GDPR — Your Data Rights
Last updated: 30 March 2026
GoNow Productions is committed to protecting your personal data and respecting your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and Organic Law 3/2018 on Personal Data Protection and the Guarantee of Digital Rights (LOPDGDD), applicable in Spain.
This page explains who we are as a data controller, how we process your data, and how you can exercise your rights.
1. Data Controller
The data controller responsible for processing your personal data in connection with the Gonow Play service is:
GoNow Productions
Owner: Jason Leven (Autónomo registered in Spain)
Barcelona, Spain
Email: info@gonowproductions.com
2. Data We Process
We process the following categories of personal data:
- Identity data: Name, display name, email address, profile picture
- Authentication data: Google OAuth tokens or hashed passwords (managed by Supabase Auth)
- Game data: Hunt sessions, scores, items found, leaderboard positions, prize claims, streaks, and in-game activity
- Submitted images: Photos taken during gameplay for AI product verification
- Technical data: IP address, device type, browser, and usage logs
3. Data Sharing with Game Operators
When you participate in a game hosted by a shopping centre or venue, personal data you have provided — including your name, email address, game results, and any additional information you choose to supply — may be shared with the operator of that venue for prize fulfilment and game administration.
Where you have given consent to receive marketing communications (e.g. by opting in during registration), venue operators may contact you about future games, promotions, and events at their location. This consent is based on Article 6(1)(a) GDPR and may be withdrawn at any time.
Each venue operator is an independent data controller responsible for ensuring their own processing complies with applicable data protection law. Operators are bound by data processing agreements with GoNow Productions and may not use your data beyond the purposes for which you have consented.
4. Legal Basis for Processing
We rely on the following legal bases under Article 6 GDPR:
- Article 6(1)(b) — Contract performance: Processing your data to provide the Gonow Play service you have registered for, including running game sessions, verifying submissions, and managing prizes.
- Article 6(1)(f) — Legitimate interests: Preventing fraud and cheating, improving the Service, and ensuring platform security.
- Article 6(1)(c) — Legal obligation: Where we are required to retain data by applicable law.
- Article 6(1)(a) — Consent: For optional communications such as marketing emails, where you have explicitly opted in.
5. Data Retention
We retain your personal data as follows:
- Active account data: Retained for the lifetime of your account.
- Game session and score data: Retained for the lifetime of your account and up to 12 months after account deletion.
- Submitted photos: Retained for a maximum of 90 days after submission, then deleted.
- Prize claim records: Retained for 7 years as required for financial and legal compliance.
- Technical logs: Retained for up to 90 days.
6. International Transfers
Your data is primarily stored and processed within the European Economic Area (EEA). Where we use third-party processors outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
7. Your Rights Under the GDPR
Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you.
Right to Rectification (Article 16)
You have the right to request that we correct any inaccurate or incomplete personal data.
Right to Erasure (Article 17)
You have the right to request deletion of your personal data where it is no longer necessary for the purpose it was collected, or where you withdraw consent.
Right to Restriction of Processing (Article 18)
You have the right to request that we restrict processing of your data in certain circumstances.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV).
Right to Object (Article 21)
You have the right to object at any time to processing based on our legitimate interests.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw your consent at any time.
Right Not to Be Subject to Automated Decision-Making (Article 22)
Our AI scoring system evaluates game submissions but does not make decisions that significantly affect your rights beyond the context of gameplay.
8. How to Exercise Your Rights
Contact our Data Protection team at:
Email: info@gonowproductions.com
Subject line: "GDPR Data Request — [Your Request Type]"
We will respond within 30 days.
9. Right to Lodge a Complaint
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6, 28001 Madrid, Spain
www.aepd.es
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
11. Changes to This Page
We may update this GDPR information page from time to time. The "Last updated" date reflects the most recent revision.
12. Contact
GoNow Productions
Owner: Jason Leven (Autónomo registered in Spain)
Barcelona, Spain
info@gonowproductions.com
