Privacy Policy
Last updated: January 2026 · GDPR-compliant
What We Collect
Identity data (name, date of birth, address, ID documents) for KYC. Contact data (email, phone). Financial data (deposit/withdrawal records, payment method tokens — not full card numbers). Usage data (games played, session duration, wagering). Technical data (device type, browser, IP address) for fraud prevention.
Why We Collect It
Legal obligation (licensing, AML regulations, tax reporting). Contractual necessity (running your account, processing payments, paying winnings). Legitimate interest (fraud prevention, responsible gaming monitoring, platform improvement). Consent (marketing emails, push notifications — opt-in only, revocable anytime).
How We Share It
Payment processors (Stripe, PayPal, Skrill) for transaction execution. Game providers (NetEnt, Pragmatic, Evolution) for gameplay delivery — no personal data shared, only anonymised session tokens. Regulators (MGA, Curaçao eGaming) on statutory request. Law enforcement on lawful order. We do not sell data to advertisers, ever.
Data Retention
Account data held for the duration of the account plus 7 years post-closure (AML compliance). Transaction records retained 7 years. Marketing data deleted within 30 days of unsubscribe. Session/technical data retained 90 days unless needed for active fraud investigation.
Your GDPR Rights
Right to access (download all your data via Settings > Privacy). Right to rectification (edit via Settings). Right to erasure (request via support — subject to AML retention obligations). Right to data portability (CSV export). Right to object (unsubscribe from marketing). Right to lodge a complaint with the Irish Data Protection Commission or the European Data Protection Board.
Cookies
Strictly necessary cookies for session management and fraud prevention — cannot be disabled. Analytics cookies (anonymised) to improve platform UX — opt-out via banner. Marketing cookies (third-party) — opt-in only. Full cookie breakdown available via the cookie preferences panel in the footer.
Security
TLS 1.3 encryption in transit. AES-256 encryption at rest. Data stored on EU servers (Ireland, Netherlands). PCI-DSS Level 1 for payment data. Regular penetration testing by independent security auditors accredited via the ISO/IEC 27001 framework. Breach notification within 72 hours as required by GDPR.
Contact
Data Protection Officer: [email protected]. Response within 5 working days on GDPR requests. For independent guidance on your rights, see the DPC individuals portal and gdpr.eu.