Legal
Supplemental UK & EEA Privacy Statement
Effective Date: August 8, 2026
Last updated: August 8, 2026
Superhyper Games – Ziya Andırın addresses this Supplemental Statement to individuals located in the European Economic Area ("EEA"), the United Kingdom ("UK"), and Switzerland only (together, "UK & EEA"). It supplements our main Privacy Policy ("Core Policy") and explains how we process your personal data under the EU General Data Protection Regulation, the UK GDPR, and the Swiss Federal Data Protection Act (together, "GDPR" for short below). If this Statement conflicts with the Core Policy, this Statement takes priority for UK & EEA residents.
1. Data controller and representatives
The data controller is Superhyper Games – Ziya Andırın, AYDEMİROĞLU MAH. ATATÜRK CAD. NO:78 CEYHAN/ADANA, Türkiye (Tax ID: 0690584396).
Under Article 27 GDPR (and the equivalent UK GDPR provision), a company outside the UK/EEA that regularly, on a large scale, offers services to UK/EEA residents may be required to appoint a local representative for data-protection purposes. We have not yet appointed an EU or UK representative. If you expect meaningful traffic or players from the UK/EEA, you should arrange one (a number of firms offer this as a paid service) before you rely on this page being complete.
2. Contacting us about privacy
Email hello@superhyper.games with any privacy question or request.
3. What we collect and how
See Section 2 of our Core Policy. We also use cookies and similar technologies as described in our Cookie Policy.
4. Purposes and legal bases
For each purpose in Section 3 of our Core Policy, we rely on one of the following legal bases under Article 6 GDPR:
- Contract performance (Art. 6(1)(b)) — providing the game or feature you've asked for, activating a purchase, giving you player support
- Legal obligation (Art. 6(1)(c)) — where a law requires us to process your data a certain way
- Legitimate interests (Art. 6(1)(f)) — operating, securing, and improving our Services, preventing fraud, communicating with you, and internal analytics, balanced against your rights (details available on request)
- Consent (Art. 6(1)(a)) — personalized/targeted advertising, and any non-essential cookies. You can withdraw consent at any time, with future effect, by emailing hello@superhyper.games
For essential cookies, the legal basis for storing and accessing information on your device is Art. 5(3) of the ePrivacy Directive as implemented locally (in the UK, the Privacy and Electronic Communications Regulations 2003, "PECR"). Any further processing of data collected via essential cookies relies on contract performance or legitimate interests (providing a working website).
UK update: since 5 February 2026, the Data (Use and Access) Act 2025 lets UK websites use certain low-risk analytics cookies (used solely for aggregate statistics) on an opt-out basis instead of requiring opt-in consent. This exception doesn't cover advertising-related cookies — our advertising cookies (see Section 6 of our Core Policy) still require your opt-in consent under PECR, since they support ad targeting. PECR fines were also raised to match UK GDPR levels (up to £17.5 million or 4% of global turnover).
5. Who receives your data
See Section 4 of our Core Policy for the categories of recipients (service providers, legal/safety disclosures, AdTech Providers, consent-based disclosures, and business transfers).
6. International data transfers
We and our processors and AdTech Providers may process your data outside the UK/EEA, including in Turkey and the United States. Turkey does not currently have a UK or EU adequacy decision, so transfers there need an additional safeguard — we rely on Standard Contractual Clauses (and the UK's International Data Transfer Addendum, where relevant) with the parties we share data with, or another valid transfer mechanism. Transfers to the U.S. rely on Standard Contractual Clauses, the EU-U.S. Data Privacy Framework (where the recipient is certified), or another valid mechanism. You can ask us for more detail on these safeguards using the contact details above.
7. How long we keep your data
See Section 12 of our Core Policy. Where we must retain data solely to meet a legal obligation, we restrict its processing to that purpose until we can delete it.
8. Your rights under GDPR
Subject to the conditions in GDPR/local law, you have the right to:
- object to our processing of your data, including for direct marketing, or where we rely on legitimate interests or the public interest
- get confirmation of, and access to, the personal data we hold about you
- have inaccurate personal data corrected
- have your personal data erased, where it's no longer needed or required by law
- request that we restrict processing of your data in certain circumstances
- receive your data in a structured, machine-readable format, and transmit it elsewhere (data portability)
- withdraw consent at any time, without affecting the lawfulness of earlier processing
- lodge a complaint with a supervisory authority
You can find your supervisory authority here:
- EEA: edpb.europa.eu
- United Kingdom: ico.org.uk
- Switzerland: edoeb.admin.ch
To exercise any of these rights, email hello@superhyper.games. We may need to verify your identity before acting on your request, and may ask follow-up questions to clarify its scope.
9. UK Children's Code
The ICO's Children's Code (Age Appropriate Design Code) applies to online services "likely to be accessed by children" — a much broader test than being deliberately child-directed, and it covers anyone under 18, not just under-13s. Casual mobile games are squarely in scope even when they're built for a general audience, and the ICO has an active monitoring programme specifically reviewing mobile games' compliance. The Code's 15 standards include things like: assessing and documenting whether your game is likely to appeal to under-18s, not showing children personalized/targeted ads, applying privacy-protective settings by default, avoiding "nudge" techniques that push children to weaken their privacy, and being cautious with randomized rewards (loot-box-style mechanics).
We haven't yet completed a documented Children's Code risk assessment for our games. If UK users are a real part of your audience, this should be a near-term priority — it's a live enforcement focus for the ICO right now, not a theoretical risk.
10. UK Online Safety Act
The UK's Online Safety Act 2023 imposes duties — including children's safety risk assessments and codes of practice — on "user-to-user" services: those that let users interact with each other, such as through chat, multiplayer features, or shared content. Our current games don't include these features, so we don't expect the Act's user-to-user duties to apply yet. If we add chat, multiplayer, or similar social features to a game, we'll need to revisit this, since Ofcom has been actively enforcing this Act, including against services based outside the UK.
11. Do you have to give us your data?
No — but we can't provide our Services without some personal data from you.
12. Changes
We may revise this Statement from time to time. We'll post changes here and update the "Last updated" date above.
This page is a general-purpose starting template and not legal advice. The missing EU/UK representative flagged in Section 1 is a real gap, not a placeholder to skip — confirm with a lawyer whether you need one given your expected UK/EEA user volume, before you rely on this page being complete.
Stuck, found a bug, or just want to say hi?
Our support team usually replies within one business day.