-
1
Identity & Contact Details of the Data Controller
The data controller responsible for the collection, storage, and processing of personal data gathered via solglimtas.com is Sol Glimt AS, incorporated under Norwegian corporate registry number and having its registered statutory seat at Grev Wedels Plass 9, 0151 Oslo, Norway. When this Privacy Policy references Sol Glimt AS, we, us, or our, it refers directly to this corporate entity.
- General privacy contact address: privacy@solglimtas.com
- Postal inquiries: Sol Glimt AS, Data Protection Unit, Grev Wedels Plass 9, 0151 Oslo, Norway.
-
2
Scope of Application & Regulatory Framework
This policy applies to all visitors, registered community members, and sweepstakes participants accessing our digital ecosystem. We process personal data in strict compliance with the European General Data Protection Regulation (Regulation EU 2016/679), the United Kingdom Data Protection Act 2018 (UK GDPR), and applicable Italian data protection statutes under Legislative Decree no. 196/2003 as modified by Legislative Decree no. 101/2018.
- Applies to online browser interactions, contact forms, account profiles, and prize fulfillment.
- Does not extend to independent external websites accessed via external links (e.g. GamCare or BeGambleAware).
-
3
Categories of Personal Data Collected
We collect information necessary to deliver safe social gameplay and execute promotional drawings. These categories include: technical device data (IP addresses, browser configurations, screen resolutions, operating system versions), account credentials (chosen username, email address, password hashes), verification documents (official government identification to verify 18+ maturity during prize fulfillment), and customer support logs.
- We do not collect or store credit card numbers or financial bank access credentials.
- Physical shipping addresses are collected solely when shipping tangible merchandise won in promotional drawings.
-
4
Lawful Bases for Data Processing
Under Article 6 of the GDPR, we establish clear legal justifications for all data processing activities. These include: (a) Performance of Contract: fulfilling our Terms of Service and delivering free game demonstrations; (b) Legal Obligation: satisfying mandatory age verification statutes (18+) and accounting standards; (c) Legitimate Interests: combating online fraud, ensuring network security, and preventing multi-accounting abuse; and (d) Consent: where explicitly given for non-essential cookies and marketing updates.
- Where processing is grounded in user consent, that consent may be revoked freely at any time.
- Legitimate interests assessments are routinely conducted to safeguard individual rights.
-
5
Strict Protection of Minors & 18+ Age Verification
Sol Glimt AS enforces a strict 18+ policy. We do not knowingly solicit, collect, or process personal data belonging to persons under eighteen years of age. Our digital perimeter incorporates electronic age gates on first arrival. If we determine that a minor has circumvented safeguards, all associated personal records and virtual credits are permanently purged immediately.
- Parents and guardians noticing unauthorized minor activity may contact us immediately at safety@solglimtas.com.
- Identity documentation submitted for prize claims undergoes manual and automated age authenticity verification.
-
6
Telemetry, Simulation Logs & Social Interaction Data
To optimize game performance across desktop, tablet, and mobile browsers, our servers record gameplay telemetry including session durations, frame rates, virtual Sun Coin balances, and peer-to-peer coin transfers. This operational telemetry is analyzed in aggregate form to enhance stability, diagnose connection lag, and improve our interactive interface.
- Telemetry records are separated from direct personal identifiers wherever technically viable.
- Peer-to-peer coin gifting records are tracked to ensure community transfer limits are respected.
-
7
Cookies, Web Beacons & Local Browser Storage
Our website implements necessary session cookies and HTML5 local storage tokens (such as age verification confirmation and cookie choice preferences). These small data files are stored locally on your device to maintain your browsing preferences without forcing repeated prompts. Detailed classification of all cookies is available in our dedicated Cookie Policy.
- Essential security cookies function without requiring prior consent under ePrivacy regulations.
- Users can modify or purge local browser storage tokens directly through client browser settings.
-
8
Third-Party Processors & Service Providers
We share personal data strictly with contracted data processors who provide vital infrastructure services under binding Data Processing Agreements (DPAs). These recipients include secure cloud hosting facilities, verified logistics and courier services (for physical prize delivery), certified email dispatch providers, and professional KYC/identity compliance verification vendors.
- All service providers are bound to process data exclusively under our documented instructions.
- We never monetize, trade, lease, or distribute user personal details to external marketing brokers.
-
9
Cross-Border Data Transfers & Standard Safeguards
Our primary servers are located within the European Economic Area (EEA) and Norway. When data is transferred to service vendors outside the EEA (such as cloud nodes in the United Kingdom), we ensure appropriate transfer mechanisms under Article 46 of the GDPR, including European Commission Standard Contractual Clauses (SCCs) and UK International Data Transfer Agreements (IDTAs).
- Norway benefits from reciprocal European data protection adequacy status under the EEA Agreement.
- Transfers to the UK rely on the European Commission statutory adequacy decision.
-
10
Data Retention Periods & Scheduled Purging
Sol Glimt AS retains personal data only for the duration strictly necessary to fulfill the objectives for which it was gathered. Operational customer service inquiries are retained for up to twelve (12) months following resolution. Identity records gathered during promotional prize redemption are retained for up to five (5) years in accordance with Norwegian commercial bookkeeping and statutory tax regulations.
- Inactive accounts that show zero interaction for twenty-four (24) months are scheduled for anonymization.
- Upon conclusion of mandatory retention spans, data is safely overwritten or permanently deleted.
-
11
Comprehensive User Rights Under GDPR
Under Chapter III of the GDPR, you possess extensive statutory prerogatives regarding your personal data. These include: the Right of Access (requesting a copy of held records); Right to Rectification (correcting inaccurate information); Right to Erasure (the right to be forgotten); Right to Restriction of Processing; Right to Data Portability (receiving data in a structured machine-readable format); and Right to Object to processing based on legitimate interests.
- To exercise any of these rights, email our team at privacy@solglimtas.com with proof of account ownership.
- We fulfill verified requests free of charge within thirty (30) calendar days.
-
12
Automated Fraud Detection & Platform Profiling
We utilize automated risk assessment algorithms to identify anomalous access patterns, unauthorized bot connections, and automated ticket generation syndicates. These systems do not make automated legal decisions producing significant discriminatory effects without human review. Any account restriction resulting from automated alerts is subject to prompt human oversight upon request.
- Users have the statutory right to request human intervention on automated account blocks.
- Algorithmic screening operates strictly to uphold fair odds for genuine sweepstakes participants.
-
13
Technical, Architectural & Organizational Security
Sol Glimt AS deploys comprehensive organizational and technological safeguards to shield personal data against unlawful destruction, loss, alteration, or unauthorized exposure. All network transmissions to and from solglimtas.com are protected by Transport Layer Security (TLS 1.3). Datastores are housed behind enterprise firewalls with role-based access control, cryptographic hashing, and automated intrusion monitoring.
- Periodic vulnerability assessments and penetration audits are conducted by external cybersecurity experts.
- Personnel with data access undergo verified background vetting and continuous GDPR compliance training.
-
14
Supervisory Authority Contact & Policy Updates
If you have unresolved concerns regarding our data handling, you hold the statutory right to submit a complaint to our lead supervisory authority, the Norwegian Data Protection Authority (Datatilsynet - Postboks 458 Sentrum, 0105 Oslo, datatilsynet.no), or to your local regulator, such as the UK Information Commissioner Office (ico.org.uk) or the Italian Garante per la protezione dei dati personali (garanteprivacy.it). We review this Privacy Policy periodically and post updates directly to this page.
- Datatilsynet (Norway Lead Authority): Postboks 458 Sentrum, 0105 Oslo, Norway.
- Direct DPO Contact: dpo@solglimtas.com, Grev Wedels Plass 9, 0151 Oslo, Norway.
-
Encrypted Storage
All user data and communications are shielded by TLS 1.3 cryptographic encryption.
-
GDPR Transparency
Full compliance with Norwegian, United Kingdom, and European privacy frameworks.
-
Oslo Data Office
Direct access to our dedicated Data Protection Officer at Grev Wedels Plass 9.