Version: 2026-06-11
1. Introduction
This Privacy Policy explains how Connection Game AS collects and processes personal data when you use our software (SaaS) for leadership and team development (the Service).
Our goal is to give leaders and teams useful insights without compromising privacy.
In brief:
- We process name, contact details, and data generated when you use the Service.
- We use data to show profiles and insights to you and your team, operate and improve the Service, and maintain security.
- For team profiling, we rely on legitimate interest as the legal basis.
- For ongoing personality profiling of team members (based on meeting data and in-app interactions), we rely on legitimate interest.
- For the Big Five personality profile (personality test), we require explicit consent.
- At a high level, Big Five results (the five main traits) may be visible to others on your team. Detailed facet-level results are individual only and are not shown to teammates. Big Five profiles may be used by AI models to personalize content in the Service.
- We do not train third-party AI models on your content.
- You may request access, rectification, erasure, and export of your data, and you may lodge a complaint with your supervisory authority.
For certain features (for example, voice analysis and the Big Five profile), we show a separate, short consent form in the Service. This Policy provides the full overview.
2. Data controller and contact
The data controller for core processing in the profiling Service (calculation and display of profiles, analyses, and recommendations) is:
Connection Game AS
Org. no.: 935 814 030
Gaustadveien 12B, 0372 Oslo, Norway
Email: kjersti@connectiongame.no
If you have questions about privacy, this Policy, or wish to exercise your rights (for example, access, rectification, or erasure), contact us by email.
Your customer organization (employer/client) is the data controller for its internal use of insights—for example, how processes are organized, who receives which reports, and how insights are used in follow-up and leadership/team development.
3. Personal data we process
When you use Connection Game, we mainly process the following categories of personal data about you, shared within your customer organization as follows:
- You (individual): access to your own profile and relevant individual analyses.
- Your team: access to aggregated team insights and team reports, without unnecessarily exposing sensitive details about individuals.
- Administrators/management at the customer: may receive extended access to reports and aggregated data in line with the customer agreement and role-based access in the Service, but not sensitive individual details (for example, full personality profiles, personal analyses, or chat history).
Basic user data
- Name
- Email address
- Date of birth (where provided)
- Link to organization (customer) and any licenses
Membership and organization
- Which team(s) you belong to
- Which customer organization you belong to
- Role in the team (for example, team lead, participant)
Profile data and analyses
- Team profile and leader profile for license holders (based on data generated in the Service, such as meeting data, reflection tasks, and in-app interactions)
- Other analyses and scoring data linked to you and your team (for example, trends over time, aggregated team statistics)
- Personality profile for team members (based on data generated in the Service)
- Big Five personality profile (personality test) — only if you have given explicit consent, and only while consent applies. The Big Five profile is used for personal insight and personalized AI analyses. A high-level summary may be shared with teammates; detailed facets are not. Profile data is never shared outside your teams.
Usage and technical data
- Basic logs of how the Service is used (for example, sign-in times, features used, device and browser information) where necessary for operations, improvement, and security
Chat history (personal AI coach)
- Messages you send to the AI coach and responses you receive
- These data are strictly personal and are never shared with teammates or third parties for their own purposes
Meeting data and voice analysis (where enabled)
- Audio recordings made or uploaded through the Service
- Text transcriptions of meetings
- Summaries and analyses at team level (for example, group dynamics and patterns)
We do not process special categories of personal data (sensitive data) unless clearly informed in advance and a separate legal basis applies (for example, explicit consent).
4. Purposes and legal bases
We use your personal data for the following purposes:
Delivering the Service to you and your organization
- Create and manage user accounts
- Link you to the correct team and organization
- Show you and your team relevant analyses and profiles
- Provide personal AI coaching and store chat history for continuity
- Manage the customer’s license and access
Legal basis: performance of a contract with the customer organization (GDPR Art. 6(1)(b)), and legitimate interest in operating a secure, well-functioning SaaS service (GDPR Art. 6(1)(f)).
Team profiling and leader profiling for license holders
This is core to the Service. We use in-Service data to provide team profiles, leader profiles, and group-dynamics analyses at team level (not automated employment, compensation, or similar decisions).
Legal basis: legitimate interest (GDPR Art. 6(1)(f)). We have assessed that this interest outweighs the impact on data subjects because the Service is voluntarily adopted, the purpose is development rather than control or sanctions, and we limit what data is used and how it is displayed.
Big Five personality profile (personality test)
The Big Five profile is optional and not required to use the Service. It provides deeper personal insight and more detailed team-dynamics analyses.
Legal basis: explicit consent (GDPR Art. 6(1)(a)). You receive clear information before taking the test and may withdraw consent at any time. If you withdraw, we stop using the data and will generally delete or anonymize your Big Five data within a reasonable time.
Voice analysis and meeting summaries
Where voice analysis is enabled, authorized users may record or upload meeting audio.
- Audio is used to create transcriptions and team-level analyses.
- Audio files are deleted within 24 hours after upload.
- Transcriptions are deleted within 180 days after the transcription is created.
- The customer organization is responsible for the legal basis for recording meetings. The Service provides clear notices, and recording can only be done by authorized users.
Legal basis: legitimate interest in team analysis and improving collaboration (GDPR Art. 6(1)(f)), and consent from meeting participants where required, obtained by the license holder in line with information provided in the Service.
Developing and improving the Service
- Analyze usage on an aggregated or pseudonymized basis
- Test new features and models
Legal basis: legitimate interest (GDPR Art. 6(1)(f)). Where possible we use aggregated or anonymized data.
Security and abuse prevention
- Protect against unauthorized access and misuse
- Troubleshooting, logging, and incident handling
Legal basis: legitimate interest (GDPR Art. 6(1)(f)) and legal obligations where applicable (GDPR Art. 6(1)(c)).
Customer support and account management
- Respond to inquiries from you or your employer
- Follow up on agreements, billing, and renewals
Legal basis: contract (GDPR Art. 6(1)(b)) and legitimate interest (GDPR Art. 6(1)(f)).
If we wish to use personal data for purposes not described here, we will inform you separately in advance and obtain the necessary legal basis before processing begins.
5. Sub-processors
To deliver analyses and profiles, we use selected sub-processors. These currently include:
- Supabase — PostgreSQL database and authentication (EU-hosted where configured).
- OpenAI — text and meeting-data analysis, AI coach, profile generation. We send only what is necessary for each analysis. OpenAI processes data as a processor under a data processing agreement. API content is not used to train OpenAI models by default.
- Soniox — speech-to-text transcription (EU API endpoint where used).
- pyannoteAI — speaker diarization and voiceprint analysis for meeting audio.
- AssemblyAI — speech-to-text transcription (EU/US regions where configured).
- Resend — transactional email (for example, team invitations).
- Stripe — payment processing for the CG Transcript product (where applicable).
- PostHog — product analytics (server- and client-side, where enabled).
- Render — cloud hosting for the application backend and related services.
Audio and other binary files may be stored temporarily on application servers during processing before retention policies apply.
The maintained sub-processor overview, including purposes, data categories, regions, and transfer mechanisms, is available in the Sub-processor List (docs/legal/sub-processors.md).
We do not sell personal data or share it with third parties for their own marketing purposes.
6. Transfers outside the EU/EEA
If sub-processors process personal data outside the EU/EEA (for example, in the USA), we ensure a valid transfer mechanism under GDPR, typically:
- EU Standard Contractual Clauses (SCCs), and
- supplementary technical and organizational measures where necessary.
Where practicable, we use services and configurations with processing in the EU/EEA and without unnecessary retention at the provider. Our current OpenAI API use may involve processing in the United States and is documented with OpenAI's DPA, SCCs, and supplementary measures in the Transfer Impact Assessment (docs/legal/tia.md).
Detailed information about transfers and safeguards is available on request.
7. Retention
We retain personal data only as long as necessary for the purposes above or as required by law.
As a general rule:
- Basic user data (name, email, team membership, license): retained while you are an active user. After termination of the customer agreement, data is deleted or anonymized within a reasonable period unless longer retention is legally required.
- Profiles and analyses: retained while the customer has an active agreement, plus a limited period afterward for documentation, support, and complaints. Where possible, anonymized aggregated data is used for improvement.
- Big Five data: retained only while your consent applies and as needed for the purpose. On withdrawal, we stop use and generally delete or anonymize within a reasonable time.
- Audio recordings: deleted within 24 hours after upload.
- Transcriptions and meeting text: deleted within 180 days after transcription.
- Technical and security logs: retained as needed for security, troubleshooting, and legal compliance (typically weeks to months depending on log type).
When retention periods expire, we delete or anonymize data so it can no longer be linked to you.
8. Security and privacy by design
We implement technical and organizational measures to protect personal data, including:
- Access control and role-based permissions
- Ongoing system maintenance and updates
- Procedures for incidents and security events
- Privacy by default and privacy by design in development and operations
Further details are maintained in Technical and Organizational Measures (docs/legal/security-measures.md).
We regularly review risk and update measures as needed.
9. Your rights
Under GDPR you have the right to:
- Access — know what data we hold and how it is used
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion in certain situations
- Restriction — limit processing for a period
- Data portability — receive certain data in a structured, machine-readable format
- Object — to processing based on legitimate interest
Where processing is based on consent (for example, Big Five), you may withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise your rights, contact kjersti@connectiongame.no. We respond as soon as possible and within 30 days. In some cases we may be required to retain certain data despite an erasure request.
You may lodge a complaint with Datatilsynet (Norwegian Data Protection Authority): www.datatilsynet.no
10. Cookies and analytics
When you visit our website or use the Service in a browser, we may use cookies and similar technologies for:
- Essential functionality (sign-in, security)
- Understanding usage patterns to improve the Service
Further information about cookies, purposes, and retention will be described in a separate cookie notice on our website where applicable.
11. Changes to this Policy
We may update this Privacy Policy when the Service, our practices, or applicable law changes. For material changes we will notify you clearly, for example in the Service or by email to affected users or administrators.
The date of the latest update is always shown at the top of this document.