A licensed casino processes personal data because law and contract require it. This policy documents precisely which data the platform processes for players in Australia, under which legal bases, with which recipients, and subject to which player rights.
Five categories cover the complete inventory:
Collection is purpose-bound; data outside these categories is not routinely gathered.
Contract covers account operation, game provision, bonus administration and payment execution — the service you registered for.
Legal obligation covers age checks, KYC, anti-money-laundering monitoring and statutory record-keeping mandated under the Curaçao eGaming licence; neither party can opt out of these.
Legitimate interest covers fraud prevention and platform security, subject to the balancing test against player rights.
Consent covers marketing alone — grantable, refusable and withdrawable at any time with no effect on account standing.
Cookies divide into two classes. Essential cookies maintain login sessions and cashier operation; the site does not function without them. Analytical cookies measure site usage and can be restricted through browser controls without affecting play. No cookie class collects more than its function requires.
Three recipient categories exist, each receiving a defined minimum:
All recipients operate under confidentiality obligations. The platform does not sell personal data — a categorical statement, not a qualified one.
Retention is rule-driven. Active accounts retain live data for service delivery. Post-closure, licensing, tax and anti-money-laundering statutes prescribe minimum holding periods, which the operator observes and does not exceed. On expiry, data is deleted or anonymised irreversibly. No indefinite retention occurs.
Six enforceable rights apply to the data held:
Requests are processed within one month. Escalation to the relevant supervisory authority is available where a response is unsatisfactory.
In transit, SSL encryption covers all traffic between player devices and platform servers — credentials, documents and payment data included. At rest, access controls restrict personal data to role-authorised staff, and KYC documentation is segregated from operational account records.
The residual risk the operator cannot control is credential hygiene. A unique, strong password for the casino account closes the most common attack path.
Direct rights requests to [email protected] from the registered account email, enabling secure matching of request to account. Live chat, available 24/7, can clarify procedure and confirm submission. Requests are processed within the GDPR one-month standard.