Privacy information
kids.gamepix.com · Effective from 25 July 2026
Scope. This notice applies exclusively to kids.gamepix.com and, for this section, replaces every other GamePix policy. The main GamePix site operates under a different model and its policies do not apply here.
In one paragraph. GamePix KIDS asks children for nothing. There is no account, no form, no cookie, no analytics and no advertising on these pages. The only personal data that exists at all is the technical log every web server writes when a page is requested, kept briefly for security and then deleted. This page sets that out in the detail Article 13 of the GDPR requires.
- Who is responsible for the data
- What is processed, why, and on what legal basis
- Cookies and similar technologies
- No advertising and no profiling
- Who else sees the data
- The games
- Where the data is processed
- Security and personal data breaches
- Children
- Your rights
- Changes to this notice
1. Who is responsible for the data
The data controller is GamePix S.r.l., registered office at Via Marsala 29h, 00185 Rome, Italy, registered with the Companies Register of Rome under REA RM-1365971, VAT and tax code 12327731001, share capital € 15,232.00 fully paid (“GamePix”, “we”).
For any question about this notice, or to exercise a right, write to info@gamepix.com or to the registered office above.
Data Protection Officer. No Data Protection Officer has been appointed. GamePix has assessed, at company level and for all of its activities, that the conditions in Article 37(1) GDPR requiring one are not met; that assessment is documented internally and kept under review. Please use the contacts above for any data protection matter.
2. What is processed, why, and on what legal basis
2.1 Information a child gives us: none
There is no registration, no login, no form, no comment box, no chat, no upload and no search field anywhere in this section. A child cannot type anything into this site, so no name, email address, age, photograph, voice recording, contact detail or location is ever provided to us. We do not ask for it, and there is no mechanism through which it could reach us.
2.2 Technical server logs
Like every web server, ours records a short technical entry each time a file is requested. The entry contains the IP address of the request, the date and time, the address requested, the HTTP status code and the browser identification string. We state this explicitly because an IP address counts as personal data under the GDPR, and as a persistent identifier under the United States Children’s Online Privacy Protection Act, even though it is never linked to a name here.
- Categories of data subject. Visitors to this section, who are mostly children accompanied by an adult.
- Purpose. Delivering the requested page, keeping the service available, and detecting and stopping attacks and abuse.
- Legal basis. Our legitimate interest in operating and protecting the service, Article 6(1)(f) GDPR. We have weighed that interest against the rights of the children who use this section and consider it proportionate: the data is not used to identify anyone, is never combined with other information, is never used for marketing, and is deleted quickly.
- Under COPPA. These identifiers are used solely to support the internal operations of the site, as that term is defined in the COPPA Rule, which is the basis on which they may be collected without verifiable parental consent. They are never used to contact any individual or device, and never for advertising of any kind, including targeted advertising.
- Retention. 30 days, after which entries are deleted automatically. We keep no personal data for longer than this, and we do not retain it indefinitely for any purpose.
- Consequences of not providing it. None arise: the data is generated by the act of requesting a page and is not something anyone chooses to provide.
We keep no other record. Nothing about which games a child opened, how long they played, or how often they return is stored anywhere by us.
3. Cookies and similar technologies
The pages of this section set no cookies at all, and use no local storage, session storage, web beacons, pixels, advertising software development kits or device fingerprinting. Nothing is written to the device by these pages and nothing identifies a returning visitor.
The one thing that may be stored on the device is game progress saved locally by a game itself, described in section 6: it stays on the device, is strictly necessary to provide the game the child asked to play, and never reaches us.
You are not shown a cookie banner, and that is deliberate: under Article 122 of the Italian Personal Data Protection Code consent is required for storing or accessing information on a user’s device except where it is strictly necessary, and because these pages store nothing at all there is nothing to ask consent for. The cookies page explains this in full.
4. No advertising and no profiling
There is no advertising on these pages. No advertising network, tag manager or measurement script is loaded by any page of this site. No automated decision-making or profiling within the meaning of Article 22 GDPR takes place, and no personal data is used to build a profile of any visitor.
This also goes beyond Article 28 of the EU Digital Services Act, which prohibits presenting advertising based on profiling where a provider is aware that a user is a minor: here there is no advertising of any kind to profile for.
5. Who else sees the data
The server logs described above sit on infrastructure operated by Amazon Web Services (AWS), which acts as our data processor under Article 28 GDPR. The relationship is governed by the AWS Data Processing Addendum, under which the provider processes the data only on our documented instructions, keeps it confidential, applies the security measures set out in that addendum, and assists us with security incidents and with requests from data subjects.
Nobody else receives anything. We do not sell, rent, share or licence personal data. No data broker, advertising partner or analytics vendor is involved in this section, and no personal data is disclosed to public authorities except where we are legally obliged to do so. If any of this ever changes, this page will name the new recipient and explain their role before the change takes effect.
6. The games
Games are made by independent developers and run inside a frame served by GamePix from its own systems. For this section we select only games that request no personal information and contain no links out, and no game may load advertising, tag-management, consent-management or measurement components of any kind: we verify this before a game is published and again every time it is updated.
A game may keep the last level reached on the device so a child can carry on where they left off; that stays on the device and is not sent to us.
If you find a game here that behaves otherwise, tell us and we will take it down while we investigate.
7. Where the data is processed
The server logs described above are held on infrastructure provided by Amazon Web Services (AWS). Cloud infrastructure is not tied to a single machine or building, and the exact data centre handling a request can vary within the provider’s network, so this notice does not name one.
The relationship is governed by the AWS Data Processing Addendum. Where processing takes place outside the European Economic Area, whether because of the region in use or because of support and maintenance access, that addendum incorporates the Standard Contractual Clauses approved by the European Commission under Article 46(2)(c) GDPR, together with the supplementary technical and organisational measures it describes. A copy can be requested from the address at the top of this page.
If the arrangement changes we will update this page and rely on a valid transfer mechanism under Chapter V GDPR before the change takes effect.
8. Security and personal data breaches
The site is served over HTTPS only. We apply technical and organisational measures appropriate to the risk, as Article 32 GDPR requires, including restricted access to log data and automatic deletion on the schedule stated above. We maintain a written information security program covering the data described in this notice, with a named person inside GamePix responsible for it, as the COPPA Rule requires. Because we hold no identifying information about children, the impact of any incident on them is inherently limited. Should a personal data breach occur we will notify the Italian supervisory authority within 72 hours where Article 33 GDPR requires it, and inform the individuals concerned where Article 34 requires it.
9. Children
This section is directed to children and is built so that the question of parental consent does not arise: there is no personal data for a parent to consent to, and nothing is withheld from a child who provides nothing.
- United States. We do not knowingly collect personal information from children under 13 other than the identifiers described above, which are used solely to support internal operations, something the COPPA Rule permits without verifiable parental consent. A parent may ask us to confirm what exists in relation to their child, to have it deleted, and to refuse any further collection: write to the address at the top of this page and we will act on it.
- European Union. Article 8 GDPR concerns consent for information society services offered to children. We do not rely on consent as a legal basis anywhere in this section, so no age verification of the child is carried out and no age declaration is requested. Italy has set the age of digital consent at 14 under Article 2-quinquies of the Personal Data Protection Code; other member states set it between 13 and 16.
- Design. Recital 38 GDPR notes that children merit specific protection, particularly as regards marketing and the creation of personality profiles. Neither exists here.
Practical guidance for families, including how the parental gate works and how games are chosen, is on the parents page.
10. Your rights
Where personal data relating to you or your child is processed, Articles 15 to 22 GDPR give you the right to request access to it, its rectification or erasure, the restriction of processing and its portability. You also have the right to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest. Where we ever relied on consent you could withdraw it at any time, without affecting processing already carried out.
Send requests to info@gamepix.com. We reply without undue delay and in any case within one month, extendable by two further months for complex requests as Article 12 GDPR allows, and we will tell you if we need that extension. Exercising these rights is free of charge. In practice most answers will confirm that nothing is held about the person concerned, because beyond short-lived server logs there is nothing to hold.
You may also lodge a complaint with a supervisory authority. In Italy this is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it. You retain the right to an effective judicial remedy under Article 79 GDPR.
11. Changes to this notice
If we change how this section works we will update this page and change the effective date at the top before the change applies. Material changes affecting children will be described in plain language here and on the parents page.
← Back to the games