Loading...

000%

En

  • En

  • De

  • Ua

  • Ru

  • Es

  • TR

  • PT

  • Privacy Policy

    This Privacy Policy ("Policy") describes the approach and practices regarding the processing of Personal Data of Users of the MANAVA Platform, implemented by MANAVA CORPORATION, the Company registered under the Law of Seychelles, registered No is 236130, registered address is House of Francis, Room 303, Ile Du Port, Mahe, Seychelles ("MANAVA", "we", "us", "our").

    This Policy has been prepared in accordance with applicable data protection legislation, including the European Union General Data Protection Regulation 2016/679 (GDPR), the ePrivacy Directive 2002/58/EC, and other applicable law.

    Terms beginning with a capital letter and not defined in this Policy have the meanings assigned in the Platform Terms and Conditions, available at https://manava.io/terms_of_use.

    The key data processing principle of MANAVA is minimisation. MANAVA has been intentionally designed as a platform with minimal collection of Personal Data, using licensed Partner-Providers for the processing of sensitive data categories.

    1. Definitions

    The following terms are used in this Policy:

    "MANAVA Platform" or "Platform" means the MANAVA Gaming Ecosystem — a competitive skill-based gaming platform provided by MANAVA through the Website and the App, including, without limitation, SWAG, MANAVA CORPORATION, MANAVA Billiards, and other games and functionality.

    "Services" and "Products" mean the digital gaming products and services offered by MANAVA through the Platform, including participation in Tournament Mode and Skill Match, WinPass, Alliance Key, Oracle subscriptions, Marketing Slots, In-game Items, closed-loop internal gaming credits (NAVA), and other digital products.

    "Personal Data" means any information relating to an identified or identifiable natural person, in accordance with the definition set out in Article 4(1) GDPR.

    "User" or "you" means any natural or legal person using the Platform, the Website, or the App, and holding an active account on the Platform.

    "Website" means https://manava.io, including all subdomains and mobile versions.

    "App" means the MANAVA mobile application for iOS and Android operating systems.

    "Partner-Providers" means independent licensed service providers engaged by MANAVA to perform specialised functions (identity verification, payment processing, analytics, etc.), acting as independent Data Controllers or Data Processors.

    2. Role of MANAVA as Data Controller

    MANAVA CORPORATION acts as the Data Controller within the meaning of Article 4(7) GDPR exclusively in respect of the minimal set of data collected directly by MANAVA for the functioning of the Platform.

    MANAVA does NOT act as Data Controller in respect of:

    • identity documents and other verification documents — such data is collected and processed by independent licensed Partner-Providers acting as separate Data Controllers;

    • biometric data (facial images, verification video recordings) — processed exclusively by independent licensed identity verification providers;

    • payment card details, bank account information, and full payment credentials — processed by licensed payment processors (including Coinflow and other providers) acting as separate Data Controllers or Data Processors;

    • data recorded on public blockchain networks — blockchain infrastructure is decentralised and not controlled by MANAVA.

    This architectural minimisation model means that MANAVA does NOT process special categories of Personal Data (Article 9 GDPR), does not conduct systematic profiling of Users, and does not perform large-scale monitoring of User behaviour within the meaning of Article 37(1)(b) and Article 35(3) GDPR.

    3. Personal Data We Collect

    MANAVA intentionally limits the collection of Personal Data to the minimum necessary for the functioning of the Platform:

    3.1. Account Data

    • email address of the User;

    • username chosen by the User;

    • public address of the User's non-custodial crypto wallet;

    • interface preferences (language, region, notification settings).

    3.2. Technical Data

    • IP address (for security and fraud prevention purposes);

    • device type, operating system, browser version;

    • date and time of access to the Platform;

    • unique device identifier (for the mobile App).

    3.3. Platform Usage Data

    • history of participation in matches and tournaments (in aggregated form);

    • User activity within the Platform (anonymised analytics);

    • statistical records of NAVA transactions (internal gaming credits);

    • public blockchain transaction addresses associated with the account.

    3.4. Support Data

    • messages submitted by the User to MANAVA support;

    • descriptions of requests, inquiries, and complaints.

    MANAVA does NOT directly collect:

    • identity documents (passport, driver's licence, ID card);

    • biometric data (facial images, video recordings, fingerprints);

    • payment card details (card number, CVV, expiration date);

    • bank account details (account number, IBAN, SWIFT);

    • data concerning health, political views, religious beliefs, or other special categories of Personal Data;

    • data concerning minors (the Platform is intended exclusively for individuals aged 18 and over).

    4. Purposes and Legal Bases for Processing

    MANAVA processes Personal Data exclusively for the following purposes and on the following legal bases:

    4.1. Performance of Contract (Article 6(1)(b) GDPR)

    Processing is necessary for the provision of Platform Services: creation and maintenance of the User account, provision of access to gaming functionality, crediting of NAVA credits, dispute resolution.

    4.2. Legitimate Interests of MANAVA (Article 6(1)(f) GDPR)

    Processing is carried out on the basis of MANAVA's legitimate interests, directed at: ensuring Platform security; preventing fraud, cheating, and abuse; protecting the rights of MANAVA and third parties; improving Platform functionality; conducting aggregated analytics.

    4.3. Compliance with Legal Obligations (Article 6(1)(c) GDPR)

    Processing is necessary to comply with applicable legal requirements, including obligations relating to anti-money laundering and counter-terrorism financing, tax reporting, and responding to lawful requests from public authorities.

    4.4. User Consent (Article 6(1)(a) GDPR)

    The User's consent is requested separately and explicitly only in the following cases: sending marketing communications; use of optional cookies; other processing where consent is the mandatory legal basis. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal.

    5. Partner-Providers and Data Processing by Third Parties

    A key principle of MANAVA's operational model is the delegation of sensitive data category processing to licensed partners acting as independent Data Controllers.

    5.1. Identity Verification (KYC)

    Where User identity verification is required, MANAVA redirects the User to the platform of an independent licensed verification provider. Such provider collects and processes identity documents and biometric data pursuant to its own privacy policy, acts as an independent Data Controller, and bears independent responsibility for GDPR compliance.

    MANAVA receives from the verification provider solely the verification outcome (verified / not verified) and a unique verification identifier.

    5.2. Payment Processing

    All payments related to the acquisition of NAVA credits or Platform subscriptions are processed by licensed payment processors (including, without limitation, Coinflow and other providers). Such payment partners collect and process payment card details, bank account information, and other payment credentials pursuant to their own privacy policies, act as separate Data Controllers or Data Processors, and ensure compliance with PCI-DSS standards.

    MANAVA receives from payment partners solely the transaction outcome (status, identifier, amount in NAVA equivalent).

    5.3. Platform Analytics (PostHog)

    For the purpose of improving Platform functionality, MANAVA uses PostHog — a product analytics service. PostHog processes data on User interaction with the interface, acting as a Data Processor.

    Analytical processing is limited to observing interaction patterns with interface elements and does not include the collection of Personal Data entered by Users into text fields, authentication forms, or other sensitive areas. Personal data masking functionality is enabled by default.

    5.4. Blockchain Screening (AML)

    In connection with the use of public blockchain networks for external settlements with independent marketing partners, MANAVA engages licensed blockchain analytics providers to screen addresses for compliance with sanctions restrictions.

    5.5. Infrastructure and Hosting

    MANAVA uses infrastructure providers for server hosting, ensuring the operation of the Website and the App, content delivery, and security. Such providers act as Data Processors on the basis of applicable data processing agreements..

    5.6. Other Providers

    MANAVA may engage other service providers for professional support of its activities, including legal advisers, auditors, and accounting firms. All such providers are bound by confidentiality obligations.

    6. International Data Transfers

    MANAVA's server infrastructure is arranged in such a way as to minimise the need for cross-border transfers of Personal Data. Personal Data processed directly by MANAVA is stored predominantly within the European Economic Area (EEA).

    Where Personal Data is processed by licensed Partner-Providers, such providers act as separate Data Controllers and apply their own mechanisms to ensure compliance with international data transfer requirements, including, where applicable, Standard Contractual Clauses and adequacy decisions.

    7. Data Retention Periods

    MANAVA retains Personal Data only for the period necessary to achieve the corresponding processing purpose:

    • account data (email, username, wallet address) is retained during the active account lifetime and deleted within 30 days of the request for account closure, except where longer retention is required by applicable law;

    • technical data (IP addresses, device identifiers) is retained for 90 days from the date of the last activity;

    • Platform usage data and statistical transaction records are anonymised within 6 months and retained in aggregated form without the possibility of User identification;

    • support data is retained for 12 months from the resolution of the relevant inquiry;

    • marketing preference data is retained until withdrawal of consent.

    8. Cookies and Similar Technologies

    MANAVA uses a minimal set of cookies and similar technologies to ensure the functioning of the Platform.

    8.1. Strictly Necessary Cookies

    MANAVA uses strictly necessary cookies required for basic Platform operation: User authentication, session management, security controls, load balancing, fraud prevention. These cookies do not require User consent pursuant to Article 5(3) of Directive 2002/58/EC.

    8.2. Functional Cookies

    MANAVA may use functional cookies to store User preferences (language, region, interface settings). These cookies are applied subject to User consent obtained through the cookie management mechanism.

    8.3. Analytical Technologies

    MANAVA uses product analytics technologies (in particular, PostHog) to observe Platform usage patterns. Analytical technologies operate with masking of User Personal Data and are activated subject to User consent.

    8.4. Cookie Preferences Management

    Upon first visit to the Website, the User is presented with the ability to manage cookie settings through a cookie banner. The User may at any time change cookie settings through the relevant settings section.

    8.5. Browser-Level Controls

    Additionally, the User may control cookies through browser settings. Disabling strictly necessary cookies may impair Platform operation.

    9. Public Blockchain Transactions

    The User expressly acknowledges and agrees that certain interactions with the Platform involve public blockchain networks, on which transaction data (including wallet addresses, amounts, timestamps) is recorded publicly and is immutable.

    MANAVA does not control public blockchain infrastructure and has no technical ability to modify, delete, or restrict access to data recorded on the blockchain. The User acknowledges that blockchain transactions are inherently public, may be analysed by third-party blockchain analytics tools, and are not subject to the Personal Data processing controls typical of centralised systems.

    MANAVA is not liable for the technical inability to exercise data subject rights (including the Right to Erasure) with respect to Personal Data recorded on public blockchain networks.

    10. User Rights

    With respect to Personal Data processed directly by MANAVA, the User has the following rights under applicable data protection law:

    • Right of Access — obtain confirmation of data processing and a copy of the processed data.

    • Right to Rectification — correction of inaccurate or incomplete data.

    • Right to Erasure — request the deletion of Personal Data, except where retention is required by law.

    • Right to Restriction of Processing — restriction of processing in cases established by law.

    • Right to Data Portability — receive data in a structured, machine-readable format.

    • Right to Object — object to processing based on legitimate interests.

    • Right to Withdraw Consent — withdraw previously given consent without consequences for the lawfulness of prior processing.

    • Right to Lodge a Complaint — file a complaint with the competent supervisory authority (for Users in the Republic of Seychelles — Information Commission of Seychelles).

    To exercise their rights, the User may submit a request through the account settings section or through the contact channels. Requests are processed within 30 days of receipt.

    With respect to Personal Data processed by Partner-Providers, User rights are exercised directly with such providers in accordance with their policies.

    11. User Consent and Acknowledgements

    By registering on the Platform, the User expressly confirms the following:

    • the User has read this Privacy Policy and the Terms and Conditions, understands their provisions, and agrees to them;

    • the User has attained the age of 18 and has full legal capacity to enter into agreements with MANAVA;

    • all Personal Data provided by the User is accurate, complete, and current; the User bears full responsibility for the accuracy of the data provided;

    • the User understands and accepts MANAVA's architectural model whereby sensitive categories of data are processed by independent licensed Partner-Providers;

    • the User understands and accepts the public and immutable nature of blockchain transactions.

    The User may at any time withdraw consent to processing based on consent (marketing, optional cookies), without affecting the lawfulness of prior processing.

    12. Security and Incident Notifications

    MANAVA applies technical and organisational security measures aimed at protecting Personal Data from unauthorised access, alteration, disclosure, or destruction, proportionate to the volume and nature of the processing.

    Such measures include encryption in transit (TLS), role-based access controls, regular security audits of infrastructure and development practices, and personnel training.

    In the event of a Personal Data security incident presenting a risk to the rights and freedoms of Users, MANAVA will notify the competent supervisory authority within 72 hours of becoming aware in accordance with Article 33 GDPR, and will notify affected Users in accordance with Article 34 GDPR.

    MANAVA is not liable for incidents occurring at Partner-Providers acting as separate Data Controllers.

    13. Contact Information

    To exercise rights, submit requests, or obtain additional information regarding the processing of Personal Data, the User may contact MANAVA:

    • through the account settings section on the Platform;

    • through the support channels indicated on the Website;

    • at the official registered office: MANAVA CORPORATION, House of Francis, Room 303, Ile Du Port, Mahe, Seychelles.

    To exercise rights in respect of data processed by Partner-Providers, the User may contact the relevant providers directly.

    14. Limitation of Liability and Protective Provisions

    The User warrants that all Personal Data provided to MANAVA is accurate, complete, and current, and that the User has full right and authority to provide it. The User undertakes to indemnify MANAVA for any losses arising from inaccurate, incomplete, or unauthorised data.

    MANAVA acts in good faith in selecting Partner-Providers and enters into applicable contractual arrangements with each of them. MANAVA is not liable for independent actions, omissions, or breaches of Partner-Providers acting as separate Data Controllers, beyond MANAVA's direct control.

    MANAVA is not liable for Personal Data incidents caused by force majeure events, including, without limitation: coordinated cyberattacks at the level of state or organised criminal actors exceeding industry-standard defensive measures; failures of third-party infrastructure providers; regulatory or governmental disclosure requirements; other circumstances reasonably beyond MANAVA's control.

    To the maximum extent permitted by applicable mandatory law, MANAVA's aggregate liability for any claims arising from or related to the processing of Personal Data is limited to the amount of payments made by the User to MANAVA during the 12 months preceding the incident, or 500 (five hundred) US dollars, whichever is lower. This limitation does not apply to liability that cannot be excluded under mandatory applicable law.

    15. Changes to the Policy

    MANAVA reserves the right to periodically update this Policy in connection with changes in legislation, data processing practices, or developments in Platform functionality. The current version of the Policy is always available on the Website.

    Material changes to the Policy are communicated to Users at least 30 days prior to their entry into force through notices on the Website, in the App, and/or by email. Continued use of the Platform after the changes take effect constitutes acceptance of the updated version.

    16. Governing Law and Jurisdiction

    This Policy is governed by the law of the Seychelles and shall be interpreted in accordance therewith, taking into account applicable European Union rules on the protection of Personal Data.

    Users located in the European Union have the right to contact the competent supervisory authority of the Member State of their habitual residence, place of work, or place of alleged infringement.