This Privacy Policy explains how Virsion Sagl processes personal data in connection with Gameheim, and the rights you have over that data. In effect since 24 July 2026, last updated 2 September 2026 (demonstration-organization measurements, sections 3 and 4).
1. Controller, Processor and contacts
For data processed within the Organization (content, User accounts, usage data), the professional Customer (typically the user’s employer) is the Data Controller; Virsion Sagl is the Processor and processes data on behalf of and under the Customer’s instructions. Processing is governed by the contract between Controller and Processor and its data-processing annexes.
For data necessary to manage the contractual relationship (Organization registration, billing and payments, administrative communications), Virsion acts as an independent Controller.
Virsion Sagl, Canton Ticino, Switzerland. UID: CHE-452.458.064. Contact: info@virsion-studio.com.
2. Applicable law
nFADP (Switzerland) and, for EU users, the GDPR.
3. Data processed
Depending on how the Service is used, Virsion processes:
- Account: name, username, email, role and Organization; language and preferences.
- Authentication and security: password (encrypted), MFA data where enabled, and a token for biometric login from the mobile app (stored as a hash; biometric data never leaves the device).
- Usage: access logs, date and time, IP address (recorded in cloud logs in shortened or pseudonymised form), country of access (country-level geolocation derived from the IP, processed internally), actions performed (audit log), AI token consumption and AI conversation history.
- Active sessions (account security): for each sign-in, the browser or app identifier declared by the device, and an approximate location (city and country) derived from the IP using a local database — the IP itself is not stored with the session. These are shown to the account holder alone, in Settings → Security, so that a sign-in they did not perform can be recognised and revoked; they are never used for any other purpose, are not visible to administrators or colleagues, and are not kept as a history: they are erased when the session ends or is revoked, and at most after its maximum lifetime. The location is approximate by nature and may be inaccurate.
- Presence and activity: real-time presence status, application heartbeats and, where the Customer uses the Agent, inactivity indicators based on the timestamp of the last OS-level input (for the “away” status). Informing Users about the use of such features in the employment context is the Controller’s (Customer’s) responsibility.
- Content: tasks, wiki pages, documents, messages and channels, comments, moodboards, attachments, custom emojis and any other content uploaded to the Organization, including any personal data therein; voice recordings (voice-acting takes) uploaded by the Customer, for which the Customer is responsible for rights and releases.
- Perforce metadata: file names and paths, states, locks, changelists and counts transmitted by the Agent. The content of files versioned in Perforce is not transmitted to Virsion.
- Prompts and AI outputs.
- Billing (Virsion as Controller): Organization billing data and payment outcomes. Full card data is processed exclusively by Stripe; Virsion does not store it.
- Mobile app (only if the user enables the features): device installation identifier, push token (FCM/APNs), platform. No personal content in notification payloads.
- Demonstration organizations only: aggregate engagement measurements, kept as daily counts and never as a record of an individual. These are sign-in counts, distinct demo accounts used, distinct visitor networks (counted, not stored), country of access, session length, rejected sign-in attempts, which areas of the product were opened and how many times, and the broad device category, operating system family, browser family and preferred language declared by the browser. Deliberately excluded: the full IP address, the raw browser identifier and its version numbers, screen or device characteristics, and any ordered trail of what a person did. Because demo credentials are issued by Virsion and shared among several people at the evaluating company, these counts describe an organization evaluating the Service, not an identified individual. Visible to Virsion administrators and kept 90 days. The measurement is disclosed when the demo credentials are issued. None of this applies to customer organizations.
- Biometric data: not collected (handled by the device, never leaves it).
- Providing account data is necessary to deliver the Service; without it the Service cannot be used.
4. Purposes and legal bases
As Processor, under the Controller’s instructions, Virsion processes data to: deliver the Service; index and search; generate AI outputs (RAG); provide collaboration and presence features; ensure security, monitoring and abuse prevention; and comply with legal obligations. Identifying the legal bases is the Controller’s responsibility.
As an independent Controller, Virsion processes registration and billing data for contract performance (art. 6(1)(b) GDPR), compliance with legal, accounting and tax obligations (art. 6(1)(c) GDPR), and protection of its rights and abuse prevention (legitimate interest, art. 6(1)(f) GDPR).
Also as an independent Controller, and only within demonstration organizations, Virsion measures engagement with the demo — audience measurement and statistical analysis — under legitimate interest (art. 6(1)(f) GDPR), so that it can tell whether an evaluation actually started, follow it up, and notice when someone is unable to sign in. The measurements are the aggregate counts described in section 3: no full IP address, no browser fingerprint, no ordered record of an individual’s activity, and no cookie or identifier stored on the device for this purpose. The measurement is disclosed to recipients when their demo credentials are issued. You may object at any time using the contact address below.
5. Recipients (sub-processors and providers)
Virsion does not sell personal data. It shares data only with providers that process it on Virsion’s behalf under contract, and only as needed to run the Service:
- Microsoft Corporation: hosting, database, storage, AI services (Azure OpenAI, Azure AI Search), key management, WAF/CDN, monitoring. European data centers. AI features run entirely within the Azure infrastructure.
- Stripe: payment processing and subscription management; also processes payment data as an independent controller under its own privacy notice.
- Google LLC (Firebase Cloud Messaging): push notification delivery on Android (token and device identifier only; no personal data in payloads).
- Apple Inc. (APNs): push notification delivery on iOS (token and device identifier only; no personal data in payloads).
- Hostinger International Ltd (Cyprus, EU): transactional emails (account verification, service notifications).
- Country-level geolocation is performed internally using a local database, so the IP is not sent to any third party for this purpose. The up-to-date list of sub-processors, the regions used and their terms are governed by Annex 1 of the contract.
6. International transfers
Data is processed in European data centers. Any transfers outside the EU or Switzerland are covered by the safeguards in the sub-processors’ DPAs (EU-US Data Privacy Framework and/or Standard Contractual Clauses).
7. Retention
Organization data is retained for the duration of the contract; on termination, the export (30 days) and deletion terms set out in the contract apply. Billing data is retained for statutory periods. Longer statutory retention obligations and the sub-processors’ technical retention remain reserved.
8. Security
Virsion implements appropriate technical and organisational measures, including encryption in transit and at rest with per-organization keys where available, Organization segregation, MFA, role-based access controls and audit logs, detailed in Annex C of the contract.
9. Automated decision-making
The Service does not carry out automated decision-making producing legal or similarly significant effects on data subjects.
10. Your rights
Users have the right of access, rectification, erasure, portability, objection and restriction. For data processed within the Organization, since Virsion acts as Processor, users exercise their rights first towards their employer or Organization (the Controller); Virsion assists the Controller. For data for which Virsion is an independent Controller (registration, billing), contact info@virsion-studio.com.
Users also have the right to lodge a complaint with the competent supervisory authority (in Switzerland the FDPIC; in the EU their national authority).
Account deletion: request to the administrator of the user’s Organization (Controller), who manages the account lifecycle.
11. Cookies
Only strictly necessary technical cookies (session/authentication, language, security). No profiling cookies and no third-party analytics. See the Cookie Policy for details.
12. Mobile app
Optional native features: push notifications (content always impersonal, only a technical token transmitted) and biometric login (biometric data stays on the device; the server only handles an encrypted, revocable token).
13. Minimum age
The Service is intended exclusively for adult users in a professional context. Virsion does not knowingly collect data from minors.
14. Changes
Changes will be published on this page with their date; material changes will be communicated through the platform.
15. Contact
Virsion Sagl, Canton Ticino, Switzerland. info@virsion-studio.com.
