Privacy Policy

Last updated: July 27, 2026.

1. Who we are

Puzzlr AB (“Puzzlr”, “we”, “us”) is a white-label puzzle game studio based in Stockholm, Sweden. This Privacy Policy explains how we handle personal data in two distinct roles:

  • As a controller – for personal data we decide the purposes and means for, such as data about visitors to our own website (puzzlr.co), people who contact us, request demos, or subscribe to our updates, and our business contacts.

  • As a processor – for personal data we handle on behalf of our customers (game publishers and other businesses that embed or license Puzzlr products) when we provide analytics, including retention measurement and session replay. For that data, our customer is the controller and decides why it is collected; we act on their documented instructions.


    Section 3 covers our controller processing. Section 4 covers our processor processing and is the section that our customers’ Consent Management Platforms (CMPs) link to. If you are an end user of one of our customers’ products and want to exercise your rights, please see Section 4.6.


Contact:

Puzzlr AB

Upplandsgatan 7, Stockholm, Sweden

Company reg. no. 5595267500

Email: info@puzzlr.co

2. Scope and definitions

“Personal data” means any information relating to an identified or identifiable person. Note that pseudonymised data – such as a hashed user ID – is still personal data under the GDPR, because it can consistently single out the same person, even though we cannot read the original ID. This Policy is written to comply with the EU General Data Protection Regulation (GDPR) and the Swedish Data Protection Act, together with the ePrivacy rules on storing and accessing information on devices.

3. When Puzzlr is the controller (our website and business)

3.1 What we collect

When you visit puzzlr.co, contact us, request a demo, or subscribe to our updates, we may process: your name and email address; the content of your message; your IP address and technical/device information; and website usage data (pages visited, links clicked) collected through cookies and similar technologies where you have consented.

3.2 Why we process it, and our legal basis

PurposeLegal basis (GDPR Art. 6)Responding to enquiries, demo requests and providing informationLegitimate interest, or steps prior to entering a contractSending updates/newsletters you subscribed toConsentManaging customer and supplier relationshipsContract / legitimate interestWebsite analytics and non-essential cookiesConsentSecurity, fraud prevention and legal complianceLegitimate interest / legal obligation

3.3 Retention

We keep this data only as long as needed for the purpose it was collected for: enquiry/demo correspondence for 24 months after last contact; newsletter data until you unsubscribe; business-relationship records for the life of the relationship plus any statutory retention (e.g. accounting records under Swedish law). 

4. When Puzzlr is a processor (analytics for our customers)

When our games or SDK run inside a customer’s product, we collect and process end-user data to provide analytics to that customer. The customer is the controller; Puzzlr is the processor acting under a Data Processing Agreement (DPA) and the customer’s instructions. This is the processing described in the customer’s consent banner/CMP, and this section is what that CMP entry links to.

4.1 What we process

Hashed user/profile ID – where the customer identifies a logged-in user, we receive and store only a hashed (pseudonymised) version of that ID. We do not store raw user IDs.Derived device ID – generated by hashing device characteristics (user agent, IP address, origin) with a salt that rotates daily. We do not use cookies for this.Product/usage events – actions taken in the product, used for metrics such as retention (whether and when users return).Session replay – where enabled by the customer, a structured (rrweb-based) recording of on-screen interactions (clicks, scrolls, navigation). Form field values are masked by default and are not recorded. This feature is off unless the customer explicitly enables it.

4.2 Purposes

To measure content performance (e.g. retention), understand audiences through statistics, and develop and improve products and user experience on behalf of our customer. We do not use this data for advertising and do not sell it.

4.3 Legal basis

The legal basis is the end user’s consent, obtained by our customer through their CMP before this processing begins, together with the customer’s configuration. Because the processing involves a persistent pseudonymised identifier and active scanning of device characteristics, it is treated as consent-based and is presented in the “processing based on consent” layer of the customer’s CMP – not as strictly necessary processing. If consent is refused or withdrawn, this processing does not take place.

4.4 Sub-processors and hosting

We use the following sub-processors to deliver the analytics service: https://docs.puzzlr.net/data-privacy/data-processing/#do-you-work-with-sub-processors.

Where personal data is transferred outside the EU/EEA, we rely on an adequacy decision or EU Standard Contractual Clauses.

4.5 Retention

Session replays are retained for 30 days and then deleted. Event and retention data is retained for 12 months. Data is deleted or returned at the end of the customer relationship in line with the DPA.

4.6 Your rights as an end user

Because the customer (the publisher/business whose product you were using) is the controller of this data, requests to access, correct, delete, or object to this processing are best directed to them. You can also contact us at info@puzzlr.co and we will assist the controller in responding. Note that because we hold only a hashed identifier, we may need additional information from the controller to locate your data.

5. Cookies and device access

On our own website we use cookies and similar technologies; non-essential cookies are set only with your consent via our cookie banner. Our analytics product is cookieless but accesses device characteristics to generate a rotating device ID; on customer products this access is governed by the customer’s consent banner as described in Section 4.

6. How we share data

We share personal data only with: our sub-processors (Section 4.4); our customer, where we act as their processor; professional advisers and authorities where legally required; and a successor entity in the event of a merger or acquisition. We do not sell personal data and do not share it with advertising networks for our analytics product.

7. Your rights (general)

Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to processing of your personal data, and the right to data portability and to withdraw consent at any time. To exercise these rights for data we control, contact info@puzzlr.co. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or your local supervisory authority.

8. Security

We apply appropriate technical and organisational measures to protect personal data, including pseudonymisation (hashing of identifiers), input masking in session replay, access controls, and encryption in transit.

9. Changes to this policy

We may update this Policy from time to time. Material changes will be posted on this page with an updated “last updated” date, and where required we will seek renewed consent.

10. Contact

Questions about this Policy or our data practices: info@puzzlr.co.