Who Controls the Data
The notice names the operator of the site as the data controller, the party that decides how and why personal data is processed, and adds that it acts together with a joint controller. The name of the operating company is not given in the notice. A Data Protection Officer has been appointed and can be reached at [email protected], which is the proper address for any question about data handling. The notice extends to Casinia and its direct and indirect subsidiaries. A reader who wishes to know more about the controller may put the question to the officer directly.
Data at Each Stage
The table arranges the categories named in the notice by the moment at which they arise. It is a reading aid, not a separate classification used by the operator.
| Stage | Data involved | Stated reason |
| Visiting the site | IP address, device identifiers, operating system, pages viewed, session times, general location | Operation, security and improvement of the service |
| Registration | Email, full name, date of birth, country, phone number, gender, postal code, username | Opening and maintaining the account |
| Verification | Identity document number, proof of address, source of funds, financial statements | Age and identity checks, anti-money-laundering duties |
| Payments | IBAN and payment system details | Carrying out deposits and withdrawals |
| Ongoing use | Game activity, inferred interests and preferences | Recommendations, risk management, responsible gaming |
In addition, the operator may obtain data from outside sources: public and government databases, financial and credit institutions, fraud-prevention agencies and information a person has made public on social media. These are used chiefly to confirm identity and to investigate suspicious activity. It is prudent to consider the whole sequence, not only the registration form, before deciding to proceed.
Legal Grounds for Processing
The notice states that data is processed in accordance with the GDPR and other applicable data protection laws, and that more than one ground may apply to the same activity. Four grounds are named:
- contract – creating and supporting the account and meeting obligations under the Terms and Conditions;
- legal obligation – verifying age and identity, determining location from IP data, preventing money laundering and fraud, and managing risks linked to problem gambling;
- legitimate interest – system security, analytics, customer segmentation, detection of cheating, and the use of machine-learning algorithms to recommend games;
- consent – direct marketing by email, SMS, telephone or notifications, personalised offers and targeted advertising.
The distinction has practical weight. Processing based on consent can be stopped by withdrawing it; processing required by law cannot be declined while the account exists. A reader may find it useful to note which activities fall into the last group of the list.
Sharing and International Transfers
Data is shared with defined categories of recipients. Inside the group, these are authorised employees, related brands of the same operator, affiliates and subsidiaries. Outside it, the notice lists payment providers and financial institutions, suppliers of customer support, messaging, technology and cloud hosting, marketing partners, fraud-prevention agencies, game providers, analytics companies, and law enforcement, regulatory and licensing bodies. Payment providers may receive identity details and verification documents so that they can meet their own obligations. Data may also pass to a new owner in the event of a merger or sale, and the notice provides that it would then be used only on the same terms unless the customer agrees otherwise.
Two further provisions deserve attention. Where a customer brings a complaint to an outside platform, such as a review site or a dispute body, the operator may disclose what is strictly necessary to identify the account and reply. And processing may take place outside the EU and EEA, in which case the notice refers to countries recognised as providing adequate protection, Standard Contractual Clauses or other recognised safeguards. Questions about a particular recipient may be addressed to the Data Protection Officer.
Storage Periods and Protection
No fixed number of years is stated. Data is retained while the account is maintained, and beyond that where legal obligations such as anti-money-laundering rules demand it; once the account is closed and no legal or business need remains, it is deleted or anonymised. Protection is described as a set of administrative, technical and physical measures against unauthorised access, loss, theft and misuse. The notice does not claim more than it can deliver: it acknowledges that no system and no transmission over the internet can be made completely secure. It is advisable, therefore, to treat one’s own password and mailbox with equal care.
Exercising Your Rights
The notice lists eight rights: access, rectification, erasure, restriction of processing, data portability, objection, withdrawal of consent and the lodging of a complaint with a supervisory authority, the last being described with reference to EU member states. Erasure applies where no compelling legal or business reason for further processing exists. A request can be made in this order:
- Name the right concerned and the data it relates to;
- Send the request to [email protected] or to [email protected];
- Give enough detail for the account to be identified, without including the password;
- Retain the correspondence until the matter is closed.
The notice does not specify how quickly a request is answered. Anyone uncertain which right applies may simply describe the situation to the officer and ask.
Cookies, Marketing and Updates
Cookies, tags, pixels and web beacons are used on the site. Those strictly necessary for its operation work without consent; all others are subject to a consent request on the first visit and can be managed afterwards through the Cookie Settings, with the particulars set out in a separate Cookie Notice. Marketing communications depend on consent as well, and withdrawing it does not affect what was done before. The operator may amend the notice as technology or the law changes, and the revised text applies from the effective date shown on the site, so an occasional re-reading is expected of the customer.
A final observation. The notice shows that personal data is also used to identify potentially harmful patterns of play and to support responsible gaming, which is a reminder that gambling carries risk and offers no assured outcome. Each reader must independently confirm that such activity is permitted in their jurisdiction before registering, making a deposit or playing. Those who decide to continue may wish to set their cookie and marketing preferences first and to keep the officer’s address at hand.