Ceqio

Privacy Policy

Effective date: 30 August 2026 · Version: beta-2026-08-30

Ceqio AS — Privacy Notice pursuant to Articles 13 and 14 of the GDPR

In brief. We collect as little personal data as possible: your account details, your gameplay, and the technical records needed to keep the game running and secure. We do not sell your data, we show no advertising, and we use no analytics trackers. Everything is hosted in the EU, and deleting your account removes your data. Questions? Write to privacy@ceqio.games. The full Notice below sets out the details.

1. Introduction and Scope

1.1 This privacy notice (the “Notice”) describes how Ceqio AS processes personal data in connection with the online card game platform available at ceqio.games (the “Service”), currently offered in a beta version.

1.2 Personal data is processed in accordance with Regulation (EU) 2016/679 (the “GDPR”), as incorporated into Norwegian law by the Personal Data Act of 15 June 2018 No. 38 (personopplysningsloven), and other applicable data protection legislation (together, the “Data Protection Legislation”).

1.3 Terms defined in the Data Protection Legislation, including “personal data”, “processing”, “controller” and “processor”, have the same meaning in this Notice.

1.4 The Service does not currently offer paid subscriptions or other payment functionality. No payment or billing data is collected. This Notice will be revised before any such functionality is introduced.

2. Controller

2.1 Ceqio AS, organisation number 938 253 617, a private limited company registered in Norway (the “Company”, “we”, “us”), is the controller of the personal data described in this Notice.

2.2 Enquiries concerning this Notice or the Company’s processing of personal data may be directed to privacy@ceqio.games.

3. Categories of Personal Data Processed

3.1 Account data. Username, display name, email address and password. Passwords are stored exclusively as salted cryptographic hashes and are at no point stored in plain text. The email address is used solely for the account-security messages described in clause 4.1(d). Provision of the account data in this clause 3.1 is a contractual requirement: an account cannot be created without it.

3.2 Optional profile details. First name, last name, country, experience level and a short self-description, processed only where the user elects to provide them in the account settings. These details are not shown to other players.

3.3 Gameplay data. Boards played, bids, card plays, scores, ratings, and match and tournament history.

3.4 Session data. An authentication cookie and a per-window session token used to maintain the user’s signed-in state and to enforce a single active session per account. Each login record includes the network (IP) address and browser user-agent string from which it was created.

3.5 Server logs. A technical record of each request handled by the Company’s servers, comprising the time of the request, the endpoint requested, the result and processing duration, the browser user-agent string, and a truncated form of the originating network address. Truncation is applied before the entry is written, such that the entry indicates the approximate network origin of a request but not the individual connection. Authentication cookies are not written to server logs, and single-use codes contained in links sent by email (password reset, address verification) are removed before the entry is written.

3.6 Error diagnostics. Where a fault occurs, a technical error report comprising the stack trace, page, release version and a pseudonymous account identifier. Error reports are configured to exclude the username, email address, network address and session cookie.

3.7 Aggregate demo counters. For public demonstrations playable without an account, the Company maintains aggregate counters only (visits commenced, hands completed, approximate duration band). No account, identifier, network address or record of any individual visit is stored, and such counters do not constitute personal data.

4. Purposes of Processing and Legal Bases

4.1 The Company processes personal data for the following purposes and on the following legal bases:

  • (a) Provision of the Service — administration of user accounts (including optional profile details provided by the user), matchmaking, ratings, history and results. Legal basis: performance of a contract to which the data subject is party, cf. GDPR Article 6(1)(b).
  • (b) Security and integrity of the Service — protection of accounts, enforcement of a single active session per account, and prevention of cheating, fraud and abuse. Legal basis: the Company’s legitimate interest in maintaining a secure and fair service, cf. GDPR Article 6(1)(f).
  • (c) Fault detection and correction — error diagnostics and operational logging. Legal basis: the Company’s legitimate interest in the technical operation and improvement of the Service, cf. GDPR Article 6(1)(f).
  • (d) Account-related communication — transactional messages concerning the security of the user’s account (password reset and address verification), the email address being the account’s verification and recovery channel. Legal basis: performance of a contract to which the data subject is party, cf. GDPR Article 6(1)(b). No marketing email is sent.

4.2 The Company does not carry out automated decision-making producing legal or similarly significant effects within the meaning of GDPR Article 22, and does not process personal data for marketing purposes.

5. Recipients and Processors

5.1 The Company does not sell personal data and does not disclose personal data for advertising purposes.

5.2 The Company engages the following processors, each of which processes personal data solely on the Company’s documented instructions and subject to a data processing agreement:

  • (a) Google Cloud EMEA Limited — hosting of the application, database and backups;
  • (b) Functional Software, Inc. (Sentry) — error monitoring, limited to the error diagnostics described in clause 3.6. The integration is configured such that the username, email address, network address and session cookie are removed before any report leaves the server or the user’s browser, and session replay is disabled;
  • (c) Google Ireland Limited (Google Workspace) — transmission of transactional email (password reset and address verification), limited to the recipient address and the contents of the message concerned.

5.3 The Company may disclose personal data where required to do so by law or by order of a competent authority.

5.4 Communications directed to the Company through third-party platforms (such as Discord) are subject to the privacy terms of the platform concerned, for which the Company accepts no responsibility. Enquiries concerning personal data should be directed to the address stated in clause 2.2.

6. Transfers Outside the EEA

6.1 The Service is hosted within the European Union. The application, database and backups are located in Sweden; error monitoring is performed in Sentry’s European region in Germany.

6.2 Transactional email under clause 5.2(c) may involve processing of the recipient address and message contents outside the European Economic Area. Such transfers are made subject to the safeguards provided for in Chapter V of the GDPR under the processor’s data processing terms.

6.3 The error-monitoring processor named in clause 5.2(b) is established in the United States. The error diagnostics it receives are stored in its European region; any access to that data from outside the EEA is likewise subject to the safeguards provided for in Chapter V of the GDPR under that processor’s data processing terms.

6.4 Beyond the cases described in this clause 6, personal data is not transferred outside the EEA. A copy of the applicable safeguards may be requested via the address stated in clause 2.2.

7. Cookies

7.1 The Service uses an authentication cookie and a per-window session token. These are strictly necessary for the provision of the Service within the meaning of the applicable rules on cookies and similar technologies, and consent is accordingly not required.

7.2 The Service does not use advertising cookies, analytics cookies or third-party tracking technologies.

8. Retention

8.1 Personal data is retained no longer than necessary for the purposes for which it is processed, and in accordance with the following periods:

  • (a) Account, profile and gameplay data — for the duration of the account. Deletion of the account removes the associated data;
  • (b) Login sessions — while the session remains in use, and no longer than 60 days after last use; deleted immediately upon sign-out;
  • (c) Server logs — up to 30 days;
  • (d) Backups — up to 14 days. Deleted data may persist in a backup until the expiry of that period;
  • (e) Error diagnostics — 30 days;
  • (f) Aggregate demo counters — retained indefinitely, as they contain no personal data.

9. Rights of the Data Subject

9.1 Subject to the conditions and limitations set out in the Data Protection Legislation, the data subject has the right to request access to, rectification or erasure of personal data, restriction of processing, the right to object to processing, and the right to data portability. Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal.

9.2 An account may be deleted at any time through the account settings, which removes the associated account data. Other requests may be directed to the address stated in clause 2.2.

9.3 The data subject has the right to lodge a complaint with a supervisory authority. The competent supervisory authority for the Company is Datatilsynet (the Norwegian Data Protection Authority).

10. Children

10.1 The Service is not directed to children under the age of 13, or such higher minimum age as may apply under the law of the user’s jurisdiction. Where the Company becomes aware that personal data has been collected from a child below the applicable age, such data will be erased. Notification may be given to the address stated in clause 2.2.

11. Amendments

11.1 The Company may amend this Notice from time to time, in particular as the Service develops during the beta period. The version and effective date stated above will be updated accordingly, and prior versions are retained on record. Material changes will be presented in the Service.