Privacy Policy of Island Hoppers
(Version dated 31 August 2026)
WHY DO WE HAVE THIS POLICY?
This Privacy Policy explains how NEXTERS GLOBAL LIMITED collects, uses, shares, retains and protects personal data in connection with Island Hoppers (the Project), and how users may exercise their privacy rights.
This Policy is an information notice. It is not a request for consent and it is not the Terms of Service. Where consent or another separate choice is required for advertising, non-essential analytics, tracking technologies, cookies or marketing communications, that choice will be requested separately and may be withdrawn or changed through the applicable controls.
WHO ARE WE?
The controller responsible for the Project is NEXTERS GLOBAL LIMITED, 107 Faneromenis Avenue, 6031 Larnaca, Cyprus (Nexters, we, us or our). Privacy enquiries and requests may be sent to privacy@nextersglobal.com or submitted through the Support section of the Project.
This Policy applies to the Project, the Project's official websites and the account, authentication, payment, community and support channels that Nexters makes available for the Project. A separate notice may apply to a specific promotion, website technology or optional feature.
WHAT DATA DO WE PROCESS AND WHY?
We process only the personal data reasonably necessary for the purposes described below. The exact information available to us depends on how a user accesses and uses the Project, the relevant platform and the choices made by that user. Where particular information is required to create or secure an Account, complete a purchase or respond to a request, the relevant interface will identify the required fields and the consequences of not providing them.
| Purpose | Legal basis | Data categories | Retention | Additional information |
|---|---|---|---|---|
| Provide and administer the Project | Contract; legitimate interests where necessary to maintain the service | Account and Project identifiers; account status; language and general region; game progress; game state; inventory; settings; achievements; entitlements and service history | While the account is active or the information is needed to provide the Project; after confirmed deletion, for the documented operational and backup cycle, subject to legal holds and the exceptions described below | Needed to create and maintain the account, save progress, provide features and restore eligible game state |
| Authentication, account recovery and security | Contract; legitimate interests in security, fraud prevention and protection of users and the Project | Login and platform identifiers; authentication linkages; IP address; device and application information; approximate country or region; security, anti-cheat, fraud and abuse signals | For the period necessary to secure the account and investigate relevant incidents, disputes or abuse; stale signals are deleted or de-identified when no longer necessary | We do not require full advertising profiles for account security. Authentication secrets are restricted and protected |
| Purchases, virtual items and entitlements | Contract; legal obligations; legitimate interests in reconciliation, fraud prevention and legal claims | Transaction and order identifiers; date, amount and currency; purchased item or entitlement; store or payment channel; refund and chargeback status | For the period required by applicable tax, accounting or consumer law and for proportionate reconciliation, refund, chargeback, fraud and claims periods | The Project's transaction record is limited to payment and entitlement information needed for these purposes and does not require full payment-card credentials |
| Customer support and account recovery | Contract; legitimate interests in resolving requests, maintaining safety and defending claims; legal obligations where applicable | Contact details provided by the user; account and device details; support correspondence; screenshots and attachments; purchase, fraud and account-recovery information relevant to the request | For the duration of the case and a limited period needed for follow-up, security, disputes or legal requirements; unnecessary attachments and closed history are deleted or minimised | Users should not include sensitive or unrelated information in free-text submissions |
| Operate, diagnose and improve essential functionality | Contract; legitimate interests in service availability, troubleshooting, performance and proportionate product improvement | Technical logs; session and service events; device, operating-system and application information; crash reports; diagnostics; performance and feature-availability information; feedback, bug reports, screenshots, recordings and test results voluntarily provided by users | User-level data and voluntarily provided test or feedback materials are retained only while reasonably needed to diagnose, validate or improve the relevant issue or feature; they may then be deleted, aggregated or anonymised | We distinguish operational information needed for the service from optional analytics or tracking that requires a separate choice |
| Optional analytics, attribution and advertising | Consent where required; where applicable law permits processing without consent, the relevant notice will identify the lawful basis and any required opt-out | Advertising identifiers; attribution events; selected usage events; device and application information; consent and opt-out signals | Until consent is withdrawn, an applicable opt-out is exercised or the information is no longer needed for the stated purpose, subject to the period shown in the relevant notice or control | Optional technologies are not activated merely because a user accepts the Terms or receives this Policy |
| Service and marketing communications | Contract or legitimate interests for service messages; consent for marketing where required, or another lawful basis identified in the relevant notice and subject to any required opt-out | Contact information; account and language information; communication preferences; delivery and interaction records | Service-message records are kept as needed for the account or relevant issue. Marketing data is kept until withdrawal, opt-out or expiry of the applicable permission | Marketing choices are separate from essential account, security, purchase and support communications |
| Community features and moderation, where made available | Contract; legitimate interests in providing community functions, safety and enforcement; legal obligations where applicable | Public posts and profile details; reports; moderation and enforcement records; limited technical and account information needed to investigate misconduct | Public content is retained while the relevant community service and account remain active. Reported content may be retained longer where needed for safety, enforcement or claims. Any contractual licence to User Content does not extend retention or processing of personal data beyond the purposes and periods described in this Policy | Private communications are not treated as a general transaction asset and are subject to additional necessity and access controls |
| Respect privacy choices and rights | Legal obligations; legitimate interests in accountability and preventing prohibited reuse | Consent version and status; withdrawals; objections; opt-outs; deletion and restriction status; rights-request and suppression records | For as long as necessary to implement the choice, complete the request, demonstrate compliance and prevent reactivation or re-import of excluded data | These records preserve the user's choice; they do not create permission for a new optional use |
| Evaluate and implement business or Project changes | Legitimate interests in evaluating and carrying out a transaction, protecting our business and assets, maintaining service continuity and handling rights and claims; contract where necessary following a valid contract transfer; consent only where applicable law requires it for the particular processing | Relevant information from the categories described in this Policy, limited to what is reasonably necessary for the relevant review, transaction or continuity purpose | Transaction-review copies are kept only while needed for the evaluation and are deleted or returned when no longer needed. Information transferred for continued operation follows the applicable purpose-specific period | This does not mean that every category or record will be disclosed or transferred |
| Comply with law and handle claims | Legal obligations; legitimate interests in establishing, exercising or defending legal claims | Information relevant to regulatory requests, litigation, fraud, tax, accounting, consumer claims, sanctions and enforcement of the Terms | For the period required by the applicable obligation, limitation period, legal hold or proceeding | Only information relevant to the obligation or claim is used for this purpose |
HOW DO WE COLLECT DATA?
Directly from users. This includes information submitted through account, support, community, purchase and privacy-choice interfaces.
Automatically from the Project. This includes account, gameplay, session, device, security, diagnostics and service events generated when the Project is used.
From other organisations. This may include app stores, authentication and payment providers, social or platform services selected by users and, where the Project changes operator, the organisations involved in that change. Where we obtain personal data indirectly, the relevant notice will identify the source or source category when required by applicable law.
HOW AND WHY MAY WE SHARE DATA?
We disclose personal data only where this is reasonably necessary for a purpose described in this Policy, required by law or requested by the user. The information and recipient depend on the relevant service, feature or event, and each disclosure remains subject to purpose limitation, data minimisation and appropriate contractual and security controls.
Recipients
Project service providers. Hosting, infrastructure, security, authentication, support, communications, diagnostics and other providers acting under appropriate contractual and security controls.
Platforms and payment providers. App stores, authentication platforms and payment providers involved in a user's access, purchase, refund or entitlement.
Advertising and analytics recipients. Only for the stated optional purpose and in accordance with the user's separate consent or other locally applicable choice.
Professional advisers and business-transaction recipients. Auditors, legal and financial advisers, financing sources, prospective or actual purchasers, affiliates and successor operators involved in a contemplated or completed transaction.
Authorities and claim recipients. Courts, regulators, law-enforcement bodies and other persons where disclosure is legally required or necessary for a properly established legal claim.
Business and Project changes
As part of the ordinary development of our business and the Project, we may disclose or transfer personal data in connection with a contemplated or completed merger, acquisition, financing, reorganisation, sale of assets, transfer of the Project or change of operator. Recipients may include an affiliate, prospective or actual purchaser, successor operator and the advisers and service providers assisting with the transaction. Any disclosure will be limited to what is reasonably necessary for the relevant transaction, protection of our business and assets, continuity of the Project, or the establishment, exercise or defence of legal claims, and will take place only as permitted by applicable law.
Where appropriate, we will use aggregated or anonymised information before disclosing personal data. Access to personal data for transaction review will be subject to confidentiality and appropriate security controls. If a proposed transaction is not completed, the recipient will be required to delete or return the personal data when it is no longer needed, except where limited retention is required by law. If responsibility for the Project changes, relevant account, gameplay, entitlement, transaction, security, support, technical, privacy-choice and age or protection information may be transferred only to the extent reasonably necessary to continue the Project and preserve users' rights and protections.
If another organisation becomes responsible for the Project or for processing personal data, Nexters or that organisation will provide a separate notice as required by applicable law. The notice will identify the new controller, relevant effective date, material changes, purposes and categories of processing and available rights. A business or operator change does not by itself authorise personalised advertising, marketing audiences, optional analytics or tracking by a new controller; those activities remain subject to a separate lawful basis and any consent or opt-out required by applicable law.
INTERNATIONAL TRANSFERS
The Project and its providers may process personal data in countries other than the user's country. Where personal data protected by the GDPR is transferred outside the European Economic Area to a country that is not covered by an applicable adequacy decision, the transfer will not take place unless a lawful mechanism under Chapter V GDPR and any required supplementary measures are in place. The applicable mechanism will be identified in the relevant notice and, depending on the circumstances, may include approved standard contractual clauses or another legally recognised safeguard. Information about the applicable safeguard and how to obtain a copy may be requested at privacy@nextersglobal.com.
The same requirements apply before a prospective purchaser or successor operator located outside the European Economic Area, or its authorised personnel outside the European Economic Area, access personal data protected by the GDPR. A new controller will provide information about its own international transfers and safeguards as required by applicable law.
HOW LONG DO WE RETAIN DATA?
The processing table states the principal periods or criteria. We also consider the purpose for which the information was collected, the status and duration of the account, security and fraud risks, the sensitivity of the information, applicable platform requirements, statutory record-keeping periods, limitation periods, pending rights requests and legal holds. Data that has reached its applicable deletion point is not retained or transferred merely to preserve a historic copy. Transaction-review copies are deleted or returned when their purpose ends or a proposed transaction is not completed, unless limited retention is required by law. When personal data is no longer required, it is deleted, anonymised or isolated from ordinary use. Backups may remain for a limited technical cycle and are not restored for a prohibited purpose.
HOW CAN USERS CONTROL THEIR DATA?
Depending on applicable law, a user may have the rights described below. We may need reasonable information to identify the relevant account and verify the request.
Access and information. Request information about processing and a copy of relevant personal data.
Correction. Correct inaccurate or incomplete personal data.
Deletion. Request deletion where the information is no longer needed or another applicable condition is met. Deleting data necessary for the account may result in loss of access, progress or entitlements, subject to mandatory rights.
Restriction and portability. Request restriction or receive portable data where the applicable legal conditions are met.
Objection. Object to processing based on legitimate interests. We will stop unless we demonstrate compelling legitimate grounds or the processing is needed for legal claims. Processing for direct marketing will stop following a valid objection.
Withdrawal of consent. Withdraw a consent at any time without affecting processing already carried out lawfully. Withdrawal applies to the optional purpose and does not constitute termination of the Terms.
Complaint. Complain to the competent data-protection authority, including the authority in the user's place of residence, work or the alleged infringement where applicable.
Requests may be submitted through the Support section of the Project or to privacy@nextersglobal.com. If responsibility for the Project changes, applicable objections, restrictions, withdrawals, opt-outs and deletion requests will continue to be respected. Where needed to complete a pending request, the minimum request and account information may be securely provided to the organisation responsible for completing it. A user will not be required to waive a privacy right as a condition of continuing to use the Project.
Automated processing
Where automated signals or tools are used to help detect fraud, cheating, security incidents or content that may breach the rules, they may support investigation, prioritisation or moderation. Nexters will not make a decision based solely on automated processing that produces legal effects or similarly significantly affects a user unless the applicable law permits it and the user receives the information and safeguards required by that law, including any available right to obtain human intervention, express a point of view and contest the decision.
CHILDREN'S PRIVACY
The Project is not intended to be used by a child in a manner prohibited by applicable law. Where applicable law requires parental or guardian authorisation for a child's use of the Project or for a particular processing activity, that authorisation must be obtained through the applicable process. We minimise information relating to children and do not use identified child accounts for behavioural advertising, look-alike audiences or optional profiling that applicable law prohibits. If COPPA applies, we will provide the notices and obtain the verifiable parental consent required by it before collecting, using or disclosing a child's personal data, except where an applicable exception permits otherwise.
A parent or guardian who believes that a child's information has been processed contrary to applicable law may contact us through Support or at privacy@nextersglobal.com to request review, correction, restriction or deletion. We may ask for proportionate verification of the adult's identity and relationship to the child.
HOW DO WE PROTECT DATA?
We use technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss and destruction. Measures are selected according to the nature and risk of the processing and may include encryption in transit and at rest, access controls, authentication, logging, segregation, testing, incident response and contractual controls for providers and other recipients. No security measure can eliminate all risk, and users should protect their credentials and devices and report suspected compromise through Support.
CHANGES AND NOTICES
We may update this Policy to reflect changes in the Project, legal requirements, processing activities or the entity responsible for the Project. The current version and effective date will be displayed with the published Policy. Material changes will be notified through the Project, email or another appropriate direct channel before they take effect where required by law. Receipt of a privacy notice is not consent to optional processing, and continued use is not treated as consent where affirmative consent is required.
CONTACT US
NEXTERS GLOBAL LIMITED
Company registration number: HE 257099
VAT number: 12257099H
107 Faneromenis Avenue
6031 Larnaca, Cyprus
Email: privacy@nextersglobal.com
This Policy is written in English. If a translation conflicts with the English version, the English version prevails to the extent permitted by applicable law.