Privacy Policy
Last updated: March 2026
1. Who we are
Flaks Tech AS is the data controller for personal data processed in connection with our services, including Flaksorama.
Flaks Tech AS
Org. no.: 936 638 449
Address: Observatorie Terrasse 7C, 0270 Oslo
Email: support@flaksorama.com
We have assessed whether we need a Data Protection Officer (DPO) and concluded that it is not required for our type of business. Privacy questions can be directed to support@flaksorama.com.
2. Who this applies to
This declaration applies to everyone using Flaks Tech AS services:
- Account holders – those who create an account and purchase access
- Players – those who participate in games without having an account
- Visitors – anyone who visits our websites
Players do not need to provide personal information to participate. The only information we collect is the nickname they choose themselves, their score, and technical logs for security purposes. Organizers only see nicknames and scores – not IP addresses or other technical information.
3. What we collect
It depends on how you use the service:
If you create an account:
- Name and email address
- Password – stored encrypted, we cannot read it
- Purchase history (amount, date, product – not card details)
- IP address, device info and login history
If you play without an account:
- Nickname you choose yourself
- Scores and results
- IP address (for security only – not visible to organizer)
Payment:
Card information is handled exclusively by Stripe Technology Europe Ltd. We never see your card number. We only store the transaction ID, amount and date for accounting purposes.
4. Why and on what legal basis
We process your data for the following purposes and on the following legal bases:
| What | Why | Basis |
|---|---|---|
| Account information | Provide the service, authentication | Contract – art. 6(1)(b) |
| Purchase history | Support, invoicing, accounting | Contract and legal obligation – art. 6(1)(b)/(c) |
| IP address and security logs | Prevent misuse and unauthorized access | Legitimate interest – art. 6(1)(f) |
| Nicknames and scores (players) | Run games, display results | Legitimate interest – art. 6(1)(f) |
| Analytics cookies | Improve the service | Consent – art. 6(1)(a) |
Where we use 'legitimate interest' as our basis, we have assessed that the security purpose outweighs the privacy impact – particularly because the data is deleted after short deadlines and is not used for other purposes. You may object to such processing, cf. GDPR art. 21.
5. How long we retain data
- Account data: as long as the account is active, then deleted within 30 days
- Security logs and IP addresses: max 90 days
- Visit logs: max 30 days
- Player data: anonymized within 30 days after the event is deleted
- Accounting data: 5 years after the end of the financial year (Bookkeeping Act § 13)
If you delete your account yourself, we initiate the deletion process immediately. Everything that can be deleted is gone within 30 days.
6. Who we share with
We only share data with vendors we depend on to operate the service. All have a data processing agreement with us.
| Vendor | What they do | Country | Transfer |
|---|---|---|---|
| Stripe Technology Europe Ltd | Payment processing | EU/EEA (Ireland) | Within EU/EEA |
| Supabase, Inc. | Database and authentication | USA (EU region) | SCCs in place |
| Vercel, Inc. | Frontend hosting | USA (EU region) | SCCs in place |
Supabase and Vercel are American companies, but we use EU regions so that data is stored in Europe. The transfer to the USA is authorized through the EU's standard contractual clauses (SCCs). Stripe is Irish and keeps all payment data within the EU/EEA.
We never sell data to third parties and never share data for marketing purposes without your consent.
7. Cookies
We use two types of cookies:
- Necessary cookies – for login, security, and language preferences. These cannot be turned off.
- Analytics cookies – to understand how the service is used. These require your consent and can be turned off at any time in the cookie settings.
A complete overview of the cookies we use can be found in the cookie overview on the website.
8. Your rights
You have the right to:
- See what we have stored about you (access – art. 15)
- Correct errors in the information (art. 16)
- Ask us to delete what we have about you (art. 17)
- Limit what we can use the data for (art. 18)
- Have your data delivered in a machine-readable format (portability – art. 20)
- Object to processing based on legitimate interest (art. 21)
- Withdraw consent at any time (art. 7(3))
Send inquiries to support@flaksorama.com. We respond within one month – free of charge.
9. Complaints
Do you believe we are processing data incorrectly? Please contact us first at support@flaksorama.com. You can also complain directly to the Norwegian Data Protection Authority:
Datatilsynet
datatilsynet.no | postkasse@datatilsynet.no | 22 39 69 00
10. Changes
We update this declaration when our services change, or when required by law. We will notify you of material changes by email at least 30 days before they take effect. The current version is always available at flakstech.no/personvern.