Privacy Policy

Last updated: September 29, 2026

1. Controller

Controller for data processing on this website:
IT-Vikings - Lukas Hansen
Kurlandstr. 20
24960 Glücksburg
Germany
Email: info@fjordsaga.de

2. Data We Process

2.1 During Registration

2.2 During Use

2.3 Bernstein Purchases (Payment Provider Paddle)

When you open the Bernstein purchase page, we load the script of our payment provider Paddle (Paddle.com Market Ltd, United Kingdom). Paddle processes your IP address to show you prices and tax for your region, and your account ID to match a completed purchase to your Fjordsaga account. Paddle acts as an independent controller (merchant of record) here, not as our processor; see Paddle's own privacy policy for details. This only applies to players who open the Bernstein purchase page, not to the rest of the game.

2.4 No Advertising or Analytics Cookies

Aside from the payment provider Paddle (see 2.3), Fjordsaga does not use analytics, tracking, or advertising cookies and does not use any other third-party scripts requiring a cookie banner. The session cookie is technically necessary to keep you signed in. Fonts are served from our own server, not from Google Fonts or another third-party provider.

3. Purpose of Processing

We process this data to operate the game for you, to protect the game and player accounts from abuse, and to send account-related emails required for account operation, such as confirmations and password resets.

4. Disclosure to Third Parties

Hosting and email delivery run with providers based in Germany; your data therefore does not leave the EU/EEA through these services. Paddle may process data outside the EU/EEA as well; Paddle states it provides appropriate safeguards for this (e.g. EU Standard Contractual Clauses), see Paddle's own privacy policy for details. We do not share your data beyond these service providers, especially not for advertising purposes.

5. Storage Period

Account and game state data is stored for as long as your account exists. Security-relevant logs, such as IP addresses from login attempts, are stored only as long as necessary for abuse detection. After deletion of your account, we remove personal data unless statutory retention duties prevent deletion.

6. Your Rights

You have the right to:

To exercise these rights, contact info@fjordsaga.de. You also have the right to lodge a complaint with a data protection supervisory authority.

7. Data Security

Connections to Fjordsaga are encrypted via HTTPS. Passwords are stored only as Argon2id hashes, never in plain text. Login attempts are rate-limited per account and per IP address to make brute-force attacks harder.

After several failed logins in a short period, the system temporarily blocks login attempts for that account. This automated block serves only account security, is not used for profiling or advertising, and is lifted automatically once the failed attempts fall outside the observation period.

8. Changes to This Policy

This Privacy Policy may be updated, for example if new features involve new data processing. The current version is always available at this address.

← Back to Fjordsaga