Privacy Policy
This Privacy Policy governs the collection, processing, storage, and protection of personal data provided by users of our online casino platform. We are committed to maintaining the highest standards of data protection in accordance with the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, and other applicable UK legislation. By accessing our gaming services, you acknowledge and consent to the practices described in this comprehensive privacy policy.
1. Data Controller and Contact Information
We act as the data controller for all personal information collected through our online casino platform. Our commitment to data protection extends beyond legal compliance to encompass ethical responsibility towards our gaming community. As a UK-licensed operator, we maintain strict adherence to regulations set forth by the UK Gambling Commission and the Information Commissioner’s Office (ICO).
For any privacy-related inquiries, data subject requests, or concerns regarding the processing of your personal information, you may contact our dedicated Data Protection Officer through our secure communication channels. We maintain a comprehensive record of all data processing activities and ensure transparent communication regarding your privacy rights and our data handling practices.
Our legal basis for processing personal data varies depending on the specific type of information and its intended use. We process data based on legitimate interests for marketing communications, contractual necessity for account management and gaming services, legal obligations for regulatory compliance, and explicit consent for specific promotional activities.
2. Types of Personal Data We Collect
We collect various categories of personal data necessary for providing secure and compliant online casino services. The scope of data collection is carefully balanced between operational requirements, regulatory obligations, and user privacy protection. Our data collection practices are designed to be transparent, proportionate, and aligned with industry best practices.
| Data Category | Information Types | Collection Method | Retention Period |
| Personal Identification | Full name, date of birth, address, phone number, email address | Registration form, verification documents | 7 years post-closure |
| Financial Information | Banking details, payment card information, transaction history | Payment processors, deposit/withdrawal forms | 7 years for tax purposes |
| Gaming Activity | Betting patterns, game preferences, session duration, win/loss records | Platform interactions, automated logging | 5 years minimum |
| Technical Data | IP address, browser type, device information, cookies | Automatic collection, website analytics | 2 years typically |
| Verification Documents | Passport, driving license, utility bills, bank statements | KYC compliance uploads | 7 years post-verification |
Additional data may be collected during customer support interactions, promotional activities, or special gaming events. We implement data minimisation principles, ensuring we only collect information that is necessary, relevant, and proportionate to our stated purposes.
3. Purposes and Legal Basis for Data Processing
We process personal data for specific, explicit, and legitimate purposes that align with our operational requirements and regulatory obligations, including when using trusted Slots Sites. Our processing activities are governed by clear legal bases as defined under UK GDPR, ensuring lawful and transparent data handling throughout your relationship with our platform.
- Account creation and management services, including user authentication, profile maintenance, and platform access control based on contractual necessity
- Financial transaction processing, including deposits, withdrawals, bonus allocations, and payment verification based on contractual performance and legitimate interests
- Regulatory compliance and anti-money laundering obligations, including Know Your Customer (KYC) verification, suspicious activity monitoring, and reporting to relevant authorities based on legal obligations
- Responsible gambling measures, including deposit limits, self-exclusion tools, behavioral analysis for problem gambling indicators based on legitimate interests and legal obligations
- Customer support services, including query resolution, technical assistance, and complaint handling based on legitimate interests and contractual performance
- Marketing communications and promotional offers, including personalised bonuses, newsletter distribution, and targeted advertising based on legitimate interests and explicit consent
- Platform security and fraud prevention, including suspicious activity detection, account security monitoring, and risk assessment based on legitimate interests
- Business analytics and service improvement, including user experience optimisation, game performance analysis, and platform development based on legitimate interests
We regularly review our processing purposes to ensure they remain necessary, proportionate, and aligned with user expectations and regulatory requirements.
4. Data Sharing and Third-Party Disclosures
We maintain strict controls over data sharing and only disclose personal information to trusted third parties when necessary for legitimate business purposes or legal compliance. All data sharing arrangements are governed by comprehensive data processing agreements that ensure recipient organisations maintain equivalent levels of data protection.
Payment processors receive financial information necessary for transaction processing, including banking details, payment amounts, and transaction timestamps. These processors are certified under international security standards and maintain strict confidentiality obligations. We conduct regular audits of payment partners to ensure continued compliance with data protection requirements.
Regulatory authorities, including the UK Gambling Commission, HMRC, and law enforcement agencies, may receive personal data when required by law or for compliance purposes. Such disclosures are made only when legally mandated and are limited to the minimum information necessary to satisfy regulatory requirements.
Technology service providers supporting our platform infrastructure receive technical data necessary for system maintenance, security monitoring, and performance optimisation. These providers operate under strict confidentiality agreements and are prohibited from using personal data for their own purposes.
We do not sell, rent, or otherwise commercialise personal data to unrelated third parties. Any data sharing for marketing purposes requires explicit user consent and provides clear opt-out mechanisms. Cross-border data transfers are conducted only with adequate safeguards, including standard contractual clauses or adequacy decisions.
5. Data Security and Protection Measures
We implement comprehensive technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. Our security framework follows industry best practices and is regularly updated to address evolving cyber threats and technological developments.
- Advanced encryption protocols for data transmission and storage, including SSL/TLS encryption for web communications and AES-256 encryption for sensitive database information
- Multi-factor authentication systems for user accounts and administrative access, reducing the risk of unauthorised account access and identity theft
- Regular security assessments and penetration testing conducted by independent cybersecurity specialists to identify and address potential vulnerabilities
- Employee training programmes on data protection principles, security awareness, and incident response procedures to maintain human-centered security practices
- Access control systems limiting data access to authorised personnel based on role-specific requirements and business necessity principles
- Automated monitoring systems detecting suspicious activities, unauthorised access attempts, and potential security breaches with real-time alerting capabilities
- Regular data backups with secure storage and tested recovery procedures ensuring business continuity and data integrity
- Incident response protocols providing structured approaches to security breaches, including containment, investigation, and notification procedures
We maintain cyber security insurance coverage and participate in information sharing initiatives with other operators and security organisations to stay informed about emerging threats and protective measures.
6. User Rights and Data Subject Requests
Under UK GDPR, users possess comprehensive rights regarding their personal data. We are committed to facilitating the exercise of these rights through transparent processes and timely responses. Our data subject request handling procedures are designed to be user-friendly while maintaining appropriate verification measures.
You have the right to access your personal data, including receiving copies of information we hold about you, understanding how it is processed, and identifying third parties with whom it has been shared. Access requests are fulfilled within one month, with possible extensions for complex requests.
The right to rectification allows you to request correction of inaccurate or incomplete personal data. We maintain processes for verifying requested changes and updating information across all relevant systems. Account holders can directly modify certain information through their user profiles.
The right to erasure, or “right to be forgotten,” enables data deletion in specific circumstances, including withdrawal of consent, objection to processing, or when data is no longer necessary for original purposes. However, erasure may be limited by regulatory retention requirements or legitimate business interests.
Data portability rights allow you to receive personal data in structured, machine-readable formats and request direct transfer to other service providers where technically feasible. This right applies primarily to data processed based on consent or contractual performance.
You may object to data processing based on legitimate interests, including direct marketing activities. We respect objections unless we can demonstrate compelling legitimate grounds that override individual interests, rights, and freedoms.
7. Policy Updates and Contact Information
This Privacy Policy is reviewed regularly and updated to reflect changes in our data processing practices, regulatory requirements, or technological developments. We notify users of material changes through email communications, website announcements, or account notifications, depending on the significance of modifications.
Updated versions include clear revision dates and summaries of key changes to help users understand how modifications may affect their privacy rights or our data handling practices. We maintain archived versions of previous privacy policies for reference and compliance purposes.
For privacy-related inquiries, complaints, or data subject requests, contact our Data Protection Officer through dedicated communication channels. We aim to respond to all privacy inquiries within 72 hours and complete data subject requests within statutory timeframes.
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge complaints with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection matters. The ICO provides guidance on privacy rights and investigates potential violations of data protection law.
We encourage users to regularly review this Privacy Policy and contact us with questions about our data handling practices. Your privacy is fundamental to our service, and we are committed to maintaining transparency, accountability, and continuous improvement in our data protection efforts.