Privacy Policy
This Privacy Policy of Middle-earth Enterprises, LLC applies to you if you are located outside the United States. If you are located in the United States, please see the U.S. Privacy Policy.
General Privacy Policy
Last Updated: July 20, 2026
1. Introduction
This Privacy Policy describes how Middle-earth Enterprises, LLC (the “Company,” or “we,” “our,” or “us”) processes your Personal Data (as defined below) when you visit the Lord of the Rings Fan Club website at https://lotr.com (or any subsequent URL which may replace it) and any Company operated subdomains, directories and subdirectories of such site that link to or expressly incorporate this Privacy Policy (the “Site”), when you are in contact with us, or when you use our various products and services (collectively, the “Services”).
We process your Personal Data only for the purposes described herein and, in each case, only to the extent necessary to achieve the respective purpose.
If you have further questions or comments regarding privacy or wish to assert your legal rights, please contact the Company using the contact details in the section “Contact Details” below.
Please read this Privacy Policy before you use or register for our Services, for information on how we collect, use and distribute your Personal Data.
2. Categories of Personal Data We Process and Why
Depending on the specific Services you use and how you interact with us, we will process various categories of your Personal Data.
Definition of Personal Data: “Personal Data” refers to any information relating to an identified or identifiable natural person. Personal Data is information that identifies you directly or indirectly (also in conjunction with other data).
Personal Data Voluntarily Provided: We may receive the following categories of Personal Data directly from you when you choose to provide it to us.
- Contact details: Name, email address, address, phone number.
- User account details: Current and prior usernames, login information (the email address or mobile phone number to which we send one-time sign-in codes), user ID, age-screen result (see Section 6), language settings, marketing preferences, and social-media username.
- Correspondence with you: Any information included in your messages, phone calls, emails and survey responses.
- Optional profile information you choose to provide: This may include your birthday information, an approximate location you set, reading and viewing lists, and fan-profile survey answers where offered. If you opt into the member map, we coarsen your chosen location to approximately an 11 km grid before storage and use it only to display the opted-in member map. We do not display your precise location.
- Content and interactions: Posts, replies, comments, reviews, reactions, survey responses, submissions, reports, other text-based content you create, and messages you send to MEE or a Website administrator. The Services do not offer private messaging between users. The account Messages area is used only for communications between MEE or a Website administrator and an individual user, such as communications about account administration, support, moderation, safety, or violations. Public posts are public; Administrator Communications are not public but may be accessed and retained by authorized personnel for the purposes described in this Policy.
- Challenge proof images: Only where a designated online contest or challenge requests photographic proof may you upload a photo or screenshot to confirm that you completed the requested task. The image is a private verification input, is not public User Content, and is never displayed to other users. We may send it to Anthropic, our artificial-intelligence provider, solely to check whether it shows the challenge task. A passing check may approve completion automatically; anything else is sent to an authorized human reviewer. The proof images are not made public and are deleted from MEE’s systems within 24 hours after a decision is made; Anthropic ordinarily deletes API inputs and outputs from its backend within 30 days. Anthropic does not use it to train its models. MEE may retain the resulting completion decision, reward, and limited anti-abuse record, but not the proof image itself. Do not include identification documents, personal financial information, intimate imagery, other sensitive or unlawful material, or material unrelated to the requested challenge. In a personal photograph taken by you or on your behalf, do not depict anyone under 18 other than yourself, and do not depict any other identifiable person unless you have that person’s permission. The restrictions in the preceding sentence do not apply to people or fictional characters depicted in pre-existing films, television programs, games, or other content lawfully made available to the public, provided that you are otherwise permitted by applicable law to submit that content.
- Privacy choices and consent records: We keep records of privacy choices you make, including the choice selected, the policy or notice version presented, the date and time of the choice, and related technical or account information needed to maintain an auditable record.
- Waitlist and invitation records: Contact details, signup time, referral or campaign source, invitation status, eligibility, and related records used to administer a staged Public Beta rollout.
- Reward, entitlement, and anti-abuse records: Mathoms, points, badges, completed challenges, earned entitlements, and limited records used to prevent duplicate rewards, fraud, or abuse**.**
Personal Data Automatically Collected: We may also collect certain categories of Personal Data from you automatically when you use our Services, including the following details about your network, device, and interactions with our Services:
- Security and request data. We process your IP address and related request information, such as the date and time of the request, requested page, user agent, and basic server log information, to operate the Site, apply security rate limits, prevent abuse, troubleshoot errors, and protect the integrity of the service. Where possible, we use IP addresses transiently for these purposes and do not use them to identify you.
- Browser and device information. We may collect browser and device information that your browser or device makes available, such as browser type and version, device type, operating system and version, language settings, time zone setting, screen or viewport size, and similar diagnostic information. We use this information to display the Site correctly, maintain compatibility, diagnose technical issues, and secure the Site.
- Participation and personalization data. If you give Personalization consent or enable a specific participation feature, we may collect activity associated with club features, including posts, replies, reactions, game plays, survey answers, activity history, pages opened, challenges completed, progress events, feature interactions, and coarsened location shares. We use this information to operate the requested participation features and personalize your experience.
- Analytics data. If you give Analytics consent, we use Google Analytics to collect usage analytics, such as pages viewed, events, session information, approximate location derived from technical signals, browser and device information, and first-party analytics cookies or similar identifiers. Google Analytics does not load unless you have given Analytics consent. If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of optional analytics and similar non-essential technologies, unless you later make a more specific choice through our consent controls.
- Referral attribution. If you arrive through a member or partner referral link, we may set a first-party referral cookie or similar identifier that remembers the referral source for up to 30 days so that the referring member or partner can be credited. Where required by applicable law, we set this cookie only with your consent.
- Bug-report metadata. If you submit a bug report, we may automatically attach technical information needed to investigate the issue, such as the page where the bug occurred, viewport size, browser type and version, operating system, and the time of submission. You may also choose to include additional information in the report.
- Special categories of Personal Data. We do not request or permit special-category Personal Data in profiles, posts, surveys, administrator-user messages, bug reports, or other submissions. This includes Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health information, genetic or biometric data used to identify a person, or data concerning sex life or sexual orientation. Do not submit special-category Personal Data about yourself or another person. If such information is detected, we may remove it and will process or retain it only where an Article 9 GDPR condition or another applicable legal basis permits or requires us to do so, such as where necessary to establish, exercise, or defend legal claims or address an immediate safety issue.
Mandatory and optional personal data. Certain fields are required for us to provide a requested feature or service. For example, if you create an account we require an email address or mobile phone number to which we send one-time sign-in codes and a username; if you contact us or an administrator, we require enough contact and correspondence information to respond. Where information is optional, we identify it as such or the feature can be used without providing it. If you do not provide required information, we may be unable to create the account, respond to the request, or provide the relevant feature.
Purposes of Processing: You can read more about our purposes for processing your Personal Data and which categories of Personal Data we process to achieve each purpose in the table below. Where we rely on legitimate interests as a legal basis, we have carried out a balancing assessment to ensure that such interests (such as operating, improving, and securing our Services and providing good customer service) do not override your fundamental rights and freedoms.
We may use information that does not identify you (including former Personal Data that has been anonymized) for other purposes.
Sources of Data: We and our service providers collect Personal Data directly from you and automatically from your device or browser, as described above. We may also receive referral-source information through a member or partner link; information about you contained in another user’s post, report, or submission; information made available when you interact with our official social-media accounts; and information from a third-party service when you direct it to provide information to us. Where Article 14 GDPR or similar law applies, we provide the required information within the applicable period, including no later than the first communication or first disclosure where required, unless a lawful exception applies.
No Automated Processing for Significant Decisions: We do not use your Personal Data to make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, except for the automated content moderation described below, which does not produce such effects. We may use analytics and statistical tools to better understand how users interact with the Site, but such processing does not result in automated decisions with legal or similarly significant effects.
Automated Content Moderation: When you post text on our Services (such as community posts, replies, and submissions), the text of your post, together with limited account information (such as your username and user ID), is automatically reviewed before publication for compliance with our Community Guidelines (set out in our Terms of Service). This review is performed on our behalf by Anthropic, a U.S.-based service provider acting as our data processor under a data processing agreement that limits its processing to providing the moderation service to us (and prohibits use of your content to train its models). Our legal basis for this processing is our legitimate interest in keeping our Services safe and enforcing such Community Guidelines.
If your post does not pass the automated review, it will not be published. You will be informed of the reason and may rephrase and resubmit your post, and you may request review of the decision by a member of our team directly within the Services: each moderation decision includes an option to ask for a second look, and our team's reply is delivered to the Messages area of your account. Certain moderation processes also include human review by default. The only automated decisions made are whether a post is published and whether a challenge completion is approved; we do not use this processing to build a profile of you, and it produces no legal or similarly significant effect concerning you. Any account-level action, such as suspension of your account, is taken only with human involvement.
Text that does not pass the automated review is not published and is not saved in MEE’s public-content database. Anthropic ordinarily deletes API inputs and outputs from its backend within 30 days, but may retain information longer where necessary to enforce its Usage Policy, including for content flagged by its safety systems, or where required by law. Our contract prohibits Anthropic from using your content to train its models. If you request human review, MEE retains the text as part of the related Administrator Communication and moderation record. Submissions that queue for human review and are not accepted are deleted from MEE’s active systems within 30 days of the decision, subject to limited legal, safety, and backup exceptions described in Section 3.
When you submit a photo or screenshot to complete a designated online contest or challenge, we may send the image to Anthropic solely to check whether it shows the requested task. A passing check may approve your completion automatically; anything else is sent to an authorized human reviewer. The proof image is not made public and is deleted after a decision is made. Anthropic does not use it to train its models. MEE may retain the resulting completion decision, reward, and limited anti-abuse record, but not the proof image itself.
3. How Long Will Your Personal Data Be Stored
We retain each category only for as long as reasonably necessary for the disclosed purpose. Core account data is retained while the account is active and afterward only as needed for security, legal compliance, disputes, and recordkeeping. Participation data is retained until you use the deletion control, withdraw the relevant choice, or delete the account; active-system deletion is described in Section 9. Earned reward and entitlement records are retained while the account is active and deleted with the account. Waitlist and invitation records are retained until you withdraw, accept access and create an account, or the relevant rollout is complete and the record is no longer needed. Prior usernames are retained while the account is active for community safety and are deleted with the account unless linked to an ongoing safety, fraud, legal, or dispute matter. Referral identifiers expire after no more than 30 days. Precise coordinates are used transiently; a coarsened location is retained until you disable the feature or delete the account. Security, diagnostic, and duplicate-reward records are retained only for the limited period reasonably necessary to protect the Services and prevent abuse. Administrator Communications, support, moderation, and complaint records are retained for as long as reasonably necessary to resolve the matter, protect users, enforce our terms, and comply with law. Consent and privacy-choice evidence is retained for as long as needed to honor the choice and demonstrate compliance, generally no longer than seven years unless a longer period is required. Marketing data is retained until you opt out or withdraw consent. Analytics is retained under the applicable settings and provider terms and, where possible, in aggregated or anonymized form. Automated moderation retention is described in Section 2. Challenge proof photos and screenshots are deleted after the verification decision; the resulting completion decision, reward, and limited anti-abuse record may be retained separately as described above.
However, in some cases, Personal Data may be stored for longer due to laws or other regulations to which we are subject, or for as long as the retention of Personal Data is required due to other legal reasons. This may include keeping your Personal Data for the period necessary for us to pursue legitimate business interests, comply with (and demonstrate compliance with) legal obligations, resolve disputes or enforce our agreements. If there are legitimate reasons opposing a deletion, for instance statutory retention or storage periods, processing of these Personal Data will be limited. In such cases, the processing of Personal Data will stop as soon as the reason for further storage ceases to exist, for example if the statutory retention period expires.
If the right to process Personal Data is based on your consent, the Personal Data will be deleted or anonymized as soon as reasonably possible after the purpose of the storage is canceled or if you withdraw your consent. You can withdraw your consent at any time. The withdrawal of your consent does not affect the lawfulness of the processing carried out on the basis of the consent before the withdrawal.
4. Which Third Parties Will Have Access to Your Personal Data?
Other users and the public
Information you choose to publish through public text-based features may be visible to other users and, where the feature is publicly accessible, to anyone on the internet. This may include your username, public profile fields, posts, replies, comments, reviews, reactions, and submissions. Challenge proof photos and screenshots are private verification inputs and are never displayed to other users. If you enable the member map, the audience selected for that feature can view the coarsened location and any associated profile information shown by the feature. Administrator Communications are not public. The Services do not offer private messaging between users. Public information may remain in copies, quotations, search indexes, or caches controlled by others after you delete it from the Services.
Our service providers
We engage a limited number of service providers, including hosting and infrastructure providers (database, authentication, transient challenge-proof image processing, and website hosting and delivery), communications providers (transactional email and SMS sign-in code delivery), analytics providers (engaged only with your consent), Anthropic for text moderation and challenge-proof verification, and marketing service providers, who may process Personal Data on our behalf for the purposes described above as our data processors. The suppliers provide services related to, for example, the Site, member communications, marketing, and IT support. The suppliers may process your Personal Data where necessary to carry out their assignments. All their processing of your Personal Data is under our responsibility. We enter into data processing agreements with our suppliers and require corresponding data-protection obligations.
Some features of the Services cause your browser to communicate directly with third-party providers: when you use the location feature, your browser sends your precise coordinates to a reverse-geocoding service provider (we then coarsen the result to an approximate location before storage, as described in Section 2); and when you view the member map, the map tiles load from a third-party map provider’s content delivery network, so your IP address reaches that provider’s servers.
Merchandise links and third-party sellers: MEE acts only as a referral source for merchandise. If you follow a merchandise link, you leave the Services and any purchase is made directly from the third-party seller through the seller’s own store, which may use Shopify or another commerce provider. MEE is not the seller or merchant of record and does not handle checkout, payment, order fulfillment, shipping, returns, or refunds. MEE does not receive your checkout, payment, order, delivery, or return information from the seller unless you separately choose to provide information to MEE in a support or other communication. The seller’s and commerce provider’s privacy terms apply to their processing. Referral attribution information described in Section 2 may be used to identify the source of a link, but it does not include checkout or payment information.
We do not sell your Personal Data.
Transfer for legal or law enforcement reasons
We may also disclose Personal Data to law enforcement or the relevant civil authorities to enforce legal rights and to comply with the law, or to comply with a decision by a government or other competent authority. Our legal basis for such sharing of Personal Data is compliance with legal requirements.
Additionally, we will disclose your Personal Data to authorities if we have reason to believe that such disclosure is required to respond to potential or actual violations or interference with the Company’s rights, property, reputation, business operations, users or others who may be harmed, or if we believe disclosures are required to protect our rights or us against fraud, or to comply with any lawsuit, court order or legal process served. Our legal basis for sharing the Personal Data is our legitimate interest in protecting and defending our business during a legal process.
Corporate Transactions
In the context of corporate transactions (acquisition, sale, restructuring of companies or company shares), third parties may gain access to your Personal Data. Our legal basis for sharing the Personal Data is our legitimate interest in participating in a corporate transaction.
5. International Transfers of Personal Data
We are a global business. Personal Data may be stored and processed in any country where we have operations or engage service providers. We may transfer Personal Data to our service providers and other recipients in countries other than the country in which the Personal Data was originally collected. Those countries may have data protection rules that differ from those of your country.
However, we will take measures to ensure that any such transfers comply with applicable data protection laws and that your Personal Data remains protected according to the standards described in this Privacy Policy. In certain circumstances, courts, law enforcement agencies, regulatory agencies, or security authorities in those other countries may be entitled to access your Personal Data.
If you are located in the European Economic Area (“EEA”), the United Kingdom (“UK”), or Switzerland, we comply with applicable laws to provide an adequate level of data protection for the transfer of your Personal Data to the U.S. and other countries outside of the EEA, the UK, and Switzerland (“Third Countries”). We ensure that international data transfers to Third Countries are governed by an adequate data transfer mechanism based on a risk assessment regarding the transfer. We rely on one or more of the following mechanisms: EU Standard Contractual Clauses, or verification that the European Commission has adopted an adequacy decision for the respective Third Country. For transfers of Personal Data originating in the UK, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and for transfers originating in Switzerland, we rely on the EU Standard Contractual Clauses as adapted for Swiss data protection law.
For further information about the EU Standard Contractual Clauses, please contact us by email at info@middleearth.com.
Where the LGPD applies, we transfer Personal Data outside Brazil only under a mechanism permitted by Article 33 of the LGPD and the ANPD International Data Transfer Regulation, including an applicable adequacy decision, the ANPD’s standard contractual clauses, approved specific contractual clauses or global corporate rules, or another legally available mechanism. You may request information about, or a copy of, the contractual safeguards applicable to a transfer by contacting info@middleearth.com. We will respond within the period required by applicable law, currently 15 days for requests covered by the ANPD regulation, subject to permitted protection of commercial and industrial secrets.
6. Children's Personal Data
Protecting children’s privacy is particularly important to us. Our Terms of Service do not permit anyone under 16, or any higher minimum age required by applicable law for member features, to create an account or use those features. A permitted user who is below the age of majority may use the Services only if permitted by applicable law and with the permission of a parent or legal guardian, as described in the Terms of Service. If applicable law requires a verified parental or guardian process that MEE does not provide, the minor may not create an account or use member features.
When you create an account, we use a neutral age screen and ask for birth month and year solely to determine whether you meet the minimum age. The age input is evaluated for that check and then discarded; it is not stored. If the age screen or other information indicates that a user is below the minimum age, we block account creation and further collection, promptly delete any Personal Data already received unless limited retention is permitted or required by law, and, as applicable, instruct our service providers to delete the information. A failed age check sets a temporary cookie for 24 hours solely to prevent repeated attempts. The optional birthday feature will not accept information indicating that a user is below the minimum age.
Because the minimum age to use the Services is 16, which equals or exceeds the age of digital consent in every EEA country and the United Kingdom, users below the applicable age of digital consent are not permitted to use the Services. Where, notwithstanding the foregoing, our processing of a child’s Personal Data is based on consent and the child is below the applicable age of digital consent in their country, that consent is valid only if it is given or authorized by the child’s parent or guardian. Consent-based features must not be used by a child below that age without such parental or guardian authorization.
Where Brazilian law applies, we process children’s and adolescents’ Personal Data in their best interests and obtain parent or guardian consent where required by the LGPD.
If we learn that we have processed a child’s Personal Data in violation of our Terms of Service or without any consent or authorization required by applicable law, we will promptly delete the relevant Personal Data, disable or restrict the relevant account or feature where appropriate, and, as applicable, instruct our service providers to delete the information, unless retention of limited information is required or permitted by applicable law.
Parents and guardians may contact us using the details in the “Contact Details” section below if they believe that a child not permitted to use the Services under our Terms of Service has provided Personal Data to us, or that a child’s Personal Data has been processed without any required consent or authorization. We may take reasonable steps to verify the requester’s identity and relationship to the child before responding.
7. Security of Personal Data
We are committed to data security within the framework of applicable data protection laws and current IT security standards. Your Personal Data is protected against unauthorized access and loss through the use of various technical, physical, administrative, and contractual measures. We have taken appropriate technical and organizational measures intended to ensure that we comply with our Privacy Policy.
All our employees are required to comply with data security and privacy policies, have appropriate instructions, and receive regular training. Individuals requiring access to perform their tasks are legally bound by a confidentiality and non-disclosure agreement.
8. Third Parties' Processing of Personal Data
We remind you that in various technical areas, we work with external partners who offer websites and services accessible from our Services. The fact that we link to a website is not an endorsement, authorization, or representation of our affiliation with that third party. If you click on a link to a third-party site, including an advertisement, you will leave the Site and go to the site you selected. The third party is responsible for their own processing of your Personal Data. If you visit a third-party site, you should consult that site's privacy policy before providing any Personal Data.
Our Site uses cookies and similar technologies. Please read our Cookies Policy to learn more about the use of cookies.
9. Data Protection Rights for European Residents
If you are located within the EEA, UK or Switzerland, you have several rights when we process your Personal Data, including those described below. You can contact us at any time if you have questions or wish to exercise any of the rights described below. Please direct your data protection requests to info@middleearth.com. We reserve the right to take appropriate security measures to ensure that you are who you claim to be when you contact us. If you cannot satisfactorily demonstrate your identity, we may not be able to fully meet your request.
Access to Personal Data
You have the right to know what Personal Data we are processing about you. If you wish to receive copies of your Personal Data, you can request a compiled register extract from us that contains all the Personal Data we process about you.
Correction and Deletion
If your Personal Data is incomplete or incorrect, you have the right to have it corrected or supplemented. You also have the right to request deletion, subject to applicable exceptions. Please keep in mind that we may not be able to provide the Services if required Personal Data is deleted. You can correct much of your Personal Data in your profile settings and can erase participation data at any time through Privacy settings (https://www.lotr.com/privacy-settings) without contacting us. “Participation data” means your activity within the club: posts, replies, reactions, game plays, survey answers, activity history, and coarsened location shares. The “Delete my participation data” control removes that information from your active account and MEE’s active systems immediately and stops its use for participation or personalization. It does not remove things you have earned (including Mathoms, points, badges, and completed challenges), records of your privacy and consent choices, prior usernames kept for community safety, Administrator Communications and support or moderation records, your waitlist and invitation record, or short-lived security and anti-abuse records used to prevent duplicate rewards. Those excluded records are retained separately under our legitimate interests or legal obligations for the purposes and periods described in Section 3. Earned reward and entitlement records are deleted when your account is deleted. Other excluded records are also deleted or deidentified when no longer needed, although limited records may be retained after account deletion where reasonably necessary for legal compliance, security, fraud or abuse prevention, dispute resolution, protection of users, or demonstrating consent. Limited backup copies may remain until overwritten through our normal backup cycle.
Restrictions of our Processing
Under certain conditions, you have the right to request that we restrict our processing of your Personal Data. This means that we mark the Personal Data so that it is only processed for certain specific purposes in the future. Please keep in mind that we may not be able to provide you with the Services if we restrict the processing of your Personal Data.
Right to Data Portability
In some circumstances you have the right to request the transfer of your Personal Data to another data controller in a structured, commonly used, and machine-readable format.
Right to Object
You have the right to object to the processing of Personal Data based on the legal basis of legitimate interest. You may also object to processing of your Personal Data for direct marketing purposes.
Right to Lodge a Complaint
If you believe that we have not processed your Personal Data correctly, you have the right to lodge a complaint with the data protection authority in your country. You can view the contact information of EEA supervisory authorities at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en, the contact information of the UK Information Commissioner’s Office at https://ico.org.uk/global/contact-us/, and the contact information of the Swiss Federal Data Protection and Information Commissioner at https://www.edoeb.admin.ch/en/contact-2.
Right to Withdraw Consent
If you have given consent to certain processing, you have the right to withdraw it at any time. We will stop the consent-based processing as soon as reasonably possible after withdrawal, except that limited records may be retained where required by law or reasonably necessary to demonstrate and honor your choice. Withdrawal does not affect processing already carried out lawfully. You can withdraw each optional consent individually, such as the Personalization and Analytics choices, through Privacy settings or the cookie settings dialog.
Where required by applicable law, we recognize browser- or device-based opt-out preference signals, including Global Privacy Control. When we detect such a signal, we treat it as a withdrawal of consent to optional analytics and similar non-essential technologies, unless you later make a more specific choice through our consent controls.
10. Rights of Individuals in Brazil
The Lei Geral de Proteção de Dados (“LGPD”) may apply where processing occurs in Brazil, where Personal Data is collected in Brazil, or where processing relates to offering or providing goods or services to individuals located in Brazil. Subject to the conditions and exceptions in the LGPD, you may request:
• confirmation of whether we process your Personal Data;
• access to your Personal Data;
• correction of incomplete, inaccurate, or outdated Personal Data;
• anonymization, blocking, or deletion of unnecessary or excessive Personal Data or Personal Data processed unlawfully;
• portability in accordance with ANPD regulations and subject to protection of commercial and industrial secrets;
• deletion of Personal Data processed on the basis of consent, subject to lawful retention;
• information about public and private entities with which Personal Data has been shared;
• information about the ability to withhold consent and the consequences of withholding it;
• revocation of consent and opposition to processing carried out without consent where the LGPD’s requirements have not been met; and
• review of decisions made solely through automated processing that affect your interests and information about the criteria and procedures used, subject to protection of commercial and industrial secrets.
You may also petition the Brazilian National Data Protection Authority (“ANPD”). Where the LGPD requires a simplified response to a confirmation or access request, we provide it immediately where practicable; otherwise, we provide a clear and complete response within the period required by the LGPD, currently 15 days.
To exercise these rights, email info@middleearth.com. We may request additional information where justified to verify your identity and protect Personal Data. Our encarregado under the LGPD may be contacted at info@middleearth.com.
11. Contact Details
If you are located in a jurisdiction outside the United States that is not specifically addressed above, you may have similar rights under applicable local data protection laws, which you may exercise by contacting us using the details below. If you have any questions, wish to file a complaint, or wish to make any request authorized by this Privacy Policy, please contact us, the controller, at the following address or email:
Email: info@middleearth.com
3142 Constitution Dr., Livermore, California 94551
If you are in the European Economic Area, you may contact our representative in the European Union pursuant to Article 27 GDPR, Middle Earth Enterprises AB, by post at:
Middle Earth Enterprises AB
Tullhusgatan 1 b, 652 09 Karlstad
Sweden
Middle Earth Enterprises AB also serves as Middle-earth Enterprises, LLC’s legal representative under Article 13 of the Digital Services Act (“DSA”). Notices intended for the DSA representative may be sent to Middle Earth Enterprises AB, Tullhusgatan 1 b, 652 09 Karlstad, Sweden; email: info@middleearth.com; telephone: +1 925 344-4045.
You may also contact our Data Protection Officer by email at dpo@embracer.com.
This Privacy Policy has been designed to be accessible to people with disabilities. If you experience any difficulties accessing the information here, please contact us at the email address stated above.
12. Changes to This Privacy Policy
From time to time, we update this Privacy Policy to reflect any changes in how we handle your Personal Data. Should we make such significant changes to how we process Personal Data that we are obliged to notify you about the changes or ask for your consent again, we will do so.
