Privacy policy
Last updated: [DATE] – version matches the “legal_version” setting in the admin.
1. Controller
[FIRST AND LAST NAME or COMPANY, ADDRESS, EMAIL] (see imprint).
2. What data we process
• Account: player name, email address, password (only as an irreversible hash), language, confirmed minimum age, time of sign-up and of accepting the terms.
• Game: world, points, stats, pocket money, items, defense plan, fights (opponent, result, time).
• Records: when you agreed to or revoked something (e.g. newsletter, activating a service).
• Technical: one session cookie for signing in; to protect against attacks we store failed sign-in attempts with IP address for at most 24 hours. Individual page requests are not logged; technical server error messages are overwritten automatically after a short time.
• Referrals: whether you came via another player's link.
• Social: friends list, friend requests, blocks and private messages with friends. Only sender and recipient can see messages; a reported message is additionally visible to moderation. Messages disappear once both sides delete them or an account is deleted.
• Reports: who reported what and when, and how we decided (Art. 16, 17 DSA).
3. Purposes and legal bases
• Providing account and game: Art. 6(1)(b) GDPR (contract).
• Security (login lockout, abuse protection): Art. 6(1)(f) GDPR (legitimate interest in secure operation).
• Newsletter: Art. 6(1)(a) GDPR (consent), revocable at any time in your account or via the link in every email.
• Sharing with other oogeloo services (e.g. Sagpoo, Aleruno): only after you activate them, Art. 6(1)(a) GDPR; revocable at any time under “My services”.
• Proof of consent: Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR.
4. What others can see
Player name, character, rank, points and record are visible to other players (leaderboard, opponent list, promotion news). Your email address is never public.
5. Recipients
• Hosting: [HOSTING PROVIDER, SEAT] as processor under Art. 28 GDPR.
• Email delivery: [Brevo (Sendinblue SAS, Paris, France – address as in the Brevo DPA) as processor under Art. 28 GDPR – OR: our own mail server].
• Other oogeloo services only after you activate them and only with the data shown there.
We do not share data with advertisers, use no tracking or analytics tools and load no fonts or scripts from third-party servers.
Advertising: we show our own banners, hosted on our server. No data is shared with advertisers and no cookies are set; we only count how often a banner is shown and clicked – without any link to a person. Ads for 18+ offers are only shown to players who confirmed that age.
6. Retention
As long as your account exists. When you delete it, we remove your data immediately; in other players' fights only your former player name remains visible. Sessions end after 7 days, failed sign-in attempts are deleted after 24 hours. Backups are deleted after 14 days.
7. Cookies and browser storage
We only set one strictly necessary session cookie (§ 25(2) TDDDG / Art. 4(5) Law 3471/2006). In your browser we store your language choice and, if applicable, an invitation code. There are no advertising or tracking cookies, hence no cookie banner.
8. Your rights
You have the right of access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR) and to withdraw consent (Art. 7(3) GDPR). Much of this works directly in your account: download your data, change your email, deactivate services, delete your account. Otherwise write to us: [CONTACT@oogeloo.com].
You can lodge a complaint with a data protection authority, in Greece the Hellenic Data Protection Authority (www.dpa.gr), or the authority where you live.
9. Minimum age
Use is permitted from the age stated at sign-up. Some services (e.g. Sagpoo) are 18+ only.
Back to home