PRIVACY POLICY — MeyerLive3D
Version 1.1 — Effective 4 June 2026 (last updated 26 June 2026)
1. DATA CONTROLLER
Owner of ocimvm.com (individual / natural person)
Norway
Contact: admin@ocimvm.com
You can reach the data controller for all privacy-related enquiries at the email address above.
There is no designated Data Protection Officer (DPO), as this service does not fall within the mandatory DPO threshold under GDPR Article 37.
2. WHAT DATA WE COLLECT AND WHY
a) Account data
- Email address: Required to send you a login or verification code. Legal basis: contract performance (GDPR Art. 6(1)(b)).
- Display name (username): Required to identify you to other players. Legal basis: contract performance (Art. 6(1)(b)).
- Email-verified flag, account timestamps (created, updated): Required for service integrity. Legal basis: contract performance (Art. 6(1)(b)).
b) Referral code
- If you enter an invitation code during registration, we store the abbreviated code (up to 10 characters). Legal basis: legitimate interest (Art. 6(1)(f)) — referral tracking.
c) Authentication codes
- A hashed one-time code is stored temporarily to verify your login. The raw code is never stored. Codes expire and are automatically purged after their expiry time. Legal basis: contract performance (Art. 6(1)(b)).
d) Game history
- Round records including your role (roller/claimant), round number, and outcome are stored per game session. Dice values shown to other players (claims) are stored; dice values you saw privately are not stored server-side. Legal basis: contract performance (Art. 6(1)(b)).
e) Match credit ledger
- All credit additions (purchases) and decrements (consumed per game) are recorded in an audit ledger with reason and timestamp. Legal basis: contract performance and legal obligation (Art. 6(1)(b)(c)).
f) Payment records
- When you purchase premium credits, we store the Stripe checkout session identifier, payment status, amount in cents, currency, and credits granted. We do NOT store full card numbers; Stripe handles payment card data under their own PCI-DSS compliance. Legal basis: contract performance and legal obligation (Art. 6(1)(b)(c)).
g) Media presence log
- We record whether you enabled your camera and/or microphone in a given game room (boolean flags only — we do not record or store the video/audio stream itself). Legal basis: legitimate interest (Art. 6(1)(f)) — used for technical quality monitoring and abuse prevention. You have the right to object at any time (see Section 6).
h) Consent records
- When you accept our Terms of Service and this Privacy Policy, we record the document version and timestamp. Legal basis: Art. 6(1)(a) — consent; and legal obligation (Art. 6(1)(c)) — demonstrating compliance.
3. THIRD-PARTY DATA PROCESSORS
We share your data with the following processors. Each processor is bound by a Data Processing Agreement (DPA) that is incorporated by reference into the service agreement we have entered into with that provider; these DPAs are binding without a separate signature:
a) Oracle Corporation (Oracle Cloud Infrastructure)
Role: Database hosting and email delivery (SMTP).
Primary data residency: Netherlands (EEA). Oracle may access data from other locations for support and incident management, subject to the data-transfer safeguards in its DPA.
Relevant service: Oracle Autonomous Database and OCI Email Delivery.
b) Stripe, Inc.
Role: Payment processing.
Location: California, USA (third country).
Transfer mechanism: Standard Contractual Clauses (SCCs) per EU Commission Decision C(2021) 3972.
Details: Stripe's Data Processing Agreement is automatically incorporated into the Stripe Services Agreement we have accepted, and binds Stripe as our processor. Stripe acts as an independent data controller for certain payment data under their own privacy policy.
Stripe Privacy Policy: https://stripe.com/privacy
c) LiveKit, Inc.
Role: Real-time WebRTC video and audio relay.
Location: USA (third country).
Transfer mechanism: Standard Contractual Clauses (SCCs).
Details: Live video and audio streams are relayed through LiveKit's infrastructure during a game session. LiveKit does not record or retain streams by default.
We do not perform any facial recognition, biometric analysis, or recording of your video and audio streams.
LiveKit Privacy Policy: https://livekit.io/privacy
d) Advertising partners (independent controllers — free tier only, advertising consent required)
Role: Display advertising shown to free-tier players. These parties act as independent data controllers and may set cookies or device identifiers under their own privacy policies. They load ONLY after you grant advertising consent, and premium (credit-holding) accounts see no ads at all.
- Google (AdSense / AdMob): https://policies.google.com/technologies/ads
- Monetag / PropellerAds: https://monetag.com/privacy-policy/
See our Cookie & Consent Policy for full details on advertising storage and how to withdraw consent.
We do NOT sell your personal data to any third party.
4. INTERNATIONAL DATA TRANSFERS
Transfers to Stripe (USA) and LiveKit (USA) are governed by Standard Contractual Clauses under GDPR Article 46(2)(c). You may request a copy of the applicable SCCs by emailing admin@ocimvm.com.
Where applicable, we rely on the EU-U.S. Data Privacy Framework (DPF) for transfers to US-based processors.
5. RETENTION PERIODS
- Account data (email, display name): Retained until you delete your account.
- Authentication codes: Automatically purged at code expiry.
- Game rounds: Retained for 12 months after the game ends, then deleted.
- Payment records (Stripe): Retained for 5 years after the transaction to comply with the Norwegian Bookkeeping Act (Bokføringsloven §13). After account deletion, the record is anonymised (your player ID is removed) but the financial data is retained for this period. the "Anonymization" process is truly irreversible: Hashing/deleting the link between the payment record and the user's specific identity.
- Match credit ledger: Retained for 5 years (same legal obligation).
- Consent records: Retained for the duration of the account, then deleted with it.
- Media presence flags: Retained until you delete your account.
6. YOUR RIGHTS (GDPR ARTICLES 15–21)
You have the following rights regarding your personal data:
Art. 15 — Right of access: You can request a copy of all personal data we hold about you.
Art. 16 — Right to rectification: You can request correction of inaccurate data (e.g., display name update via the app).
Art. 17 — Right to erasure ("right to be forgotten"): You can delete your account directly in the app (Your Rights panel). This deletes all account data; payment records are anonymised as described above.
Art. 18 — Right to restriction of processing: You can request that we restrict processing of your data while a dispute is pending.
Art. 20 — Right to portability: You can download a JSON export of all your personal data directly in the app (Your Rights panel).
Art. 21 — Right to object: You can object to processing based on legitimate interest (e.g., the media presence log). Email admin@ocimvm.com. We will assess and respond within 30 days; this may be extended by two further months for complex requests, in which case we will inform you of the delay.
To exercise any of these rights, use the in-app tools (export/delete) or email admin@ocimvm.com. We will respond within 30 calendar days (Art. 12).
7. SUPERVISORY AUTHORITY
If you believe your rights have not been respected, you have the right to lodge a complaint with:
Datatilsynet (Norwegian Data Protection Authority)
Website: www.datatilsynet.no
Email: postkasse@datatilsynet.no
You may also lodge a complaint with the supervisory authority in your country of residence within the EEA.
8. CHANGES TO THIS POLICY
We will notify you of material changes by displaying a notice in the app and requiring re-acceptance of the updated policy. The current version and effective date are always shown at the top of this document.