Freshbet casino

Privacy Policy

This Privacy Policy governs the collection, processing, storage, and protection of personal data by our online gaming platform operating under UK jurisdiction. We are committed to maintaining the highest standards of data protection in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy outlines our practices regarding personal information collected from users accessing our gaming services, including slot machines, table games, and other gambling activities. By using our platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. We reserve the right to modify this policy at any time, with changes becoming effective immediately upon posting. Your continued use of our services following any modifications constitutes acceptance of the revised policy.

Data Controller Information

We operate as the data controller for all personal information collected through our gaming platform. Our company is registered and licensed to conduct gambling operations within the United Kingdom under the supervision of the UK Gambling Commission. As your data controller, we are responsible for determining the purposes and means of processing your personal data in accordance with applicable UK data protection laws. We maintain comprehensive records of all data processing activities and ensure that appropriate technical and organisational measures are implemented to protect your information.

Our designated Data Protection Officer oversees all aspects of data protection compliance and serves as your primary contact for privacy-related inquiries. We are committed to transparency in our data processing practices and will respond to all legitimate requests regarding your personal information within the timeframes specified by UK data protection legislation. Should you have any concerns about how we handle your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).

Categories of Personal Data Collected

We collect various types of personal data necessary to provide our gaming services and comply with regulatory requirements. The collection of this information is essential for account creation, identity verification, responsible gambling measures, and legal compliance. Below is a comprehensive overview of the data categories we process:

Data CategoryExamplesPurpose
Personal IdentifiersFull name, date of birth, address, phone number, email addressAccount creation, identity verification, communication
Financial InformationPayment method details, transaction history, deposit and withdrawal recordsProcessing payments, fraud prevention, financial reporting
Technical DataIP address, device information, browser type, operating systemSecurity monitoring, service optimisation, fraud detection
Gaming ActivityGame preferences, betting patterns, session duration, gameplay statisticsResponsible gambling monitoring, service personalisation
Verification DocumentsPassport, driving licence, utility bills, bank statementsIdentity verification, age verification, compliance obligations

Legal Basis for Data Processing

Our processing of your personal data is based on several legal grounds as defined by UK GDPR. The primary legal basis varies depending on the type of data and the purpose of processing. We ensure that all data processing activities have a valid legal foundation before collection and throughout the retention period.

  1. Contractual necessity: Processing required to perform our contract with you, including account management, payment processing, and service delivery.
  2. Legal obligation: Processing necessary to comply with UK gambling regulations, anti-money laundering laws, and tax obligations.
  3. Legitimate interests: Processing for fraud prevention, security monitoring, marketing communications, and business operations, balanced against your privacy rights.
  4. Consent: Processing based on your explicit consent for specific activities such as promotional communications and enhanced personalisation features.
  5. Vital interests: Processing necessary to protect your fundamental interests or those of another person in emergency situations.

We regularly review our legal bases to ensure continued compliance with data protection requirements and will inform you of any changes that may affect your rights or our processing activities.

Data Processing Purposes

Your personal data is processed for specific, explicit, and legitimate purposes related to our gaming operations and regulatory compliance. We do not process your information for purposes incompatible with those for which it was originally collected, unless we have obtained your consent or are required by law to do so.

Account management represents our primary processing purpose, encompassing user registration, profile maintenance, authentication, and access control. We utilise your personal information to create and maintain your gaming account, verify your identity, and ensure secure access to our platform. Payment processing involves handling deposits, withdrawals, and transaction records to facilitate your gaming activities and maintain accurate financial records.

Regulatory compliance necessitates extensive data processing to meet UK gambling licensing requirements, including age verification, responsible gambling monitoring, and reporting obligations. We analyse gaming patterns and financial transactions to identify potential problem gambling behaviours and implement appropriate protective measures. Security and fraud prevention activities involve monitoring account activity, detecting suspicious transactions, and protecting both individual users and our platform from fraudulent activities.

Data Sharing and Third-Party Disclosure

We maintain strict controls over data sharing and only disclose personal information to third parties when necessary for service provision, legal compliance, or with your explicit consent. All third-party processors are carefully selected and bound by comprehensive data processing agreements that ensure appropriate protection of your information.

  1. Payment processors: Financial institutions and payment service providers processing deposits, withdrawals, and transaction verification.
  2. Identity verification services: Specialised providers conducting age verification, identity checks, and document authentication.
  3. Regulatory authorities: UK Gambling Commission, HM Revenue & Customs, and other government agencies as required by law.
  4. Technology service providers: Cloud hosting providers, software developers, and technical support services operating under strict confidentiality agreements.
  5. Legal and professional advisors: Solicitors, accountants, and consultants providing professional services subject to professional confidentiality obligations.

We do not sell, rent, or otherwise commercially exploit your personal data. Any data sharing arrangements are governed by comprehensive agreements that specify the purposes, duration, and security measures applicable to the shared information.

Data Security Measures

We implement comprehensive technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. Our security framework is regularly reviewed and updated to address emerging threats and maintain compliance with industry best practices and regulatory requirements.

Technical security measures include advanced encryption protocols for data transmission and storage, secure server infrastructure with regular security updates, multi-factor authentication systems, and continuous monitoring for suspicious activities. Our platform utilises industry-standard SSL/TLS encryption to protect all data communications between your device and our servers. Database security is maintained through access controls, encryption at rest, and regular security audits conducted by independent cybersecurity professionals.

  1. Access controls limiting data access to authorised personnel based on job requirements and security clearance levels.
  2. Regular security training for all staff handling personal data, including awareness of phishing attacks and social engineering tactics.
  3. Incident response procedures for immediate containment and investigation of potential data breaches or security incidents.
  4. Regular backup procedures ensuring data availability and recovery capabilities in case of system failures or cyberattacks.
  5. Vendor security assessments ensuring all third-party processors maintain appropriate security standards.

International Data Transfers

While we primarily process data within the United Kingdom, certain processing activities may involve transfers to countries outside the UK or European Economic Area. All international data transfers are conducted in accordance with UK data protection law and include appropriate safeguards to ensure your information receives adequate protection.

When transferring data internationally, we implement appropriate transfer mechanisms such as adequacy decisions, standard contractual clauses, or certification schemes recognised by UK data protection authorities. We conduct regular assessments of the security and legal frameworks in destination countries to ensure continued protection of your personal information. You have the right to obtain information about international transfers affecting your data and request copies of the safeguards in place.

Data Retention and Deletion

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, and protect our legitimate business interests. Our retention periods are determined based on regulatory requirements, contractual obligations, and operational necessities. We maintain detailed retention schedules specifying the duration for different data categories and regularly review these periods to ensure they remain appropriate and proportionate.

Active account data is retained throughout your relationship with us and for a period following account closure to meet regulatory obligations and resolve any outstanding issues. Financial transaction records are preserved for seven years in accordance with UK financial regulations and anti-money laundering requirements. Marketing communications and preferences are retained until you withdraw consent or request deletion, whichever occurs first.

Upon expiration of applicable retention periods, personal data is securely deleted or anonymised using industry-standard methods that prevent recovery or reconstruction of the original information. We maintain logs of deletion activities for audit purposes and can provide confirmation of data deletion upon request.

Your Privacy Rights

Under UK data protection law, you possess comprehensive rights regarding your personal data. We are committed to facilitating the exercise of these rights and will respond to all legitimate requests within one month of receipt, or sooner when possible. These rights enable you to maintain control over your personal information and ensure transparency in our processing activities.

  1. Right of access: Request confirmation of whether we process your data and obtain copies of your personal information along with details about our processing activities.
  2. Right to rectification: Request correction of inaccurate or incomplete personal data and ensure your information remains current and accurate.
  3. Right to erasure: Request deletion of your personal data when it is no longer necessary for the original purpose or when you withdraw consent.
  4. Right to restrict processing: Limit how we use your data in certain circumstances, such as when you contest its accuracy or legality.
  5. Right to data portability: Receive your data in a structured, machine-readable format and transmit it to another service provider where technically feasible.
  6. Right to object: Oppose processing based on legitimate interests, including direct marketing activities and automated decision-making.
  7. Rights regarding automated decision-making: Obtain information about automated processing and request human intervention in decisions significantly affecting you.

To exercise these rights, contact our Data Protection Officer using the details provided in this policy. We may request additional information to verify your identity and ensure we respond to legitimate requests from data subjects. If you are dissatisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office.