Privacy Policy
Introduction
Effective date: March 30, 2026. This privacy policy covers data practices on bookofdead-demo.nz. I run this site alone as a technical documentation project. All data entry, updates and checks come from me without external help or funding. Contact me at [email protected]. The domain targets New Zealand users but accepts global visitors. No physical address exists since operations happen remotely.
This informational resource focuses on slot game demos like the Book of dead. Expect details on mechanics, features and play without real money involvement. No gambling services operate here. Data handling stays minimal to match the site's scope.
Review applies to anyone accessing pages, reading content or interacting minimally. Policies follow New Zealand Privacy Act 2020 basics alongside general web standards. Updates occur rarely; check date above for current version.
Data I Collect
Collection limits to essentials for site function and basic monitoring. Server logs capture IP addresses, browser types, device info, visited pages, referral sources and timestamps for each request. These logs help diagnose errors and track usage patterns.
No forms exist for user input so names, emails or payment details never enter my systems. Analytics run server-side only without third-party trackers like Google Analytics. Cookie use confines to session management; no persistent identifiers store.
Geolocation derives indirectly from IP addresses but never requests precise location data. Search queries or page parameters log if present in URLs. Volume remains low given traffic levels on a niche documentation site.
If contact occurs via email, that message data processes separately under standard email protocols. Site itself generates no user accounts or profiles.
How Data Gets Collected
Data arrives automatically during page loads. Web servers record HTTP request headers including IP from the connection. Timestamps mark exact arrival times in UTC adjusted to site timezone.
Cookies set via standard HTTP responses for session continuity. Browser sends back on subsequent requests. No JavaScript trackers inject extra data collection.
Referral info pulls from HTTP referer header when available. User agents parse for OS, browser version and screen resolution hints. All happens passively without active polling.
Periodic log rotation clears old entries; current setup retains basics for short periods only. No aggregation into user profiles occurs across visits.
Purposes for Collected Data
Primary use focuses on site operation. Logs spot broken links, server overloads or unusual traffic spikes. Patterns inform content updates like popular sections needing expansion.
Session cookies maintain page state if navigation requires it, though most pages stand alone. IP data blocks evident abuse like repeated error requests from single sources.
Basic stats guide decisions on hosting needs or content focus without identifying individuals. No marketing or ad targeting employs this data. Improvements target technical accuracy over user engagement metrics.
Email contacts receive direct replies; no lists build from them. Overall approach keeps data tied to immediate operational needs.
CTA
High-conversion casino CTA goes here but since informational, adapt to demo play.
Sharing Data with Others
No data shares with third parties. Hosting provider accesses raw logs for infrastructure management under strict contracts. No sales, trades or disclosures happen.
Legal requests compel disclosure if served properly, though rare for this scale. Aggregated anonymous stats might appear in public updates but never link to specifics.
No ad networks, partners or affiliates receive access. Email communications stay private between sender and my address.
Future changes would announce here first with opt-out if applicable, but current practice holds zero sharing.
Cookies and Similar Tech
Site sets session cookies only, expiring on browser close. No third-party cookies load from external domains. Purpose limits to basic navigation persistence.
Local storage or indexedDB avoid entirely. HTTP-only flags prevent JavaScript access where set. Cookie policy aligns with minimalism.
Browsers allow cookie management; disable if preferred, though functionality drops slightly. No essential cookies force acceptance banners.
Tracking pixels or beacons absent. Privacy respects default browser settings without overrides.
Data Storage and Retention
Logs store on secure hosting servers in New Zealand data centers. Retention spans 30 days max before automated purge. Exceptions for security incidents extend slightly.
Cookies hold no long-term data. Email archives follow personal retention based on relevance, typically short.
Backups encrypt and rotate frequently. No cloud services beyond hosting use data copies. Physical access controls at provider level.
Deletion happens on schedule without recovery paths for routine data.
Your Rights Regarding Data
Request access to logged data tied to your IP by emailing [email protected] with details. I provide summaries within reasonable time.
Correction applies if inaccuracies found, though logs reflect raw facts. Deletion requests honored for non-essential data post-retention.
Objection to processing grounds in legitimate interests reviewed case-by-case. Withdrawal of consent not applicable since no explicit consents collect.
Portability limited due to data format. Complaints direct to me first; escalation to NZ Privacy Commissioner if unresolved.
Security Measures in Place
Hosting uses HTTPS everywhere with TLS 1.3 certificates renewed automatically. Servers patch regularly against known vulnerabilities.
Firewall rules block malicious IPs. Logs monitor for intrusion attempts with alerts. No public databases expose.
Passwords use strong hashing if any internal. Backups offsite encrypt fully. Access logs audit admin actions, which is just me.
Regular scans detect malware. Updates apply promptly to all software stacks.
Children's Privacy
Site targets adults interested in slot info. No content aims at under-16s. Data collection assumes mature users.
No verified age gates exist; parents supervise as needed. If child data arrives accidentally, delete on notice.
No special protections beyond general policy since no kid-focused features.
International Data Transfers
Data stays within New Zealand hosting. No transfers outside occur. IP logs might resolve to foreign origins but store locally.
If future expansion changes this, adequacy decisions or safeguards apply. Current setup avoids cross-border flows.
Policy Changes
Updates post here with new effective date. Major shifts email subscribers if any exist. Check back periodically.
Version history tracks silently. No retroactive application without notice.
Contact Information
Reach me at [email protected] for questions. Responses aim quick. No phone or form; email only.
Include IP or visit details for specific requests. I handle personally.
