Privacy Policy
Your data is processed lawfully, fairly and transparently.
Who we are
The controller of the personal data we process about you is Casinox N.V., a company incorporated in Curaçao, licensed by the Curaçao Gaming Control Board and the Anjouan Offshore Finance Authority, with registered office at the address published on /legal/contact. We are the data controller under the GDPR (where the GDPR applies to our processing), under the UK Data Protection Act, under the California Consumer Privacy Act, under Brazil's LGPD and under the data-protection statutes of Curaçao and Anjouan.
We have written this Privacy Policy to be readable by humans, not just by lawyers. We answer four questions in detail: (1) what data do we collect, (2) why do we collect it, (3) who do we share it with, and (4) what rights do you have. If anything is unclear, contact [email protected] and our Data Protection Officer will respond within five (5) business days.
If you are in the European Union, the European Economic Area or the United Kingdom, you have a statutory right to contact our Data Protection Officer directly. Reach the DPO at [email protected]. The DPO is independent of our commercial operation, reports directly to our board, has the authority to block any processing activity that they consider unlawful, and is required by law to respond to your requests within thirty (30) days. The DPO will never ask you for your password, your 2FA code, your private keys or any other authentication credential. Any message that does so is a phishing attempt and should be reported to [email protected].
What we collect
We collect only the personal data we genuinely need to operate the Service safely, lawfully, and in compliance with our gambling licence and our anti-money-laundering obligations. We do not collect data "just in case" we may want it later. The categories of personal data we process are:
- Identification and contact data: full legal name, date of birth, nationality, residential address, country of habitual residence, email address, mobile phone number, government-issued identification numbers (passport, national identity card, driving licence) and copies/scans of identification documents (front, back and a selfie liveness check).
- Verification and KYC data: when KYC is triggered we additionally collect proof of address (utility bill, bank statement or tax notice issued within the last three months), and — for KYC Tier 3 — proof of source of funds (pay slip, business invoice, exchange statement, notarised gift letter). KYC files are encrypted at rest using AES-256 and are accessible only to a strictly-limited group of compliance reviewers.
- Transactional and financial data: deposit addresses and amounts, blockchain transaction hashes, on-chain risk metadata returned by our blockchain-analytics providers (e.g. counterparty cluster tags, source-of-funds risk scores), every wager and its result, every bonus claim and its progress, every withdrawal request and its on-chain confirmation hash.
- Device, network and security data: IP address, geolocation derived from the IP address, browser user agent, browser fingerprint (hashed only, never raw), time-zone, language headers, the device-binding cookies (igx_session, igx_csrf, igx_af), session metadata (login time, logout time, idle time, active page, in-flight bets), and anti-fraud telemetry such as web-application-firewall events and content-security-policy violation reports.
- Communication and support data: emails you send us, support tickets and their full conversation history, live-chat transcripts with our support staff, in-product chat messages you post on public rains/tips, any documents you upload to support a complaint or an appeal, and voice recordings of voice-call escalations (when applicable and only with prior in-product notification).
Why we collect it
We process your personal data only on the following clearly-identified legal bases, and only for the purposes corresponding to each basis: (a) the performance of the contract that exists between you and us when you use the Service — to accept and settle bets, accept and process deposits and withdrawals, manage your balance and support your account; (b) compliance with legal obligations — to satisfy KYC, AML, counter-terrorism financing, sanctions screening, tax reporting and responsible-gambling duties imposed on us by the Curaçao Gaming Control Board, the Anjouan Offshore Finance Authority and the law of every other jurisdiction whose law applies to us; (c) legitimate interests — to detect, investigate and prevent fraud, bonus abuse, money laundering, account takeover, multi-accounting, chat abuse and similar harms, to secure our infrastructure, to perform aggregated commercial analytics and to defend ourselves in litigation; and (d) consent — for any processing that is genuinely optional, including marketing communications, optional analytics cookies and optional functional cookies. Consent is always granular and is withdrawable at any time without affecting the lawfulness of processing carried out before the withdrawal.
We do not, and we will never, sell your personal data to any third party — not to advertising networks, not to data brokers, not to lead generators, not to credit bureaux. We do not run third-party advertising surveillance technology (no Facebook Pixel, no Google Ads conversion, no TikTok Pixel, no equivalent). We do not run cross-context behavioural advertising. We do not enrich your profile with third-party data unless you have explicitly authorised the enrichment for KYC. These are deliberate, foundational design choices and they are not negotiable.
Legal basis
The legal basis depends on the purpose: contract performance for account data, legal obligation for AML/KYC, legitimate interest for fraud prevention, consent for marketing.
You can withdraw consent for marketing at any time from your profile.
Who we share with
KYC and identity-verification providers (currently Veriff and SumSub) for the purpose of verifying your identity, age and the authenticity of your identification documents.
Blockchain-analytics providers (currently TRM Labs and Chainalysis) for the purpose of screening incoming deposits and outgoing withdrawals against sanctions, dark-market exposure, ransomware exposure and other AML risk indicators.
Game studios and live-casino studios that supply slot games and live-table content (e.g. Pragmatic Play, Hacksaw Gaming, Nolimit City, Push Gaming, BGaming, Spinomenal, Endorphina, Evolution Gaming, Pragmatic Play Live and others). These studios receive the minimum data required to deliver the game session (session identifier, currency, stake limits) and do not receive identifying personal data.
Retention
We retain transactional and KYC data for at least 5 years after account closure, as required by AML law. Marketing preferences are retained until you withdraw consent.
After the legal retention period, data is permanently deleted from backups within 90 days.
Your rights
Subject to the limits imposed by our regulatory obligations, you have the following rights over your personal data. You can exercise any of them by emailing [email protected] from the email address on your account. We will respond within thirty (30) days. If we refuse a request — for example because we are required by law to retain the data — we will tell you why in writing.
- Right of access — request a complete, machine-readable copy of every piece of personal data we hold about you, in a structured, commonly-used format (we provide JSON by default and CSV on request). Free of charge for the first request in any twelve-month period; reasonable administrative fee may apply to repeated requests.
- Right to rectification — request correction of any inaccurate or incomplete personal data we hold about you. We action rectifications within seven (7) business days of receiving sufficient evidence of the inaccuracy.
- Right to erasure — request irretrievable deletion of personal data we no longer need, subject only to overriding legal obligations (in particular, KYC and AML records that we are required to retain for five (5) years after account closure). We confirm deletion in writing within thirty (30) days.
- Right to data portability — receive the personal data you have provided to us in a structured, commonly-used and machine-readable format that you can transmit to another data controller.
- Right to object and right to restriction — object to any processing carried out on the basis of our legitimate interests, and request that we restrict processing while a dispute is being resolved. To exercise any of these rights, email [email protected] from the registered email on your account. We respond within thirty (30) days. If we refuse a request — for example because we are required by law to retain the data — we will tell you why in writing and we will tell you about your right to lodge a complaint with your local data-protection authority.
Security
We protect your personal data with a layered set of technical and organisational measures. Transport-layer encryption (TLS 1.3 with HSTS preload, modern cipher suites only). At-rest encryption of sensitive fields (AES-256-GCM, with keys held in a hardware security module). Argon2id hashing of every password with conservative parameters. End-to-end signed and verified two-factor authentication for every withdrawal. Network segmentation between the public application, the internal services and the database tier. A continuously-updated web-application firewall and DDoS protection (Cloudflare). Continuous anomaly detection on every authentication, payment and bet stream with sub-second alerting.
We complement those technical controls with organisational controls: a documented information-security management system aligned with ISO 27001 control families and NIST CSF; mandatory security training for every employee on day one and annually thereafter; a dual-control / four-eyes principle for every privileged action that touches user funds; an annual external penetration test by an independent CREST-certified vendor; and a continuously-running public bug bounty programme accessible at [email protected]. Where we discover a personal-data breach, we notify the relevant data-protection authority within seventy-two (72) hours and, if the breach is likely to result in a high risk to your rights, we notify you directly.
Children
We do not knowingly collect data from anyone under 18. If you become aware that a minor has registered, please contact us so we can delete the account.
International transfers
Casinox operates internationally. Where the recipient of personal data is located outside the European Economic Area, the United Kingdom, Switzerland, or any other jurisdiction that is the subject of an adequacy decision, we transfer the data under the Standard Contractual Clauses adopted by the European Commission, supplemented by technical and organisational measures that satisfy the Schrems II ruling (in particular, end-to-end TLS, application-level encryption for sensitive fields, and on-paper challenge of any government access request).
A current list of our sub-processors, the jurisdiction in which each is located, the categories of personal data processed by each, and the safeguards applicable to each transfer is published on /legal/privacy/subprocessors and is updated within thirty (30) days of any change. By using the Service you authorise these transfers under the safeguards listed.