VIRTWAVE – PRIVACY POLICY
Last Updated: 01.05.2022
Company: VIRTWAVE GLOBAL FZCO
Registered Address: Unit No: 1608-029, Jumeirah Bay 2,
Plot No: JLT-PH2-X2A, Jumeirah Lakes Towers, Dubai, UAE
Company Number: DMCC191668
Website: https://www.virtwave.com
1. INTRODUCTION
1.1. This Privacy Policy (“Policy”) describes how VIRTWAVE GLOBAL FZCO (“VIRTWAVE”, “we”, “our”, “us”) collects, uses, stores, transfers, discloses, and protects personal data of individuals (“Users”, “Customers”, “you”, “your”) who interact with the website www.virtwave.com and any of its subdomains (the “Website”).
1.2. VIRTWAVE is committed to maintaining the highest standards of privacy compliance, including adherence to:
- the General Data Protection Regulation (EU) 2016/679 (“GDPR”),
- the UK GDPR and Data Protection Act 2018,
- relevant UAE data protection frameworks,
- applicable regional data protection laws worldwide.
1.3. This Policy applies to all interactions with the Website, including:
- browsing the Website,
- creating an account,
- purchasing digital products (“Digital Content”),
- communicating with customer support,
- participating in promotions,
- engaging with cookies or analytics tools.
1.4. This Policy forms part of the Terms & Conditions and must be read together with:
- Cookie Policy,
- Refund & Delivery Policy,
- Anti-Fraud Policy (internal framework).
1.5. If you do not agree with any part of this Policy, you must immediately discontinue use of the Website.
2. SCOPE OF THE POLICY
2.1. This Policy applies to all processing of personal data carried out by VIRTWAVE in connection with the provision of digital goods and services.
2.2. It applies to Users:
- located in the EU/EEA,
- located in the United Kingdom,
- located in Switzerland,
- located in the United States or Canada,
- and all other international jurisdictions.
2.3. This Policy does not apply to:
- external Platform providers (e.g., Steam, PlayStation, Xbox),
- payment processors acting as independent controllers,
- third-party websites linked from the Website.
2.4. Users are encouraged to review external privacy policies before interacting with third-party services.
3. CONTROLLER INFORMATION
3.1. For purposes of GDPR and other data protection regulations, the data controller responsible for the processing of personal data is:
VIRTWAVE GLOBAL FZCO
Unit No: 1608-029, Jumeirah Bay 2
Plot No: JLT-PH2-X2A
Jumeirah Lakes Towers
Dubai, United Arab Emirates
Company Number: DMCC191668
Email: [email protected]
3.2. VIRTWAVE may appoint external processors to support operational functions such as:
- payment processing,
- customer support,
- cloud hosting,
- analytics services,
- fraud detection systems.
3.3. All processors operate under binding contractual obligations consistent with Article 28 GDPR or equivalent standards.
4. DEFINITIONS
For the purpose of this Policy:
4.1. Personal Data
Any information relating to an identified or identifiable natural person.
4.2. Processing
Any operation performed on personal data including collection, storage, analysis, transmission, or deletion.
4.3. Controller
The party determining the purposes and means of processing (VIRTWAVE).
4.4. Processor
A third party processing personal data on behalf of the Controller.
4.5. Digital Content
Electronic products delivered digitally, including:
- activation keys,
- software licenses,
- vouchers,
- subscriptions,
- wallet top-ups.
4.6. Platform
Third-party ecosystem where Digital Content is redeemed (Steam, PSN, Xbox, Ubisoft, Epic Games, etc.).
4.7. Automated Decision-Making
Processing that produces legal or significant effects without human intervention, including fraud analysis algorithms.
4.8. Profiling
Automated processing used to evaluate behavior, preferences, or risk.
4.9. Supervisory Authority
National data protection authority under GDPR or equivalent laws.
5. CATEGORIES OF PERSONAL DATA WE PROCESS
VIRTWAVE collects and processes only the data necessary to deliver Digital Content, comply with legal obligations, prevent fraud, and improve customer experience.
We categorize personal data as follows:
5.1. Account and Identification Data
Collected when you create an account or make a purchase.
- Full name (if provided)
- Email address
- Username or display name
- Password (hashed and salted)
- Country of residence
- Preferred language
- Communication preferences
5.2. Transaction and Billing Data
Processed when completing purchases.
- Order history
- Products purchased
- Billing address (where applicable)
- Partial payment details (e.g., masked card data)
- Payment processor identifiers
- Transaction timestamps
- Currency and payment method used
VIRTWAVE does not store credit card numbers or CVV codes.
5.3. Technical and Device Data
Automatically collected when using the Website.
- IP address and geolocation (city-level accuracy)
- Device type and OS
- Browser type and version
- Device fingerprint identifiers
- Screen resolution and system settings
- Referral URLs
- Session activity logs
This data is essential for:
- fraud prevention,
- regional compliance,
- Website functionality,
- security logging.
5.4. Usage and Interaction Data
Collected through cookies, analytics, and interaction with Website features.
Includes:
- pages viewed,
- click events,
- time spent on pages,
- shopping cart activity,
- promotional interactions,
- affiliate campaign identifiers.
5.5. Fraud Prevention Data
Collected through automated tools and manual review.
Includes:
- IP anomalies,
- VPN/proxy indicators,
- chargeback history,
- device uniqueness hashes,
- repeated failed payment attempts,
- mismatched geographic or billing details.
This category is essential for ensuring secure transactions and preventing abuse.
5.6. Communication and Support Data
Collected when contacting customer support.
- email correspondence,
- support ticket logs,
- chat transcripts,
- attachments provided (e.g., screenshots),
- verification documentation (if voluntarily submitted).
5.7. Cookies and Tracking Data
Collected through:
- first-party cookies,
- third-party cookies (with consent),
- analytics scripts,
- security and bot-protection services.
6. SPECIAL CATEGORIES OF PERSONAL DATA
6.1. VIRTWAVE does not intentionally process special categories of personal data, such as:
- biometric data,
- health data,
- religious beliefs,
- political opinions,
- ethnicity,
- sexual orientation.
6.2. If a User voluntarily submits such data during support conversations, VIRTWAVE will immediately delete it where technically feasible.
7. MINORS
7.1. The Website is not intended for individuals under the age of 18.
7.2. VIRTWAVE does not knowingly collect personal data from minors.
7.3. If such data is discovered, VIRTWAVE will promptly delete it.
8. LEGAL BASES FOR PROCESSING PERSONAL DATA
8.1. VIRTWAVE processes personal data only where a lawful basis exists under GDPR or equivalent legislation. The following legal bases apply:
8.1.1. Contract Performance (Article 6(1)(b) GDPR)
Processing necessary to:
- register and maintain your account,
- process orders and deliver Digital Content,
- provide customer support,
- manage billing or transaction-related issues.
Without this processing, VIRTWAVE cannot fulfill its contractual obligations.
8.1.2. Legal Obligations (Article 6(1)(c) GDPR)
Processing required to comply with:
- accounting and tax laws,
- anti-money laundering rules where applicable,
- record keeping requirements,
- responding to legal requests, court orders, or regulatory inquiries.
8.1.3. Legitimate Interests (Article 6(1)(f) GDPR)
Processing necessary for:
- fraud detection and prevention,
- securing the Website and systems,
- internal business analytics,
- customer service operations,
- preventing misuse or abuse of services.
VIRTWAVE carefully balances its interests with the rights and freedoms of Users.
8.1.4. Consent (Article 6(1)(a) GDPR)
Used only when:
- deploying optional marketing cookies,
- sending promotional communications (where required),
- processing certain analytics data.
Users may withdraw consent at any time.
8.1.5. Protection of Vital Interests (rare)
Applied only in exceptional situations involving threats to life or physical safety.
8.1.6. Compliance With International Laws
In certain regions, additional lawful bases may apply depending on local regulation.
9. PURPOSES OF DATA PROCESSING
VIRTWAVE processes personal data for clearly defined purposes.
9.1. Account Creation and Management
We process personal data to:
- register accounts,
- authenticate logins,
- synchronize preferences,
- maintain purchase records.
Without this processing, the Website cannot function.
9.2. Processing Orders and Delivering Digital Content
Necessary to:
- complete payments,
- detect fraudulent activity,
- send confirmation emails,
- deliver activation keys and codes,
- handle order inquiries.
9.3. Customer Support and Communication
We use personal data to:
- respond to inquiries,
- troubleshoot issues,
- investigate technical problems,
- provide guidance for product activation,
- verify identity when necessary.
9.4. Fraud Prevention and Security Monitoring
A critical function to protect both Users and VIRTWAVE.
Includes:
- IP analysis,
- VPN/proxy detection,
- device fingerprinting,
- behavioral anomaly detection,
- repeated purchase pattern analysis,
- verification of transaction consistency.
Fraud prevention may involve limited automated decision-making.
9.5. Analytics and Website Optimization
We analyze Website interactions to:
- improve design and functionality,
- enhance product recommendations,
- detect technical errors,
- better understand usage patterns.
Analytics platforms may include:
- privacy-focused tools,
- first-party analytics,
- third-party vendors with appropriate safeguards.
9.6. Marketing and Promotional Activities
Only with consent where required.
Includes:
- newsletters,
- promotional offers,
- discount notifications,
- remarketing campaigns.
Users may opt out at any time.
9.7. Legal and Regulatory Compliance
We may process data to:
- comply with tax regulations,
- document transaction records,
- respond to lawful requests,
- cooperate with payment processors’ compliance checks.
10. COOKIES AND TRACKING TECHNOLOGIES
10.1. Overview
VIRTWAVE uses both first-party and third-party cookies to ensure:
- Website functionality,
- performance monitoring,
- fraud detection,
- personalization,
- secure transactions.
Cookies may be:
- essential (required),
- functional (preferences),
- analytics (usage insights),
- marketing (advertising, optional).
10.2. Types of Cookies Used
10.2.1. Strictly Necessary Cookies
These enable:
- login functionality,
- shopping cart management,
- checkout flow,
- fraud detection,
- security protections.
They cannot be disabled.
10.2.2. Functional Cookies
Used to remember:
- language preferences,
- region selections,
- user interface customizations.
10.2.3. Analytics Cookies
Used to measure:
- traffic sources,
- most visited pages,
- conversion rates,
- customer journeys.
Analytics data is aggregated where possible.
10.2.4. Marketing and Advertising Cookies
Used to:
- display relevant promotions,
- measure campaign effectiveness,
- support affiliate programs.
These require explicit consent in many regions.
10.3. Cookie Management
Users may:
- configure browser settings,
- manage cookie preferences on the Website,
- withdraw consent for optional cookies.
Disabling necessary cookies may limit Website functionality.
10.4. Third-Party Trackers
Some cookies originate from:
- analytics providers,
- fraud prevention services,
- advertising networks (with consent).
Each operates under its own privacy policy.
11. ANALYTICS, LOGGING, AND PERFORMANCE MONITORING
VIRTWAVE uses analytics tools to understand how Users interact with the Website.
11.1. Data Collected via Analytics
May include:
- IP address (truncated where possible),
- device model and OS,
- browser type,
- pages viewed and time spent,
- referral paths,
- click actions.
Where required, such data is processed with consent.
11.2. Server Logs
Automatically collected for:
- security,
- debugging,
- performance monitoring.
Includes:
- timestamps,
- API call results,
- error diagnostics,
- connection metadata.
11.3. Aggregated or Anonymized Data
VIRTWAVE may generate aggregated statistical insights that cannot identify individuals, such as:
- traffic trends,
- conversion rates,
- performance metrics.
Aggregated data may be used for internal business improvement.
12. FRAUD PREVENTION AND AUTOMATED DECISION-MAKING
12.1. Purpose
Fraud prevention is essential to maintain secure transactions and protect both Customers and VIRTWAVE from fraudulent behavior.
12.2. Methods
We use:
- device fingerprinting,
- IP geolocation checks,
- evaluation of mismatched data (billing vs. IP location),
- behavioral scoring models,
- payment risk profiling.
12.3. Automated Flags
Automated systems may temporarily:
- hold an order for manual review,
- require additional verification,
- restrict account activity,
- block suspicious transactions.
12.4. Legal Basis
Fraud prevention relies primarily on:
- legitimate interests (Art. 6(1)(f) GDPR),
- contract necessity (Art. 6(1)(b) GDPR).
12.5. User Rights Regarding Automation
Users may:
- request human review,
- contest automated decisions,
- provide additional evidence for verification.
13. RETENTION OF PERSONAL DATA
13.1. General Retention Periods
Personal data is stored only as long as necessary for the purposes identified.
13.2. Specific Retention Durations
- Account data: retained while account remains active.
- Order and billing records: retained for 5–10 years (legal obligations).
- Fraud prevention records: retained between 12 months and 5 years, depending on severity.
- Customer support interactions: retained up to 3 years after closure.
- Analytics data: retained in aggregated form where possible.
13.3. Criteria for Determining Retention
Factors include:
- legal requirements,
- contractual necessity,
- fraud prevention needs,
- dispute resolution periods,
- business requirements.
13.4. Account Deletion Requests
Upon request:
- account access is terminated,
- personal data is deleted or anonymized,
except where retention is required by law (e.g., financial records).
13.5. Deletion Limitations
We cannot delete data necessary for:
- tax compliance,
- legal claims,
- fraud prevention tracking.
These are retained in accordance with statutory obligations.
14. INTERNATIONAL DATA TRANSFERS
14.1. VIRTWAVE operates in a global environment and may transfer personal data to countries outside your residence, including:
- the United Arab Emirates,
- European Union / EEA member states,
- the United States,
- the United Kingdom,
- other jurisdictions where third-party processors are located.
14.2. International transfers are conducted only when adequate protections are in place.
14.1. Transfers From the EU/EEA
14.1.1. When transferring personal data from the EU or EEA to third countries, VIRTWAVE relies on legal safeguards, including:
- European Commission Standard Contractual Clauses (SCCs),
- adequacy decisions where applicable,
- contractual assurances of data protection equivalence.
14.1.2. Copies of SCCs may be requested where legally permissible.
14.2. Transfers to the United Arab Emirates
14.2.1. Data stored or processed in UAE-based servers is protected by:
- contractual safeguards,
- technical and organizational security measures,
- internal access controls,
- the principles of this Policy.
14.3. Transfers to the United States
14.3.1. Some service providers may be located in the U.S.
Where necessary, transfers are protected by:
- SCCs,
- Privacy Framework participation (if applicable),
- risk assessments confirming adequate protection.
14.4. Global Cloud Infrastructure
14.4.1. Cloud hosting providers may operate in multiple jurisdictions.
Data location is determined by:
- performance needs,
- redundancy requirements,
- regulatory obligations.
14.4.2. Such transfers comply with applicable laws and agreements.
15. SHARING PERSONAL DATA WITH THIRD PARTIES
15.1. Categories of Recipients
VIRTWAVE shares personal data with carefully selected third parties only when necessary.
These may include:
- Payment processors (independent controllers)
- Cloud hosting providers
- Analytics and performance monitoring services
- Fraud prevention and risk scoring partners
- Email delivery and communication tools
- Customer support platforms
- Regulatory bodies or law enforcement (when legally required)
15.2. Payment Processors
15.2.1. Payment processors handle:
- payment authentication,
- anti-fraud checks,
- transaction authorization.
15.2.2. VIRTWAVE does not receive or store:
- full card numbers,
- CVV codes,
- PINs.
15.2.3. Payment processors act as independent data controllers for the purpose of financial data.
15.3. Third-Party Platforms
15.3.1. When purchasing Digital Content redeemable on external Platforms (e.g., Steam, Xbox), VIRTWAVE may provide:
- activation keys,
- metadata necessary to deliver the Product.
15.3.2. These Platforms process personal data independently and under their own terms.
15.4. Fraud Detection Partners
15.4.1. We may share risk data with:
- fraud databases,
- verification vendors,
- chargeback monitoring systems.
15.4.2. Such sharing is necessary to:
- detect fraudulent activity,
- protect legitimate Users,
- maintain platform integrity.
15.5. Legal and Regulatory Disclosures
15.5.1. VIRTWAVE may disclose personal data to:
- tax authorities,
- regulatory bodies,
- law enforcement agencies,
- courts or litigants.
15.5.2. Disclosures occur only when legally required or necessary to protect VIRTWAVE’s rights.
15.6. Business Transfers
15.6.1. In the event of:
- a merger,
- acquisition,
- restructuring,
- sale of assets,
- bankruptcy,
personal data may be transferred to the successor entity.
15.6.2. Any successor is bound by this Policy.
16. DATA SECURITY MEASURES
16.1. VIRTWAVE implements robust technical and organizational measures to secure personal data, including:
- encryption in transit (HTTPS/TLS),
- encryption at rest where supported,
- hashed and salted passwords,
- strict access controls,
- firewalls and anti-DDoS protection,
- continuous monitoring systems,
- secure development practices,
- regular vulnerability assessments.
16.2. Access Controls
Access to customer data is:
- limited to authorized personnel,
- granted on a need-to-know basis,
- monitored and logged.
16.3. Data Breach Response
16.3.1. In the event of a security incident, VIRTWAVE will:
- investigate the breach promptly,
- contain and mitigate damage,
- notify affected Users where legally required,
- notify regulators if necessary.
16.3.2. Notifications will occur without undue delay.
16.4. No Absolute Guarantee
16.4.1. Despite strong safeguards, no system is fully immune to security threats.
16.4.2. Users acknowledge inherent risks of online data transmission.
17. USER RIGHTS UNDER GDPR AND EQUIVALENT LAWS
Users located in the EU/EEA, UK, and certain other jurisdictions are entitled to specific rights relating to their personal data.
17.1. Right to Access
You may request:
- confirmation whether VIRTWAVE processes your data,
- a copy of your personal data,
- categories of data processed,
- processing purposes,
- data retention periods,
- data sharing recipients.
17.2. Right to Rectification
You may request correction of:
- inaccurate data,
- incomplete information.
Updates may be made directly in your account dashboard.
17.3. Right to Erasure (“Right to Be Forgotten”)
You may request deletion of your personal data where:
- it is no longer needed for its original purpose,
- consent is withdrawn and no other legal basis applies,
- processing was unlawful,
- erasure is required by law.
VIRTWAVE may retain data when legally required for compliance or fraud prevention.
17.4. Right to Restrict Processing
Applicable when:
- accuracy is contested,
- processing is unlawful,
- data is no longer needed but required for legal claims,
- an objection is pending.
17.5. Right to Data Portability
You may request:
- export of your personal data,
- in a structured, commonly used, machine-readable format,
- for transmission to another controller where technically feasible.
Only applies to data processed based on consent or contract.
17.6. Right to Object
You may object to processing based on:
- legitimate interests,
- direct marketing.
Unless compelling legitimate grounds exist, processing will cease.
17.7. Rights Regarding Automated Decision-Making
You may request:
- human intervention,
- explanation of the automated decision,
- contestation of the decision.
This applies primarily to fraud checks.
17.8. Withdrawal of Consent
You may withdraw consent for:
- marketing communications,
- optional cookies,
- analytics tracking.
Withdrawal does not affect prior lawful processing.
17.9. Right to Lodge a Complaint
You have the right to lodge a complaint with your local supervisory authority, such as:
- an EU data protection authority,
- the UK Information Commissioner’s Office (ICO),
- the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Users may also contact VIRTWAVE directly at:
[email protected]
18. REGION-SPECIFIC PRIVACY NOTICES
Data protection laws vary across jurisdictions.
This section describes additional rights or obligations depending on your region.
18.1. European Union (EU) and European Economic Area (EEA)
18.1.1. If you are located in the EU or EEA, VIRTWAVE processes your personal data according to the GDPR.
18.1.2. You have the rights described in Section 17, including:
- access,
- rectification,
- erasure,
- restriction of processing,
- data portability,
- objection,
- withdrawal of consent.
18.1.3. You also have the right to:
- lodge a complaint with your national data protection authority,
- rely on mandatory consumer protections under EU law,
- challenge automated decisions.
18.1.4. VIRTWAVE ensures that transfers outside the EU are protected with SCCs or equivalent safeguards.
18.2. United Kingdom (UK GDPR)
18.2.1. The UK has adopted its own version of the GDPR, known as the UK GDPR.
18.2.2. If you reside in the UK, you have equivalent rights to EU Users.
18.2.3. The supervisory authority for UK Users is:
Information Commissioner’s Office (ICO)
https://ico.org.uk
18.2.4. International transfers follow UK-approved adequacy regulations or contractual safeguards.
18.3. Switzerland (FADP)
18.3.1. Users in Switzerland benefit from protections under the Federal Act on Data Protection (FADP).
18.3.2. Data transfers to third countries comply with:
- European SCCs,
- Swiss-specific transfer rules.
18.4. United States (CCPA/CPRA and other state laws)
18.4.1. While there is no federal privacy law, certain states grant privacy rights, including:
- California (CCPA/CPRA),
- Colorado (CPA),
- Virginia (VCDPA),
- Connecticut (CTDPA).
18.4.2. These rights include:
- right to know/access personal data,
- right to delete data,
- right to data portability,
- right to opt-out of targeted advertising or certain data sharing.
18.4.3. VIRTWAVE does not sell personal data under U.S. definitions.
18.4.4. U.S. Users may submit requests to:
[email protected]
18.5. Canada (PIPEDA)
18.5.1. Users in Canada have rights under PIPEDA, including rights to:
- access,
- correction,
- transparency.
18.5.2. Transfers to third countries are protected via contractual and technical safeguards.
18.6. Other Jurisdictions
18.6.1. Users located outside the above regions may still be entitled to additional local privacy rights.
18.6.2. VIRTWAVE endeavors to provide a reasonable level of global privacy protection regardless of location.
19. THIRD-PARTY PLATFORMS AND EXTERNAL SERVICES
19.1. External Platforms
19.1.1. Digital Content purchased from VIRTWAVE must often be redeemed on external Platforms such as:
- Steam,
- PlayStation Network,
- Xbox,
- Ubisoft Connect,
- EA,
- Epic Games Store,
- Nintendo.
19.1.2. These Platforms collect and process personal data independently.
19.1.3. Users must review the respective Platform’s privacy policies.
19.1.4. VIRTWAVE is not responsible for:
- Platform privacy practices,
- account bans or suspensions,
- policy changes made by publishers,
- updates affecting redemption or functionality.
19.2. Payment Providers
19.2.1. Payment processors act as independent controllers for payment-related data.
19.2.2. Their privacy policies govern:
- card information,
- chargeback investigations,
- identity verification,
- fraud assessment.
19.2.3. VIRTWAVE receives only limited data necessary for:
- order verification,
- fraud detection,
- customer support.
19.3. Advertising and Affiliate Networks
19.3.1. Marketing cookies or tracking pixels may be used (subject to consent) for:
- referral attribution,
- campaign measurement,
- personalized offers.
19.3.2. Users may opt out via the cookie banner or browser settings.
20. CHILDREN’S DATA
20.1. The Website is not intended for Users under the age of 18.
20.2. VIRTWAVE does not knowingly collect personal data from minors.
20.3. If a minor’s data is inadvertently collected, VIRTWAVE will:
- promptly delete it,
- terminate the account where applicable.
20.4. Guardians may contact [email protected] to request deletion.
21. RETENTION, ARCHIVING & DELETION
21.1. VIRTWAVE applies the following retention principles:
- Data is kept only as long as necessary for the original purpose.
- Legal obligations may require extended retention (e.g., tax laws).
- Fraud prevention logs may be maintained longer for security reasons.
- Data may be anonymized for statistical purposes.
21.2. Specific Retention Timelines
- Accounts: retained until User requests deletion.
- Order and billing records: 5–10 years for legal compliance.
- Fraud records: 12 months–5 years depending on severity.
- Customer support logs: up to 3 years.
- Marketing data: until consent is withdrawn.
- Cookies: lifespan depends on cookie type (see Cookie Policy).
21.3. Account Deletion
Upon request:
- your account is permanently closed,
- identifiable data is removed or anonymized,
- legal exceptions apply for financial compliance.
22. DATA ACCURACY
22.1. Users must ensure that personal data provided is:
- accurate,
- current,
- complete.
22.2. Inaccurate data may:
- delay deliveries,
- trigger fraud checks,
- limit account functionality.
23. CHANGES TO THIS PRIVACY POLICY
23.1. VIRTWAVE may modify this Policy at any time due to:
- regulatory updates,
- business changes,
- new features or services,
- legal interpretations,
- operational requirements.
23.2. Updated versions will include a new “Last Updated” date.
23.3. Significant changes may be communicated via:
- email notifications,
- Website announcements,
- account messages.
23.4. Continued use of the Website constitutes acceptance of changes.
24. SUBMITTING REQUESTS UNDER THIS POLICY
24.1. Request Channels
Users may submit privacy-related requests by contacting:
Email: [email protected]
Address:
VIRTWAVE GLOBAL FZCO
Unit No: 1608-029, Jumeirah Bay 2
Plot No: JLT-PH2-X2A
Jumeirah Lakes Towers, Dubai, UAE
24.2. Identity Verification
To protect your data, VIRTWAVE may request verification steps, including:
- confirming email ownership,
- providing order information,
- submitting additional verification documentation (optional).
24.3. Response Timeframes
- GDPR requests: within 30 days.
- Extensions may apply for complex cases.
- Users will be notified if additional time is required.
25. COMPLAINTS AND DISPUTE RESOLUTION
25.1. Users dissatisfied with VIRTWAVE’s handling of personal data may contact: [email protected]
25.2. EU and UK Users may file complaints with:
- local supervisory authorities,
- the ICO (UK),
- national DPAs.
25.3. VIRTWAVE encourages resolving issues amicably before regulatory escalation.
26. ADDITIONAL DISCLOSURES AND LEGAL NOTICES
26.1. No Sale of Personal Data
26.1.1. VIRTWAVE does not sell personal data under:
- GDPR definitions,
- CPRA/CCPA definitions,
- UAE data protection frameworks,
- any other jurisdiction’s privacy regulations.
26.1.2. Any data sharing described in this Policy is strictly limited to:
- contractual processors,
- lawful disclosures,
- security and fraud protection,
- service providers necessary to operate the Website.
26.2. Automated Decision-Making Notice
26.2.1. Automated processing may occur for:
- fraud detection,
- transaction risk scoring,
- suspicious pattern recognition.
26.2.2. Automated decisions never:
- deny Users their legal rights,
- involve marketing profiling without consent,
- produce irreversible effects without human review.
26.2.3. Users may always request:
- human intervention,
- explanation of logic involved,
- contestation of automated decisions.
26.3. Links to Third-Party Websites
26.3.1. The Website may contain links to external resources not controlled by VIRTWAVE.
26.3.2. VIRTWAVE is not responsible for:
- privacy practices,
- data security,
- content,
- terms of external sites.
26.3.3. Users are encouraged to review third-party privacy policies before engaging with external services.
26.4. Data in Backups or Archived Systems
26.4.1. When personal data is deleted, it may persist temporarily in:
- encrypted backups,
- log archives,
- system snapshots.
26.4.2. Such data will be fully purged according to automated retention cycles.
26.4.3. Archived data is never used for:
- profiling,
- decision-making,
- marketing,
- active processing.
26.5. Aggregate and Anonymized Data
26.5.1. VIRTWAVE may use anonymized or aggregated data for:
- analytics,
- product development,
- business intelligence.
26.5.2. Such data cannot be re-identified and falls outside the scope of GDPR.
27. ADDITIONAL PROTECTIONS FOR HIGH-RISK PROCESSING
Where processing activities pose increased risk (such as fraud detection), VIRTWAVE implements:
- increased encryption standards,
- segregated data storage,
- zero-trust access models,
- use of pseudonymization where possible,
- strict internal audit logs,
- role-based access control policies,
- periodic privacy impact assessments (PIAs).
28. RECORDS OF PROCESSING ACTIVITIES (RoPA)
28.1. VIRTWAVE maintains detailed documentation as required under GDPR Article 30, including:
- categories of data processed,
- purposes of processing,
- legal bases,
- categories of data recipients,
- international transfers,
- retention periods,
- security measures.
28.2. These records demonstrate VIRTWAVE’s commitment to GDPR accountability principles.
29. DATA PROTECTION IMPACT ASSESSMENTS (DPIA)
29.1. For high-risk processing that may significantly affect Users, VIRTWAVE conducts a DPIA.
29.2. DPIAs may apply to:
- fraud monitoring tools,
- advanced analytics systems,
- changes to data infrastructure,
- new cookie-based tracking technologies.
29.3. DPIAs ensure:
- necessity and proportionality,
- mitigation of risks,
- compliance with GDPR Art. 35 requirements.
30. CONTACTING VIRTWAVE REGARDING PRIVACY MATTERS
Users may contact VIRTWAVE with privacy inquiries, requests, or complaints using the following information:
Email: [email protected]
Address:
VIRTWAVE GLOBAL FZCO
Unit No: 1608-029, Jumeirah Bay 2
Plot No: JLT-PH2-X2A
Jumeirah Lakes Towers
Dubai, United Arab Emirates
Company Number: DMCC191668
VIRTWAVE will make reasonable efforts to respond promptly and transparently.
31. DATA PROTECTION OFFICER (IF APPLICABLE)
31.1. VIRTWAVE may appoint a Data Protection Officer (“DPO”) in the future as required by EU or Member State law.
31.2. If appointed, DPO contact details will be published on the Website and incorporated into this Policy.
32. GOVERNING LAW, DISPUTES, AND INTERPRETATION
32.1. Governing Law
32.1.1. This Privacy Policy is governed by the laws of the United Arab Emirates.
32.1.2. This does not limit mandatory protections afforded under:
- GDPR for EU/EEA Users,
- UK GDPR for UK Users,
- Federal or provincial laws for Canadian Users,
- U.S. state privacy laws for U.S. Users.
32.2. Resolution of Privacy Disputes
32.2.1. Users should first contact VIRTWAVE to resolve concerns amicably.
32.2.2. EU/EEA/UK Users may escalate to their national supervisory authorities if needed.
32.2.3. Nothing in this Policy restricts your right to lodge a complaint with a regulator.
32.3. Interpretation
32.3.1. Section titles are for convenience only and do not affect interpretation.
32.3.2. Any reference to legislation includes amendments and updates.
32.3.3. The English version of this Policy prevails over translations.
33. ANNEX A – EXTENDED DEFINITIONS
This Annex supplements the definitions in Section 4.
A.1. “Processing”
Includes:
- collection,
- storage,
- retrieval,
- analysis,
- modification,
- disclosure,
- transmission,
- deletion.
A.2. “Controller”
The entity determining:
- why personal data is processed,
- how personal data is processed.
A.3. “Processor”
Any third party acting on VIRTWAVE’s instructions, bound by contractual obligations.
A.4. “Personal Data Breach”
Any event leading to:
- accidental loss,
- unauthorized disclosure,
- alteration,
- destruction,
- or access to personal data.
A.5. “Pseudonymization”
Processing personal data such that it cannot be attributed to a specific individual without additional information.
A.6. “Data Subject”
Any natural person whose personal data is processed.
A.7. “Sensitive Data”
Special categories under GDPR including:
- racial or ethnic origin,
- political opinions,
- religious beliefs,
- genetic or biometric data,
- health data,
- sex life or orientation.
VIRTWAVE does not process such data intentionally.
A.8. “Supervisory Authority”
A government body responsible for enforcing data protection law within a specific region.
34. FINAL STATEMENT
34.1. By using the Website or purchasing Digital Content from VIRTWAVE, you acknowledge that:
- you have read and understood this Privacy Policy,
- you agree to its terms,
- you consent to the processing of your personal data as described herein,
- you understand your rights and how to exercise them.
34.2. VIRTWAVE is committed to maintaining transparency, security, and respect for User privacy at every stage of data processing.