This Policy explains how Casinofy handles personal data on the public website, during sales and onboarding, and when supporting authorised operator users. Separate data-processing terms govern player and operational data processed for an operator.
For operator player data, the operator is generally the controller and Casinofy acts as a processor under the signed DPA. For website, sales, security, and account-administration data, Casinofy may act as a controller.
1. Who this policy covers
This Policy covers business contacts, prospective customers, operator administrators, authorised platform users, suppliers, and people who communicate with Casinofy. It does not replace an operator’s player-facing privacy notice.
2. Data we collect
We collect information needed to operate a secure B2B relationship and respond to enquiries.
- Identity and business-contact data, such as name, role, company, email, telephone, and preferred language.
- Corporate and onboarding data, including ownership, licensing, jurisdiction, billing, and verification records.
- Account and security data, including user IDs, roles, authentication events, IP address, device and browser information.
- Commercial and support records, such as enquiries, Order Forms, product choices, tickets, calls, and correspondence.
- Technical usage and diagnostic data, including logs, timestamps, route activity, errors, and performance telemetry.
3. Sources and purposes
Data may come directly from you, your company, platform activity, integrations you enable, public corporate or regulatory sources, and service providers used for verification and security.
We use it to respond to enquiries, assess eligibility, provision and administer accounts, secure the service, provide support, meet legal duties, prevent fraud, bill and reconcile services, and improve reliability and product experience.
4. Legal bases
Depending on the context and applicable law, processing may be necessary to take steps before or perform a contract, comply with legal obligations, protect vital security interests, or pursue legitimate interests such as B2B communication, service administration, fraud prevention, and product improvement. Where required, optional marketing and non-essential analytics rely on consent.
5. Sharing and subprocessors
We share personal data only where needed for the purposes described above, including with hosting, security, communication, professional-adviser, verification, payment, support, and infrastructure providers; corporate affiliates; regulators and authorities where legally required; and parties to a legitimate corporate transaction.
Player data subprocessors and product integrations are governed by the operator agreement and DPA. We do not sell business-contact personal data.
6. International transfers and retention
Services may involve processing across jurisdictions. Where required, Casinofy uses contractual and organisational safeguards appropriate to the transfer and the parties’ roles.
We retain data only for as long as reasonably needed for the relevant relationship, security, support, accounting, dispute, and legal purposes. Retention periods vary by record type and applicable obligations; data is deleted, anonymised, or access-restricted when no longer required.
7. Security
Casinofy applies technical and organisational measures designed for the risk, including access controls, authentication, encryption in transit where applicable, environment separation, logging, monitoring, backup controls, vulnerability management, and incident procedures.
No internet service can promise absolute security. Operators are responsible for securing their users, endpoints, credentials, integrations, and authorised access.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, withdraw consent, and complain to a supervisory authority. Rights may be limited by legal, security, contractual, or evidentiary requirements.
Send a request to [email protected] with enough information to identify the relevant relationship. We may verify identity and authority before acting. Operator players should normally contact their operator first.
9. Children, updates, and contact
Casinofy’s website and operator platform are business services and are not directed to children. Operators remain responsible for player age controls.
We may update this Policy to reflect changes in law, processing, or services. The effective date above identifies the current website version. Privacy questions can be sent to [email protected].