Privacy Policy
Senast uppdaterad 28.7.2026
This Privacy Policy explains how Arctic Virtual Trade Oy (CSKejsaren) processes your personal data when you use the CSKejsaren service or otherwise interact with us. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable data protection legislation.
1. Data Controller
- Company
- Arctic Virtual Trade Oy
- Business ID
- 3212263-5
- Address
- Sädekuja 4, 16300 Orimattila, Finland
- [email protected]
2. Contact Person for Data Protection Matters
- Name
- Veeti Mattila
- [email protected]
- Phone
- +358 41 313 7417
3. What Personal Data We Process
We process the following categories of data:
- Contact and customer data: your name, email address, phone number, address and bank details (account number or Swish number) that you provide to us in connection with a transaction or other interaction.
- Identification data: data received in connection with strong electronic authentication, such as your name and personal identity number, when you use Advance Payment. Authentication is carried out through Signicat using, for example, BankID or bank credentials. Signicat processes identification data as a processor on our behalf and retains it in its own systems for the period specified in the data processing agreement concluded with us.
- Transaction data: information about the items you have sold, purchase prices, payments, your Steam trade link and your trading history.
- Steam account data: when you sign in to the Service with your Steam account (Automated Sale), we receive your Steam identifier (SteamID) and the publicly available profile and item information of your Steam account. We do not receive your Steam password or access to your Steam account.
- Communication data: the history of your communication with us in the chat, by email or in other channels.
- Technical data: data concerning the use of the website, such as your IP address, browser and device information, the time and duration of your visit and the pages visited. This data is collected using cookies and similar technologies as described in Section 6.
- Data concerning breaches of contract: information about breaches of contract related to Advance Payment (for example reversing a trade during the Trade Protection period), the related receivables and collection measures.
Providing contact, identification and payment data is a precondition for the transaction: without it we cannot complete the transaction or pay the purchase price.
4. Where We Obtain the Data
As a rule, we obtain the data from you when you interact with us, make transactions, authenticate yourself or contact us. In addition, we receive:
- identification data from the strong authentication service provider Signicat in connection with your authentication;
- technical data from cookies and from the providers of analytics and marketing tools; and
- transaction-related data from the Steam platform (Valve Corporation), such as the status of a trade, as well as your Steam identifier and public profile and item information in connection with Steam Sign-In.
5. Purposes and Legal Bases of Processing
| Purpose | Data categories | Legal basis |
|---|---|---|
| Completing transactions, payments and customer service | Contact, transaction, payment and communication data | Performance of a contract (GDPR 6(1)(b)) |
| Verifying identity and preventing and investigating fraud and other misuse | Identification, transaction and communication data | Legitimate interest (6(1)(f)) and a possible legal obligation (6(1)(c)) |
| Collection of receivables and establishing, exercising and defending legal claims | Contact, transaction and breach-of-contract data | Legitimate interest (6(1)(f)) |
| Taking previous breaches of contract into account in new transactions (see Section 10) | Breach-of-contract data | Legitimate interest (6(1)(f)) |
| Accounting | Transaction and payment data | Legal obligation (6(1)(c), the Finnish Accounting Act) |
| Developing the Service and statistical analysis | Technical data | Consent (6(1)(a), statistics cookies) |
| Marketing and ad targeting | Technical data, email address | Consent (6(1)(a), marketing cookies); for direct marketing, legitimate interest based on the customer relationship (see Section 11) |
| Informing you about the Service (for example maintenance breaks and transaction-related notifications) | Contact data | Performance of a contract (6(1)(b)) |
6. Cookies
We use cookies and similar technologies on our website. Cookies fall into four categories:
- Necessary: enable the basic functions and security of the website, such as remembering your cookie choices and maintaining the sign-in session of the Automated Sale. These cannot be disabled.
- Functional: cookies of the chat customer service (Tidio Ltd). The chat is loaded when you give consent to functional cookies or open the chat yourself.
- Statistics: we collect information about the use of the website with Google Analytics (Google Ireland Ltd), for example the duration of your visit, the pages visited and browser and device information. We do not seek to identify individual visitors.
- Marketing: Google Ads conversion tracking (Google Ireland Ltd), the Meta pixel (Meta Platforms Ireland Ltd) and the X pixel (X Corp.) for measuring and targeting advertising. These are loaded only with your consent.
Apart from necessary cookies, cookies are used only with your consent. The consent is valid for 12 months, and you can change your choices or withdraw your consent at any time in the website's cookie settings. You can also block cookies in your browser settings; in that case some functions of the website may not work.
7. Recipients of the Data
We use the following service providers (processors), which process data on our behalf and in accordance with our instructions:
- chat customer service: Tidio Ltd
- analytics: Google Ireland Ltd (Google Analytics)
- marketing: Google Ireland Ltd (Google Ads), Meta Platforms Ireland Ltd, X Corp.
- strong authentication: Signicat (authentication using, for example, BankID or bank credentials)
- IT and server infrastructure: Hetzner Online GmbH (data centre services) and Cloudflare, Inc. (content delivery network and security, through which the website's traffic is routed)
In addition, we may disclose personal data to:
- Jacob Pay Ab, which in Swish transactions purchases the items in CSKejsaren's name and on its behalf; we disclose to Jacob Pay Ab the information necessary for completing the transaction and the payment, and Jacob Pay Ab may also process this data to comply with legislation applicable to it;
- our collection partner Svea for the recovery of receivables if you breach the contractual terms concerning Advance Payment;
- our advisors, such as auditors and legal advisors, to the extent necessary;
- authorities, courts and other public bodies where the law requires or permits disclosure (for example in connection with a criminal complaint); and
- banks and payment intermediaries for the execution of payments.
We do not sell your personal data to third parties.
8. Transfers of Data Outside the EU or EEA
We aim to process personal data primarily within the EU and EEA. However, some of the service providers we use (for example Google, Meta, X and Cloudflare) may transfer data to the United States or elsewhere outside the EU and EEA. In such cases, the transfers are based on safeguards approved by the European Commission, such as the EU–US Data Privacy Framework or the Commission's standard contractual clauses.
9. Retention Periods
We retain personal data only for as long as necessary for the purpose of the processing or as required by law:
- Transaction and payment data: for the period required by the Finnish Accounting Act, as a rule 6 years from the end of the year during which the financial year ended.
- Identification data: 3 years from the transaction or from the last event related to it, which corresponds to the general limitation period for debts and covers possible collection and the handling of legal claims. Data retained by Signicat in its own systems is subject to the retention period based on the data processing agreement referred to in Section 3. Personal identity numbers are retained only for as long as there is a specific and justified need to process them.
- Data concerning breaches of contract and collection: for as long as necessary for recovering the receivable and handling legal claims, at most 10 years from the last event.
- Communication data (chat, email): where a transaction is made in the sales chat, the communication forms part of the transaction and contract documentation, because the provision of information and the formation of the agreement take place through the chat. Communication data is therefore retained for the period required by the Finnish Accounting Act, as a rule 6 years from the end of the year during which the financial year ended. If a transaction involves a dispute or collection, communication data may be retained for at most 10 years from the last event for the purpose of handling legal claims.
- Technical data and analytics: in accordance with the validity periods of the individual cookies.
When retention is no longer necessary, we delete or anonymise the data. If deletion is not technically possible (for example backups), we isolate the data from other processing until deletion is possible.
10. Profiling and Automated Decision-Making
We do not make decisions based solely on automated processing that would have legal effects concerning you or similarly significant effects.
We may, however, take information recorded in the customer register about previous breaches of contract (for example misuse of Advance Payment) into account when assessing new transactions. The assessment is always made by a human.
11. Direct Marketing and Newsletter
We may send you newsletters and offers by email if you have interacted with us and provided your email address, or if you have separately subscribed to the newsletter. You can opt out of direct marketing at any time using the unsubscribe link included in every message or by notifying us at [email protected].
12. Data Security
We protect personal data with appropriate technical and organisational measures, including encryption of data transfers, access control and limiting access rights to those persons whose work duties require it. Our employees and partners who process personal data are bound by confidentiality and process the data only in accordance with our instructions.
13. Your Rights
Under data protection legislation you have the right to:
- know whether we process your personal data and obtain access to that data;
- request the rectification of inaccurate or incomplete data;
- request the erasure of your data ("the right to be forgotten"), to the extent that we have no statutory or other legitimate ground to retain it;
- request the restriction of processing in certain situations;
- object to processing based on legitimate interest, including direct marketing, on grounds relating to your particular situation;
- receive the data you have provided in a portable format, where the processing is based on consent or a contract; and
- withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
You can exercise your rights by contacting us at [email protected]. We may ask you to verify your identity before processing the request.
If you consider that the processing of your personal data infringes data protection legislation, you have the right to lodge a complaint with a supervisory authority. The supervisory authority of the data controller is the Office of the Data Protection Ombudsman in Finland (www.tietosuoja.fi). You may also lodge a complaint with the supervisory authority of the EU member state of your habitual residence — in Sweden, the Swedish Authority for Privacy Protection (IMY, www.imy.se).
14. Data of Minors
Our Service is not directed at children under 13 years of age. If a minor (13–17 years old) uses the Service in accordance with the Terms of Service with the consent of a guardian, we process their data as described in this Policy. Advance Payment and the related strong authentication are available only to adults.
15. Changes to This Policy
We may update this Privacy Policy, for example when the Service or legislation changes. The version currently in force is available at cskejsaren.se, and the date of the most recent change is indicated at the beginning of the Policy. We aim to announce material changes on our website.
16. Contact
For all questions concerning this Policy or the processing of your personal data, please contact:
Arctic Virtual Trade Oy, Sädekuja 4, 16300 Orimattila, Finland, [email protected]