Privacy Policy
Last updated: July 20, 2026
1. Scope
This policy describes how GameLabs Sweden AB (“GameLabs”, “we”, “us”) handles personal data from the public DragonKeep website and inquiries. Processing of customer project content for a canon-risk audit, pilot, or Studio deployment is additionally governed by the signed order, statement of work, data-processing terms, and documented deployment mode.
2. Public Website and Inquiries
When you contact us, we receive the information you choose to send, such as your name, work email, company or team, and the brief context you provide. We use it to respond, qualify the requested conversation, and maintain relevant business records.
Public-site inquiries are submitted to an Amazon Web Services endpoint in the Stockholm region and delivered to our business mailbox through Amazon Simple Email Service. The public form does not accept project files. Operational API and function logs exclude the submitted message and are configured with a 30-day retention period.
Our hosting provider may process standard technical logs such as IP address, request time, browser information, and requested URL for delivery, reliability, and security. This website does not use advertising cookies. Any future optional analytics will be disclosed and, where required, activated only with consent.
3. Project Content
Project content is not collected through this public website. Before customer content moves, the engagement documentation identifies where it will be processed, which infrastructure and model path are used, who can access it, what is logged, how long it is retained, and how it is exported or deleted.
Customer-hosted and local-model configurations can be scoped where required. If managed infrastructure or an external provider is used, the applicable data flow and subprocessors are disclosed for approval in the engagement terms.
4. Ownership and Model Training
Customers retain ownership of their project content. GameLabs does not use customer project content to train general-purpose AI models. Any limited right needed to process content for the contracted service is defined in the applicable agreement and ends according to its retention and deletion terms.
5. Legal Bases and Retention
We process inquiry data to respond to your request and pursue legitimate business interests, and we process contracted data to perform agreements and meet legal obligations. Inquiry and business records are kept only as long as reasonably needed for those purposes and applicable legal requirements. Project-content retention follows the signed engagement terms.
6. Your Rights
Subject to the GDPR and applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
7. Contact
For privacy inquiries, contact contact@dragonkeep.cloud.
8. Changes
We may update this policy as the website or supported deployment modes change. The date above shows the latest published version.

