller of your card payment information.
How we use your personal data
We will only use your personal data where the law allows us. This is likely to be limited to the following examples.
- When you register as a host or player and enter into a contract with us
- When responding to your enquiry you have made
- To carry out our obligations arising from any contracts entered by you, your company and us
- For our own internal record keeping where there is either a legal requirement for us to do so or where it is in our legitimate interest
- To control access to, and/or provide security of our systems
- To seek your views or comments on the services we provide
- Maintain a record of your game play history
- Publish your results on our scoreboard. We will only use your quiz name
- To contact you by email and in-app messaging with promotional offers and services from Kwizzbit and from hosts you may have played with. We will only send you promotional messages where it is either in our legitimate interest to do so or where you have consented to receive marketing.
Disclosure of your personal data
We will only ever disclose your personal data to a third party where we are contractually required to do so (for example player data to a host) and have your consent, or are required to do so by law. We also use data processors to help deliver our services to you. This is limited to Amazon Web Services who host Kwizzbit and our data analytics platform. When using third party service providers we only disclose the personal data that is necessary to deliver the service. We have a contract in place that requires them to keep your information secure and prohibits them from using your data for their own purposes. All contractors are subject to a duty of confidentiality.
Security of your personal data
We undertake regular IT security and data protection auditing to ensure our systems meet the expectations of the law and those of our clients. Those of our employees and contractors who have access to personal data are required to undertake data protection training.
Transfers of data outside of the EEA
We may transfer your personal information to third party data processors who are based in countries outside the European Economic Area (EEA). We use some US-based companies that provide services such as IT, communications and data analytics service such as MailChimp and Google Analytics. We only use US-based organisations that are self-certified as adhering to the EU-US Privacy Shield. We will not transfer your information to any processors based in other countries outside the EEA unless there is a European Commission adequacy decision for the specific country to which the data is transferred, or where we can be certain that there are adequate safeguards provided for your information and individual rights standards that meet the GDPR requirements.
How long we keep your personal data
We will retain your personal data as long as is necessary to provide the services to which you have requested, or where we have another legitimate and lawful reason to do so. We may need to retain some information to comply with our legal obligations such as financial and accounting records. Unless there is an ongoing business relationship, we will only retain your personal data for 7 years after our last contact with you. In most cases player personal data will be deleted 2 years after your last log-in. We may contact you before we delete your account to give you the opportunity to keep it active.
Cookies and similar tracking technology
A cookie is a small file placed on your devices hard drive. It enables our website to identify you and your device as you view different pages on our websites and app and play. Cookies allow websites and applications to store your preferences in order to present content, options or functions that are specific to you. They also enable us to see information like how many people use the website, app and the way in which you use these.
- Analyse our web traffic using an analytics package. Aggregated usage data helps us improve the website structure, design, content and functions
- Recognise when you return to our websites. We may show your relevant content, or provide functionality you used previously
- Identify the web browser you are using, operating systems and device type
- Operate our webform
We have included a tool within our website to enable you to enable and disable all non-essential cookies.
Your rights in respect of your personal data
You have a number of rights under data protection law. In summary these include:
- Subject Access – you have the right to request details of the personal data which we hold about you and a copy of that data
- Right to Withdraw Consent – where our use of your personal data is based upon your consent, you have the right to withdraw that consent at any time. In the event you wish to withdraw your consent to processing, please contact us using. You should be aware that withdrawing consent may result in us no longer being able to provide you with the service you originally requested
- Data Portability – you may, in certain circumstances request us to provide with a copy of your data for transfer to another organisation. In view of the services we offer it is unlikely that this right would be relevant to our data relationship with you
- Rectification – we want to ensure that the personal data we hold is accurate and up to date. If you believe that any data we have about you is incorrect or incomplete, please let us know. To the extent required by applicable laws, we will rectify or update any incorrect or inaccurate personal data about you
- Erasure (‘right to be forgotten’) – you have the right to have your personal data ‘erased’ in certain specified situations
- Restriction of processing – you have the right in certain specified situations to require us to stop processing your personal data and to only store such personal data
- Object to processing – You have the right to object to specific types of processing of your personal data, for example, where we are processing your personal data for the purposes of direct marketing
- Prevent automated decision-taking – in certain circumstances, you have the right not to be subject to decisions being taken solely on the basis of automated processing
To exercise any of these rights or if you have any questions about our Privacy Notice please contact our Data Protection Team by email email@example.com
While we hope to be able to resolve any concerns you have about the way that we are processing your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your data has been processed in a way that does not comply with the GDPR or have any wider concerns about our compliance with data protection law. You can do so by calling the ICO helpline on 0303 123 1113 or via their website https://ico.org.uk/
We keep our privacy notices under regular review. This notice was last updated on 5th June 2020.