Privacy Policy for Midhem Online
Last updated: July 16, 2026
This policy explains how personal data is processed when you use the Midhem website, create or manage an account, play the game, contact support, make a purchase, or submit diagnostic information.
Data controller and contact
ArrowKey Gaming / Midhem Online, Sweden, is responsible for the processing described in this policy.
Privacy requests may be sent to noreply@midhem.com. Logged-in users may also use the Helpdesk. We may ask for information needed to verify that a requester controls the relevant account.
What we process, why, and for how long
| Data and purpose | Legal basis | Retention |
|---|---|---|
| Account email, password hash, account settings, country selection, recovery information, characters, game progress, inventories, sanctions, and transaction history. Used to create, secure, and provide the account and game service. | Performance of our contract with you. Security and abuse-prevention processing may also rely on our legitimate interests. | While the account is active. Following a valid closure request, data is deleted or anonymised unless it must be retained for legal obligations, fraud prevention, dispute handling, or legal claims. |
| IP addresses, login times, device or platform information, security events, and limited request logs. Used for account security, rate limiting, troubleshooting, and abuse prevention. | Legitimate interests in protecting users and the service. | Short-lived visitor activity logs are routinely cleared. Registration and account-security information may be retained for the active life of the account and, where necessary, for up to 12 months afterward. |
| Support tickets, replies, feedback, reports, and related account information. | Performance of our contract and legitimate interests in customer support and dispute resolution. | Normally up to 24 months after a ticket is closed. Information needed for an unresolved dispute or legal claim may be kept longer. |
| Payment transaction IDs, payer email supplied by the payment provider, amount, currency, account ID, purchased content, and anti-fraud records. We do not receive or store full card details. | Performance of our contract, compliance with accounting obligations, and legitimate interests in fraud prevention. | For the period required by applicable accounting and tax rules, normally up to seven years, and while a payment dispute remains open. |
| Optional crash dumps, client logs, performance telemetry, UID, player name, platform information, and written feedback. | Your consent where the client offers an optional submission, or our legitimate interests when the information is necessary to diagnose a request you initiated. | Crash reports and performance telemetry are automatically removed after 90 days. Written feedback logs are removed after 180 days. |
| Automatic death screenshots, when enabled in account settings, for incident investigation and compensation claims. | Your consent, which can be withdrawn in Account Settings. | Automatically removed after 90 days. We will not publish a death screenshot for promotional use without separate permission. |
| Newsletter status and email address for optional news, promotions, and coupons. | Your consent. | Until you unsubscribe or the account is deleted. You can withdraw through My Account or an unsubscribe link. |
| Cookie and similar-technology choices. | Consent for non-essential purposes; legitimate interests and the electronic-communications exemption for strictly necessary storage. | The consent choice is stored for 180 days. See the Cookie Policy. |
Recipients and service providers
Personal data is available only to authorised Midhem administrators and suppliers that need it for a defined purpose. Depending on the feature you use, recipients may include:
- Website, database, game-server, backup, and infrastructure hosting providers.
- Email-delivery providers used for verification, recovery, and service messages.
- PayPal and other payment partners when you choose their payment method.
- Google Analytics, only after analytics consent.
- Discord, YouTube, and external-media hosts, only after external-content consent or when you follow an external link.
- Professional advisers or authorities where disclosure is legally required.
We do not sell personal data.
International transfers
Some optional suppliers, including Google, Discord, YouTube, PayPal, and CDN providers, may process information outside the EU/EEA. Where GDPR transfer rules apply, transfers must rely on an applicable adequacy decision, approved standard contractual clauses, or another lawful safeguard. Optional analytics and external content remain disabled until you consent.
Your rights
Subject to the conditions and exceptions in GDPR, you may request:
- Information about and access to your personal data.
- Correction of inaccurate or incomplete information.
- Deletion of information that is no longer needed or is processed unlawfully.
- Restriction of processing.
- A portable, machine-readable copy of data you supplied when processing is based on consent or contract.
- Objection to processing based on legitimate interests.
- Withdrawal of consent at any time, without affecting earlier lawful processing.
Send requests to noreply@midhem.com. We normally respond within one month. You also have the right to lodge a complaint with Sweden's supervisory authority, Integritetsskyddsmyndigheten (IMY).
Automated processing
Automated controls may rate-limit requests, detect unusual activity, or prevent suspected abuse. We do not use website data to make solely automated decisions that produce legal or similarly significant effects on you.
Children
Midhem is not intended for children under 13. A person under 13 must not provide consent for optional marketing, analytics, screenshots, or other consent-based processing without permission from a parent or guardian. Parents or guardians who believe a child has supplied personal data should contact us.
Security
We use access controls, HTTPS, secure session cookies, salted password hashing, restricted private storage, backups, and logging intended to protect confidentiality, integrity, and availability. No online service can eliminate every risk, and users should use a unique password and protect their recovery information.
Changes to this policy
Material changes will be dated on this page and, where appropriate, communicated through the website, account service, or email.