Política de Privacidad

Actualizado el 15 septiembre 2025 - Versión 1.15

We have implemented strict safety and confidentiality protocols to protect your data. Your privacy is our top priority, and we collect personal data only with your explicit consent. This Privacy Policy explains how and why we process your personal data on our Website and outlines your rights as a data subject.

We are committed to processing your personal data lawfully and for legitimate purposes. We prioritize your privacy and take measures to ensure the security of your data. Specifically, we handle your personal data in compliance with Regulation (EU) 2016/679, known as the General Data Protection Regulation (GDPR), which governs the protection of individuals' personal data and its free movement within the European Union. For more information, you can view the full text of the GDPR here.

1. Data Controller

The data controller of your personal data is Erysta Limited a company incorporated in Hong Kong under the number 76111914, and having its registered office at Unit 2A, 17/F, Glenealy Tower, Central, Hong Kong SAR.

Our contact details:

2. Who Does This Privacy Notice Apply To?

This privacy notice applies to individuals who access, browse, and use our Website. Its aim is to inform you how we collect and process your personal data through your use of the Website.

We receive and store any information you enter on our Website or provide to us in other ways, such as browsing our Website, registering an account, purchasing products, contacting us, or posting material. By doing so, you consent to our collection and use of this information for the specified purpose.

If we ask for your personal information for a secondary purpose, such as marketing, we will either ask you directly for your explicit consent or provide you with an opt-out option.

Your personal information will not be shared with third parties without your consent and only within the limits permitted by law.

You can always choose not to provide certain information, even though it might be necessary to make a purchase or use all Erysta services.

3. Types of Personal Data We Process

The information we gather from customers helps us personalize and continually improve your shopping experience at www.erysta.com. Here are the types of information we collect:

  • Information You Give Us

    This includes personal details you provide when creating an account, browsing product pages, subscribing to newsletters, or making purchases. For example, this may include your name, email address, phone number, and payment information. We use this information to respond to your requests, personalize future shopping experiences, improve our services, and communicate with you. We handle personal data based on your implied or expressed consent, or as required by law.

  • Automatic Information

    We use "cookies" and collect certain types of information when your web browser accesses www.erysta.com. This includes your IP address, browser type, operating system, and browsing activity. Cookies help us simplify the login process, ensure the security of registered users, facilitate online shopping, and analyze website traffic to enhance user experience.

  • Third-Party Data

    We may obtain data from third-party sources, including social media platforms, to offer you personalized content and services. For instance, if you log in using a third-party service like Google or Discord, additional data such as your profile information may be collected. We do not share or sell this data without your explicit consent. If you use third-party services to access our Website, be aware that additional data may be stored and subject to their privacy practices.

4. Why We Collect Your Data

We collect personal data to provide and improve our services. The table below explains in detail the purposes of processing, the legal basis under the GDPR, and how long we keep your data.

Below is a summary of the personal data we collect, the purposes for which we process it, the legal basis under the GDPR, and the applicable retention periods. This table is intended to provide clear and transparent information in compliance with Articles 13 and 14 of the GDPR.

PurposeLegal BasisRetention Period
Managing your accountContract (Art. 6(1)(b))Until account deletion
Guest cart savingLegitimate interest (Art. 6(1)(f))5 days
Orders & Tax ComplianceLegal/contract (Art. 6(1)(c)/(b))10 years or as required by law
Customer SupportLegitimate interest (Art. 6(1)(f))Until you ask for deletion
Newsletter and marketingConsent (Art. 6(1)(a))Until you unsubscribe
Backups and system integrityLegitimate interest (Art. 6(1)(f))1 year
Security & Legal ComplianceLegal/legit. interest (Art. 6(1)(c)/(f))Up to 10 years
Legal Claims & Dispute ResolutionLegal obligation (Art. 6(1)(c))As long as required by law

For any questions regarding your data or to request deletion, you can contact us at [email protected] or manage your privacy settings in your user account.

6. Your Rights

Under data protection laws, you have several important rights regarding your personal data. Below is a summary of these rights:

  • Right of Access: You have the right to request access to the personal data we hold about you. This allows you to verify whether we are processing your data and to obtain a copy of it.
  • Right to Rectification: If you believe that any personal data we hold about you is inaccurate or incomplete, you have the right to request that it be corrected. You can also update certain information directly by logging into your account.
  • Right to Erasure ("Right to be Forgotten"): You can request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or if you withdraw your consent.
  • Right to Restrict Processing: You may ask us to restrict the processing of your personal data in certain cases, for example when you contest its accuracy or object to its processing.
  • Right to Object: You have the right to object to the processing of your personal data when it is based on our legitimate interests or used for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.
  • Right to Data Portability: You may request to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller, where technically feasible.
  • Right to Lodge a Complaint: If you believe that your data protection rights have been violated, you have the right to file a complaint with a supervisory authority, typically in your country of residence or work.
  • Right to Withdraw Consent: If we process your personal data based on your consent, you may withdraw that consent at any time. This does not affect the lawfulness of processing carried out prior to withdrawal.

To exercise any of these rights, or if you have questions or concerns about how we process your personal data, please contact us at [email protected]. We will respond as promptly as possible, in accordance with applicable data protection laws.

7. How We Protect Your Data

  • Data Security: We implement appropriate technical and organizational security measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. These measures include, but are not limited to, encryption, access controls, pseudonymization, and regular security audits.
  • Data Backup: We perform encrypted daily backups of personal data to ensure data integrity and availability. These backups are securely stored in geographically distributed data centers located in Germany, France, and the United Kingdom (London). This redundancy ensures resilience, disaster recovery, and compliance with European data residency requirements.
  • Data Breach Notification: In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and, if required, we will inform affected users without undue delay, in accordance with applicable data protection laws.

7. External Data Sources

We may use data obtained from external sources, including social media platforms, to provide you with personalized content and services. This data is never shared without your explicit consent. If you use third-party services to log in to or access our Website, additional data may be stored.

This data is used to enable or enhance features such as:

  • Log-in Experience (e.g. Single Sign-On via external providers)
  • Browsing Preferences (e.g. setting your language or displaying prices in your local currency)

If you use a "Single Sign-On" (SSO) option from services such as Google, Discord, or Steam, the following data may be collected and stored:

  • Profile Picture
  • Username
  • External Account ID
  • External Account Provider

8. Third-Party Services

We may use third-party providers—such as payment gateways, communication platforms, and technical service providers—who collect, use, and process your personal data strictly as necessary to deliver the services they offer on our behalf.

We use PayPal for payments and other services. When you use PayPal to make payments on our Website, PayPal may collect personal data you provide, such as payment and identifying information. PayPal uses this information to operate and improve its services, including for fraud detection, harm and loss prevention, authentication, and legal compliance. The processing of this information is subject to the PayPal Privacy Statement.

We encourage you to review the privacy policies of any third-party providers you interact with during transactions on our platform, to understand how they handle and safeguard your personal data.

We may share your personal data with the following categories of recipients:

  • Payment Operators: To process payments related to your purchases or account activity.
  • Service Providers: For technical, IT, and infrastructure services.
  • Accounting, Legal, and Advisory Entities: To comply with financial, regulatory, or legal requirements.
  • Social Media Platforms: If you engage with social login features or share content from our Website.
  • Publishers: For digital product delivery (e.g., Games, DLC or Gift Card). We may share non-personally identifiable information such as your country, IP address, and a unique system-generated identifier. In specific cases like gift card activation, publishers may require personal details (name, address, date of birth), which will only be shared with your consent at checkout.

Please note: when interacting with third-party services, your data may be subject to the laws of the jurisdictions in which these providers or their infrastructure operate.

9. Cookies

Cookies are small text files stored on your device when you visit a website. They contain information about your preferences, settings, and interactions with the site, helping enhance and personalize your browsing experience. Our Website uses two main types of cookies:

  • Persistent Cookies: These remain on your device for a defined duration or until you delete them. They help remember your settings and preferences for future visits.
  • Session Cookies: These are temporary cookies that are automatically deleted when you log out, leave the website, or close your browser. They are used to maintain session continuity during your visit.

You can manage your cookie preferences through your browser settings. However, disabling certain cookies may limit the functionality of www.erysta.com.

10. Cookies We Use

Cookies play an essential role in ensuring the proper functioning and enhanced usability of our Website. We use the following categories of cookies:

  • Essential Cookies: These cookies are strictly necessary for the operation of our Website and services. They enable core functionalities such as user authentication, shopping cart management, language and currency selection. Because they are essential to the functioning of the Website, they cannot be disabled. Without them, key features of the site would not work as intended.
  • Analytics Cookies: We use Google Analytics to better understand how users interact with our Website and to improve performance and user experience. While these cookies do not serve advertising purposes directly, some data may be linked to Google Ads and Google Merchant Center for technical integration. The data collected is anonymized and not used to build personal advertising profiles.
  • Embedded Content Cookies: Some pages on our Website may include embedded content from third-party platforms such as YouTube. These platforms may place cookies that are outside of our control, even if we do not use their services for advertising purposes. We do our best to prevent unnecessary tracking, but due to the way embedded media works, some cookies may still be set.
  • Payment Gateway Cookies: When using third-party payment providers such as PayPal, Apple Pay, or Google Pay, these services may set their own cookies during the checkout or redirection process. These cookies are managed by the respective payment platforms and are necessary to complete and secure your transaction. We do not control these cookies, and we recommend reviewing the privacy policies of the respective providers for more information.

For more details about how we use cookies and your rights in relation to them, please refer to our Privacy Policy.

11. Transfer of Data Outside the EU

Our Website is operated by a company headquartered in Hong Kong, which is also the legal entity responsible for your personal data. However, the majority of our infrastructure, systems, and databases are hosted within the European Union (EU), meaning that your data is primarily stored and processed in the EU.

In certain cases, your personal data may be transferred to and processed in countries outside of the EU. This occurs when we rely on third-party providers — such as payment gateways, authentication platforms, or cloud services — who may be located outside the European Economic Area (EEA).

For example, if you log in using external platforms like Google, Discord, or Steam, or complete a payment via providers like PayPal or Apple Pay, your data may be transferred to and processed by these companies in their respective jurisdictions.

The main third-party services we use and their registered addresses include:

  • Google: Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, US.
  • X: X Corp. - 1355 Market Street, Suite 900, San Francisco, CA 94103, US.
  • Steam: Valve Corp. - 10400 NE 4th Street, Suite 1400, Bellevue, WA 98004, US.
  • Discord: Discord Inc. - 444 De Haro St, San Francisco, CA 94107, US.
  • Twitch: Twitch Interactive Inc. - 350 Bush Street, 2nd Floor, San Francisco, CA 94104, US.
  • Meta: Meta Platforms Inc. - 1 Meta Way, Menlo Park, California, 94025, US.
  • PayPal (US): PayPal, Inc. - 2211 North First Street, San Jose, California 95131, US.
  • PayPal (HK): PayPal Hong Kong Ltd. - 15th Floor, Rooms 1506-07, Wan Chai, 999077, HK.
  • Apple Pay: Apple Inc. - One Apple Park Way, Cupertino, California 95014, US.
  • Google Pay: Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, US.
  • Cryptomus: Xeltox Enterprises Ltd. - 422 Richards Street, Unit 170, Vancouver, British Columbia, V6B 2Z4 CA,
  • Cryptomus: Xeltox Enterprises Ltd. - 422 Richards Street, Unit 170, Vancouver, British Columbia, V6B 2Z4 CA,

All transfers are conducted in accordance with applicable data protection laws, including the implementation of adequate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent legal mechanisms.

12. Children’s Personal Data

Our Platform and services are intended exclusively for individuals aged 18 or older, or who meet the minimum legal age required in their country to enter into binding contracts and assume full legal responsibility.

We do not knowingly collect or process personal data from individuals under the age of 18. If we become aware that we have unintentionally collected such data without verifiable parental or guardian consent, we will promptly delete it upon confirmation.

If you believe that a minor has provided us with personal data, please contact us at [email protected]. We will investigate and take appropriate action without delay.

13. Links

Our Website may include links to third-party websites, plug-ins, or applications. Clicking these links or enabling those features may allow third parties to collect or share data about you.

We do not control these third-party platforms and are not responsible for their privacy practices, terms, or content. We strongly encourage you to review their respective Privacy Policies and Terms & Conditions before interacting with them.

14. Changes to this Privacy Policy

This Privacy Policy was last updated on June 23, 2025, and is effective as of that date.

We may modify this Privacy Policy periodically to reflect changes in our practices, legal obligations, or for other operational reasons. Updates will be posted on this page, and we may also notify you through other appropriate means.

Your continued use of our Website after any changes constitutes your acceptance of the revised Privacy Policy.