Personal data is the entry fee of any licensed casino — identity checks and payment processing cannot run without it. This policy explains what data the platform gathers, what is done with it, and the control GDPR gives you.
Collection follows the account lifecycle:
Nothing outside these categories is gathered as a matter of course.
GDPR requires a lawful basis for every processing purpose, and four apply here.
Performing the contract with you covers account operation, game delivery, bonus crediting and payment processing. Legal obligations — flowing largely from the Gaming Commission of Ireland licence (OGL/2024/589/0556) — mandate age verification, KYC and anti-money-laundering record-keeping. Legitimate interests support fraud detection and platform security, always weighed against player rights. Consent, freely given and freely withdrawn, governs marketing messages alone — refusing it never restricts your account.
Cookies keep you logged in, hold preferences and show how the site is used. The essential ones are non-negotiable — without them sessions break and the cashier cannot function. Analytics cookies are controllable through browser settings, and blocking them leaves play unaffected.
Data leaves the platform in three directions only.
Payment providers receive the transaction details needed to move money in your chosen method — a card processor sees what a card processor must. KYC verification services receive identity documents to confirm age and identity as licensing law demands. Regulators receive data where statute compels disclosure.
Each recipient gets the minimum its function requires and carries its own confidentiality obligations. Selling player data is not part of the model, full stop.
Retention tracks legal duty rather than convenience. While an account is open, its data stays live. After closure, licensing, tax and anti-money-laundering rules dictate mandatory holding periods, and data survives only that long. Past those deadlines, records are erased or anonymised beyond recovery.
The regulation grants you enforceable rights over the file the casino holds:
Responses arrive within the GDPR standard of one month. If the outcome dissatisfies you, complaint to a data protection supervisory authority remains open.
Transport security first: SSL encryption wraps every exchange between your device and the servers, covering passwords, documents and payment traffic alike. Internally, access to personal data is confined to staff whose role requires it, and KYC documents sit apart from routine account records on secured systems.
Your side of the bargain is a strong, unique password. No server-side measure protects an account whose credentials leak from another website.
Send data requests — access, correction, deletion, portability, objection — to [email protected] from your registered email address, so the request can be verified against the account. The 24/7 live chat can explain the procedure and confirm receipt. Straightforward requests conclude well inside the one-month window.