Skip to content
PRIVACY POLICY
1. INTRODUCTION AND SCOPE This Privacy Policy explains how Misc Games AS ("Misc Games", "we", "us", "our") collects, uses, shares and protects personal data when you visit the website shipsatsea.com, including all its subpages (/presskit, /dedicated-server, /impressum and any future pages). This policy covers this website only. It does not cover: - the Ships At Sea game client or our game servers - our corporate website at miscgames.com and de.miscgames.com - our support portal at support.miscgames.com - our presence on Steam, the Epic Games Store, Discord, YouTube, Facebook, Bluesky, Reddit or X. Those platforms operate under their own privacy policies, and we have no control over their processing. Misc Games AS is established in Norway. Norway is part of the European Economic Area, so the EU General Data Protection Regulation (GDPR) applies to us, implemented in Norwegian law by the Personal Data Act (personopplysningsloven). Rules on cookies and similar technologies follow from the Norwegian Electronic Communications Act (ekomloven) and, for visitors in Germany, from Section 25 of the German Digital Services Data Protection Act (TDDDG). We have written this policy to be read by people, not lawyers. Where we have to use a legal term, we explain it.
2. WHO IS RESPONSIBLE (DATA CONTROLLER) The controller responsible for the processing described here is: Misc Games AS Urhammerveien 24A 4375 Hellvik Norway Telephone: +47 47 51 11 00 Email: info@miscgames.no Support: support@miscgames.no Business enquiries: business@miscgames.no Press enquiries: press@miscgames.no Organisation number: 828 183 532 VAT number: NO 828 183 532 MVA Responsible for editorial content: Misc Games AS, at the address above.
3. KEY TERMS Personal data - any information relating to an identifiable person. An IP address counts, even though it looks like a number. Processing - anything done with personal data: collecting, storing, using, sharing, deleting. Cookie - a small text file a website stores in your browser. First-party cookies come from the site you are visiting; third-party cookies come from another company whose content is embedded in the page. Similar technologies - local storage, session storage, pixels and device fingerprinting. The law treats these the same as cookies, and so does this policy. Where we say "cookies", we mean all of them. Controller and processor - a controller decides why and how data is processed. A processor only acts on the controller's instructions. The distinction matters because it determines who you complain to.

4. OVERVIEW - WHAT WE PROCESS AT A GLANCE Server log data When: every page view Legal basis: legitimate interest Who receives it: Onepage GmbH (processor) Necessary cookies When: every page view Legal basis: legitimate interest and statutory exemption Who receives it: Onepage GmbH (processor) Statistics (Onepage Analytics) When: only with consent Legal basis: consent Who receives it: Onepage GmbH (processor) Trello board (Roadmap) When: only with consent Legal basis: consent Who receives it: Atlassian (own controller) YouTube trailer When: only with consent Legal basis: consent Who receives it: Google (own controller) Email correspondence When: when you write to us Legal basis: contract or legitimate interest Who receives it: nobody outside Misc Games Nothing on this website requires you to create an account, and we do not sell personal data. We do not run advertising on this website.

5. LEGAL BASES WE RELY ON Every processing operation needs a legal basis under Article 6(1) GDPR. We use exactly three. (a) Consent - Article 6(1)(a) GDPR, and Section 25(1) TDDDG for the storage itself. Used for everything that is not strictly necessary: statistics, the Trello board and the YouTube trailer. You give consent through our cookie banner. You can withdraw it at any time, and withdrawal is as easy as giving it. See section 11.7. (b) Performance of a contract or pre-contractual steps - Article 6(1)(b) GDPR. Used when you contact us about a business matter, a partnership or a job application. (c) Legitimate interests - Article 6(1)(f) GDPR. Used for the technical delivery and security of the website. Our legitimate interest is operating a functioning, secure website that is not taken down by attacks. We have weighed this against your interests: the data involved is minimal, retained briefly, and not used to profile you. You may object at any time. See section 11.6.

6. WHERE THIS WEBSITE IS HOSTED This website is built and hosted on the Onepage platform. Onepage GmbH Hanauer Landstrasse 172 60314 Frankfurt am Main, Germany Commercial register: HRB 194510 B, Amtsgericht Charlottenburg Onepage acts as our processor under Article 28 GDPR. We have concluded a data processing agreement with them. Onepage delivers the site from infrastructure operated by Google Cloud and Amazon Web Services; according to Onepage, all servers and stored data are located within the European Union, and both providers have contractually confirmed EU-only storage. Images, fonts and video assets are delivered through Onepage's content delivery network at onecdn.io. Fonts are hosted by Onepage itself. No font is loaded from Google Fonts or any other external font service, so no connection to a third-party font provider is made when you visit.

7. WHAT WE PROCESS IN DETAIL 7.1 SERVER LOG FILES Every time your browser requests a page, our platform provider records technical data. This happens automatically and cannot be switched off, because without it the page cannot be delivered. Data: your IP address, date and time of the request, the specific page requested, HTTP status code, volume of data transferred, the website you came from (referrer), browser type and version, operating system and its interface, and browser language. Purpose: delivering the website, diagnosing technical faults, and detecting and defending against attacks and abuse. Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable operation of the website. Retention: Onepage records, for debugging purposes, the IP address, request type and status code of 1 percent of visitors, selected at random, and stores this for one month. We cannot determine whether you are among that 1 percent. Onepage additionally applies firewalls, DDoS protection, rate limiting and CAPTCHA at infrastructure level. Note: we do not combine log data with any other data, and we do not use it to identify individuals. 7.2 NECESSARY COOKIES AND CONSENT MANAGEMENT To remember your cookie decision and to protect forms against abuse, a small number of strictly necessary cookies are set. These do not require consent. Storing them is permitted under Section 25(2) TDDDG because they are strictly necessary to provide a service you have expressly requested. Data: your consent status per category, the date and time of your decision, a consent version identifier, and a session identifier. Purpose: so the banner does not reappear on every page, so we can demonstrate that consent was given as required by Article 7(1) GDPR, and so submitted forms are protected against cross-site request forgery. Legal basis: Section 25(2) no. 2 TDDDG for the storage; Article 6(1)(f) and Article 7(1) GDPR for the processing. Retention: see the cookie list in section 8. The consent record is kept for the duration of the consent plus the period needed to prove it. We ask again at the latest after 12 months, so your decision does not silently persist indefinitely. 7.3 ONEPAGE ANALYTICS (STATISTICS) - CONSENT ONLY To understand how our website is used, we use the analytics function built into the Onepage platform. This runs only if you consent to the "Statistics" category. Onepage has developed this in-house rather than using an external analytics provider. According to Onepage's own data protection documentation, the system stores no personal data such as IP addresses, and all data is held in the EU. Data: pages viewed, order of navigation, time spent, approximate referrer, device category and browser type, in pseudonymous form. Purpose: measuring reach and improving the structure, content and performance of the website. Legal basis: Article 6(1)(a) GDPR and Section 25(1) TDDDG, your consent. Recipient: Onepage GmbH as our processor. No transfer outside the EU. Retention: see section 8. Aggregated statistics that no longer permit any reference to a person may be retained longer, as they are no longer personal data. Withdrawal: click the lock icon in the bottom right corner of any page and deselect "Statistics". 7.4 ONEPAGE BRANDING ELEMENT Depending on our subscription, the platform provider may display a small Onepage reference in the page footer. This is a static element and does not process personal data beyond the log data already described in section 7.1. 7.5 TRELLO BOARD - DEVELOPMENT ROADMAP (CONSENT ONLY) On our homepage, in the Roadmap section, we embed a publicly visible Trello board so you can follow the development of Ships At Sea. Trello is a project management service operated by Atlassian. Board embedded: https://trello.com/b/MJqb4SWR This content loads only after you have given your consent to the "External media" category. Until then it is replaced by a placeholder. If you prefer not to consent, you can open the board directly at the address above, in which case Atlassian's own privacy policy applies to that visit alone. Provider: Atlassian Pty Ltd, Level 6, 350 Bourke Street, Sydney NSW 2000, Australia and Atlassian, Inc., 350 Bush Street, Floor 13, San Francisco, CA 94104, USA What happens technically: once loaded, your browser opens a direct connection to Atlassian's servers. We cannot see, intercept or prevent the data exchanged in that connection. Atlassian acts as its own controller for it, not as our processor. That means for this processing you must exercise your rights against Atlassian, and Atlassian's own privacy policy governs it. Data transmitted to Atlassian: your IP address, date and time of access, the page you loaded the board from, browser type and version, operating system, device and screen characteristics, language settings, and pseudonymous identifiers stored in cookies and local storage. If you are logged in to Trello at the same time, Atlassian can link this visit to your Trello account. To avoid that, log out of Trello before visiting, or use a separate browser profile. Purpose: displaying our development roadmap. On Atlassian's side, additionally the security of their infrastructure, product analytics and, depending on your Atlassian settings, advertising. Legal basis: Article 6(1)(a) GDPR and Section 25(1) TDDDG, your consent. Third country: processing in the USA and Australia cannot be ruled out. Atlassian relies on the European Commission's Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR. See section 10. Retention: see the cookie list in section 8. From the length of a browser session up to 24 months on Atlassian's side. More information: Atlassian Privacy Policy: https://www.atlassian.com/legal/privacy-policy Atlassian Cookies and Tracking Notice: https://www.atlassian.com/legal/cookies 7.6 YOUTUBE VIDEO - TRAILER (CONSENT ONLY) On our homepage we embed the Ships At Sea trailer from YouTube. Video embedded: https://www.youtube.com/watch?v=Jkigm8iLty4 https://www.youtube.com/watch?v=tByxAjwKQDA This content loads only after you have given your consent to the "External media" category. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for visitors in the EEA, part of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA What happens technically: loading the player opens a direct connection to Google's servers. Google acts as its own controller for this processing. A substantial number of cookies is set, and further identifiers are written to your browser's local storage, which is why section 3 treats local storage the same as cookies. Data transmitted to Google: your IP address, date and time of access, the page containing the video, browser type and version, operating system, device and screen characteristics, language settings, the fact that you loaded this page, whether and how long you played the video, and pseudonymous identifiers from cookies and local storage. If you are logged in to a Google account, Google can associate all of this with that account and, depending on your ad personalisation settings, use it to select advertising. To avoid that, log out of Google before visiting. Purpose: displaying the trailer. On Google's side, additionally spam and fraud prevention, view measurement, feature rollouts and, subject to your Google ad settings, advertising personalisation. Legal basis: Article 6(1)(a) GDPR and Section 25(1) TDDDG, your consent. Third country: processing in the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework, so transfers are covered by the European Commission's adequacy decision pursuant to Article 45 GDPR. Standard Contractual Clauses apply in addition. See section 10. Retention: see the cookie list in section 8. From the length of a browser session up to 24 months on Google's side. More information: Google Privacy Policy: https://policies.google.com/privacy How Google uses cookies: https://policies.google.com/technologies/cookies Google ad settings: https://myadcenter.google.com 7.7 LINKS TO EXTERNAL WEBSITES Our website links to third-party services: Steam, the Epic Games Store, Discord, our YouTube channel, Facebook, Bluesky, Reddit, X, our corporate site at miscgames.com, our support portal, and the server hosting partners BisectHosting, 4Netplayers and G-Portal. These are ordinary links, not embeds. No connection to those providers is made and no cookie of theirs is set until you click. From the moment you click, the privacy policy of the site you land on applies and we have no influence over or insight into their processing. We have checked the linked pages for unlawful content at the time of linking, but we cannot monitor them continuously. The hosting partner links contain a referral parameter (for example ?ref=miscgames), which lets the provider recognise that you came from our website. We do not receive personal data from this, only aggregate information about referrals. 7.8 CONTACTING US BY EMAIL Our website lists email addresses for business enquiries, partnerships, press and player support. There is currently no contact form on this website. If we add one, we will update this policy before it goes live. Data: your email address, your name if you provide it, the content of your message and any attachments, plus the date and time. Purpose: handling and responding to your enquiry, and any follow-up correspondence. Legal basis: Article 6(1)(b) GDPR where your enquiry relates to a contract or pre-contractual steps, for example a partnership, a licence or a job application. Otherwise Article 6(1)(f) GDPR, our legitimate interest in responding to enquiries addressed to us. Retention: until your enquiry has been fully dealt with and no further questions arise, then deleted, unless statutory retention obligations apply. In particular commercial and tax record-keeping duties, which in Norway generally require business documentation to be kept for five years. Please note: email is not encrypted end-to-end in transit by default. We recommend you do not send sensitive information by unencrypted email. If you need a secure channel, write to us and we will arrange one. 7.9 NEWSLETTER We do not currently operate a newsletter from this website. Should we introduce one, it will use a double opt-in procedure, and we will extend this policy accordingly before launch. 7.10 JOB APPLICATIONS If you apply for a position by email, we process your application data (name, contact details, CV, references, cover letter) for the purpose of the application procedure, on the basis of Article 6(1)(b) GDPR and the applicable provisions on employment data. Unsuccessful applications are deleted no later than six months after the procedure concludes, unless you have consented to a longer retention in a talent pool. 8. COOKIES AND SIMILAR TECHNOLOGIES - FULL LIST The lists below cover every cookie and storage entry we are aware of. Names and durations set by Atlassian and Google are taken from those providers' documentation. Because they change these from time to time without notice, the values are indicative rather than guaranteed. We review this list regularly. GROUP A - NECESSARY (NO CONSENT REQUIRED) Consent cookie Name: [COOKIE-NAME] Provider: Misc Games / Onepage (first party) Purpose: stores which cookie categories you accepted or rejected, and when Duration: [LAUFZEIT], typically 6 to 12 months Session and CSRF token Name: [COOKIE-NAME] Provider: Misc Games / Onepage (first party) Purpose: protects form submissions against cross-site request forgery Duration: session GROUP B - STATISTICS (CONSENT REQUIRED) Onepage Analytics identifier Provider: Onepage GmbH, Germany Purpose: pseudonymous measurement of page views and navigation. No IP address stored, data held in the EU Duration: session to 12 months GROUP C - EXTERNAL MEDIA: TRELLO (CONSENT REQUIRED) All of the following are set on the domain .trello.com __cf_bm - Cloudflare bot detection protecting the Trello infrastructure. Necessary (Trello). 30 minutes. _cfuvid - distinguishes requests so rate limits can be applied. Necessary (Trello). Session. atl_xid - anonymous cross-product visitor ID linking usage across Atlassian services. Marketing and analytics. 12 months. ajs_anonymous_id - pseudonymous ID so returning visitors are recognised in analytics. Analytics. 12 months. ajs_user_id - associates usage data with a logged-in Trello account. Analytics. 12 months. _ga and _ga_* - Google Analytics measurement of the Trello interface. Analytics. 24 months. _gcl_au - stores ad-click information for Google conversion measurement. Marketing. 90 days. optimizelyEndUserId - A/B testing and feature rollouts within Trello. Analytics and functional. 6 months. cloud.session.token - keeps an existing Trello login active. Functional. 30 days. token - authentication token for logged-in Trello users. Functional. 30 days. dsc - CSRF protection token. Functional. Session. atlCohort - stores your A/B test group assignment. Functional. 12 months. atlOptOut - records an objection to Atlassian tracking. Functional. 12 months. GROUP D - EXTERNAL MEDIA: YOUTUBE, ALWAYS SET ONCE THE PLAYER LOADS Set on .youtube.com unless stated otherwise. __Secure-YNID - unique identifier used to remember player and site preferences, detect spam and fraud, measure engagement and, subject to your Google ad settings, personalise advertising. Successor to VISITOR_INFO1_LIVE and NID. Marketing and analytics. Approximately 6 months. VISITOR_INFO1_LIVE - estimates your bandwidth to select the player interface and video quality, also used for view measurement. Marketing. 6 months. VISITOR_PRIVACY_METADATA - stores your cookie consent state for your region. Necessary. 6 months. YSC - registers a unique ID to keep statistics of which videos you have seen this session. Analytics. Session. __Secure-ROLLOUT_TOKEN - controls staged rollout of new YouTube features to your browser. Functional. 6 months. PREF - stores player preferences: quality, volume, autoplay, interface language. Functional. Up to 24 months. DEVICE_INFO - stores device and screen characteristics to select a suitable player layout. Functional. 6 months. TESTCOOKIESENABLED - checks whether your browser accepts cookies at all. Necessary. 1 minute. remote_sid - enables YouTube functionality inside the embedded iframe. Necessary. Session. wide - remembers whether the player was set to wide-screen mode. Functional. Session. CONSENT - records your consent choices for Google services. Necessary. Up to 24 months. SOCS - stores the state of the Google cookie consent dialogue. Necessary. 13 months. AEC - anti-abuse, ensures requests in a session come from you and not another site. Necessary. 6 months. NID (on .google.com) - unique ID used to remember preferences and serve personalised ads on Google properties. Marketing. 6 months. GROUP E - EXTERNAL MEDIA: YOUTUBE, ADDITIONALLY SET IF YOU ARE SIGNED IN TO GOOGLE LOGIN_INFO - stores the authenticated session so you can watch as a signed-in user. Functional. 24 months. SID, HSID, SSID - signed and encrypted records of your Google account ID and last sign-in time. Authentication and protection against fraudulent use of credentials. Functional. 24 months. APISID, SAPISID - used by Google APIs to authenticate requests and personalise content and ads. Marketing. 24 months. __Secure-1PSID and __Secure-3PSID - first-party and third-party variants of the signed-in session ID, HTTPS only. Functional and marketing. 24 months. __Secure-3PAPISID - third-party API session ID used for cross-site ad personalisation. Marketing. 24 months. SIDCC, __Secure-1PSIDCC, __Secure-3PSIDCC - security cookies protecting your data against unauthorised access. Functional. 12 months. GROUP F - EXTERNAL MEDIA: GOOGLE ADVERTISING SERVICES Set when the player is served from youtube.com and ad delivery is active. IDE (on .doubleclick.net) - registers and reports your actions after seeing or clicking an ad, to measure ad effectiveness and present targeted advertising. Marketing. 13 months in the EEA. test_cookie (on .doubleclick.net) - checks whether your browser supports cookies before ad cookies are set. Necessary. 15 minutes. LOCAL STORAGE YouTube in particular writes identifiers and player state to your browser's local storage and session storage. Legally this is treated exactly like cookies, and it falls under the same consent requirement. Unlike cookies, local storage has no automatic expiry. It remains until you or the site clears it. You can remove it in your browser under Settings, then Privacy, then Clear browsing data, then Cookies and site data. MANAGING COOKIES IN YOUR BROWSER Independently of our banner, you can configure your browser to refuse cookies, delete existing ones, or ask you each time. Blocking all cookies may break parts of this or other websites. Instructions: Chrome: https://support.google.com/chrome/answer/95647 Firefox: https://support.mozilla.org/kb/cookies-information-websites-store-on-your-computer Safari: https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac Edge: https://support.microsoft.com/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09 9. WHO RECEIVES YOUR DATA PROCESSORS - act only on our instructions, under a data processing agreement pursuant to Article 28 GDPR: Onepage GmbH, Frankfurt am Main, Germany Role: website platform, hosting, CDN, analytics Location of processing: European Union INDEPENDENT CONTROLLERS - decide on their own processing, we cannot instruct them: Atlassian Pty Ltd and Atlassian, Inc. Triggered by: Trello board, after consent Own policy: https://www.atlassian.com/legal/privacy-policy Google Ireland Ltd and Google LLC Triggered by: YouTube trailer, after consent Own policy: https://policies.google.com/privacy OTHER RECIPIENTS: public authorities and courts, where we are legally obliged to disclose; our legal advisers, where necessary to establish, exercise or defend legal claims. We do not sell personal data, and we do not share it for third-party advertising purposes. 10. TRANSFERS OUTSIDE THE EEA Some processing may take place outside the European Economic Area. This only happens with the third-party embeds described in sections 7.5 and 7.6. The website itself and its analytics stay in the EU. Google LLC Country: USA Safeguard: adequacy decision. Certified under the EU-US Data Privacy Framework, Article 45 GDPR. Standard Contractual Clauses in addition. Atlassian, Inc. Country: USA Safeguard: Standard Contractual Clauses, Article 46(2)(c) GDPR. Atlassian Pty Ltd Country: Australia Safeguard: Standard Contractual Clauses, Article 46(2)(c) GDPR. What this means in practice. Countries outside the EEA may not offer a level of data protection equivalent to the GDPR. In particular, public authorities in third countries may under certain circumstances access data without you being informed and without an effective legal remedy being available to you. We cannot exclude this risk. By consenting to the external media category, you also consent to this transfer within the meaning of Article 49(1)(a) GDPR, insofar as the safeguards above should prove insufficient. You can request a copy of the Standard Contractual Clauses from us at any time. 11. YOUR RIGHTS You have the following rights regarding your personal data. Exercising them is free of charge, and we will respond within one month, extendable by two further months for complex requests, in which case we will tell you. 11.1 Right of access, Article 15. You may ask whether we process data about you and, if so, request a copy along with information about purposes, categories, recipients, retention periods and the origin of the data. 11.2 Right to rectification, Article 16. You may have inaccurate data corrected and incomplete data completed. 11.3 Right to erasure, Article 17. You may request deletion, for instance where the data is no longer needed, where you withdraw consent, or where processing was unlawful. We may refuse where a legal retention obligation or the defence of legal claims requires us to keep the data. We will tell you which. 11.4 Right to restriction of processing, Article 18. In certain situations you may require us to keep the data but stop using it, for example while we verify a contested accuracy. 11.5 Right to data portability, Article 20. Where processing rests on consent or a contract and is carried out automatically, you may receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller. 11.6 RIGHT TO OBJECT, ARTICLE 21. PLEASE READ THIS SPECIFICALLY. Where we process your data on the basis of a legitimate interest under Article 6(1)(f) GDPR, in this policy the server log files in section 7.1 and the correspondence handling in section 7.8, you have the right to object at any time, on grounds relating to your particular situation. If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims. An objection is informal. A message to [privacy@miscgames.com] stating that you object is enough. No particular form or wording is required. 11.7 Right to withdraw consent, Article 7(3). Where processing rests on your consent, you may withdraw it at any time, and withdrawing must be as easy as giving it. Withdrawal does not affect the lawfulness of processing carried out before it. How to withdraw: click the lock icon in the bottom right corner of any page on this website. This reopens the cookie settings, where you can deselect individual categories or reject everything. You may also write to [privacy@miscgames.com], or delete the cookies in your browser. 11.8 Right not to be subject to automated decision-making, Article 22. See section 13. This does not arise here. 11.9 How to exercise your rights. Write to [privacy@miscgames.com] or to the postal address in section 2. To protect your data we may need to verify your identity before acting. We will only ask for what is genuinely necessary for that. IMPORTANT LIMITATION. These rights apply against us. For the processing carried out by Atlassian and Google as independent controllers, described in sections 7.5 and 7.6, you must address those companies directly. We can neither access nor delete data held in their systems. Their contact points are linked in section 9. 12. RIGHT TO LODGE A COMPLAINT If you believe we are processing your data unlawfully, you may complain to a data protection supervisory authority, Article 77 GDPR. Our lead authority is: Datatilsynet (Norwegian Data Protection Authority) Postboks 458 Sentrum, 0105 Oslo, Norway Telephone: +47 22 39 69 00 https://www.datatilsynet.no If you are in the EU, you may also complain to the supervisory authority of your habitual residence or place of work. In Germany that is the data protection authority of your federal state; a list is maintained by the Federal Commissioner for Data Protection at https://www.bfdi.bund.de We would appreciate the chance to resolve the matter first, but this is entirely your choice and not a precondition for complaining. 13. NO AUTOMATED DECISION-MAKING OR PROFILING We do not use automated decision-making within the meaning of Article 22 GDPR, and we do not create profiles of visitors to this website. No decision affecting you is taken automatically on the basis of the data described here. Third-party providers whose content you consent to may carry out profiling for their own purposes. That is described in sections 7.5 and 7.6 and governed by their own policies. We have no part in it and receive no results from it. 14. IS PROVIDING DATA MANDATORY? No. You are under no statutory or contractual obligation to provide any personal data to visit this website. - The technical data in section 7.1 is transmitted automatically by your browser. It is unavoidable for any website; without it no connection can be established. - All consent-based processing is entirely voluntary. Declining costs you nothing: the website works, and every page remains fully readable. You lose only the embedded display of the roadmap and the trailer, both of which you can reach directly through the links we provide. - If you contact us, we need at least a way to reply. Withholding it simply means we cannot respond. We do not use cookie walls. Access is never conditional on consent. 15. DATA SECURITY We use TLS encryption (HTTPS) for all transmission between your browser and this website, so third parties cannot read the data in transit. You can recognise this by the lock symbol in your browser's address bar and the https:// prefix. Our platform provider additionally operates firewalls, DDoS protection, rate limiting, CAPTCHA and regular backups. Details are set out in the Onepage data processing agreement. Please note that data transmission over the internet can never be guaranteed completely secure. We protect your data to the best of our ability, but no method of transmission or storage is absolutely impenetrable. 16. CHILDREN This website is not directed at children. We do not knowingly collect personal data from children under 16 years of age. If you are under 16, please obtain the consent of a parent or guardian before submitting any personal data or accepting optional cookies. If you believe a child has provided us with personal data, contact [privacy@miscgames.com] and we will delete it without undue delay. 17. CHANGES TO THIS POLICY We will update this policy when our website, the services we use or the legal requirements change. The current version always applies and is available at this address. Substantive changes, for example adding a new third-party service, take effect only for the future. Where they concern consent-based processing we will ask for your consent again rather than assume it. Version: 1.0 Effective date: [DATUM] 18. CONTACT For any question about this policy or your data: Misc Games AS - Privacy Urhammerveien 24A, 4375 Hellvik, Norway [privacy@miscgames.com] +47 47 51 11 00 RELATED PAGES Imprint: https://www.shipsatsea.com/impressum EULA: https://www.miscgames.com/eula Terms and Conditions: https://de.miscgames.com/terms-and-conditions Cookie settings: lock icon, bottom right of any page