Privacy Policy

This Privacy Policy governs the collection, use, processing, and protection of personal information by our online casino platform operating under United Kingdom jurisdiction. We are committed to safeguarding your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and UK Data Protection Act 2018. This policy outlines how we handle your personal data when you access our services, create accounts, participate in gaming activities, or interact with our customer support.

1. Information We Collect

We collect various types of personal information necessary to provide our online casino services effectively and maintain regulatory compliance. The scope of data collection is designed to ensure optimal user experience while meeting legal obligations under UK gambling regulations and anti-money laundering requirements.

Data CategoryInformation TypesCollection Purpose
Personal IdentificationFull name, date of birth, gender, nationalityAccount verification and age validation
Contact InformationEmail address, phone number, postal addressCommunication and account security
Financial DataPayment methods, transaction history, withdrawal preferencesPayment processing and fraud prevention
Technical InformationIP address, device information, browser detailsPlatform security and user experience optimization
Gaming ActivityGame preferences, betting patterns, session durationResponsible gambling monitoring and service improvement

We also collect information through automated technologies including cookies, web beacons, and similar tracking mechanisms. This data helps us understand user behaviour patterns, detect suspicious activities, and enhance platform functionality. Additionally, we may receive information from third-party sources such as payment processors, identity verification services, and affiliate partners to supplement the data you provide directly.

2. Legal Basis for Processing

Under GDPR and UK data protection legislation, we process personal data based on several legal grounds depending on the specific purpose and context of data collection. Our primary legal bases include contractual necessity for account management and service provision, legitimate interests for business operations and security measures, legal compliance for regulatory obligations, and explicit consent for marketing communications.

  1. Contractual necessity applies when processing data essential for account creation, payment processing, game participation, and customer support services
  2. Legal compliance covers data processing required by UK Gambling Commission regulations, anti-money laundering laws, and tax obligations
  3. Legitimate interests encompass fraud prevention, platform security, business analytics, and service improvement activities
  4. Consent-based processing includes marketing communications, personalised promotions, and optional data sharing with selected partners
  5. Vital interests may apply in exceptional circumstances where data processing is necessary to protect user safety or prevent harm

We ensure that legitimate interests assessments are conducted regularly to balance our business needs against your privacy rights and freedoms. Where consent is the legal basis, you maintain the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.

3. Data Usage and Purposes

Personal information collected through our platform serves multiple essential purposes aligned with providing comprehensive online casino services and maintaining regulatory compliance. We utilise your data to facilitate seamless gaming experiences, ensure platform security, and meet legal obligations imposed by UK gambling authorities.

Primary usage purposes include account management and verification processes, payment processing and financial transaction handling, game provision and random number generation verification, customer support and dispute resolution, responsible gambling monitoring and intervention, fraud detection and prevention systems, regulatory reporting and compliance activities, platform improvement and feature development.

We employ advanced analytics to understand user preferences and gaming patterns, enabling personalised game recommendations and tailored promotional offers. Marketing communications are sent only with explicit consent and include information about new games, bonus opportunities, tournaments, and platform updates. Data analysis helps identify potential problem gambling behaviours, triggering appropriate intervention measures and support resources.

Technical data supports platform optimisation, security enhancement, and troubleshooting processes. We use aggregated and anonymised information for statistical analysis, market research, and business intelligence purposes without identifying individual users.

4. Data Sharing and Disclosure

We maintain strict controls over data sharing and disclosure practices, ensuring personal information is shared only when necessary for service provision, legal compliance, or with explicit user consent. Our data sharing framework prioritises privacy protection while enabling essential business operations and regulatory compliance.

  1. Service providers and third-party processors receive limited data necessary for specific functions including payment processing, identity verification, customer support, and technical maintenance
  2. Regulatory authorities may receive information as required by UK Gambling Commission regulations, anti-money laundering laws, or court orders
  3. Law enforcement agencies may access data when legally mandated through proper judicial procedures or statutory obligations
  4. Business partners including game developers and affiliate networks may receive aggregated, anonymised data for analytics and performance measurement
  5. Merger or acquisition scenarios may involve data transfer to acquiring entities under strict confidentiality and continuity agreements

All third-party data recipients are bound by comprehensive data processing agreements ensuring adequate protection standards and compliance with applicable privacy laws. We conduct regular audits and assessments of data sharing arrangements to verify ongoing compliance and security standards.

Cross-border data transfers outside the UK and European Economic Area are conducted only with appropriate safeguards including adequacy decisions, standard contractual clauses, or certification schemes approved by relevant data protection authorities.

5. Cookies and Tracking Technologies

Our platform employs various cookies and tracking technologies to enhance user experience, ensure security, and provide personalised services. We categorise cookies based on their functionality and obtain appropriate consent for non-essential tracking mechanisms as required by UK cookie legislation and GDPR requirements.

Essential cookies are strictly necessary for platform functionality and cannot be disabled without affecting core services. These include session management cookies, security tokens, load balancing identifiers, and authentication mechanisms. Performance cookies collect anonymous information about platform usage patterns, popular games, and technical performance metrics.

Functional cookies remember user preferences, language settings, display options, and accessibility configurations to provide personalised experiences. Marketing cookies, deployed only with explicit consent, track user behaviour across sessions to deliver targeted promotional content and measure advertising effectiveness.

Third-party cookies from analytics providers, payment processors, and advertising networks operate under their respective privacy policies. We provide comprehensive cookie management tools enabling granular control over cookie preferences and tracking settings.

Alternative tracking technologies including web beacons, pixel tags, and local storage mechanisms serve similar purposes to cookies and are subject to the same consent and control frameworks.

6. Data Security Measures

We implement comprehensive technical, organisational, and administrative security measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. Our security framework follows industry best practices and regulatory requirements specific to online gambling operations.

  1. Encryption protocols protect data transmission and storage using advanced cryptographic standards including TLS 1.3 for communications and AES-256 for data at rest
  2. Access controls ensure data availability only to authorised personnel based on role-based permissions and need-to-know principles
  3. Network security measures include firewalls, intrusion detection systems, and regular vulnerability assessments to prevent unauthorised access
  4. Data backup and recovery procedures ensure business continuity while maintaining data integrity and availability
  5. Employee training programmes ensure staff understand privacy obligations, security procedures, and incident response protocols
  6. Regular security audits and penetration testing identify potential vulnerabilities and verify security control effectiveness
  7. Incident response procedures enable rapid detection, containment, and resolution of security breaches

We maintain cyber security insurance coverage and collaborate with specialised security firms to stay ahead of emerging threats. Physical security measures protect server infrastructure and data storage facilities through restricted access, surveillance systems, and environmental controls.

Data retention policies ensure personal information is stored only for necessary periods and securely disposed of when no longer required for business or legal purposes.

7. Your Privacy Rights

Under GDPR and UK Data Protection Act 2018, you possess comprehensive rights regarding your personal data processing. We are committed to facilitating the exercise of these rights through accessible procedures and reasonable response timeframes.

Right of access enables you to obtain confirmation of data processing activities and receive copies of personal information we hold about you. Right to rectification allows correction of inaccurate or incomplete personal data. Right to erasure, also known as the right to be forgotten, permits deletion of personal data under specific circumstances including withdrawal of consent or objection to processing.

Right to restrict processing enables limitation of data processing activities while maintaining data storage. Right to data portability allows you to receive personal data in structured, commonly used formats and transmit this information to other data controllers. Right to object provides grounds for opposing data processing based on legitimate interests or for direct marketing purposes.

Rights related to automated decision-making and profiling include the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or significantly affects you.

To exercise these rights, contact our data protection team through designated channels provided in the contact information section. We respond to rights requests within one month, though complex requests may require up to three months with appropriate notification and justification.

8. Data Retention Policies

We maintain comprehensive data retention policies balancing business needs, legal obligations, and privacy rights. Retention periods vary depending on data types, processing purposes, and regulatory requirements specific to online gambling operations in the UK jurisdiction.

Account information and transaction records are retained for seven years following account closure to meet UK Gambling Commission requirements and anti-money laundering obligations. Marketing consent records are maintained until consent withdrawal plus additional periods necessary for legal compliance and dispute resolution.

Technical logs and security data are retained for periods necessary to ensure platform security and investigate incidents, typically ranging from one to three years. Customer support communications are preserved for reasonable periods to resolve ongoing issues and improve service quality.

Gaming activity data including betting history and responsible gambling monitoring information are retained for periods required by regulatory obligations and duty of care responsibilities. Financial transaction data is maintained according to tax authorities’ requirements and payment processing regulations.

Data deletion procedures ensure secure and irreversible removal of personal information when retention periods expire or legal bases for processing cease to exist. Anonymisation techniques may be applied to historical data for statistical and analytical purposes while eliminating personal identification capabilities.

9. Contact Information and Complaints

We maintain dedicated data protection and privacy contact channels to address inquiries, rights requests, and complaints regarding personal data processing. Our data protection officer oversees privacy compliance and serves as the primary contact for data protection matters.

For privacy-related inquiries, rights requests, or complaints, contact our data protection team via email at [email protected] or through secure messaging systems available in your account dashboard. Postal correspondence may be directed to our data protection officer at our registered business address.

We acknowledge receipt of privacy inquiries within 48 hours and provide substantive responses within statutory timeframes. Complex matters may require additional investigation periods, which we communicate clearly with regular progress updates.

If you are unsatisfied with our response to privacy concerns, you have the right to lodge complaints with the Information Commissioner’s Office (ICO), the UK’s independent data protection regulator. The ICO can be contacted through their website at ico.org.uk or by telephone at 0303 123 1113.

We encourage direct communication with our privacy team before escalating concerns to regulatory authorities, as we strive to resolve privacy issues promptly and satisfactorily through direct dialogue and cooperation.